1
Protection of Information Assets
medium
An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?