HIPAA Business Associate Agreements 4 — Questions and Answers
Question 1: Which of the following workforce members of a business associate is directly subject to HIPAA's workforce conduct requirements?
- Only the business associate's Privacy Officer
- All workforce members of the business associate who handle PHI (Correct answer)
- Only those workforce members who sign a personal BAA
- Only contractors, not employees
Correct answer: All workforce members of the business associate who handle PHI
All workforce members of a business associate who handle PHI must comply with HIPAA safeguards, not just designated officers.
Question 2: A marketing firm offers to analyze patient data and share aggregated results with third parties for profit. A covered entity wants to hire this firm. What HIPAA concern arises?
- Marketing firms are exempt from BAA requirements
- The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes (Correct answer)
- The covered entity only needs a data use agreement, not a BAA
- This arrangement is permitted as long as the data is anonymized before sharing
Correct answer: The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes
A BAA must prohibit business associates from using PHI for their own purposes, including commercial gain, beyond what the agreement permits.
Question 3: A hospital system acquires a smaller clinic. The clinic has an existing BAA with a billing vendor. What should the hospital do regarding this BAA?
- Assume the existing BAA transfers automatically with no changes needed
- Review and update the BAA to reflect the new covered entity relationship and ensure it meets current HIPAA standards (Correct answer)
- Terminate all existing BAAs and start fresh after 90 days
- File the existing BAA with HHS for approval
Correct answer: Review and update the BAA to reflect the new covered entity relationship and ensure it meets current HIPAA standards
After an acquisition, the new covered entity should review existing BAAs to confirm they are adequate and properly reflect the new organizational structure.
Question 4: What does HIPAA require a BAA to say about the business associate's obligation to report security incidents?
- Security incidents must only be reported at the end of each fiscal year
- The business associate must report security incidents, including unsuccessful attempts, to the covered entity (Correct answer)
- Only breaches resulting in patient harm must be reported under the BAA
- Security incidents are the business associate's sole responsibility and need not be reported to the covered entity
Correct answer: The business associate must report security incidents, including unsuccessful attempts, to the covered entity
BAAs must require business associates to report security incidents, including unsuccessful attempts to breach security, to the covered entity.
Question 5: A business associate goes out of business and cannot return or destroy PHI it holds. What is the recommended course of action?
- The covered entity assumes full liability and no further action is needed
- The BAA should address this scenario and typically requires the business associate to notify the covered entity and attempt to transfer PHI securely (Correct answer)
- The PHI automatically becomes public domain
- HHS takes custody of the PHI
Correct answer: The BAA should address this scenario and typically requires the business associate to notify the covered entity and attempt to transfer PHI securely
BAAs should include provisions for PHI disposition when the business associate ceases operations, ensuring the covered entity is notified and PHI is protected.
Question 6: Which of the following best describes a 'hybrid entity' in the context of BAAs?
- An organization that is both a covered entity and a business associate simultaneously
- An organization that operates both covered and non-covered functions and designates its healthcare component for HIPAA purposes (Correct answer)
- A foreign entity that does business in the United States under a HIPAA waiver
- A nonprofit hospital that also runs a for-profit pharmacy
Correct answer: An organization that operates both covered and non-covered functions and designates its healthcare component for HIPAA purposes
A hybrid entity designates a healthcare component subject to HIPAA; BAAs are only required for that component's business associates, not the entire organization.
Question 7: A BAA is in place, but the business associate experiences a ransomware attack that encrypts PHI. Under HIPAA, is this presumed to be a breach?
- No, ransomware is a cybersecurity event, not a HIPAA breach
- Yes, ransomware is presumed to be a breach unless the covered entity can demonstrate a low probability of PHI compromise (Correct answer)
- Only if the attackers publicly release the data
- No, if the PHI is recovered within 72 hours
Correct answer: Yes, ransomware is presumed to be a breach unless the covered entity can demonstrate a low probability of PHI compromise
HHS guidance states that ransomware attacks are presumed breaches because the attacker gained unauthorized access or control over PHI, unless the risk assessment shows low probability of compromise.
Which of the following workforce members of a business associate is directly subject to HIPAA's workforce conduct requirements?