Courseiva
AI Governance and Ethics →mediumMultiple Choice

AI0-001 AI Governance and Ethics Practice Question

A healthcare AI startup is developing a model to predict patient readmission risk. The model will be used to allocate post-discharge resources. Which regulatory framework primarily governs the use of patient data in this scenario?

⚠ Common exam trap

CompTIA AI+ often tests the distinction between data privacy regulations (HIPAA, GDPR, CCPA) and AI-specific regulations (EU AI Act). Candidates may incorrectly assume the EU AI Act governs all AI data use, but the underlying data type (healthcare PHI) dictates the primary framework.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HIPAA

HIPAA (Health Insurance Portability and Accountability Act) is the correct regulatory framework because the scenario involves a healthcare AI startup using protected health information (PHI) to predict patient readmission risk. HIPAA governs the use, disclosure, and safeguarding of PHI by covered entities and their business associates, which includes AI models processing patient data for post-discharge resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GDPR

    Why it's wrong here

    GDPR governs processing of personal data for EU data subjects; it does not specifically regulate US healthcare providers handling protected health information. It is tempting because patient data is personal data, but in a US clinical setting HIPAA, not GDPR, is the primary framework governing that data's use.

  • ✗

    CCPA

    Why it's wrong here

    CCPA governs California consumer privacy, not protected health information held by covered entities; it exempts HIPAA-regulated data. It is tempting because CCPA does cover some health-adjacent data, and would be correct for a consumer app handling California residents' personal information outside healthcare provider contexts.

  • ✓

    HIPAA

    Why this is correct

    HIPAA governs protected health information held by covered entities and their business associates, so it directly constrains how the startup handles patient records for readmission prediction. Its Privacy and Security Rules dictate permissible use, disclosure and safeguarding of that data, satisfying the stem's requirement for the framework primarily regulating patient data in US healthcare.

  • ✗

    EU AI Act

    Why it's wrong here

    The EU AI Act classifies risk and imposes obligations on AI systems placed on the EU market, but it does not govern the use of patient data itself. It is tempting because readmission prediction may be high-risk, and the Act would be the correct framework for an AI system deployed in the EU.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.