A security analyst at a healthcare company is triaging an alert generated by an AI-based anomaly detection system. The alert flags a nurse who accessed 800 patient records in 4 hours. Before escalating as a potential insider threat, what contextual factor is most important to check?
- A.Whether the records accessed are in the nurse's usual ward, since cross-ward access is always suspicious; false positive rates fall automatically as alert volume grows, because online learning converges on the analyst's preferences without labeled feedback
- B.Whether the nurse was working a mass-casualty shift, covering multiple wards, or performing a legitimate bulk record export for a quality improvement audit - all of which would explain the volume without indicating malicious activity
- C.Whether the nurse has ever accessed more than 100 records in a single shift before