HIPAA Business Associate Agreements 2 — Questions and Answers
Question 1: A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data. Under HIPAA, does this vendor require a BAA?
- No, because it cannot decrypt the PHI
- Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity (Correct answer)
- Only if the vendor is based in the United States
- Only if the covered entity has more than 500 patients
Correct answer: Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity
A vendor that maintains PHI on behalf of a covered entity is a business associate regardless of whether it can access or decrypt the data.
Question 2: Which of the following is a required element in every Business Associate Agreement?
- A fixed pricing schedule for services rendered
- A prohibition on the business associate using or disclosing PHI beyond what is permitted by the agreement (Correct answer)
- A requirement to store PHI only in the covered entity's data center
- An annual audit conducted by the covered entity
Correct answer: A prohibition on the business associate using or disclosing PHI beyond what is permitted by the agreement
BAAs must prohibit the business associate from using or disclosing PHI in any manner not permitted or required by the agreement.
Question 3: A business associate discovers a breach of unsecured PHI. Within how many calendar days must it notify the covered entity?
- Within 24 hours
- Within 30 calendar days of discovery
- Without unreasonable delay and no later than 60 calendar days after discovery (Correct answer)
- Within 90 calendar days of the fiscal quarter end
Correct answer: Without unreasonable delay and no later than 60 calendar days after discovery
The HIPAA Breach Notification Rule requires business associates to notify covered entities without unreasonable delay and within 60 calendar days of discovering a breach.
Question 4: What happens to a BAA when the underlying service contract between a covered entity and a business associate expires?
- The BAA automatically converts to a subcontractor agreement
- The BAA remains in force indefinitely until formally terminated
- The BAA obligations typically terminate along with the service contract unless PHI return/destruction obligations remain (Correct answer)
- The business associate must retain PHI for an additional 10 years
Correct answer: The BAA obligations typically terminate along with the service contract unless PHI return/destruction obligations remain
BAA obligations generally end when the contract ends, but the BAA must address return or destruction of PHI at termination.
Question 5: A payroll company processes employee health benefit deductions for a hospital. Is the payroll company a business associate of the hospital?
- Yes, because it handles financial data related to health benefits
- No, because payroll functions are excluded from the definition of business associate
- Yes, if it receives PHI in the course of performing payroll services (Correct answer)
- No, because employees are not patients
Correct answer: Yes, if it receives PHI in the course of performing payroll services
A payroll company becomes a business associate only if it receives PHI (e.g., health plan enrollment data) to perform its services.
Question 6: Under the HIPAA Omnibus Rule, which party is directly liable for HIPAA compliance failures?
- Only covered entities
- Only business associates acting as agents of covered entities
- Both covered entities and business associates are directly liable (Correct answer)
- Subcontractors only when they sign a BAA with the covered entity
Correct answer: Both covered entities and business associates are directly liable
The 2013 Omnibus Rule made business associates directly liable for HIPAA violations, not just contractually liable through the BAA.
Question 7: A covered entity wants to share a de-identified dataset with a vendor. Is a BAA required?
- Yes, all vendor relationships require a BAA regardless of data type
- No, because de-identified data is not PHI and BAA requirements do not apply (Correct answer)
- Yes, but only if the vendor will re-identify the data
- No, unless the dataset contains more than 500 records
Correct answer: No, because de-identified data is not PHI and BAA requirements do not apply
De-identified data is not PHI under HIPAA, so sharing it with a vendor does not trigger the BAA requirement.
A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data.
Under HIPAA, does this vendor require a BAA?