Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium

A healthcare organization is adopting a hybrid cloud strategy to store patient health information (PHI). Some PHI will reside in a private cloud, while other PHI will be processed by a public cloud analytics service. The organization needs to ensure that the public cloud portion meets HIPAA (Health Insurance Portability and Accountability Act) requirements. Which of the following is the MOST crucial contractual element to include in the agreement with the public cloud service provider (CSP) to address HIPAA compliance?

  1. AA Business Associate Agreement (BAA) specifically outlining PHI responsibilities.
  2. BA detailed Service Level Agreement (SLA) guaranteeing 99.999% uptime.
  3. CA commitment from the CSP to use only open-source software.
  4. DClauses for unlimited data storage and bandwidth.
Show answer & explanation

Correct answer: A. A Business Associate Agreement (BAA) specifically outlining PHI responsibilities.

For HIPAA compliance, a Business Associate Agreement (BAA) is legally required when a covered entity (like a healthcare organization) engages a business associate (like a CSP) that creates, receives, maintains, or transmits PHI. The BAA outlines the responsibilities of both parties regarding the protection of PHI.

Why the other options are wrong

  • B. Uptime is important for availability but does not directly address the specific legal requirements for PHI protection under HIPAA.
  • C. The choice of software licensing (open-source vs. proprietary) is not a direct HIPAA compliance requirement.
  • D. Storage and bandwidth are operational concerns and unrelated to the specific legal requirements for PHI under HIPAA.

Business Associate Agreement (BAA)

A legally required contract under HIPAA that defines the responsibilities of a 'business associate' (e.g., CSP) in protecting Protected Health Information (PHI) when performing services for a 'covered entity' (e.g., healthcare provider).

  • Mandatory for HIPAA compliance.
  • Outlines permitted uses and disclosures of PHI.
  • Specifies security safeguards and breach notification procedures.

Memory trick: For PHI in the cloud, a BAA is the HIPAA crown.

More Legal, Risk and Compliance questions