You have been hired as a Data Protection Officer in a large organization. One of the underlined responsibilities is ensuring the patient records’ security. The issue is that management has no appreciation of specific security issues regarding patient records.
The Board has provided the management with some specific considerations that are listed as questions below:
- What exactly can be considered as the Confidentiality, Integrity, and Availability issues that will be faced in securing patient records
- What precautions must be put in place to ensure the protection of stored data and data in motion for these patient records
- What would represent a suitable risk mitigation approach for at least one identified risk associated with patient records
- What are the OWASP provisions that speak to how the health care records could be compromised
- There is a Health care legislation referred to as HIPAA that can be used to guide the protection of the patient record
Complete Answer: