CRISC Information Technology and Security Practice Question
A hospital's radiology department wants to let contracted teleradiologists read CT scans from home. The scans contain protected health information (PHI) and must remain within the hospital's HIPAA compliance boundary. The CIO asks the risk practitioner to recommend an access approach that minimizes the risk of PHI residing on unmanaged personal devices. Which of the following is the BEST recommendation?
⚠ Common exam trap
The trap here is assuming that encryption on a laptop or VPN transport alone satisfies HIPAA, when the real exposure is PHI stored on devices the organization does not control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide teleradiologists with virtual desktop infrastructure (VDI) sessions hosted in the hospital's data center, with local drive and clipboard redirection disabled.
Centralizing PHI in hospital-controlled infrastructure while presenting only a remote display is the most effective way to keep protected health information off unmanaged endpoints. Virtual desktop infrastructure with drive and clipboard redirection disabled preserves clinical workflow yet blocks the common exfiltration paths of copy, print, and local save. Endpoint-centric alternatives leave PHI resident outside the compliance boundary and are far harder to govern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provide teleradiologists with virtual desktop infrastructure (VDI) sessions hosted in the hospital's data center, with local drive and clipboard redirection disabled.
Why this is correct
VDI keeps PHI inside the hospital-controlled data center because only pixels are streamed to the endpoint, and disabling drive and clipboard redirection prevents scans from being copied to unmanaged home devices. This directly limits data-at-rest exposure while preserving the teleradiology workflow, making it the strongest control for the stated risk.
- ✗
Issue each teleradiologist a hospital-owned laptop with full-disk encryption and require them to sign an acceptable use policy.
Why it's wrong here
A hospital-owned encrypted laptop reduces some risk, but PHI is still stored and processed locally on a device that leaves the compliance boundary and sits in an uncontrolled home network. Encryption protects against device theft only; it does not prevent malware, screen capture, or unapproved copies, so it is weaker than keeping data centralized.
- ✗
Publish the CT images to a password-protected cloud file-sharing folder and email time-limited download links to each teleradiologist.
Why it's wrong here
Emailing download links and hosting PHI in a general-purpose file-sharing service spreads identifiable data to third-party infrastructure and endpoint downloads without a business associate agreement governing image handling. Once downloaded, the files persist on unmanaged devices, directly contradicting the requirement to minimize PHI on personal equipment.
- ✗
Grant teleradiologists VPN access to the PACS and let them install the vendor's diagnostic viewer on their personal computers.
Why it's wrong here
A VPN encrypts data in transit but the diagnostic viewer caches and stores PHI locally on personal computers the hospital does not manage or audit. This creates uncontrolled copies of PHI outside the compliance boundary and is difficult to remediate when a contractor leaves, so it does not meet the objective.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.