問題文
A hospital's analytics team wants to add a field that records whether a patient is enrolled in a substance-use treatment program. From a privacy governance standpoint, which consequence should the engineer plan for before the field is added?
選択肢
- The field is acceptable if the analytics team commits in writing to use it only for aggregate reporting, because the purpose limitation recorded in that commitment is what determines the level of protection that the data requires.
- The field can be added under the existing controls, because the treatment program name is not an identifier and therefore does not change the sensitivity of the record.
- The field raises the impact level of the whole record, so the access, logging, and retention controls for that table have to be tightened, not just the new column.
- The field should be stored as a one-way hash so that the value cannot be read, which removes the need to change the surrounding controls or to revisit who may query the table.