ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a pre-audit review for a U.S. telehealth provider planning to move its electronic health record (EHR) application to a public IaaS cloud, the compliance team notes that encryption at rest, role-based access controls, and continuous monitoring are already in place. However, the team says one nontechnical requirement mandated by HIPAA/HITECH for cloud service arrangements is still missing. Which action must the organization complete before it can claim full compliance?
Obtain a PCI DSS Attestation of Compliance (AOC) from a Qualified Security Assessor.
Arrange for an annual ISAE 3402 Type II assurance report covering the cloud provider.
Segregate the cloud network into distinct electronic security perimeters as defined by NERC CIP.
Execute a Business Associate Agreement (BAA) with the cloud service provider.
HIPAA and its companion HITECH Act treat any cloud service provider that stores or processes electronic protected health information (ePHI) on behalf of a covered entity as a business associate. HIPAA requires that the covered entity (or an upstream business associate) execute a Business Associate Agreement (BAA) with every such service provider, contractually binding the provider to safeguard ePHI and report breaches within the statutory time frames. Technical safeguards such as encryption, RBAC, and monitoring are necessary but do not remove the contractual obligation. The other options reference requirements from PCI DSS (Attestation of Compliance), NERC CIP (electronic security perimeter), or an ISAE 3402 assurance report-none of which fulfills HIPAA's explicit BAA mandate.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Business Associate Agreement (BAA)?
Open an interactive chat with Bash
What is the role of encryption at rest in HIPAA compliance?
Open an interactive chat with Bash
How does HIPAA/HITECH define a cloud service provider as a Business Associate?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .