Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To require the business associate to comply with HIPAA Privacy and Security Rules

A BAA ensures that business associates handling PHI will appropriately safeguard the information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To transfer ownership of PHI to the business associate

    Why it's wrong here

    A Business Associate Agreement (BAA) explicitly defines the terms under which a business associate may create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of a covered entity. It does not, however, transfer ownership of PHI. The covered entity retains legal ownership and ultimate accountability for the PHI, while the BAA establishes the business associate's role as a steward responsible for safeguarding that data according to HIPAA regulations.

  • To authorize the use of PHI for marketing purposes

    Why it's wrong here

    While a Business Associate Agreement (BAA) outlines permissible uses and disclosures of Protected Health Information (PHI) for healthcare operations, it does not inherently authorize the use of PHI for marketing purposes. Marketing activities, especially those involving remuneration, typically require a separate, specific, and explicit authorization from the individual whose PHI is being used, as mandated by the HIPAA Privacy Rule, distinct from the BAA's scope.

  • To require the business associate to comply with HIPAA Privacy and Security Rules

    Why this is correct

    The primary purpose of a Business Associate Agreement (BAA) is to contractually obligate the business associate to comply with the applicable provisions of the HIPAA Privacy and Security Rules. This legally binding agreement ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect Protected Health Information (PHI), reports breaches, and limits PHI use and disclosure to only what is necessary for the services provided, thereby extending the chain of trust.

  • To allow the business associate to disclose PHI to any third party

    Why it's wrong here

    A Business Associate Agreement (BAA) does not grant a business associate carte blanche to disclose Protected Health Information (PHI) to any third party. Instead, the BAA strictly limits disclosures to those explicitly permitted by the agreement itself and by HIPAA regulations, typically for treatment, payment, or healthcare operations, or as required by law. Any further disclosure requires specific authorization from the covered entity or the individual, adhering to the minimum necessary standard.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.