CompTIA Project+ (PK0-005)Basics of IT and GovernanceEasy

A project involves deploying a new patient management system for a hospital. The system will store highly sensitive patient health information. Which regulation is MOST likely to directly impact the project's data privacy and security requirements in the United States?

  1. AHIPAA
  2. BCCPA
  3. CSOX
  4. DGDPR
Show answer & explanation

Correct answer: A. HIPAA

HIPAA (Health Insurance Portability and Accountability Act) is the primary U.S. federal law governing the privacy and security of patient health information.

Why the other options are wrong

  • B. CCPA (California Consumer Privacy Act) is a California state law focused on consumer data privacy.
  • C. SOX (Sarbanes-Oxley Act) primarily deals with corporate financial reporting and governance.
  • D. GDPR (General Data Protection Regulation) is a European Union regulation.

HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that protects sensitive patient health information from being disclosed without the patient's consent or knowledge.

  • Applies to Covered Entities (e.g., healthcare providers, health plans) and Business Associates.
  • Establishes national standards for electronic healthcare transactions.
  • Includes the Privacy Rule and the Security Rule to protect Protected Health Information (PHI).

Memory trick: HIPAA: Health Info, Private Always, US-based Act.

More Basics of IT and Governance questions