CRISC Information Technology and Security Practice Question
A hospital's risk practitioner is evaluating a new telehealth platform that will process protected health information (PHI). The platform will be hosted by a third-party vendor. Which of the following is the MOST critical risk to address during contract negotiations?
⚠ Common exam trap
The trap here is focusing on operational issues like uptime or data location, while overlooking the contractual need to transfer or share liability for PHI breaches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vendor's data breach notification timeline and liability for regulatory penalties.
When a third party processes PHI, the hospital must ensure the business associate agreement clearly assigns responsibility for breach notification and regulatory penalties. This contractual protection is the most critical risk treatment because it directly addresses the hospital's legal and financial exposure under HIPAA. Other concerns like subcontractors, uptime, and data residency are important but secondary to the allocation of liability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor's service level agreement (SLA) for platform uptime.
Why it's wrong here
Uptime is important for clinical operations, but it is an availability risk, not the most critical risk when PHI is involved. A breach of PHI can trigger massive regulatory fines, lawsuits, and loss of patient trust. The contract's breach notification and liability clauses directly address the legal and financial exposure that the hospital cannot transfer away.
- ✗
The vendor's use of subcontractors to support the platform.
Why it's wrong here
Subcontractor use is a legitimate concern that requires flow-down of security and privacy obligations, but it is a secondary risk. The most critical issue is whether the vendor will accept legal responsibility for safeguarding PHI and complying with HIPAA. Without a clear allocation of liability and breach notification duties, the hospital could bear full regulatory and financial consequences.
- ✓
The vendor's data breach notification timeline and liability for regulatory penalties.
Why this is correct
Under HIPAA, the covered entity remains responsible for PHI even when a business associate handles it. The contract must define when and how the vendor will notify the hospital of a breach and who bears the cost of regulatory penalties and patient notifications. Without these terms, the hospital faces unmitigated financial and reputational risk.
- ✗
The vendor's geographic location and data residency practices.
Why it's wrong here
Data residency can affect compliance with state laws and cross-border transfer restrictions, but it is not the foremost risk. Even if data stays in-country, a breach can still occur. The hospital's primary concern is ensuring the vendor is contractually obligated to notify and indemnify the hospital for breaches, which is more fundamental than location.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.