A healthcare organization must comply with HIPAA. Which of the following is a key requirement for protecting electronic protected health information (ePHI)?
Trap 1: Data masking for all patient data
Data masking is not specifically mandated by HIPAA; encryption is the primary control.
Trap 2: Annual penetration testing
Penetration testing is not specifically mandated by HIPAA.
Trap 3: Public key infrastructure for all users
PKI is not explicitly required; alternative controls may be acceptable.
- A
Data masking for all patient data
Why it fails: Data masking is not specifically mandated by HIPAA; encryption is the primary control.
- B
Encryption of ePHI at rest and in transit
HIPAA Security Rule includes encryption as an addressable specification for ePHI.
- C
Annual penetration testing
Why it fails: Penetration testing is not specifically mandated by HIPAA.
- D
Public key infrastructure for all users
Why it fails: PKI is not explicitly required; alternative controls may be acceptable.