The correct answer is A because the incident involves PHI — protected health information. Healthcare organizations are subject to regulatory requirements such as HIPAA, and incidents involving unauthorized access to PHI commonly require regulatory reporting and notification to affected individuals.
Exact supporting extract: the Secbay CySA+ guide states that some regulations require organizations to report incidents and notify affected individuals when privacy-impacting incidents occur. It also gives the specific example of a healthcare organization experiencing a breach of patient records and explains that reporting to regulatory authorities and notifying affected individuals demonstrates compliance, accountability, and transparency.
Another exact supporting extract states that PHI includes medical records and must be protected in specific ways under HIPAA. It also states that incident response should coordinate with regulatory bodies for industries such as healthcare.
The official CompTIA CySA+ CS0-003 objectives also place this under incident response reporting and communication, including legal, public relations/customer communication, regulatory reporting, and law enforcement.
Why the other options are incorrect:
B is incorrect because patient notification is not primarily done to appease stakeholders.
C is partially related, but not the best answer. The direct reason is regulatory compliance.
D is incorrect because communicating with patients is separate from communicating with law enforcement.