CPA · Question 09 · Area II: Security
A healthcare provider stores patient records in a cloud database. To comply with HIPAA, they must ensure that even if the database storage media is stolen, the data remains unreadable. Which control is MOST appropriate to address this specific risk?
Answer options:
Encryption in transit
Encryption at rest
Tokenization
Multi-Factor Authentication (MFA)
82 questions · hints · full answers · grading