A United States healthcare provider operates a web portal that allows patients to view medical records and pay out-of-pocket expenses using credit cards. Which of the following regulatory compliance frameworks must the organization adhere to in order to protect patient health records and credit card transactions? (Select TWO.)
- Health Insurance Portability and Accountability Act (HIPAA)Cevap
- Payment Card Industry Data Security Standard (PCI-DSS)Cevap
- CSarbanes-Oxley Act (SOX)
- DFamily Educational Rights and Privacy Act (FERPA)
Cevap
Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI-DSS) are the required compliance standards.
The Health Insurance Portability and Accountability Act (HIPAA) governs the privacy and security of patient medical records (PHI). The Payment Card Industry Data Security Standard (PCI-DSS) is an industry mandate required for any organization processing credit card payments. Because the web portal handles both medical records and payment card transactions, both frameworks apply.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Scope and Data Protection Frameworks
Tahmini Süre:1m 0s