mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: A healthcare organization is moving patient…
A healthcare organization is moving patient records to a cloud storage service. Which of the following is the MOST important requirement to ensure data security and compliance with HIPAA?
⚠ Common exam trap
The trap here is that candidates often focus on technical security controls like encryption or MFA, overlooking the foundational legal and regulatory requirement of a signed Business Associate Agreement, which is the non-negotiable first step for HIPAA compliance with a cloud provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A signed Business Associate Agreement (BAA) with the cloud provider
Under HIPAA, a covered entity must have a signed Business Associate Agreement (BAA) with any cloud service provider that creates, receives, maintains, or transmits protected health information (PHI). Without a BAA, the provider is not contractually bound to safeguard PHI, making the organization non-compliant regardless of technical controls. While encryption and MFA are important security measures, they cannot substitute for the legal and regulatory requirement of a BAA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multi-factor authentication for all cloud access
Why it's wrong here
While multi-factor authentication (MFA) is a critical security control and a highly recommended best practice for protecting access to Protected Health Information (PHI), HIPAA's Security Rule does not explicitly mandate MFA as a specific technical requirement. Instead, it requires covered entities to implement 'person or entity authentication' and 'access control' mechanisms, allowing flexibility in choosing appropriate solutions based on their risk analysis. Therefore, while highly advisable, it is not the most fundamental or explicitly required step by HIPAA when engaging a cloud provider.
- ✗
Encryption of data in transit using TLS 1.2
Why it's wrong here
Encrypting Protected Health Information (PHI) during transmission using strong protocols like TLS 1.2 is an essential technical safeguard under HIPAA's Security Rule, specifically addressing the 'Transmission Security' standard. However, this technical control alone does not establish the necessary legal and contractual framework for sharing PHI with a third-party cloud provider. The primary and overarching requirement for engaging a business associate is the Business Associate Agreement (BAA), which governs the entire relationship and responsibilities.
- ✓
A signed Business Associate Agreement (BAA) with the cloud provider
Why this is correct
Under HIPAA, a cloud provider storing or processing Protected Health Information (PHI) is considered a Business Associate. Before any PHI can be legally shared or stored with such a provider, a signed Business Associate Agreement (BAA) is a mandatory contractual requirement. This agreement legally obligates the cloud provider to comply with HIPAA's Security and Privacy Rules, safeguarding PHI and outlining their responsibilities, permitted uses, disclosures, and breach notification procedures.
- ✗
Encryption of data at rest using AES-256
Why it's wrong here
Encrypting Protected Health Information (PHI) at rest using robust algorithms like AES-256 is a crucial technical safeguard under HIPAA's Security Rule, specifically addressing the 'Integrity' and 'Confidentiality' of electronic PHI. While highly recommended and often considered a de-facto standard for protecting data from unauthorized access, HIPAA does not explicitly mandate encryption for data at rest, but rather requires 'addressable' implementation specifications for 'encryption and decryption.' However, even with strong encryption, the fundamental legal requirement for engaging a third-party service that handles PHI remains the BAA.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Regulatory requirement
A regulatory requirement is a rule issued by a government or industry authority that organizations must follow, often to protect data, ensure safety, or maintain fair practices.
Key term
Safeguard
A safeguard is a control, measure, or action designed to protect an organization's assets from threats, vulnerabilities, and risks.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.