CompTIA Project+ (PK0-005)Basics of IT and GovernanceEasy
A project involves deploying a new patient management system for a hospital. The system will store highly sensitive patient health information. Which regulation is MOST likely to directly impact the project's data privacy and security requirements in the United States?
- AHIPAA
- BCCPA
- CSOX
- DGDPR
Show answer & explanationAnswer & explanation
Correct answer: A. HIPAA
HIPAA (Health Insurance Portability and Accountability Act) is the primary U.S. federal law governing the privacy and security of patient health information.
Why the other options are wrong
- B. CCPA (California Consumer Privacy Act) is a California state law focused on consumer data privacy.
- C. SOX (Sarbanes-Oxley Act) primarily deals with corporate financial reporting and governance.
- D. GDPR (General Data Protection Regulation) is a European Union regulation.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that protects sensitive patient health information from being disclosed without the patient's consent or knowledge.
- Applies to Covered Entities (e.g., healthcare providers, health plans) and Business Associates.
- Establishes national standards for electronic healthcare transactions.
- Includes the Privacy Rule and the Security Rule to protect Protected Health Information (PHI).
Memory trick: HIPAA: Health Info, Private Always, US-based Act.