CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A healthcare provider plans to store electronic protected health information (ePHI) with a third-party cloud storage provider. Before migrating any data, which document must be executed between the two parties to satisfy HIPAA requirements?

  1. ANon-disclosure agreement (NDA)
  2. BService level agreement (SLA)
  3. CBusiness associate agreement (BAA)
  4. DMaster services agreement (MSA)
Show answer & explanation

Correct answer: C. Business associate agreement (BAA)

HIPAA requires that any third party handling ePHI on behalf of a covered entity sign a Business Associate Agreement, which legally binds the vendor to specific safeguards and breach notification obligations.

Why the other options are wrong

  • A. An NDA protects confidential information generally but is not the HIPAA-mandated document.
  • B. An SLA defines performance metrics but does not satisfy HIPAA's legal requirements for handling PHI.
  • D. An MSA establishes general contract terms but does not address HIPAA-specific PHI obligations.

Business Associate Agreement (BAA)

A HIPAA-required contract between a covered entity and any third party (business associate) that creates, receives, maintains, or transmits PHI on its behalf.

  • Legally mandated under the HIPAA Privacy Rule
  • Outlines safeguards and breach notification duties
  • Cloud providers storing ePHI must sign a BAA before onboarding

Memory trick: BAA = 'Before Any Access' to PHI, sign the agreement

More Governance, Risk, Compliance and Security questions