Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?

⚠ Common exam trap

CCSP often tests the misconception that geographic location or a generic security certification (ISO 27001) satisfies HIPAA — the legally required mechanism is the BAA, not location or certification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cloud provider must sign a Business Associate Agreement (BAA)

Under HIPAA, a cloud provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate, and the covered entity must have a signed Business Associate Agreement (BAA) in place before ePHI is hosted. The BAA contractually obligates the provider to safeguard ePHI and comply with applicable HIPAA Privacy and Security Rule provisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cloud provider must be located within the United States

    Why it's wrong here

    HIPAA imposes no US-location requirement; ePHI may be hosted offshore provided a Business Associate Agreement governs the provider. Data residency is tempting because many regulated sectors demand in-country storage, and it would be the deciding factor where legislation or contract mandates local hosting, but HIPAA itself does not.

  • ✓

    The cloud provider must sign a Business Associate Agreement (BAA)

    Why this is correct

    HIPAA requires a Business Associate Agreement before a cloud provider creates, receives, maintains or transmits ePHI on behalf of the covered entity. The BAA contractually binds the provider to safeguard ePHI and report breaches, satisfying the Privacy and Security Rules.

  • ✗

    The cloud provider must be certified under ISO 27001

    Why it's wrong here

    HIPAA does not mandate ISO 27001 certification; the requirement is a Business Associate Agreement binding the provider to safeguard ePHI. ISO 27001 is tempting because it evidences a mature security programme, and it would satisfy due diligence where an organisation seeks demonstrable controls, but it is not the primary prerequisite for hosting ePHI.

  • ✗

    The covered entity must obtain written authorization from each patient

    Why it's wrong here

    Patient authorisation governs uses and disclosures of PHI for purposes such as marketing or research, not the selection of a hosting provider. A Business Associate Agreement is what HIPAA requires before a cloud provider handles ePHI. Authorisation is tempting because consent features heavily in privacy regulation, yet it addresses disclosure, not vendor safeguarding obligations.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.