CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

An organization is preparing its annual compliance report for HIPAA. A cybersecurity analyst is tasked with providing evidence of ongoing security monitoring and incident detection capabilities. Which of the following log snippets, if consistently collected and reviewed, would BEST demonstrate adherence to HIPAA's security rule regarding audit controls and incident detection?

  1. ALog Snippet 1: ``` 2023-10-26 14:35:01 User: jsmith@example.com logged in from IP: 192.168.1.10 ```
  2. BLog Snippet 4: ``` 2023-10-26 14:38:20 Antivirus: Scan completed on workstation_007. Threats found: 0 ```
  3. CLog Snippet 2: ``` 2023-10-26 14:36:15 Firewall: Blocked connection from 203.0.113.44 to internal_server on port 3389 (RDP) ```
  4. DLog Snippet 3: ``` 2023-10-26 14:37:05 EHR_System: Access denied for user: jsmith@example.com to patient_record_12345 (insufficient privileges) ```
Show answer & explanation

Correct answer: D. Log Snippet 3: ``` 2023-10-26 14:37:05 EHR_System: Access denied for user: jsmith@example.com to patient_record_12345 (insufficient privileges) ```

HIPAA's Security Rule (45 CFR Part 164.308(a)(1)(ii)(D) and 164.312(b)) emphasizes audit controls to record and examine information system activity. A log indicating 'Access denied for user... to patient_record_12345 (insufficient privileges)' directly demonstrates that access controls are enforced, audit trails are being generated, and potential unauthorized access attempts to Protected Health Information (PHI) are being detected and logged, which is crucial for compliance and incident detection.

Why the other options are wrong

  • A. A successful login is a routine event and doesn't directly show incident detection or access control enforcement related to PHI access attempts.
  • B. An antivirus scan completion log is a preventative measure, not directly related to audit controls for PHI access or incident detection of unauthorized access attempts.
  • C. A blocked firewall connection shows perimeter defense, but not necessarily internal system audit control or attempts to access PHI.

HIPAA Audit Controls Evidence

Evidence demonstrating that organizations record and examine information system activity, especially related to Protected Health Information (PHI) access.

  • Required by HIPAA Security Rule.
  • Involves logging access attempts, modifications, and security events.
  • Crucial for detecting and investigating security incidents involving PHI.

Memory trick: HIPAA needs logs that show who TRIED to see patient data and got STOPPED.

More Reporting and Communication questions