CCSP Legal, Risk, and Compliance Practice Question
A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?
⚠ Common exam trap
CCSP often tests the misconception that geographic location or a generic security certification (ISO 27001) satisfies HIPAA — the legally required mechanism is the BAA, not location or certification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The cloud provider must sign a Business Associate Agreement (BAA)
Under HIPAA, a cloud provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate, and the covered entity must have a signed Business Associate Agreement (BAA) in place before ePHI is hosted. The BAA contractually obligates the provider to safeguard ePHI and comply with applicable HIPAA Privacy and Security Rule provisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloud provider must be located within the United States
Why it's wrong here
HIPAA imposes no US-location requirement; ePHI may be hosted offshore provided a Business Associate Agreement governs the provider. Data residency is tempting because many regulated sectors demand in-country storage, and it would be the deciding factor where legislation or contract mandates local hosting, but HIPAA itself does not.
- ✓
The cloud provider must sign a Business Associate Agreement (BAA)
Why this is correct
HIPAA requires a Business Associate Agreement before a cloud provider creates, receives, maintains or transmits ePHI on behalf of the covered entity. The BAA contractually binds the provider to safeguard ePHI and report breaches, satisfying the Privacy and Security Rules.
- ✗
The cloud provider must be certified under ISO 27001
Why it's wrong here
HIPAA does not mandate ISO 27001 certification; the requirement is a Business Associate Agreement binding the provider to safeguard ePHI. ISO 27001 is tempting because it evidences a mature security programme, and it would satisfy due diligence where an organisation seeks demonstrable controls, but it is not the primary prerequisite for hosting ePHI.
- ✗
The covered entity must obtain written authorization from each patient
Why it's wrong here
Patient authorisation governs uses and disclosures of PHI for purposes such as marketing or research, not the selection of a hosting provider. A Business Associate Agreement is what HIPAA requires before a cloud provider handles ePHI. Authorisation is tempting because consent features heavily in privacy regulation, yet it addresses disclosure, not vendor safeguarding obligations.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.