ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A healthcare provider is developing a new mobile application for patients to access their medical records. The application will store sensitive patient health information (PHI). Before launching, the provider must ensure compliance with HIPAA regulations. Which aspect of security is primarily being addressed by focusing on HIPAA compliance?
- ALegal and regulatory requirements
- BPrivacy
- CEthics
- DData protection
Show answer & explanationAnswer & explanation
Correct answer: A. Legal and regulatory requirements
HIPAA (Health Insurance Portability and Accountability Act) is a specific federal law that mandates security and privacy standards for healthcare data. Therefore, ensuring compliance with HIPAA directly addresses legal and regulatory requirements.
Why the other options are wrong
- B. Privacy is a concept HIPAA helps enforce, but HIPAA itself is a specific legal requirement.
- C. Ethics relates to moral principles, which are broader than specific legal mandates.
- D. Data protection is a broad goal, which HIPAA contributes to, but HIPAA itself is a regulation.
Legal and Regulatory Requirements
Mandatory laws, regulations, and standards established by governmental bodies or industry organizations that an entity must comply with.
- Non-compliance can lead to severe penalties, fines, and legal action.
- Examples include GDPR, HIPAA, PCI DSS, SOX.
- Often drive the implementation of specific security controls and practices.
Memory trick: Laws must be followed, Ethics are your compass, Privacy is personal, Data protection is the shield.