Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A healthcare organization is moving patient…

A healthcare organization is moving patient records to a cloud storage service. Which of the following is the MOST important requirement to ensure data security and compliance with HIPAA?

⚠ Common exam trap

The trap here is that candidates often focus on technical security controls like encryption or MFA, overlooking the foundational legal and regulatory requirement of a signed Business Associate Agreement, which is the non-negotiable first step for HIPAA compliance with a cloud provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A signed Business Associate Agreement (BAA) with the cloud provider

Under HIPAA, a covered entity must have a signed Business Associate Agreement (BAA) with any cloud service provider that creates, receives, maintains, or transmits protected health information (PHI). Without a BAA, the provider is not contractually bound to safeguard PHI, making the organization non-compliant regardless of technical controls. While encryption and MFA are important security measures, they cannot substitute for the legal and regulatory requirement of a BAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Multi-factor authentication for all cloud access

    Why it's wrong here

    While multi-factor authentication (MFA) is a critical security control and a highly recommended best practice for protecting access to Protected Health Information (PHI), HIPAA's Security Rule does not explicitly mandate MFA as a specific technical requirement. Instead, it requires covered entities to implement 'person or entity authentication' and 'access control' mechanisms, allowing flexibility in choosing appropriate solutions based on their risk analysis. Therefore, while highly advisable, it is not the most fundamental or explicitly required step by HIPAA when engaging a cloud provider.

  • Encryption of data in transit using TLS 1.2

    Why it's wrong here

    Encrypting Protected Health Information (PHI) during transmission using strong protocols like TLS 1.2 is an essential technical safeguard under HIPAA's Security Rule, specifically addressing the 'Transmission Security' standard. However, this technical control alone does not establish the necessary legal and contractual framework for sharing PHI with a third-party cloud provider. The primary and overarching requirement for engaging a business associate is the Business Associate Agreement (BAA), which governs the entire relationship and responsibilities.

  • A signed Business Associate Agreement (BAA) with the cloud provider

    Why this is correct

    Under HIPAA, a cloud provider storing or processing Protected Health Information (PHI) is considered a Business Associate. Before any PHI can be legally shared or stored with such a provider, a signed Business Associate Agreement (BAA) is a mandatory contractual requirement. This agreement legally obligates the cloud provider to comply with HIPAA's Security and Privacy Rules, safeguarding PHI and outlining their responsibilities, permitted uses, disclosures, and breach notification procedures.

  • Encryption of data at rest using AES-256

    Why it's wrong here

    Encrypting Protected Health Information (PHI) at rest using robust algorithms like AES-256 is a crucial technical safeguard under HIPAA's Security Rule, specifically addressing the 'Integrity' and 'Confidentiality' of electronic PHI. While highly recommended and often considered a de-facto standard for protecting data from unauthorized access, HIPAA does not explicitly mandate encryption for data at rest, but rather requires 'addressable' implementation specifications for 'encryption and decryption.' However, even with strong encryption, the fundamental legal requirement for engaging a third-party service that handles PHI remains the BAA.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.