A penetration tester working for a hospital must comply with which federal regulation protecting patient health information?

Prepare for the EC-Council Certified Ethical Hacker (CEH) Certification. Master concepts with flashcards and multiple choice questions, each enriching your understanding. Ready yourself to succeed in your exam!

Multiple Choice

A penetration tester working for a hospital must comply with which federal regulation protecting patient health information?

Explanation:
Protecting patient health information is governed by HIPAA. In a hospital, PHI must be kept confidential and secure, with the Security Rule outlining administrative, physical, and technical safeguards, plus procedures for risk assessments and breach responses. A penetration tester hired by a hospital operates under HIPAA rules, and any access to PHI during testing should be covered by a Business Associate Agreement that defines permissible activities and safeguards. GLBA targets financial information, FERPA covers student education records, and SOX focuses on financial reporting and corporate governance. Therefore, HIPAA is the federal regulation that protects patient health information.

Protecting patient health information is governed by HIPAA. In a hospital, PHI must be kept confidential and secure, with the Security Rule outlining administrative, physical, and technical safeguards, plus procedures for risk assessments and breach responses. A penetration tester hired by a hospital operates under HIPAA rules, and any access to PHI during testing should be covered by a Business Associate Agreement that defines permissible activities and safeguards.

GLBA targets financial information, FERPA covers student education records, and SOX focuses on financial reporting and corporate governance. Therefore, HIPAA is the federal regulation that protects patient health information.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy