mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: A healthcare provider is subject to HIPAA…
A healthcare provider is subject to HIPAA regulations. They are planning to use a public cloud provider. Which design consideration is most important to ensure compliance?
⚠ Common exam trap
ISC2 often tests the misconception that technical controls like containerization or multi-cloud strategies are primary compliance tools, when in reality, foundational legal and geographic controls like data residency are the first and most critical step for regulated data in the cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data residency
Data residency is the most critical design consideration for a healthcare provider subject to HIPAA when using a public cloud, because HIPAA requires that protected health information (PHI) be stored and processed only in jurisdictions where the cloud provider can guarantee compliance with the HIPAA Privacy and Security Rules. If the cloud provider replicates data across regions or countries without explicit control, the organization may violate the HIPAA requirement to ensure that PHI is not exposed to unauthorized access or disclosure, and may also breach the Breach Notification Rule if data crosses borders into regions with weaker protections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containerization
Why it's wrong here
Containerization is a deployment technology, not a compliance control.
- ✗
Cost optimization
Why it's wrong here
Cost optimization is important but not the primary compliance driver.
- ✗
Multi-cloud strategy
Why it's wrong here
Multi-cloud strategy can offer flexibility but is not a direct compliance requirement.
- ✓
Data residency
Why this is correct
Data residency ensures data is stored in approved locations, meeting HIPAA requirements.
Go deeper
Related to this question
About these practice questions
One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.