A medical imaging clinic based in the United States plans to migrate its patient diagnostic archives to a third-party cloud storage and analytics platform. The archives contain sensitive Protected Health Information (PHI). Before transmitting any data to the cloud service provider, which mandatory legal agreement or compliance instrument must the chief information security officer (CISO) execute to satisfy Health Insurance Portability and Accountability Act (HIPAA) regulatory requirements?
- AA Service Level Agreement (SLA) specifying 99.99% uptime guarantees and high-availability disaster recovery metrics.
- A Business Associate Agreement (BAA) contractually binding the provider to implement required HIPAA security safeguards.Cevap
- CA Payment Card Industry Data Security Standard (PCI DSS) Attestation of Compliance (AoC) for the cloud repository.
- DStandard Contractual Clauses (SCCs) authorizing cross-border personal data transfers under European privacy directives.
Cevap
Executing a Business Associate Agreement (BAA) contractually binding the cloud provider to implement required HIPAA security safeguards is the mandatory compliance requirement.
Under HIPAA regulatory rules, when a covered entity (such as a medical imaging clinic) utilizes a third-party vendor to store or process Protected Health Information (PHI), the parties must enter into a formal Business Associate Agreement (BAA). The BAA legally obligates the vendor to maintain appropriate administrative, physical, and technical security controls and report any security incidents or data breaches.
Adım Adım Çözüm
Anahtar Kavram
HIPAA Business Associate Agreements (BAA) for Third-Party Vendors