Q: 6
A healthcare provider is storing patient medical records in the cloud. They must ensure that the data is
encrypted both in transit and at rest, and that encryption keys are securely managed to comply with
regulatory requirements such as HIPAA. Which strategy should the healthcare provider implement to
best meet these requirements?
Options
Discussion
D , saw a super similar question in a practice set and it was all about showing compliance. SSL/TLS + customer-managed keys checks both HIPAA and encryption needs.
I picked C because asymmetric encryption seems stronger for key management, and IPSec does encrypt in transit. But now I’m realizing customer-managed keys in D probably match HIPAA compliance better. Anyone else thought C looked close?
Its D for sure, official study guides and cloud provider docs both cover customer-managed keys and SSL/TLS as HIPAA best practices.
D, If the keys are managed by the customer for server-side encryption, that covers HIPAA’s control requirements, but only if implemented properly.
Probably D-SSL/TLS covers in-transit encryption and server-side encryption with customer-managed keys fits HIPAA by giving control over the key lifecycle. Saw a similar question in other exam reports. Makes sense for compliance.
Be respectful. No spam.