hardMultiple Choice
Requiring a BAA from Cloud Providers for HIPAA Compliance
A healthcare organization is planning to migrate patient data to a cloud provider. The risk assessment identifies that the provider's SOC 2 report does not cover HIPAA controls. What is the BEST course of action?
Quick Answer
The correct course of action is to require the cloud provider to sign a Business Associate Agreement (BAA). Under HIPAA, a BAA is a mandatory contract that ensures any business associate handling electronic protected health information (ePHI) agrees to implement appropriate safeguards and is liable for breaches. Without a BAA, the cloud provider has no contractual obligation to protect patient data, even if they have a SOC 2 report that lacks HIPAA-specific controls. On the CompTIA SecurityX CAS-004 exam, this scenario tests your understanding of the legal and regulatory layers of cloud risk management, often appearing as a distractor where candidates mistakenly accept a SOC 2 report as sufficient. A common trap is thinking encryption alone or risk acceptance replaces the need for a BAA—remember, HIPAA mandates a contractual chain of accountability. Memory tip: BAA = “Before All Access,” meaning you secure the agreement before any ePHI touches the cloud.
⚠ Common exam trap
The trap is treating a SOC 2 report as sufficient evidence of HIPAA compliance — candidates must recognize that SOC 2 and HIPAA are different frameworks, and only a BAA creates the legal obligation required by HIPAA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the provider to sign a Business Associate Agreement (BAA)
Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. A SOC 2 report that does not cover HIPAA controls does not satisfy the requirement; the BAA is the contractual mechanism that binds the cloud provider to HIPAA safeguards and breach notification obligations. Therefore, requiring the provider to sign a BAA is the best course of action before migrating PHI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request the provider's most recent SOC 3 report
Why it's wrong here
A SOC 3 report is a public seal summarising trust principles, containing no detailed control descriptions or HIPAA mapping, so it cannot close the identified gap. It is tempting because it is freely available, but a SOC 2 plus HIPAA-mapped controls or a BAA is needed.
- ✗
Accept the risk and proceed with migration
Why it's wrong here
Accepting the risk leaves protected health information handled without verified HIPAA safeguards, breaching the covered entity's compliance obligation regardless of contract terms. It is tempting when migration deadlines loom, but risk acceptance is only valid for low residual risk after controls and a signed BAA exist.
- ✓
Require the provider to sign a Business Associate Agreement (BAA)
Why this is correct
A BAA is legally required under HIPAA before a business associate handles protected health information. Since the SOC 2 report omits HIPAA controls, the BAA contractually binds the provider to safeguard patient data, satisfying the compliance obligation the report cannot evidence.
- ✗
Require the provider to encrypt all data at rest and in transit
Why it's wrong here
Encrypting data at rest and in transit addresses confidentiality only; it does not evidence the administrative, physical and technical HIPAA safeguards a covered entity must verify. It is tempting as a quick technical control, but a Business Associate Agreement plus HIPAA-mapped attestation is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A healthtech startup is developing a mobile app that collects PHI. They plan to use a third-party cloud provider for data storage. What is the most critical compliance requirement before signing the contract?
hard- A.Verify the provider's data center locations comply with data residency laws
- ✓ B.Execute a Business Associate Agreement (BAA) with the provider
- C.Review the provider's SOC 2 Type II report
- D.Ensure all data is encrypted at rest and in transit
Why B: Under HIPAA, a Business Associate Agreement (BAA) is a mandatory contract that ensures the third-party cloud provider (a business associate) will safeguard Protected Health Information (PHI). Without a BAA, the startup would be in direct violation of HIPAA's Privacy and Security Rules, regardless of other security measures. This requirement is non-negotiable before any PHI is shared or stored by the provider.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.