Courseiva
hardMultiple ChoiceObjective-mapped

Requiring a BAA from Cloud Providers for HIPAA Compliance

A healthcare organization is planning to migrate patient data to a cloud provider. The risk assessment identifies that the provider's SOC 2 report does not cover HIPAA controls. What is the BEST course of action?

Quick Answer

The correct course of action is to require the cloud provider to sign a Business Associate Agreement (BAA). Under HIPAA, a BAA is a mandatory contract that ensures any business associate handling electronic protected health information (ePHI) agrees to implement appropriate safeguards and is liable for breaches. Without a BAA, the cloud provider has no contractual obligation to protect patient data, even if they have a SOC 2 report that lacks HIPAA-specific controls. On the CompTIA SecurityX CAS-004 exam, this scenario tests your understanding of the legal and regulatory layers of cloud risk management, often appearing as a distractor where candidates mistakenly accept a SOC 2 report as sufficient. A common trap is thinking encryption alone or risk acceptance replaces the need for a BAA—remember, HIPAA mandates a contractual chain of accountability. Memory tip: BAA = “Before All Access,” meaning you secure the agreement before any ePHI touches the cloud.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require the provider to sign a Business Associate Agreement (BAA)

Under HIPAA, a healthcare organization must have a Business Associate Agreement (BAA) in place with any cloud provider that handles protected health information (ePHI). The BAA contractually obligates the provider to safeguard ePHI and comply with HIPAA Privacy and Security Rules. The fact that the provider's SOC 2 report does not cover HIPAA controls indicates that the provider has not been audited specifically for HIPAA compliance, but a BAA establishes the required legal protections. Option A is incorrect because a SOC 3 report, like the SOC 2, does not guarantee HIPAA controls. Option B is incorrect because simply accepting the risk without a BAA would violate HIPAA requirements. Option D is incorrect because encryption, while important, does not substitute for the contractual safeguards required by a BAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Request the provider's most recent SOC 3 report

    Why it's wrong here

    SOC 3 is a summary and still may not cover HIPAA

  • Accept the risk and proceed with migration

    Why it's wrong here

    Risk should be mitigated, not automatically accepted

  • Require the provider to sign a Business Associate Agreement (BAA)

    Why this is correct

    Mandatory under HIPAA for covered entities

  • Require the provider to encrypt all data at rest and in transit

    Why it's wrong here

    Encryption is necessary but not sufficient without BAA

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A healthtech startup is developing a mobile app that collects PHI. They plan to use a third-party cloud provider for data storage. What is the most critical compliance requirement before signing the contract?

hard
  • A.Verify the provider's data center locations comply with data residency laws
  • B.Execute a Business Associate Agreement (BAA) with the provider
  • C.Review the provider's SOC 2 Type II report
  • D.Ensure all data is encrypted at rest and in transit

Why B: Under HIPAA, a Business Associate Agreement (BAA) is a mandatory contract that ensures the third-party cloud provider (a business associate) will safeguard Protected Health Information (PHI). Without a BAA, the startup would be in direct violation of HIPAA's Privacy and Security Rules, regardless of other security measures. This requirement is non-negotiable before any PHI is shared or stored by the provider.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.