ISC2 Certified Cloud Security Professional (CCSP) Practice Question
While working as the security operations manager for a cloud service provider that hosts an electronic health record (EHR) SaaS platform, you learn that an attacker has downloaded protected health information (PHI) belonging to a single hospital tenant. The master services agreement mandates breach notification within four hours, and the hospital is a HIPAA covered entity. To comply with accepted cloud-security communication practices, which outbound notification should you make first?
Release a public media statement acknowledging the breach and outlining remediation steps.
Notify the hospital's designated incident-response contact using the four-hour contractual breach-notification process.
Email all affected patients advising them to change passwords and monitor accounts for identity theft.
Submit an immediate breach report to the U.S. Department of Health and Human Services Office for Civil Rights (OCR).
Under HIPAA, a cloud service provider that handles PHI on behalf of a healthcare organization is a business associate. When a breach is discovered, the HIPAA Breach Notification Rule requires the business associate to notify the affected covered entity "without unreasonable delay" so the covered entity can in turn notify patients and regulators. Cloud service agreements usually mirror this requirement with explicit notification time frames. Reporting directly to regulators, contacting patients, or issuing a public statement may be necessary later, but they occur only after (or in coordination with) the customer's designated contact. Therefore, the correct first action is to follow the contract and notify the customer's incident response contact immediately.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PHI under HIPAA?
Open an interactive chat with Bash
What is the HIPAA Breach Notification Rule?
Open an interactive chat with Bash
What is a business associate under HIPAA?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .