ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy
A healthcare provider is deploying a new Electronic Health Record (EHR) system. The system will store highly sensitive patient medical information. To comply with HIPAA and other privacy regulations, the organization must ensure that patient data is not used for purposes beyond direct patient care, billing, and healthcare operations without explicit consent. Which privacy principle is primarily being addressed here?
- APurpose limitation
- BData accuracy
- CData minimization
- DStorage limitation
Show answer & explanationAnswer & explanation
Correct answer: A. Purpose limitation
Purpose limitation dictates that personal data collected for a specific, explicit, and legitimate purpose should not be further processed in a manner that is incompatible with those purposes. The scenario directly states that data should not be used for purposes 'beyond direct patient care, billing, and healthcare operations without explicit consent', which is the essence of purpose limitation.
Why the other options are wrong
- B. Data accuracy refers to the correctness and up-to-dateness of the data, not its usage scope.
- C. Data minimization focuses on collecting only the necessary data, not its subsequent use.
- D. Storage limitation addresses how long data is retained, not the purposes for its use.
Purpose Limitation
A privacy principle stating that personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Data usage must align with the initial stated purpose.
- Requires explicit consent for new, incompatible purposes.
- A core principle in regulations like GDPR and HIPAA.
Memory trick: Purpose limits use, like a target's clue.