CAS-003 · Question #554
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a specific platform was discovered, allowing an attacker to…
The correct answer is A. Cardholder data C. Personal health information. A pharmacy's online billing and records system transmits cardholder data and personal health information over SSL, making both data types directly at risk when an SSL interception vulnerability is exploited.
Question
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a specific platform was discovered, allowing an attacker to capture the data between the end user and the web server providing these services. After the new vulnerability, it was determined that web services provided are being impacted by this new threat. Which of the following data types MOST likely at risk of exposure based on this new threat? (Select Two)
Options
- ACardholder data
- BIntellectual property
- CPersonal health information
- DEmployee records
- ECorporate financial data
How the community answered
(35 responses)- A86% (30)
- B3% (1)
- D3% (1)
- E9% (3)
Why each option
A pharmacy's online billing and records system transmits cardholder data and personal health information over SSL, making both data types directly at risk when an SSL interception vulnerability is exploited.
Online payment functionality requires the transmission of cardholder data between the client and web server, and an attacker exploiting the SSL vulnerability can intercept this data in transit, exposing card numbers, expiration dates, and authentication values.
Intellectual property such as proprietary business assets is not transmitted through a client-facing pharmacy payment and health records portal.
Patient prescription records and health information constitute PHI regulated under HIPAA, and the pharmacy's online records access feature transmits this data over the vulnerable SSL channel, making it directly exposed to interception and unauthorized disclosure.
Employee records are internal HR data not exposed through the pharmacy's client-facing online billing and records services.
Corporate financial data refers to internal business accounting, not the individual client payment transactions handled by the pharmacy's web portal.
Concept tested: Data types at risk during SSL/TLS man-in-the-middle attacks
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
Topics
Community Discussion
No community discussion yet for this question.