220-1102 Question 713
Single answerCompliance with government regulationsA support technician at a medical clinic is preparing to replace several laptops used by nurses to access patient charts. The old laptops will be returned to a leasing company. The drives contain electronic protected health information (ePHI), and the clinic's compliance officer wants to reduce the risk of a reportable data breach while meeting regulatory obligations. Which action should the technician take FIRST before the laptops leave the clinic?
- A
Perform a cryptographic wipe or other approved data sanitization on the drives and document the process
- B
Delete user profiles and clear the browser cache so patient information is no longer easily accessible
- C
Reimage the laptops with the clinic's standard operating system image before shipping them
- D
Remove the laptops from the wireless network and asset inventory so they are no longer associated with the clinic
Show answer and explanation
Correct answer: A
Explanation
This question focuses on compliance with government regulations in a real support scenario. Because the clinic handles ePHI, HIPAA is the key regulation. Under the HIPAA Security Rule, covered entities must implement policies and procedures for the final disposition of electronic media and the removal of ePHI before reuse or transfer. In practice, technicians should follow documented media disposal and sanitization procedures before devices leave organizational control. NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, is widely referenced for approved sanitization methods, including clear, purge, and destroy, depending on the media type and risk. For encrypted drives, a properly executed cryptographic erase can be appropriate. Documentation of the sanitization process is also important for auditability and demonstrating due diligence. The other choices are plausible operational tasks, but they do not satisfy the primary compliance requirement of securely sanitizing regulated data before transfer.
- A. Correct.
Correct. Devices that stored ePHI must be properly sanitized before disposal, transfer, or return to a third party. For leased laptops leaving the clinic's control, the safest and most compliant first step is to perform approved media sanitization, such as a cryptographic erase when appropriate or another validated sanitization method, and document it. This aligns with HIPAA's requirement to protect ePHI and with media sanitization best practices described by NIST.
- B. Incorrect.
Incorrect. Deleting profiles and clearing caches does not adequately remove sensitive data from storage media. Recoverable remnants of ePHI may remain on the drive, creating a compliance and breach risk. This is a common mistake because it feels like data has been removed, but it does not meet accepted sanitization standards.
- C. Incorrect.
Incorrect. Reimaging installs a fresh operating system, but it does not guarantee that underlying data is irrecoverable. Portions of patient data may still exist in unallocated space or elsewhere on the drive. Reimaging alone is an operational step, not a compliant sanitization method for regulated health data.
- D. Incorrect.
Incorrect. Disconnecting the laptops from the network and removing inventory records may be part of decommissioning, but it does nothing to protect data remaining on the drives. In fact, removing asset tracking too early could weaken chain-of-custody documentation, which is important in regulated environments.