During a penetration test of a healthcare provider's network, you capture unencrypted traffic containing what appears to be patient names, dates of birth, and diagnosis codes. Your engagement scope covers network security testing but does not explicitly mention PHI handling procedures. What is your MOST appropriate immediate action?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AWaiting until the end of testing leaves regulated health data exposed and unreported for days, which breaks the duty to escalate sensitive discoveries promptly.
- BDeleting captured data on your own destroys evidence the client may need for breach assessment, and the decision belongs to the client, not the tester.
- CWritten authorization for network testing does not cover handling protected health information, so continuing as planned ignores a scope gap you just found.
- DCorrect: stopping the capture, preserving what was collected with chain of custody and escalating to the compliance officer protects patients, evidence and the client's obligations.