CCSP Legal, Risk, and Compliance Practice Question
A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?
⚠ Common exam trap
The trap here is assuming that encrypting ePHI or reporting the provider to OCR eliminates the need for a BAA with the cloud provider for all regions where ePHI is stored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the cloud provider to sign a BAA that covers all regions where ePHI is stored, including the offshore region, or disable backup replication to that region.
HIPAA requires a Business Associate Agreement (BAA) with any entity that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate. A cloud provider storing ePHI backups in an offshore region acts as a subcontractor, so a BAA must cover that region. If the provider refuses, the company must either negotiate an expanded BAA or disable replication to that region to maintain compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the ePHI backups in the offshore region and continue operations without a BAA for that region.
Why it's wrong here
Encryption is an addressable implementation specification under the HIPAA Security Rule, but it does not eliminate the requirement for a BAA with a business associate or subcontractor. The cloud provider remains a business associate even if data is encrypted, and the offshore region still involves a subcontractor. Without a BAA, the company would be in violation of HIPAA's business associate agreement requirements.
- ✗
Terminate the BAA with the cloud provider and migrate all ePHI to an on-premises data center.
Why it's wrong here
Terminating the BAA and moving ePHI on-premises would eliminate the cloud provider as a business associate, but it does not address the immediate compliance gap and may be operationally infeasible. HIPAA does not require avoiding cloud services; it requires ensuring that any business associate, including a cloud provider, adequately safeguards ePHI. This action is overly drastic and does not consider that the provider might still be able to comply with reasonable safeguards.
- ✓
Require the cloud provider to sign a BAA that covers all regions where ePHI is stored, including the offshore region, or disable backup replication to that region.
Why this is correct
Under HIPAA, a covered entity or business associate must have a BAA with any subcontractor that creates, receives, maintains, or transmits ePHI. The cloud provider is a business associate, and its offshore backup storage is a subcontractor relationship. The company must ensure the BAA covers all locations where ePHI is stored, or prevent storage in non-covered regions. This is the most direct and compliant action.
- ✗
Report the cloud provider to the HHS Office for Civil Rights (OCR) and continue using the service while awaiting guidance.
Why it's wrong here
Reporting the provider to OCR does not resolve the compliance obligation. HIPAA requires the company to have a BAA in place before allowing a business associate to handle ePHI. Continuing to use the service without a BAA for the offshore region would perpetuate the violation. Reporting may be appropriate in cases of known noncompliance, but it does not substitute for the required contractual safeguards.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.