CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A healthcare organization is developing a new mobile application for patient data access. The project team is considering various security frameworks to guide their development process. They need a framework that provides detailed guidance on securing personal health information (PHI) and ensuring compliance with healthcare-specific regulations. Which of the following frameworks would be MOST appropriate for this context?

  1. APCI DSS
  2. BCOBIT 5
  3. CHIPAA Security Rule
  4. DISO/IEC 27001
Show answer & explanation

Correct answer: C. HIPAA Security Rule

The HIPAA Security Rule specifically addresses the safeguards required to protect electronic protected health information (ePHI) and is mandated for healthcare organizations in the US.

Why the other options are wrong

  • A. PCI DSS (Payment Card Industry Data Security Standard) is for securing credit card data, not personal health information.
  • B. COBIT 5 is an IT governance and management framework, broader than just security and not specific to healthcare data.
  • D. ISO/IEC 27001 is a general information security management system standard, not specific to healthcare data or regulations.

HIPAA Security Rule

A US federal law that establishes national standards to protect individuals' electronic protected health information (ePHI) that is created, received, used, or maintained by a covered entity.

  • Mandatory for US healthcare entities.
  • Focuses on administrative, physical, and technical safeguards.
  • Ensures confidentiality, integrity, and availability of ePHI.

Memory trick: For 'Health' data, 'HIPAA' is the 'Hero'.

More Information Technology and Security questions