CV0-003 · Question #353
When considering a public cloud implementation in a hospital, which of the following would the Chief Information Officer (CIO) have to check with respect to storing patient information?
The correct answer is D. Laws and regulations. Storing patient health information in a public cloud requires compliance with healthcare privacy laws such as HIPAA, making regulatory review the CIO's primary obligation before implementation.
Question
When considering a public cloud implementation in a hospital, which of the following would the Chief Information Officer (CIO) have to check with respect to storing patient information?
Options
- AThe board of directors
- BOfferings on the market for budgeting
- CBusiness need
- DLaws and regulations
How the community answered
(40 responses)- B3% (1)
- C5% (2)
- D93% (37)
Why each option
Storing patient health information in a public cloud requires compliance with healthcare privacy laws such as HIPAA, making regulatory review the CIO's primary obligation before implementation.
The board of directors provides organizational governance, but verifying legal and regulatory compliance for patient data storage is a technical and compliance responsibility that falls to the CIO and legal teams, not the board.
Evaluating market offerings for budgeting is a procurement consideration and does not address the mandatory legal requirements that govern whether patient data can lawfully be stored in a public cloud.
Business need is a valid driver for cloud adoption but does not override or substitute for the mandatory legal and regulatory framework that governs patient health information storage.
Healthcare organizations are legally bound by regulations such as HIPAA (Health Insurance Portability and Accountability Act) that govern how Protected Health Information (PHI) is stored, accessed, and protected. Before moving patient data to a public cloud, the CIO must verify that the provider meets these requirements - including executing a Business Associate Agreement (BAA) - to avoid violations and penalties.
Concept tested: Healthcare regulatory compliance for public cloud patient data
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
Topics
Community Discussion
No community discussion yet for this question.