HIPAA Business Associate Agreements 5 — Questions and Answers
Question 1: A telehealth platform vendor processes video visits for a covered entity. The vendor argues it is merely a 'conduit' like the postal service and does not need a BAA. Is this correct?
- Yes, all technology transmission services qualify as conduits exempt from BAA requirements
- No, the conduit exception applies only to entities that transmit PHI without storing it; a telehealth platform that processes and stores PHI is a business associate (Correct answer)
- Yes, if the vendor uses end-to-end encryption
- No, but only a data use agreement is needed instead of a BAA
Correct answer: No, the conduit exception applies only to entities that transmit PHI without storing it; a telehealth platform that processes and stores PHI is a business associate
The conduit exception covers mere transmission with no PHI storage; a telehealth platform that stores or processes visit data is a business associate requiring a BAA.
Question 2: When a BAA is required but never executed, which party bears the greatest regulatory risk if PHI is misused?
- The business associate alone, because it holds the PHI
- The covered entity, because it is responsible for ensuring BAAs are in place before sharing PHI (Correct answer)
- Both parties share equal liability with no distinction
- HHS, for failing to enforce the requirement proactively
Correct answer: The covered entity, because it is responsible for ensuring BAAs are in place before sharing PHI
Covered entities are responsible for obtaining signed BAAs before sharing PHI; failing to do so exposes the covered entity to HIPAA penalties.
Question 3: A business associate agrees to provide data analytics but later expands its services to include direct patient communications without amending the BAA. What HIPAA issue does this create?
- No issue, because the original BAA covers all services the business associate performs
- The business associate's new activities may exceed the permitted uses of PHI under the existing BAA, creating a violation (Correct answer)
- The business associate must notify patients but does not need to amend the BAA
- This is permitted as long as the covered entity gives verbal approval
Correct answer: The business associate's new activities may exceed the permitted uses of PHI under the existing BAA, creating a violation
Using PHI for purposes beyond those specified in the BAA violates HIPAA; the BAA must be amended to authorize new activities involving PHI.
Question 4: A research institution receives de-identified data from a hospital for a study, then re-identifies the data using a secondary dataset it possesses. What HIPAA obligation may the hospital have failed to meet?
- Nothing; once data is de-identified the hospital has no further HIPAA obligations
- The hospital should have executed a BAA and data use agreement to restrict re-identification by the institution (Correct answer)
- The hospital only needed to obtain IRB approval, not a BAA
- The research institution is solely at fault for any violation
Correct answer: The hospital should have executed a BAA and data use agreement to restrict re-identification by the institution
If there is a reasonable basis to believe re-identification could occur, the hospital should use a limited data set with a data use agreement or a full BAA to prohibit re-identification.
Question 5: Under HIPAA, what must a BAA require regarding the business associate's minimum necessary standard when using PHI?
- The business associate may use all PHI it receives as broadly as needed to complete its work
- The business associate must use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose (Correct answer)
- The minimum necessary standard only applies to covered entities, not business associates
- The business associate must reduce PHI use to zero unless it is a healthcare provider
Correct answer: The business associate must use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose
Business associates are bound by the minimum necessary standard and must limit their use and disclosure of PHI to what is needed for the specified purpose.
Question 6: A covered entity operates under an existing BAA with a vendor. The vendor is then acquired by a larger corporation. What must happen to the BAA?
- The BAA automatically binds the acquiring corporation with no further action needed
- The covered entity should review and update or re-execute the BAA to ensure the new entity is bound by its terms (Correct answer)
- The acquisition voids the BAA and PHI sharing must immediately cease
- A new HHS filing is required before PHI can continue to flow to the vendor
Correct answer: The covered entity should review and update or re-execute the BAA to ensure the new entity is bound by its terms
Corporate acquisitions can affect BAA applicability; the covered entity should confirm the new corporate entity is formally bound by a valid BAA.
Question 7: Which of the following best describes the difference between a Business Associate Agreement (BAA) and a Data Use Agreement (DUA) under HIPAA?
- A BAA covers fully identifiable PHI disclosures while a DUA is used for limited data sets that exclude direct identifiers such as names and addresses (Correct answer)
- A DUA is required for all PHI disclosures while a BAA applies only to electronic PHI
- A BAA is optional while a DUA is mandatory for all data sharing
- There is no meaningful distinction; both documents serve the same HIPAA function
Correct answer: A BAA covers fully identifiable PHI disclosures while a DUA is used for limited data sets that exclude direct identifiers such as names and addresses
A BAA governs the use of full PHI by business associates, while a DUA is a lighter agreement used specifically for limited data sets that have had direct identifiers removed.
A telehealth platform vendor processes video visits for a covered entity.
The vendor argues it is merely a 'conduit' like the postal service and does not need a BAA.
Is this correct?