100-160 exam dumps

100-160 practice question 251 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 251

Single answer

A healthcare organization stores patient data on a cloud platform. During an internal audit, you discover that sensitive patient information is being shared with a third-party analytics company without proper encryption or patient consent. Which compliance framework is most relevant to addressing this issue, and what steps should the organization take to remain compliant?

  1. A

    HIPAA; ensure data encryption and obtain patient consent before sharing sensitive health information.

  2. B

    GDPR; implement stronger encryption and anonymize all patient data before sharing with third parties.

  3. C

    PCI-DSS; focus on securing payment card information and avoid sharing patient financial data.

  4. D

    FISMA; conduct a federal security assessment for patient data stored in the cloud.

Show answer and explanation

Correct answer: A

Explanation

HIPAA is the most relevant compliance framework for protecting sensitive patient health information in the United States. In this scenario, the organization is at risk of violating HIPAA due to the lack of encryption and patient consent when sharing PHI with a third-party analytics company. To address this, the organization must ensure proper encryption of the data and obtain patient consent before sharing it with any external parties.

  • A. Correct.

    HIPAA (Health Insurance Portability and Accountability Act) governs the protection of sensitive health information (PHI). The organization must encrypt the data and ensure patient consent is obtained before sharing it with third parties to remain compliant.

  • B. Incorrect.

    GDPR focuses on the protection of personal data of individuals in the EU. While encryption is a good practice, GDPR does not specifically address healthcare data outside of the EU, making it less relevant in this scenario.

  • C. Incorrect.

    PCI-DSS (Payment Card Industry Data Security Standard) pertains to securing payment card information and is not applicable to healthcare data such as patient health records.

  • D. Incorrect.

    FISMA (Federal Information Security Management Act) applies to federal agencies and contractors working with federal data, and it is not relevant to the healthcare organization in this scenario unless it is a federal entity.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam