CISSP Security and Risk Management Practice Question
A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A business associate agreement (BAA)
HIPAA requires covered entities to have a business associate agreement (BAA) with any third party that will handle PHI on their behalf. The BAA ensures the business associate will safeguard the PHI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A memorandum of understanding (MOU)
Why it's wrong here
A Memorandum of Understanding (MOU) is a general agreement expressing mutual intent between parties. However, it lacks the specific legal requirements and detailed provisions mandated by HIPAA for safeguarding Protected Health Information (PHI). An MOU does not establish the necessary legal obligations, liability, or compliance framework required for business associates under the HIPAA Privacy and Security Rules, making it insufficient for PHI sharing.
- ✗
A data processing agreement under GDPR
Why it's wrong here
A Data Processing Agreement (DPA) is a specific contractual requirement under the European Union's General Data Protection Regulation (GDPR), designed for organizations processing personal data of EU residents. The question specifies a healthcare organization covered by HIPAA, which operates under U.S. jurisdiction and regulations. Therefore, unless the organization also processes data subject to GDPR, a DPA is not the applicable legal instrument for sharing Protected Health Information (PHI) in this context.
- ✗
A consent form from each patient
Why it's wrong here
While patient consent is a fundamental principle for many disclosures of Protected Health Information (PHI), HIPAA permits covered entities to share PHI with their business associates for specific healthcare operations, such as billing or claims processing, without individual patient authorization. This is permissible when a legally binding Business Associate Agreement (BAA) is in place, which obligates the associate to protect the PHI. Relying solely on individual consent forms for every operational disclosure to a business associate would be administratively burdensome and is not mandated by HIPAA for these specific scenarios.
- ✓
A business associate agreement (BAA)
Why this is correct
A Business Associate Agreement (BAA) is a legally mandated contract under HIPAA that must be established between a covered entity and its business associates before Protected Health Information (PHI) is shared. This agreement obligates the business associate to implement specific administrative, physical, and technical safeguards to protect PHI, adhering to the HIPAA Security and Privacy Rules. The BAA ensures accountability and extends the covered entity's compliance responsibilities to third parties handling PHI on its behalf, making it the correct and essential mechanism for such sharing.
Go deeper
Related to this question
Learn chapter
Incident Response and Business Continuity
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Safeguard
A safeguard is a control, measure, or action designed to protect an organization's assets from threats, vulnerabilities, and risks.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.