Courseiva

Hybrid Cloud for HIPAA Compliance: Keeping PHI On-Premises While Scaling with Public Cloud

A healthcare organization must store electronic health records in a cloud environment that meets HIPAA compliance requirements. The organization wants to keep sensitive patient data on-premises servers while using cloud resources for less critical workloads and to handle peak demand. Which cloud deployment model would BEST meet these requirements?

Quick Answer

The answer is hybrid cloud. This model is the correct choice because it allows a healthcare organization to keep protected health information (PHI) on-premises for strict HIPAA compliance while leveraging public cloud resources for less critical workloads and to handle peak demand, effectively balancing data sovereignty with scalability. On the CompTIA A+ Core 1 220-1101 exam, this question tests your understanding of cloud deployment models and their real-world constraints, often appearing as a scenario where you must distinguish hybrid from public or private cloud. A common trap is choosing “private cloud” alone, but that misses the need for scaling with public resources; the key is recognizing the “both-and” requirement. Memory tip: think “Hybrid = Home + Hotel” — keep your valuables (PHI) at home (on-premises), but rent extra space (public cloud) when guests (peak demand) arrive.

⚠ Common exam trap

CompTIA often tests the distinction between hybrid cloud and community cloud, where candidates mistakenly choose community cloud because it sounds 'shared' like healthcare, but the key requirement here is the combination of on-premises and public resources, not just shared infrastructure among similar organizations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hybrid cloud

A hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud resources, allowing the healthcare organization to keep sensitive patient data on-premises for HIPAA compliance while using the public cloud for less critical workloads and to handle peak demand. This architecture provides the necessary data sovereignty and security controls for protected health information (PHI) while offering scalability and cost efficiency for non-sensitive tasks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Public cloud

    Why it's wrong here

    A public cloud places all workloads on shared provider infrastructure, so sensitive patient data would leave the on-premises servers the stem requires. It is tempting because public cloud handles peak demand cheaply, but it cannot satisfy the requirement to retain electronic health records locally.

    When this WOULD be correct

    A public cloud would be correct for a non-healthcare organization that needs to store non-sensitive data with high scalability and low upfront cost, without specific regulatory compliance requirements.

  • ✗

    Private cloud

    Why it's wrong here

    A private cloud dedicates infrastructure to one organisation but does not combine on-premises servers with cloud resources for peak demand. It is tempting because private clouds suit HIPAA-sensitive data, yet the stem's hybrid split between local records and cloud bursting is what hybrid cloud delivers.

    When this WOULD be correct

    A financial institution must store all customer data in a fully isolated environment due to strict regulatory requirements and cannot use any public cloud resources. Which cloud deployment model would best meet these requirements?

  • ✓

    Hybrid cloud

    Why this is correct

    Hybrid cloud keeps electronic health records on on-premises servers, satisfying the HIPAA-driven requirement to retain sensitive patient data locally, while bursting less critical workloads to public cloud capacity for peak demand. This split satisfies both the data-residency constraint and the elasticity requirement simultaneously.

  • ✗

    Community cloud

    Why it's wrong here

    A community cloud is shared by organisations with common concerns, not a mix of on-premises and cloud resources. It is tempting because healthcare providers often form community clouds for HIPAA workloads, but the stem requires sensitive data to remain on-premises alongside cloud bursting, which is hybrid.

    When this WOULD be correct

    A healthcare consortium of multiple hospitals wants to share a cloud environment that meets HIPAA compliance for storing electronic health records, with each hospital having equal control and security requirements. A community cloud would be the best deployment model.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓Hybrid cloudCorrect answer▾

Why this is correct

Hybrid cloud keeps electronic health records on on-premises servers, satisfying the HIPAA-driven requirement to retain sensitive patient data locally, while bursting less critical workloads to public cloud capacity for peak demand. This split satisfies both the data-residency constraint and the elasticity requirement simultaneously.

✗Public cloudWrong answer — click to see why▾

Why this is wrong here

A public cloud alone cannot meet HIPAA compliance requirements for storing sensitive patient data, as it lacks the dedicated control and security assurances needed for protected health information (PHI).

★ When this WOULD be the correct answer

A public cloud would be correct for a non-healthcare organization that needs to store non-sensitive data with high scalability and low upfront cost, without specific regulatory compliance requirements.

Why candidates choose this

Candidates may think public cloud providers offer HIPAA-compliant services, but they overlook that the organization wants to keep sensitive data on-premises, which a pure public cloud cannot accommodate.

✗Private cloudWrong answer — click to see why▾

Why this is wrong here

A private cloud keeps all resources within a single organization's infrastructure, but the question requires keeping sensitive data on-premises while using cloud resources for less critical workloads and peak demand, which necessitates a hybrid model combining on-premises and cloud.

★ When this WOULD be the correct answer

A financial institution must store all customer data in a fully isolated environment due to strict regulatory requirements and cannot use any public cloud resources. Which cloud deployment model would best meet these requirements?

Why candidates choose this

Candidates may think private cloud is the only compliant option for healthcare, overlooking that hybrid cloud can also meet HIPAA by keeping sensitive data on-premises while leveraging public cloud for non-sensitive workloads.

✗Community cloudWrong answer — click to see why▾

Why this is wrong here

A community cloud is shared by several organizations with common concerns, but the question requires keeping sensitive patient data on-premises while using cloud for less critical workloads. A community cloud does not inherently support a hybrid on-premises/cloud split; a hybrid cloud does.

★ When this WOULD be the correct answer

A healthcare consortium of multiple hospitals wants to share a cloud environment that meets HIPAA compliance for storing electronic health records, with each hospital having equal control and security requirements. A community cloud would be the best deployment model.

Why candidates choose this

Candidates may think 'community cloud' fits healthcare because it implies shared compliance among similar organizations, but they overlook the specific requirement for on-premises storage of sensitive data, which is a hybrid cloud characteristic.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1101

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A financial services company must store customer data on-premises due to strict regulatory requirements. However, they want to leverage cloud resources to run analytics on that data during peak reporting periods. The company plans to use a cloud provider that can securely access the on-premises data and provide additional compute capacity only when needed. Which cloud deployment model BEST describes this configuration?

easy
  • A.Public cloud
  • B.Private cloud
  • ✓ C.Hybrid cloud
  • D.Community cloud

Why C: The hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud resources, connected via a secure VPN or dedicated link. This allows the company to keep sensitive customer data on-premises for regulatory compliance while bursting compute-intensive analytics workloads to the public cloud during peak reporting periods, paying only for additional capacity when needed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.