100-160 exam dumps

100-160 practice question 250 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 250

Select 2

A healthcare organization has experienced a data breach that exposed sensitive patient information, including medical records and personal details. Which compliance frameworks require the organization to notify affected individuals and relevant authorities about the breach?

  1. A

    HIPAA

  2. B

    GDPR

  3. C

    PCI-DSS

  4. D

    FERPA

  5. E

    FISMA

Show answer and explanation

Correct answers: A, B

Explanation

Both HIPAA and GDPR have explicit breach notification requirements. HIPAA applies to healthcare organizations and requires them to notify affected individuals and authorities about breaches involving protected health information. GDPR applies to organizations handling personal data of EU citizens and requires timely notification of breaches to supervisory authorities and affected individuals if their rights are at risk. PCI-DSS, FERPA, and FISMA do not have explicit breach notification requirements for individuals and authorities in their frameworks.

  • A. Correct.

    HIPAA (Health Insurance Portability and Accountability Act) mandates that covered entities notify affected individuals, the Department of Health and Human Services (HHS), and in some cases the media, about breaches involving protected health information (PHI).

  • B. Correct.

    Under GDPR (General Data Protection Regulation), organizations must notify the supervisory authority within 72 hours of a breach involving personal data and inform affected individuals if the breach poses a high risk to their rights and freedoms.

  • C. Incorrect.

    PCI-DSS (Payment Card Industry Data Security Standard) focuses on securing payment card information and does not specifically mandate breach notification to individuals or authorities.

  • D. Incorrect.

    FERPA (Family Educational Rights and Privacy Act) governs the privacy of student education records and does not include specific breach notification requirements.

  • E. Incorrect.

    FISMA (Federal Information Security Management Act) applies to federal agencies and contractors, and while it emphasizes securing federal information systems, it does not prescribe breach notification requirements to individuals or external authorities.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam