Business Associate Agreements Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Business Associate Agreements flashcards as text
A cloud storage vendor hosts encrypted PHI for a covered entity but claims it cannot access the data. Under HIPAA, does this vendor require a BAA?
Answer: Yes, because it still creates, receives, maintains, or transmits PHI on behalf of the covered entity
A vendor that maintains PHI on behalf of a covered entity is a business associate regardless of whether it can access or decrypt the data.
Which of the following is a required element in every Business Associate Agreement?
Answer: A prohibition on the business associate using or disclosing PHI beyond what is permitted by the agreement
BAAs must prohibit the business associate from using or disclosing PHI in any manner not permitted or required by the agreement.
A business associate discovers a breach of unsecured PHI. Within how many calendar days must it notify the covered entity?
Answer: Without unreasonable delay and no later than 60 calendar days after discovery
The HIPAA Breach Notification Rule requires business associates to notify covered entities without unreasonable delay and within 60 calendar days of discovering a breach.
What happens to a BAA when the underlying service contract between a covered entity and a business associate expires?
Answer: The BAA obligations typically terminate along with the service contract unless PHI return/destruction obligations remain
BAA obligations generally end when the contract ends, but the BAA must address return or destruction of PHI at termination.
A payroll company processes employee health benefit deductions for a hospital. Is the payroll company a business associate of the hospital?
Answer: Yes, if it receives PHI in the course of performing payroll services
A payroll company becomes a business associate only if it receives PHI (e.g., health plan enrollment data) to perform its services.
Under the HIPAA Omnibus Rule, which party is directly liable for HIPAA compliance failures?
Answer: Both covered entities and business associates are directly liable
The 2013 Omnibus Rule made business associates directly liable for HIPAA violations, not just contractually liable through the BAA.
A covered entity wants to share a de-identified dataset with a vendor. Is a BAA required?
Answer: No, because de-identified data is not PHI and BAA requirements do not apply
De-identified data is not PHI under HIPAA, so sharing it with a vendor does not trigger the BAA requirement.