Soru

Zorluk: Çok zorData Privacy and Compliance Regulations

An IT compliance administrator at a healthcare technology organization is configuring an integrated cloud application. The system manages patient clinical records, processes patient credit card co-payments, and handles registration details for European Union (EU) residents enrolled in international medical trials.

Which of the following regulatory compliance controls MUST the administrator implement to simultaneously satisfy PCI-DSS and GDPR requirements? (Select TWO.)

  1. Isolate the billing sub-network to prevent the post-authorization storage of Sensitive Authentication Data (SAD), such as CVV2/CVC security codes.Cevap
  2. Implement technical mechanisms that allow EU trial participants to request data portability and provide explicit consent before processing their personal records.Cevap
  3. C
    Store encrypted credit card CVV2 security codes within the primary health records database for recurring co-pays, provided AES-256 encryption is applied at rest.
  4. D
    Enforce HIPAA Privacy Rule procedures to govern payment card processing for all patient transactions, replacing PCI-DSS requirements in medical settings.

Cevap

The administrator must isolate the billing processing environment to prevent post-authorization storage of Sensitive Authentication Data (CVV2/CVC) in accordance with PCI-DSS, and implement consent and data portability mechanisms for EU trial participants as required by GDPR.
Adhering to regulatory requirements across multi-functional applications requires respecting the boundaries of each framework. PCI-DSS mandates that Sensitive Authentication Data (CVV2/CVC codes) must never be stored after payment authorization. Simultaneously, GDPR mandates explicit consent and structural mechanisms supporting rights like data portability for EU residents' personal data.

Adım Adım Çözüm

1
Analyze PCI-DSS constraints for payment card processing
PCI-DSS Requirement 3 forbids storing Sensitive Authentication Data (SAD), such as card validation codes (CVV2/CVC), once transaction authorization is complete.
Retaining SAD post-authorization creates severe vulnerability risks and violates PCI-DSS standards regardless of encryption.
2
Analyze GDPR requirements for handling EU resident data
GDPR applies extra-territorially to any entity processing data of EU residents, requiring explicit user consent and technical workflows for rights such as data portability.
EU data protection laws require organizations to empower data subjects with direct control and ownership over their personal information.
3
Evaluate jurisdictional overlap between HIPAA and payment security standards
HIPAA applies strictly to Protected Health Information (PHI) and does not exempt or replace PCI-DSS mandates for payment card infrastructure.
Organizations operating across domains must enforce compliance across all relevant frameworks concurrently.

Anahtar Kavram

Multi-Framework Regulatory Compliance (PCI-DSS & GDPR)
Bu soruyu puanla