nerdexam
Isaca

CISA · Question #200

A healthcare organization is implementing internet of Things (IoT) technology to receive customer health information from medical service providers at the point of data creation. Which of the followin

The correct answer is A. Compliance to privacy legislation. Given the sensitivity of health information and the stringent regulations around the protection of personal data (such as HIPAA in the U.S. or GDPR in Europe), ensuring compliance with privacy legislation is critical. The healthcare sector must ensure that IoT systems collecting

Submitted by skyler.x· Apr 18, 2026Protection of Information Assets

Question

A healthcare organization is implementing internet of Things (IoT) technology to receive customer health information from medical service providers at the point of data creation. Which of the following is the MOST important element to include in the audit plan?

Options

  • ACompliance to privacy legislation
  • BTechnology compatibility
  • CDisaster recovery plan (DRP) for the system
  • DSystem response times

How the community answered

(58 responses)
  • A
    74% (43)
  • B
    16% (9)
  • C
    7% (4)
  • D
    3% (2)

Explanation

Given the sensitivity of health information and the stringent regulations around the protection of personal data (such as HIPAA in the U.S. or GDPR in Europe), ensuring compliance with privacy legislation is critical. The healthcare sector must ensure that IoT systems collecting and transmitting health data adhere to data protection laws to safeguard patient privacy and avoid legal penalties. While technology compatibility, disaster recovery, and system response times are important considerations, the most pressing concern in this context is compliance with privacy regulations due to the handling of sensitive personal health information.

Topics

#IoT security#Data privacy#Regulatory compliance#Healthcare IT

Community Discussion

No community discussion yet for this question.

Full CISA Practice