nerdexam
Exams400-007Questions#114
Cisco

400-007 · Question #114

400-007 Question #114: Real Exam Question with Answer & Explanation

The correct answer is D: technical integrity and transmission security. The core problem is a data integrity violation: PHI was modified without authorization. Under HIPAA's Technical Safeguards (45 CFR §164.312), the Integrity control requires covered entities to implement electronic mechanisms to corroborate that ePHI has not been improperly altere

Question

A healthcare provider discovers that protected health information of patients was altered without patient consent. The healthcare provider is subject to HIPAA compliance and is required to protect PHI data. Which type of security safeguard should be implemented to resolve this issue?

Options

  • Atechnical and physical access control
  • Badministrative security management processes
  • Cphysical device and media control
  • Dtechnical integrity and transmission security

Explanation

The core problem is a data integrity violation: PHI was modified without authorization. Under HIPAA's Technical Safeguards (45 CFR §164.312), the Integrity control requires covered entities to implement electronic mechanisms to corroborate that ePHI has not been improperly altered or destroyed, and Transmission Security ensures PHI is not modified during transit. These two controls directly address unauthorized alteration. Access control (A) governs who can authenticate and access systems, but alone cannot prevent an authorized user or a man-in-the-middle attack from modifying data in transit. Administrative security management (B) covers policies and risk analysis - important but not the direct technical resolution. Physical device and media control (C) addresses hardware custody (disposal, re-use), not data modification in transit or at rest.

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice