CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A healthcare provider plans to store electronic protected health information (ePHI) with a third-party cloud storage provider. Before migrating any data, which document must be executed between the two parties to satisfy HIPAA requirements?
- ANon-disclosure agreement (NDA)
- BService level agreement (SLA)
- CBusiness associate agreement (BAA)
- DMaster services agreement (MSA)
Show answer & explanationAnswer & explanation
Correct answer: C. Business associate agreement (BAA)
HIPAA requires that any third party handling ePHI on behalf of a covered entity sign a Business Associate Agreement, which legally binds the vendor to specific safeguards and breach notification obligations.
Why the other options are wrong
- A. An NDA protects confidential information generally but is not the HIPAA-mandated document.
- B. An SLA defines performance metrics but does not satisfy HIPAA's legal requirements for handling PHI.
- D. An MSA establishes general contract terms but does not address HIPAA-specific PHI obligations.
Business Associate Agreement (BAA)
A HIPAA-required contract between a covered entity and any third party (business associate) that creates, receives, maintains, or transmits PHI on its behalf.
- Legally mandated under the HIPAA Privacy Rule
- Outlines safeguards and breach notification duties
- Cloud providers storing ePHI must sign a BAA before onboarding
Memory trick: BAA = 'Before Any Access' to PHI, sign the agreement