ISC2 Governance, Risk and Compliance (CGRC) Practice Question

A hospital is documenting handling requirements for a new telehealth platform that will store and transmit patients' laboratory results, diagnoses and billing information. To satisfy HIPAA requirements for protected health information, which statement about encryption must the security team include in the system documentation?

  • Encryption of PHI in transit is required, but encryption at rest is optional and needs no justification if omitted.

  • Encryption decisions for PHI are left entirely to individual patients; covered entities have no specific obligations under HIPAA.

  • The Security Rule treats encryption as an addressable safeguard; the organization must either implement it or document and justify an alternative control if encryption is not reasonable and appropriate.

  • AES-256 encryption of all PHI, both in transit and at rest, is a non-negotiable HIPAA mandate for covered entities.

ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot