HIPAA Business Associate Agreements 3 — Questions and Answers
Question 1: A business associate engages a subcontractor to perform data analytics involving PHI. What must the business associate do?
- Obtain written approval from HHS before engaging the subcontractor
- Enter into a BAA with the subcontractor that imposes equivalent PHI protections (Correct answer)
- Notify all affected patients before sharing their PHI with the subcontractor
- Ensure the subcontractor is a covered entity
Correct answer: Enter into a BAA with the subcontractor that imposes equivalent PHI protections
Business associates must obtain satisfactory assurances from subcontractors through a BAA that imposes the same PHI safeguards required of the business associate.
Question 2: Which of the following scenarios would NOT require a Business Associate Agreement?
- A billing company submitting insurance claims on behalf of a physician practice
- A janitorial company whose staff may incidentally view PHI on a whiteboard (Correct answer)
- An IT firm that remotely accesses servers storing PHI to provide maintenance
- A transcription service that converts physician voice recordings into clinical notes
Correct answer: A janitorial company whose staff may incidentally view PHI on a whiteboard
Incidental exposure by a janitorial company does not make it a business associate; BAAs apply to those who handle PHI as a function of their service.
Question 3: A BAA must require the business associate to make its internal practices available to which government agency upon request?
- The Federal Trade Commission (FTC)
- The Department of Health and Human Services (HHS) (Correct answer)
- The Social Security Administration (SSA)
- The Centers for Medicare & Medicaid Services (CMS)
Correct answer: The Department of Health and Human Services (HHS)
BAAs must require the business associate to make its books, records, and practices available to HHS for purposes of determining the covered entity's compliance.
Question 4: If a covered entity cannot obtain a BAA from a business associate despite good-faith efforts, what should the covered entity do?
- Continue sharing PHI while documenting the failed attempts
- Cease sharing PHI with that vendor and seek an alternative that will sign a BAA (Correct answer)
- Report the vendor to the state attorney general only
- Apply for a waiver from HHS to proceed without a BAA
Correct answer: Cease sharing PHI with that vendor and seek an alternative that will sign a BAA
If a business associate refuses to enter a BAA, the covered entity must stop sharing PHI with that vendor to remain compliant.
Question 5: What is the primary purpose of the 'termination for cause' provision typically included in a BAA?
- To allow either party to exit the contract without penalty for financial reasons
- To permit the covered entity to terminate the BAA if the business associate materially breaches its PHI obligations (Correct answer)
- To enable the business associate to end the contract if the covered entity changes its EHR system
- To set automatic renewal terms for the BAA
Correct answer: To permit the covered entity to terminate the BAA if the business associate materially breaches its PHI obligations
The termination for cause provision allows the covered entity to end the relationship if the business associate violates the BAA's PHI protection requirements.
Question 6: A hospital's legal counsel argues that emails exchanged with the hospital's outside law firm are exempt from HIPAA if they contain PHI. Is this correct?
- Yes, attorney-client privilege supersedes HIPAA requirements
- No, law firms that receive PHI on behalf of a covered entity are business associates and need a BAA (Correct answer)
- Yes, law firms are expressly excluded from the definition of business associate
- No, but a BAA is only required if the law firm bills the hospital separately for HIPAA work
Correct answer: No, law firms that receive PHI on behalf of a covered entity are business associates and need a BAA
Law firms that receive PHI while providing legal services to a covered entity are business associates and must sign a BAA.
Question 7: Under HIPAA, a covered entity discovers its business associate experienced a security incident that did not result in acquisition or viewing of PHI. What is the covered entity's obligation?
- Issue breach notifications to all potentially affected individuals immediately
- Determine whether the incident constitutes a reportable breach using the four-factor risk assessment (Correct answer)
- No further action is required because no PHI was accessed
- Automatically terminate the BAA
Correct answer: Determine whether the incident constitutes a reportable breach using the four-factor risk assessment
Even when PHI access appears unlikely, the covered entity must conduct the four-factor risk assessment to determine if a reportable breach occurred.
A business associate engages a subcontractor to perform data analytics involving PHI.
What must the business associate do?