hardMultiple ChoiceObjective-mapped
CISSP Practice Question: A large healthcare organization is subject to…
A large healthcare organization is subject to both HIPAA and GDPR. They are creating a data retention policy for electronic protected health information (ePHI) concerning European patients. HIPAA requires retention for 6 years from creation or last effective date, while GDPR requires that personal data not be kept longer than necessary for the purpose, with a general guideline of retaining for the duration of the relationship plus a reasonable period. The organization wants to minimize storage costs while ensuring compliance. Which approach should they take?
⚠ Common exam trap
A common mix-up: candidates assume they must choose a single retention period (the longer or shorter) to satisfy both regulations, rather than recognizing that a tiered classification approach is the only way to meet conflicting requirements simultaneously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a tiered retention policy based on data classification
A tiered retention policy based on data classification allows the organization to apply different retention periods to different categories of ePHI, satisfying both HIPAA's 6-year minimum for medical records and GDPR's principle of storage limitation. This approach minimizes storage costs by deleting data that is no longer necessary for the original purpose (e.g., billing records after the statutory period) while retaining data that must be kept longer (e.g., patient treatment records). It avoids the all-or-nothing trap of picking a single regulatory timeline, which would either violate GDPR (if retaining too long) or HIPAA (if deleting too soon).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retain data for the longer of the two regulatory requirements (HIPAA 6 years)
Why it's wrong here
Applying a blanket retention period based on the longer of the two regulatory requirements, such as HIPAA's 6-year minimum, to all data is often inefficient and non-compliant with other regulations. This approach leads to over-retention of data not specifically covered by HIPAA, increasing storage costs, expanding the attack surface, and directly violating GDPR's 'storage limitation' principle, which mandates data be kept only as long as necessary for its processing purpose. Such over-retention can result in significant fines under GDPR.
- ✓
Implement a tiered retention policy based on data classification
Why this is correct
Implementing a tiered retention policy based on data classification is the most effective and compliant strategy for organizations operating under multiple regulatory frameworks like HIPAA and GDPR. This approach allows for granular, specific retention periods to be applied to different data types based on their sensitivity, purpose, and the most stringent applicable legal or business requirements. For example, ePHI might adhere to HIPAA's 6-year rule, while marketing data for EU citizens could be deleted much sooner, optimizing resources and ensuring compliance with both regulations.
- ✗
Retain all data indefinitely
Why it's wrong here
Retaining all data indefinitely is a severe violation of modern data privacy regulations, particularly GDPR's 'storage limitation' principle (Article 5(1)(e)), which explicitly prohibits keeping personal data for longer than necessary. This practice not only incurs excessive storage costs and complicates data management but also significantly expands the scope of data subject to potential breaches, increasing the organization's legal and financial risk profile. It is an unsustainable and non-compliant data governance strategy.
- ✗
Retain data for the shorter requirement (GDPR-defined necessity period)
Why it's wrong here
Retaining data solely for the shorter, GDPR-defined necessity period would likely result in non-compliance with specific, longer retention mandates from other regulations like HIPAA. For instance, HIPAA requires certain administrative documentation, such as policies, procedures, and breach notifications, to be retained for a minimum of six years from their creation or last effective date. Deleting ePHI or related records prematurely based only on GDPR's 'as long as necessary' principle would expose the organization to significant HIPAA penalties and legal liabilities.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.