Question

Difficulty: EasyRegulatory Compliance and Legal Requirements Management

A United States healthcare provider operates a web portal that allows patients to view medical records and pay out-of-pocket expenses using credit cards. Which of the following regulatory compliance frameworks must the organization adhere to in order to protect patient health records and credit card transactions? (Select TWO.)

  1. Health Insurance Portability and Accountability Act (HIPAA)Answer
  2. Payment Card Industry Data Security Standard (PCI-DSS)Answer
  3. C
    Sarbanes-Oxley Act (SOX)
  4. D
    Family Educational Rights and Privacy Act (FERPA)

Answer

Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI-DSS) are the required compliance standards.
The Health Insurance Portability and Accountability Act (HIPAA) governs the privacy and security of patient medical records (PHI). The Payment Card Industry Data Security Standard (PCI-DSS) is an industry mandate required for any organization processing credit card payments. Because the web portal handles both medical records and payment card transactions, both frameworks apply.

Step-by-Step Solution

1
Identify the types of sensitive data described in the scenario.
The portal processes Protected Health Information (PHI) and Credit Card Holder Data (CHD).
Regulatory frameworks are determined by the specific categories of data processed and stored by the organization.
2
Match the identified data categories to their corresponding compliance mandates.
PHI falls under HIPAA regulations, while credit card processing falls under PCI-DSS standards.
HIPAA governs healthcare information privacy in the US, while PCI-DSS is required for processing credit card payments.

Key Concept

Regulatory Scope and Data Protection Frameworks
Estimated Time:1m 0s
Rate this question