712-50 Question 34
Single answerA global healthcare company is modernizing its infrastructure. Its electronic health record (EHR) system contains highly sensitive patient data subject to strict residency and audit requirements, while its patient-facing appointment portal experiences unpredictable seasonal traffic spikes. The CIO proposes moving everything to a single cloud model to reduce complexity. As the CISO, which approach BEST balances security, compliance, scalability, and operational risk?
- A
Adopt a private cloud for both the EHR system and the appointment portal so the organization retains maximum control over security and compliance.
- B
Adopt a public cloud for both the EHR system and the appointment portal because major cloud providers inherently eliminate most security and compliance concerns through their managed services.
- C
Adopt a hybrid cloud: keep the EHR system in a private cloud or tightly controlled dedicated environment, and place the appointment portal in a public cloud with strong identity, encryption, logging, and network segmentation controls.
- D
Adopt a community cloud shared with other healthcare organizations for both workloads because industry alignment automatically reduces audit scope and data residency concerns.
Show answer and explanation
Correct answer: C
Explanation
The best choice is the hybrid cloud approach because it maps different workloads to the cloud model that best fits their security, compliance, and operational characteristics. In practice, private cloud is often selected for highly sensitive or tightly regulated workloads when the organization needs increased control over architecture, location, segmentation, and oversight. Public cloud is often preferred for workloads needing rapid elasticity, broad availability, and cost-efficient scaling. Hybrid cloud is valuable when an enterprise must balance both objectives across different systems.
From a CCISO perspective, the decision should be driven by risk appetite, regulatory obligations, business continuity needs, data classification, and the shared responsibility model. Sensitive healthcare data may require stricter control over residency, access, audit logging, encryption key management, and third-party risk. At the same time, customer-facing services with variable traffic are strong candidates for public cloud because of autoscaling and resilience benefits. However, public cloud does not transfer accountability for security and compliance to the provider.
Relevant best practices and references include NIST SP 800-145 for cloud service characteristics and deployment models, NIST SP 800-53 and NIST SP 800-207 for control selection and zero trust principles, the CSA Cloud Controls Matrix for cloud governance and security domains, and general regulatory guidance for healthcare data protection and auditability. A CISO should ensure that whichever model is chosen, governance includes vendor due diligence, contractual security requirements, continuous monitoring, IAM, encryption in transit and at rest, incident response integration, and clear responsibility matrices.
- A. Incorrect.
This is not the best answer. A private cloud can provide greater control, customization, and potentially easier alignment to strict regulatory or residency requirements for the EHR system. However, placing the internet-facing appointment portal entirely in private cloud may be less cost-effective and less elastic for handling unpredictable demand spikes. The option overemphasizes control and underutilizes the scalability and operational advantages of public cloud for variable workloads.
- B. Incorrect.
This is incorrect. Public cloud providers offer strong security capabilities, but they do not eliminate the customer's compliance obligations. Under the shared responsibility model, the organization remains accountable for data classification, identity and access management, secure configuration, monitoring, and many compliance controls depending on the service model. For highly sensitive healthcare workloads with strict residency and audit requirements, moving everything to public cloud may be possible in some cases, but this option is flawed because it assumes managed services inherently resolve most security and compliance concerns.
- C. Correct.
This is the best answer. A hybrid cloud model aligns workloads to business and risk requirements. Keeping the EHR system in a private cloud or similarly controlled environment supports stronger governance over sensitive regulated data, residency, and auditability. Hosting the appointment portal in public cloud leverages elasticity, geographic reach, and operational efficiency for fluctuating demand. The answer also correctly emphasizes that security controls such as strong IAM, encryption, centralized logging, and segmentation are still required. This reflects a practical, risk-based cloud strategy rather than a one-size-fits-all approach.
- D. Incorrect.
This is incorrect. A community cloud may be appropriate in limited sector-specific situations, but sharing infrastructure with other healthcare entities does not automatically reduce audit scope, residency obligations, or security risk. Compliance requirements still depend on how data is stored, processed, accessed, and governed. This option reflects the misconception that industry-specific hosting alone satisfies regulatory and security needs.