CCSP Cloud Concepts, Architecture, and Design Practice Question
A healthcare organization is designing a cloud solution to store and process electronic protected health information (ePHI). The organization must comply with HIPAA and wants to ensure that the cloud service provider (CSP) meets the necessary security and privacy requirements. The organization is evaluating a CSP that offers a Business Associate Agreement (BAA). Which of the following is the MOST critical factor to verify before signing the BAA?
⚠ Common exam trap
The trap here is focusing on the BAA as a document rather than on the underlying security controls. A BAA is necessary but not sufficient; the CSP must actually implement the required safeguards, and the organization must verify this through audits or certifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CSP has implemented appropriate administrative, physical, and technical safeguards to protect ePHI.
The HIPAA Security Rule requires covered entities and their business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Before signing a BAA, the healthcare organization must verify that the CSP has these safeguards in place. While data residency, contractual clauses, and SLAs are relevant, they do not replace the need for comprehensive security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CSP's BAA includes a clause allowing the CSP to use ePHI for its own purposes.
Why it's wrong here
A BAA must restrict the CSP's use and disclosure of ePHI to the purposes specified in the agreement, typically to provide services to the covered entity. A clause allowing the CSP to use ePHI for its own purposes would violate HIPAA and is not acceptable. The organization should reject such a clause, not verify it as a critical factor.
- ✗
The CSP's data center locations are within the United States.
Why it's wrong here
While data residency can be a compliance consideration, HIPAA does not mandate that ePHI remain within the United States. The critical factor is whether the CSP can provide the necessary safeguards and controls to protect ePHI, regardless of location. Verifying data center locations alone does not ensure that the CSP meets the full range of HIPAA requirements, such as access controls, audit logging, and breach notification.
- ✓
The CSP has implemented appropriate administrative, physical, and technical safeguards to protect ePHI.
Why this is correct
Under HIPAA, a covered entity must ensure that its business associates, including CSPs, implement appropriate safeguards to protect ePHI. The BAA itself is a contractual requirement, but the most critical factor is verifying that the CSP actually has the necessary administrative, physical, and technical safeguards in place. This includes access controls, encryption, audit controls, and integrity controls, which are essential to comply with the HIPAA Security Rule.
- ✗
The CSP offers a 99.999% uptime service level agreement (SLA).
Why it's wrong here
While high availability is important for operational continuity, it is not the most critical factor for HIPAA compliance. A robust SLA does not guarantee that the CSP has implemented the required security safeguards for ePHI. The organization must prioritize the CSP's ability to protect the confidentiality, integrity, and availability of ePHI through appropriate security measures, not just uptime guarantees.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.