While assessing a healthcare application, a penetration tester discovers unprotected database tables containing Protected Health Information (PHI). The tester hashes the data locally to use as proof of exploit. Which statement about compliance is MOST accurate?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ALiability does not hinge on moving hashed records off the network; accessing PHI at all brings regulatory duties that apply wherever the data sits.
- BHashing transforms the tester's copy but does not undo the exposure or satisfy the client's obligations under privacy rules such as HIPAA.
- CCorrect: discovering exposed PHI still requires the agreed escalation path and lets the client assess its HIPAA reporting and breach-notification duties, whatever the tester does with the evidence.
- DContacting federal law enforcement is not a mandatory first step for a finding in an authorized test, and it would not block remediation of the exposed tables.