A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data.Under HIPAA, does this vendor require a BAA?