220-1102 Question 752
Single answerRegulatory and business compliance requirementsA technician at a medical clinic is preparing several retired laptops for disposal. The laptops were used by nurses to access patient charts, and some may contain locally stored reports and cached data. The clinic's policy requires compliance with healthcare privacy regulations and internal data-retention procedures. Which action should the technician take FIRST before sending the laptops to an approved recycling vendor?
- A
Perform a documented drive sanitization or destruction process according to company policy, and maintain records of the disposition
- B
Remove the laptops from the domain and delete the user accounts associated with the devices
- C
Reinstall the operating system so the next owner cannot access the previous files
- D
Affix an asset disposal label to each laptop and send them directly to the recycling vendor
Show answer and explanation
Correct answer: A
Explanation
The best first step is to ensure the laptops' storage is securely sanitized or destroyed in accordance with organizational policy and regulatory obligations, and that the process is documented. In a medical clinic, patient information may qualify as protected health information (PHI), so improper disposal could create a privacy breach. From an A+ Core 2 perspective, this tests applying regulatory and business compliance requirements to hardware disposal. A strong real-world approach includes following the company's retention and disposal policy, using approved media sanitization methods, maintaining asset and chain-of-custody records, and then transferring equipment to an authorized recycler or disposal vendor. Industry best practice commonly references NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, for approved sanitization methods. Organizational policy and any applicable healthcare privacy requirements should drive the exact procedure.
- A. Correct.
Correct. In a healthcare environment, devices that may contain protected health information (PHI) must be handled in a way that prevents unauthorized disclosure. Before disposal, storage media should be sanitized or destroyed using an approved process, and the organization should document the chain of custody and final disposition. This aligns with common compliance expectations under healthcare privacy programs and with industry guidance such as NIST SP 800-88 for media sanitization.
- B. Incorrect.
Incorrect. Removing systems from the domain and deleting accounts is an administrative cleanup step, but it does not address data remaining on the laptop's storage. PHI or other sensitive business data could still be recoverable from the drive, so this action does not satisfy the core compliance requirement for secure disposal.
- C. Incorrect.
Incorrect. Reinstalling the operating system is not a reliable data sanitization method. Standard OS reinstallation may leave recoverable data on the drive. A candidate might choose this option because it sounds like a reset, but compliance-focused disposal requires proper sanitization or destruction, not just reimaging.
- D. Incorrect.
Incorrect. Labeling assets and using an approved vendor may be part of the disposal workflow, but sending devices out before ensuring data is sanitized creates a compliance risk. Vendor use does not remove the organization's responsibility to protect regulated data unless the process explicitly includes approved sanitization and documentation.