220-1102 Question 749
Single answerHealthcare dataA help desk technician at a medical clinic is replacing a nurse station PC that was used to access electronic health records (EHRs). The old PC will be sent to a third-party recycler. The technician confirms the system drive may contain cached patient information and locally stored documents. Which action should the technician take FIRST to best protect healthcare data and help the clinic remain compliant with privacy requirements?
- A
Perform a documented sanitization of the drive using the organization's approved data destruction process before releasing the PC
- B
Delete the nurse's user profile and clear the browser cache, then send the PC to recycling
- C
Reimage the PC with the standard clinic image so the next owner cannot access the old files
- D
Remove the PC from the domain and disable the nurse's account before disposal
Show answer and explanation
Correct answer: A
Explanation
The best answer is to sanitize the storage media using the organization's approved process before the device leaves organizational control. In healthcare settings, electronic protected health information must be safeguarded not only during use but also during disposal and reuse. HIPAA's Security Rule requires covered entities and business associates to implement appropriate administrative, physical, and technical safeguards for ePHI. In practice, this includes media disposal and reuse procedures so patient data is not exposed when devices are retired, transferred, or recycled. Industry best practices also align with NIST media sanitization guidance, which emphasizes using approved sanitization or destruction methods and maintaining documentation or chain-of-custody records where required by policy. Simply deleting files, clearing caches, reimaging, or disabling accounts does not adequately address the risk of data remanence on a drive that may contain healthcare data.
- A. Correct.
Correct. Healthcare environments must protect electronic protected health information (ePHI) throughout the device lifecycle, including disposal. If a drive may contain cached patient data or local documents, the safest first step is to follow the organization's approved media sanitization or destruction process and document it. This aligns with standard security practice and supports HIPAA expectations for protecting ePHI from unauthorized disclosure.
- B. Incorrect.
Incorrect. Deleting a user profile and clearing browser cache is not sufficient because recoverable patient data may still remain on the drive in unallocated space, temporary files, application data, swap files, or other locations. This is a common misconception because the system may appear clean, but the data has not been properly sanitized.
- C. Incorrect.
Incorrect. Reimaging alone does not guarantee that previous data is unrecoverable. Depending on the imaging method, remnants of data may remain and be recoverable with forensic tools. Reimaging is useful for redeployment, but for disposal or transfer to a third party, approved sanitization or destruction is the appropriate control.
- D. Incorrect.
Incorrect. Removing the computer from the domain and disabling the nurse's account may be appropriate account-management tasks, but they do not address the main risk in the scenario: residual ePHI on the storage device. Someone might choose this option because it sounds security-related, but it does not protect stored healthcare data on the device being recycled.