Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A business associate agreement (BAA)

HIPAA requires covered entities to have a business associate agreement (BAA) with any third party that will handle PHI on their behalf. The BAA ensures the business associate will safeguard the PHI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A memorandum of understanding (MOU)

    Why it's wrong here

    A Memorandum of Understanding (MOU) is a general agreement expressing mutual intent between parties. However, it lacks the specific legal requirements and detailed provisions mandated by HIPAA for safeguarding Protected Health Information (PHI). An MOU does not establish the necessary legal obligations, liability, or compliance framework required for business associates under the HIPAA Privacy and Security Rules, making it insufficient for PHI sharing.

  • A data processing agreement under GDPR

    Why it's wrong here

    A Data Processing Agreement (DPA) is a specific contractual requirement under the European Union's General Data Protection Regulation (GDPR), designed for organizations processing personal data of EU residents. The question specifies a healthcare organization covered by HIPAA, which operates under U.S. jurisdiction and regulations. Therefore, unless the organization also processes data subject to GDPR, a DPA is not the applicable legal instrument for sharing Protected Health Information (PHI) in this context.

  • A consent form from each patient

    Why it's wrong here

    While patient consent is a fundamental principle for many disclosures of Protected Health Information (PHI), HIPAA permits covered entities to share PHI with their business associates for specific healthcare operations, such as billing or claims processing, without individual patient authorization. This is permissible when a legally binding Business Associate Agreement (BAA) is in place, which obligates the associate to protect the PHI. Relying solely on individual consent forms for every operational disclosure to a business associate would be administratively burdensome and is not mandated by HIPAA for these specific scenarios.

  • A business associate agreement (BAA)

    Why this is correct

    A Business Associate Agreement (BAA) is a legally mandated contract under HIPAA that must be established between a covered entity and its business associates before Protected Health Information (PHI) is shared. This agreement obligates the business associate to implement specific administrative, physical, and technical safeguards to protect PHI, adhering to the HIPAA Security and Privacy Rules. The BAA ensures accountability and extends the covered entity's compliance responsibilities to third parties handling PHI on its behalf, making it the correct and essential mechanism for such sharing.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.