CAS-003 · Question #551
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a special platform was discovered, allowing an attacker to…
The correct answer is A. Cardholder data C. Personal health information. A pharmacy's online payment and health records portal exposes cardholder data and personal health information when an SSL vulnerability allows an attacker to intercept encrypted traffic.
Question
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a special platform was discovered, allowing an attacker to capture the data between the end user and the web server providing these services. After invest the new vulnerability, it was determined that the web services providing are being impacted by this new threat. Which of the following data types a MOST likely at risk of exposure based on this new threat? (Select TWO)
Options
- ACardholder data
- Bintellectual property
- CPersonal health information
- DEmployee records
- ECorporate financial data
How the community answered
(21 responses)- A76% (16)
- B14% (3)
- D5% (1)
- E5% (1)
Why each option
A pharmacy's online payment and health records portal exposes cardholder data and personal health information when an SSL vulnerability allows an attacker to intercept encrypted traffic.
The pharmacy accepts online payments, meaning cardholder data including card numbers and verification values is transmitted between the client browser and the web server and is directly captured by an attacker exploiting the SSL interception vulnerability.
Intellectual property such as proprietary formulas or trade secrets is not transmitted through a client-facing pharmacy billing and records web portal.
Patient prescription and medical record data accessed through the pharmacy portal constitutes personal health information protected under HIPAA, and this PHI is transmitted over the vulnerable SSL channel, making it directly at risk of interception and exposure.
Employee records are internal HR data that are not exposed through the pharmacy's client-facing online services.
Corporate financial data refers to internal business accounting information, not the client payment transactions processed through the pharmacy's web portal.
Concept tested: Data classification risk in SSL/TLS interception attacks
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
Topics
Community Discussion
No community discussion yet for this question.