100-160 Question 253
Single answerA healthcare organization suspects a data breach involving patient records. Under which compliance framework are they required to notify affected individuals and report the breach to the appropriate authority within a specified timeframe?
- A
GDPR (General Data Protection Regulation)
- B
HIPAA (Health Insurance Portability and Accountability Act)
- C
PCI-DSS (Payment Card Industry Data Security Standard)
- D
FERPA (Family Educational Rights and Privacy Act)
Show answer and explanation
Correct answer: B
Explanation
HIPAA is the correct compliance framework because it is specific to the healthcare industry in the United States. Under HIPAA's Breach Notification Rule, healthcare organizations must notify affected individuals, the Department of Health and Human Services (HHS), and in some cases, the media, depending on the size of the breach. Other compliance frameworks like GDPR, PCI-DSS, and FERPA have different scopes and do not specifically address the requirements for healthcare data breaches.
- A. Incorrect.
GDPR applies to the protection of personal data for individuals in the European Union and requires breach notifications, but it is not specific to healthcare organizations.
- B. Correct.
HIPAA is specific to the healthcare industry in the United States and mandates breach notifications when patient health information is compromised.
- C. Incorrect.
PCI-DSS focuses on protecting payment card information and does not address healthcare or patient records.
- D. Incorrect.
FERPA protects the privacy of student education records but does not apply to healthcare organizations or patient records.