Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: A large healthcare organization is subject to…

A large healthcare organization is subject to both HIPAA and GDPR. They are creating a data retention policy for electronic protected health information (ePHI) concerning European patients. HIPAA requires retention for 6 years from creation or last effective date, while GDPR requires that personal data not be kept longer than necessary for the purpose, with a general guideline of retaining for the duration of the relationship plus a reasonable period. The organization wants to minimize storage costs while ensuring compliance. Which approach should they take?

⚠ Common exam trap

A common mix-up: candidates assume they must choose a single retention period (the longer or shorter) to satisfy both regulations, rather than recognizing that a tiered classification approach is the only way to meet conflicting requirements simultaneously.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a tiered retention policy based on data classification

A tiered retention policy based on data classification allows the organization to apply different retention periods to different categories of ePHI, satisfying both HIPAA's 6-year minimum for medical records and GDPR's principle of storage limitation. This approach minimizes storage costs by deleting data that is no longer necessary for the original purpose (e.g., billing records after the statutory period) while retaining data that must be kept longer (e.g., patient treatment records). It avoids the all-or-nothing trap of picking a single regulatory timeline, which would either violate GDPR (if retaining too long) or HIPAA (if deleting too soon).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Retain data for the longer of the two regulatory requirements (HIPAA 6 years)

    Why it's wrong here

    Applying a blanket retention period based on the longer of the two regulatory requirements, such as HIPAA's 6-year minimum, to all data is often inefficient and non-compliant with other regulations. This approach leads to over-retention of data not specifically covered by HIPAA, increasing storage costs, expanding the attack surface, and directly violating GDPR's 'storage limitation' principle, which mandates data be kept only as long as necessary for its processing purpose. Such over-retention can result in significant fines under GDPR.

  • Implement a tiered retention policy based on data classification

    Why this is correct

    Implementing a tiered retention policy based on data classification is the most effective and compliant strategy for organizations operating under multiple regulatory frameworks like HIPAA and GDPR. This approach allows for granular, specific retention periods to be applied to different data types based on their sensitivity, purpose, and the most stringent applicable legal or business requirements. For example, ePHI might adhere to HIPAA's 6-year rule, while marketing data for EU citizens could be deleted much sooner, optimizing resources and ensuring compliance with both regulations.

  • Retain all data indefinitely

    Why it's wrong here

    Retaining all data indefinitely is a severe violation of modern data privacy regulations, particularly GDPR's 'storage limitation' principle (Article 5(1)(e)), which explicitly prohibits keeping personal data for longer than necessary. This practice not only incurs excessive storage costs and complicates data management but also significantly expands the scope of data subject to potential breaches, increasing the organization's legal and financial risk profile. It is an unsustainable and non-compliant data governance strategy.

  • Retain data for the shorter requirement (GDPR-defined necessity period)

    Why it's wrong here

    Retaining data solely for the shorter, GDPR-defined necessity period would likely result in non-compliance with specific, longer retention mandates from other regulations like HIPAA. For instance, HIPAA requires certain administrative documentation, such as policies, procedures, and breach notifications, to be retained for a minimum of six years from their creation or last effective date. Deleting ePHI or related records prematurely based only on GDPR's 'as long as necessary' principle would expose the organization to significant HIPAA penalties and legal liabilities.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.