ボブは最近、大規模なサイバー セキュリティ侵害を経験した医療会社に雇われました。多くの患者が、個人の医療記録がインターネット上で完全に公開されており、誰でも Google 検索で簡単に見つけられると不満を言っています。ボブの上司は、それらのデータを保護する規制について非常に心配しています。次の規制のうち、最も違反されているのはどれですか。
正解:A
HIPPA/PHI is the regulation that is mostly violated in the above scenario. HIPPA (Health Insurance Portability and Accountability Act) is a US federal law that sets standards for protecting the privacy and security of health information. PHI (Protected Health Information) is any information that relates to the health or health care of an individual and that can identify the individual, such as name, address, medical records, etc.
HIPPA/PHI requires covered entities, such as health care providers, health plans, or health care clearinghouses, and their business associates, to safeguard PHI from unauthorized access, use, or disclosure .
In the scenario, the medical company experienced a major cyber security breach that exposed the personal medical records of many patients on the internet, which violates HIPPA/PHI regulations. PII (Personally Identifiable Information) is any information that can be used to identify a specific individual, such as name, address, social security number, etc. PII is not specific to health information and can be regulated by various laws, such as GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), etc.
PCI DSS (Payment Card Industry Data Security Standard)is a set of standards that applies to entities that store, process, or transmit payment card information, such as merchants, service providers, or payment processors.
PCI DSS requires them to protect cardholder data from unauthorized access, use, or disclosure. ISO 2002 (International Organization for Standardization 2002) is not a regulation, but a standard for information security management systems that provides guidelines and best practices for organizations to manage their information security risks.