โ† All HIPAA Flashcard Decks

Business Associate Agreements Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Business Associate Agreements flashcards as text
  1. A telehealth platform vendor processes video visits for a covered entity. The vendor argues it is merely a 'conduit' like the postal service and does not need a BAA. Is this correct?

    Answer: No, the conduit exception applies only to entities that transmit PHI without storing it; a telehealth platform that processes and stores PHI is a business associate

    The conduit exception covers mere transmission with no PHI storage; a telehealth platform that stores or processes visit data is a business associate requiring a BAA.

  2. When a BAA is required but never executed, which party bears the greatest regulatory risk if PHI is misused?

    Answer: The covered entity, because it is responsible for ensuring BAAs are in place before sharing PHI

    Covered entities are responsible for obtaining signed BAAs before sharing PHI; failing to do so exposes the covered entity to HIPAA penalties.

  3. A business associate agrees to provide data analytics but later expands its services to include direct patient communications without amending the BAA. What HIPAA issue does this create?

    Answer: The business associate's new activities may exceed the permitted uses of PHI under the existing BAA, creating a violation

    Using PHI for purposes beyond those specified in the BAA violates HIPAA; the BAA must be amended to authorize new activities involving PHI.

  4. A research institution receives de-identified data from a hospital for a study, then re-identifies the data using a secondary dataset it possesses. What HIPAA obligation may the hospital have failed to meet?

    Answer: The hospital should have executed a BAA and data use agreement to restrict re-identification by the institution

    If there is a reasonable basis to believe re-identification could occur, the hospital should use a limited data set with a data use agreement or a full BAA to prohibit re-identification.

  5. Under HIPAA, what must a BAA require regarding the business associate's minimum necessary standard when using PHI?

    Answer: The business associate must use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose

    Business associates are bound by the minimum necessary standard and must limit their use and disclosure of PHI to what is needed for the specified purpose.

  6. A covered entity operates under an existing BAA with a vendor. The vendor is then acquired by a larger corporation. What must happen to the BAA?

    Answer: The covered entity should review and update or re-execute the BAA to ensure the new entity is bound by its terms

    Corporate acquisitions can affect BAA applicability; the covered entity should confirm the new corporate entity is formally bound by a valid BAA.

  7. Which of the following best describes the difference between a Business Associate Agreement (BAA) and a Data Use Agreement (DUA) under HIPAA?

    Answer: A BAA covers fully identifiable PHI disclosures while a DUA is used for limited data sets that exclude direct identifiers such as names and addresses

    A BAA governs the use of full PHI by business associates, while a DUA is a lighter agreement used specifically for limited data sets that have had direct identifiers removed.