easyMultiple Choice
200-201 Practice Question: A healthcare organization has a security policy…
A healthcare organization has a security policy that mandates immediate reporting of any potential data breach to the privacy officer. An analyst notices that an employee accidentally emailed a patient list to the wrong recipient. The recipient is known to be a trusted partner, but the email contained PHI. The analyst contacts the recipient who acknowledges receipt and agrees to delete the email. What should the analyst do next?
⚠ Common exam trap
The trap here is the assumption that recipient cooperation or data deletion erases the reporting obligation — candidates pick 'do nothing' or 'warn the employee' because the outcome seems benign, but policy and HIPAA require escalation regardless of perceived harm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the incident as a data breach to the privacy officer as per policy.
Under HIPAA and most organizational security policies, any unauthorized disclosure of PHI — even accidental and even to a trusted partner — must be reported to the privacy officer so it can be assessed and documented. The analyst is not authorized to make the breach determination or to close the incident; only the privacy officer can evaluate whether notification obligations apply. The recipient's verbal agreement to delete the email does not eliminate the disclosure event or the reporting requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the access control list to prevent similar mistakes.
Why it's wrong here
Access control lists govern mailbox and resource permissions, not misaddressed outbound email, so they cannot remediate this disclosure. It tempts as a preventive hardening step, and would be correct if the root cause were unauthorised access rather than an accidental send.
- ✗
Do nothing further since the data was deleted.
Why it's wrong here
The policy requires reporting any potential breach, even if data is retrieved.
- ✗
Send a warning email to the employee without reporting.
Why it's wrong here
The email disclosed PHI to an unauthorised recipient, so the incident is a reportable potential breach regardless of the recipient's trustworthiness or deletion promise. Warning the employee privately suppresses the mandated notification. The analyst must escalate to the privacy officer; employee discipline is a separate, later matter.
- ✓
Report the incident as a data breach to the privacy officer as per policy.
Why this is correct
Policy mandates immediate reporting of any potential breach involving PHI, regardless of recipient trustworthiness or deletion. The analyst must not self-assess severity; the privacy officer determines notification obligations, so reporting preserves compliance and the audit trail.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.