CISSP Security and Risk Management Practice Question
Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To require the business associate to comply with HIPAA Privacy and Security Rules
A BAA ensures that business associates handling PHI will appropriately safeguard the information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To transfer ownership of PHI to the business associate
Why it's wrong here
A Business Associate Agreement (BAA) explicitly defines the terms under which a business associate may create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of a covered entity. It does not, however, transfer ownership of PHI. The covered entity retains legal ownership and ultimate accountability for the PHI, while the BAA establishes the business associate's role as a steward responsible for safeguarding that data according to HIPAA regulations.
- ✗
To authorize the use of PHI for marketing purposes
Why it's wrong here
While a Business Associate Agreement (BAA) outlines permissible uses and disclosures of Protected Health Information (PHI) for healthcare operations, it does not inherently authorize the use of PHI for marketing purposes. Marketing activities, especially those involving remuneration, typically require a separate, specific, and explicit authorization from the individual whose PHI is being used, as mandated by the HIPAA Privacy Rule, distinct from the BAA's scope.
- ✓
To require the business associate to comply with HIPAA Privacy and Security Rules
Why this is correct
The primary purpose of a Business Associate Agreement (BAA) is to contractually obligate the business associate to comply with the applicable provisions of the HIPAA Privacy and Security Rules. This legally binding agreement ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect Protected Health Information (PHI), reports breaches, and limits PHI use and disclosure to only what is necessary for the services provided, thereby extending the chain of trust.
- ✗
To allow the business associate to disclose PHI to any third party
Why it's wrong here
A Business Associate Agreement (BAA) does not grant a business associate carte blanche to disclose Protected Health Information (PHI) to any third party. Instead, the BAA strictly limits disclosures to those explicitly permitted by the agreement itself and by HIPAA regulations, typically for treatment, payment, or healthcare operations, or as required by law. Any further disclosure requires specific authorization from the covered entity or the individual, adhering to the minimum necessary standard.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Safeguard
A safeguard is a control, measure, or action designed to protect an organization's assets from threats, vulnerabilities, and risks.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.