ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization is procuring a SaaS analytics tool that will ingest lab results containing patient identifiers. Before any production data is sent to the vendor, which action is explicitly required under HIPAA when a covered entity discloses protected health information to a third-party service provider?
Execute a written Business Associate Agreement that defines each party's responsibilities for safeguarding PHI.
Ensure the application is hosted only in a data center that has achieved FedRAMP High authorization.
File a data-use notification with the HHS Office for Civil Rights before the transfer occurs.
Require the vendor to store all PHI using AES-256 encryption while at rest in its cloud.
HIPAA's Privacy and Security Rules require a covered entity to obtain "satisfactory assurances" that a business associate will appropriately safeguard PHI. Those assurances must be documented through a Business Associate Agreement (BAA) that spells out each party's responsibilities, permitted uses, breach notification duties, and required safeguards. Encryption, data-center certifications, or filings with regulators may be prudent controls, but none are explicitly mandated by HIPAA as a prerequisite for sharing PHI; without a signed BAA the data transfer would violate 45 CFR §164.308(b) and related provisions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Business Associate Agreement (BAA) under HIPAA?
Open an interactive chat with Bash
Why isn't AES-256 encryption explicitly required under HIPAA?
Open an interactive chat with Bash
What penalties can result from failing to execute a BAA before sharing PHI?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .