A U.S.-based healthcare software provider is migrating its web application infrastructure to a third-party public cloud vendor. The cloud vendor will host databases containing Protected Health Information (PHI). To ensure compliance with federal privacy regulations, which of the following legal instruments must the organization execute with the cloud vendor before transferring PHI to the platform?
- Business Associate Agreement (BAA)Cevap
- BStandard Contractual Clauses (SCC)
- CService Level Agreement (SLA)
- DNon-Disclosure Agreement (NDA)
Cevap
Business Associate Agreement (BAA)
Under HIPAA regulatory requirements, a Business Associate Agreement (BAA) is mandatory whenever a third-party vendor (such as a cloud infrastructure provider) stores, processes, or transmits Protected Health Information (PHI) for an organization. The BAA establishes legal liability and requires the vendor to uphold HIPAA Privacy and Security Rule controls.
Adım Adım Çözüm
Anahtar Kavram
Business Associate Agreement under HIPAA