hardMultiple Choice
CCSP Practice Question: A healthcare company uses a cloud-based patient…
A healthcare company uses a cloud-based patient management system. The cloud provider experiences a security incident that may have exposed protected health information (PHI). The provider notifies the company within 72 hours, as required by the service agreement. The company's internal breach response policy requires a legal review of the incident before notifying affected individuals. The legal review typically takes 48 hours. However, the company is required to notify patients within 60 days under HIPAA. With the 72-hour notification from the provider, the company has 60 days to notify patients. What is the most effective approach to meet the 60-day notification requirement while ensuring compliance with internal policy?
⚠ Common exam trap
ISC2 often tests the misconception that you must choose between compliance and internal policy, when in fact parallel processing of legal review and notification preparation is the correct approach to meet both requirements without violating the 60-day HIPAA deadline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Begin the legal review immediately and prepare patient notification in parallel.
It allows the company to satisfy both the HIPAA 60-day notification requirement and its internal legal review policy by running the legal review and patient notification preparation concurrently. This parallel approach minimizes delay while ensuring that the notification content is legally vetted before release, which is critical for PHI incidents under HIPAA's Breach Notification Rule (45 CFR § 164.404).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify patients immediately and then perform the legal review.
Why it's wrong here
Notifying before legal review breaches the internal policy that mandates review first, and premature disclosure risks inaccurate statements. It is tempting because speed appears safest, and would be correct only where regulation demanded notification faster than the 48-hour review allowed.
- ✗
Wait for the legal review to complete before notifying patients.
Why it's wrong here
Waiting for legal review before notifying patients delays notification and risks breaching the 60-day HIPAA deadline if review overruns. Legal review is tempting because internal policy demands it, and it would be correct where no regulatory notification clock applies or where the deadline comfortably exceeds review time.
- ✗
Notify patients immediately based on the provider's notification.
Why it's wrong here
Notifying on the provider's word alone skips the mandated legal review, which determines whether the incident is a reportable breach at all. It is tempting because HIPAA permits 60 days, and immediate notification would be correct only if the review could not finish within that window.
- ✓
Begin the legal review immediately and prepare patient notification in parallel.
Why this is correct
Running the legal review concurrently with notification preparation uses the 72-hour provider notice and 60-day HIPAA window efficiently. Sequential review would consume 48 hours unnecessarily, yet parallel work still preserves the required legal approval before patients are contacted.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.