Business Associate Agreements Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Business Associate Agreements flashcards as text
Which of the following workforce members of a business associate is directly subject to HIPAA's workforce conduct requirements?
Answer: All workforce members of the business associate who handle PHI
All workforce members of a business associate who handle PHI must comply with HIPAA safeguards, not just designated officers.
A marketing firm offers to analyze patient data and share aggregated results with third parties for profit. A covered entity wants to hire this firm. What HIPAA concern arises?
Answer: The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes
A BAA must prohibit business associates from using PHI for their own purposes, including commercial gain, beyond what the agreement permits.
A hospital system acquires a smaller clinic. The clinic has an existing BAA with a billing vendor. What should the hospital do regarding this BAA?
Answer: Review and update the BAA to reflect the new covered entity relationship and ensure it meets current HIPAA standards
After an acquisition, the new covered entity should review existing BAAs to confirm they are adequate and properly reflect the new organizational structure.
What does HIPAA require a BAA to say about the business associate's obligation to report security incidents?
Answer: The business associate must report security incidents, including unsuccessful attempts, to the covered entity
BAAs must require business associates to report security incidents, including unsuccessful attempts to breach security, to the covered entity.
A business associate goes out of business and cannot return or destroy PHI it holds. What is the recommended course of action?
Answer: The BAA should address this scenario and typically requires the business associate to notify the covered entity and attempt to transfer PHI securely
BAAs should include provisions for PHI disposition when the business associate ceases operations, ensuring the covered entity is notified and PHI is protected.
Which of the following best describes a 'hybrid entity' in the context of BAAs?
Answer: An organization that operates both covered and non-covered functions and designates its healthcare component for HIPAA purposes
A hybrid entity designates a healthcare component subject to HIPAA; BAAs are only required for that component's business associates, not the entire organization.
A BAA is in place, but the business associate experiences a ransomware attack that encrypts PHI. Under HIPAA, is this presumed to be a breach?
Answer: Yes, ransomware is presumed to be a breach unless the covered entity can demonstrate a low probability of PHI compromise
HHS guidance states that ransomware attacks are presumed breaches because the attacker gained unauthorized access or control over PHI, unless the risk assessment shows low probability of compromise.