350-201 · Question #61
A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on hold because other…
The correct answer is C. Turn off all access to the patient portal to secure patient records. When PII is actively being disclosed in real-time, immediate containment by disabling the affected system is the first priority to stop ongoing harm.
Question
A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on hold because other patients are experiencing the same issue. An incident has been declared, and an engineer is now on the incident bridge as the CyberOps Tier 3 Analyst. There is a concern about the disclosure of PII occurring in real- time. What is the first step the analyst should take to address this incident?
Options
- AEvaluate visibility tools to determine if external access resulted in tampering
- BContact the third-party handling provider to respond to the incident as critical
- CTurn off all access to the patient portal to secure patient records
- DReview system and application logs to identify errors in the portal code
How the community answered
(40 responses)- A15% (6)
- B5% (2)
- C78% (31)
- D3% (1)
Why each option
When PII is actively being disclosed in real-time, immediate containment by disabling the affected system is the first priority to stop ongoing harm.
Evaluating visibility tools to check for tampering is an investigative step that should follow containment - continuing to run a compromised portal while investigating prolongs the active PII exposure.
Contacting a third-party handler may be a required step but is not the first action, since active data exposure must be stopped before escalation and coordination activities begin.
Disabling all access to the patient portal immediately halts the active PII disclosure, which is the highest priority when sensitive data is being exposed in real-time. This containment action protects patients from further harm and limits breach scope before investigation begins, satisfying HIPAA breach response obligations.
Reviewing logs to find code errors is a root-cause analysis activity that belongs after containment, as it does not stop the ongoing unauthorized disclosure of patient records.
Concept tested: Incident containment to stop active PII disclosure
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/index.html
Topics
Community Discussion
No community discussion yet for this question.