CHP Business Associates & Vendor Management Flashcards
6 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CHP Business Associates & Vendor Management flashcards as text
Under HIPAA, a Business Associate Agreement (BAA) is required when a vendor does which of the following?
Answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity
A BAA is required whenever a vendor creates, receives, maintains, or transmits PHI while performing services or functions on behalf of a covered entity.
Which of the following is NOT a required element of a HIPAA Business Associate Agreement?
Answer: The business associate's annual revenue and profit margins
Financial figures such as annual revenue are not required elements of a HIPAA Business Associate Agreement.
When a business associate discovers a breach of unsecured PHI, it must notify the covered entity:
Answer: Without unreasonable delay and no later than 60 days after discovery
Business associates must notify the covered entity of a breach without unreasonable delay and within no more than 60 days after discovery.
Under HIPAA, subcontractors of business associates who handle PHI are treated as:
Answer: Business associates with direct HIPAA obligations
Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves considered business associates with direct HIPAA obligations.
Which federal legislation made business associates directly subject to HIPAA compliance obligations?
Answer: The Health Information Technology for Economic and Clinical Health (HITECH) Act
The HITECH Act of 2009 made business associates directly liable for HIPAA compliance, extending obligations beyond covered entities.
A covered entity discovers that its business associate has violated the terms of their BAA. What is the covered entity's first required step?
Answer: Take reasonable steps to cure the breach or end the violation
Upon discovering a BAA violation, the covered entity must first take reasonable steps to cure the breach or end the violation before escalating.