Courseiva

CISSP Security and Risk Management Practice Question

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

⚠ Common exam trap

CISSP often tests the definition of a business associate, and candidates may incorrectly include entities that do not handle PHI, such as janitorial services or patients themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A cloud service provider hosting ePHI

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with a cloud service provider that hosts electronic protected health information (ePHI). This is because the cloud provider is a business associate, as it creates, receives, maintains, or transmits ePHI on behalf of the covered entity. The BAA ensures the business associate safeguards the ePHI and complies with HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A cloud service provider hosting ePHI

    Why this is correct

    A cloud service provider that hosts electronic Protected Health Information (ePHI) on behalf of a covered entity is unequivocally a Business Associate under HIPAA. By storing or processing ePHI, the CSP creates, receives, maintains, or transmits this data, making them directly subject to HIPAA's Security Rule and certain aspects of the Privacy Rule. A Business Associate Agreement (BAA) is mandatory to define their responsibilities and ensure appropriate safeguards are in place for the ePHI.

  • ✗

    A janitorial service that cleans the office

    Why it's wrong here

    A janitorial service typically does not qualify as a Business Associate because their routine duties do not involve the creation, receipt, maintenance, or transmission of Protected Health Information (PHI). While they may incidentally be present in areas containing PHI, their contractual agreement is for cleaning services, not for accessing or handling patient data. Unless their role explicitly requires access to PHI, they fall under the 'conduit exception' or are simply not involved with PHI in a HIPAA-defined capacity.

  • ✗

    A government regulator conducting an audit

    Why it's wrong here

    A government regulator conducting an audit, such as the Department of Health and Human Services (HHS) or the Office for Civil Rights (OCR), is not considered a Business Associate. These entities operate under their statutory authority to enforce HIPAA compliance, rather than performing a service or function on behalf of the covered entity. Their access to PHI is for oversight and investigation purposes, which is distinct from the service-oriented relationship defined for Business Associates.

  • ✗

    A patient requesting their medical records

    Why it's wrong here

    A patient requesting their medical records is not a Business Associate under HIPAA. Patients are the individuals whose health information is protected by HIPAA and are the direct beneficiaries of its privacy and security rules. Their interaction with a covered entity is as a data subject exercising their fundamental right to access their own Protected Health Information, not as an entity performing a service for the covered entity.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.