CHP CHP Business Associates & Vendor Management 1 — Questions and Answers
Question 1: Under HIPAA, a Business Associate Agreement (BAA) is required when a vendor does which of the following?
- Sells medical supplies directly to patients
- Creates, receives, maintains, or transmits PHI on behalf of a covered entity (Correct answer)
- Provides building maintenance services to a hospital
- Delivers food and catering services to a healthcare facility
Correct answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is required whenever a vendor creates, receives, maintains, or transmits PHI while performing services or functions on behalf of a covered entity.
Question 2: Which of the following is NOT a required element of a HIPAA Business Associate Agreement?
- Description of permitted uses and disclosures of PHI
- Obligation to report security incidents to the covered entity
- Agreement to use PHI only as permitted by the BAA
- The business associate's annual revenue and profit margins (Correct answer)
Correct answer: The business associate's annual revenue and profit margins
Financial figures such as annual revenue are not required elements of a HIPAA Business Associate Agreement.
Question 3: When a business associate discovers a breach of unsecured PHI, it must notify the covered entity:
- Within 24 hours of discovery
- Within 72 hours of discovery
- Without unreasonable delay and no later than 60 days after discovery (Correct answer)
- Within 30 calendar days of discovery
Correct answer: Without unreasonable delay and no later than 60 days after discovery
Business associates must notify the covered entity of a breach without unreasonable delay and within no more than 60 days after discovery.
Question 4: Under HIPAA, subcontractors of business associates who handle PHI are treated as:
- Covered entities subject to the Privacy Rule only
- Business associates with direct HIPAA obligations (Correct answer)
- Exempt third parties not covered by HIPAA
- Workforce members of the original covered entity
Correct answer: Business associates with direct HIPAA obligations
Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves considered business associates with direct HIPAA obligations.
Question 5: Which federal legislation made business associates directly subject to HIPAA compliance obligations?
- The Affordable Care Act (ACA)
- The Health Information Technology for Economic and Clinical Health (HITECH) Act (Correct answer)
- The Medicare Modernization Act of 2003
- The Sarbanes-Oxley Act
Correct answer: The Health Information Technology for Economic and Clinical Health (HITECH) Act
The HITECH Act of 2009 made business associates directly liable for HIPAA compliance, extending obligations beyond covered entities.
Question 6: A covered entity discovers that its business associate has violated the terms of their BAA. What is the covered entity's first required step?
- Immediately terminate the BAA without investigation
- Report the violation directly to HHS OCR
- Take reasonable steps to cure the breach or end the violation (Correct answer)
- File a lawsuit against the business associate
Correct answer: Take reasonable steps to cure the breach or end the violation
Upon discovering a BAA violation, the covered entity must first take reasonable steps to cure the breach or end the violation before escalating.
Under HIPAA, a Business Associate Agreement (BAA) is required when a vendor does which of the following?