100-160 Question 254
Single answerA healthcare organization is implementing a new patient data management system. As part of the deployment, the IT team is ensuring compliance with relevant regulations. Which compliance framework mandates the protection of patient health information (PHI) and requires breach notifications to affected individuals within a specific timeframe?
- A
GDPR
- B
HIPAA
- C
PCI-DSS
- D
FERPA
Show answer and explanation
Correct answer: B
Explanation
HIPAA is the correct answer because it is specifically designed to protect patient health information (PHI) and includes requirements for breach notifications to affected individuals. GDPR, PCI-DSS, and FERPA are compliance frameworks focused on other types of data protection that do not specifically address PHI or healthcare-specific reporting and notification requirements.
- A. Incorrect.
GDPR (General Data Protection Regulation) is a European Union framework focused on the protection of personal data and privacy for EU citizens. While it includes breach notification requirements, it does not specifically address patient health information (PHI).
- B. Correct.
HIPAA (Health Insurance Portability and Accountability Act) is a U.S. compliance framework that strictly governs the protection of patient health information (PHI). It also requires organizations to notify individuals affected by a data breach within 60 days of discovery.
- C. Incorrect.
PCI-DSS (Payment Card Industry Data Security Standard) is a framework designed to protect payment card information and does not govern patient health information (PHI) or include breach notification requirements for healthcare data.
- D. Incorrect.
FERPA (Family Educational Rights and Privacy Act) is a U.S. framework focused on protecting student education records, not patient health information (PHI).