nerdexam
Cisco

350-201 · Question #61

A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on hold because other…

The correct answer is C. Turn off all access to the patient portal to secure patient records. When PII is actively being disclosed in real-time, immediate containment by disabling the affected system is the first priority to stop ongoing harm.

Processes

Question

A patient views information that is not theirs when they sign in to the hospital's online portal. The patient calls the support center at the hospital but continues to be put on hold because other patients are experiencing the same issue. An incident has been declared, and an engineer is now on the incident bridge as the CyberOps Tier 3 Analyst. There is a concern about the disclosure of PII occurring in real- time. What is the first step the analyst should take to address this incident?

Options

  • AEvaluate visibility tools to determine if external access resulted in tampering
  • BContact the third-party handling provider to respond to the incident as critical
  • CTurn off all access to the patient portal to secure patient records
  • DReview system and application logs to identify errors in the portal code

How the community answered

(40 responses)
  • A
    15% (6)
  • B
    5% (2)
  • C
    78% (31)
  • D
    3% (1)

Why each option

When PII is actively being disclosed in real-time, immediate containment by disabling the affected system is the first priority to stop ongoing harm.

AEvaluate visibility tools to determine if external access resulted in tampering

Evaluating visibility tools to check for tampering is an investigative step that should follow containment - continuing to run a compromised portal while investigating prolongs the active PII exposure.

BContact the third-party handling provider to respond to the incident as critical

Contacting a third-party handler may be a required step but is not the first action, since active data exposure must be stopped before escalation and coordination activities begin.

CTurn off all access to the patient portal to secure patient recordsCorrect

Disabling all access to the patient portal immediately halts the active PII disclosure, which is the highest priority when sensitive data is being exposed in real-time. This containment action protects patients from further harm and limits breach scope before investigation begins, satisfying HIPAA breach response obligations.

DReview system and application logs to identify errors in the portal code

Reviewing logs to find code errors is a root-cause analysis activity that belongs after containment, as it does not stop the ongoing unauthorized disclosure of patient records.

Concept tested: Incident containment to stop active PII disclosure

Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/index.html

Topics

#incident response#PII protection#containment#data breach

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice