Soru

Zorluk: OrtaData Privacy and Compliance Regulations

An IT technician is configuring data storage policies and access permissions for an organization that handles both patient intake appointments and billing payment transactions. Which of the following compliance actions directly adhere to the regulatory mandates of the Payment Card Industry Data Security Standard (PCI-DSS) and Health Insurance Portability and Accountability Act (HIPAA)? (Select TWO.)

  1. Encrypting or masking Primary Account Numbers (PAN) stored in transaction logsCevap
  2. Restricting access to patient clinical records and medical history strictly to authorized personnelCevap
  3. C
    Retaining sensitive authentication data such as card verification values (CVV) permanently for auditing purposes
  4. D
    Applying educational privacy guidelines under FERPA to govern the retention of medical appointment logs

Cevap

The correct answers are encrypting or masking Primary Account Numbers (PAN) stored in transaction logs and restricting access to patient clinical records and medical history strictly to authorized personnel.
PCI-DSS mandates the protection of cardholder data by encrypting or masking the Primary Account Number (PAN) during storage and transmission. HIPAA regulates Protected Health Information (PHI), requiring organizations to restrict access to patient medical histories and clinical records strictly to authorized individuals.

Adım Adım Çözüm

1
Identify the data privacy regulations referenced in the scenario
The scenario references PCI-DSS for payment card data and HIPAA for medical information.
Different regulations govern specific categories of sensitive information.
2
Match required security controls to PCI-DSS
PCI-DSS requires safeguarding cardholder data like PAN via encryption/masking and forbids retaining CVV data post-authorization.
PAN protection is a core technical requirement of PCI-DSS.
3
Match required security controls to HIPAA
HIPAA requires confidentiality and strict access controls for Protected Health Information (PHI), such as clinical records.
PHI safeguards prevent unauthorized disclosure of patient health data.

Anahtar Kavram

Data Privacy and Compliance Regulations
Bu soruyu puanla