Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 408 discussion

Actual exam question from ISC's CISSP
Question #: 408
Topic #: 1
[All CISSP Questions]

If a medical analyst independently provides protected health information (PHI) to an external marketing organization, which ethical principal is this a violation of?

  • A. Higher ethic in the worst case
  • B. Informed consent
  • C. Change of scale test
  • D. Privacy regulations
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
l00t
Highly Voted 1 year, 9 months ago
Selected Answer: B
The ethical principle that is violated by a medical analyst who independently provides protected health information (PHI) to an external marketing organization is informed consent. Informed consent is the principle that every medical professional should allow the patient to retain control over their body and their data, and that the patient should be informed of and agree to any use or disclosure of their PHI. By providing PHI to an external organization without the patient’s knowledge and consent, the medical analyst is violating the patient’s right to privacy and autonomy.
upvoted 6 times
...
Chris
Most Recent 4 months, 2 weeks ago
Selected Answer: B
Based on the CISSP Official Study Guide, the violation of providing PHI to an external marketing organization without patient consent touches upon several ethical principles. Let's clarify the key principles involved: Informed Consent: This principle emphasizes that individuals must be informed about how their personal data will be used and must give explicit permission for its use. Providing PHI without the patient’s consent directly violates this principle. Privacy Regulations: Legal frameworks like HIPAA in the U.S. strictly regulate the handling and sharing of PHI. Sharing PHI without proper authorization is a direct violation of these regulations. Considering both points, your selected answer, B. Informed consent, is indeed valid as it directly addresses the ethical principle of ensuring that patients are aware of and agree to any use or disclosure of their PHI. However, it is also closely tied to privacy regulations (answer D), which legally enforce this ethical principle.
upvoted 2 times
...
50e940e
4 months, 4 weeks ago
Selected Answer: B
D is not a Principle
upvoted 1 times
...
Skittle4710
5 months, 1 week ago
Selected Answer: B
Answer: B - Informed Consent. Key word: Ethical Principle. Privacy Regulations - Laws Informed Consent - Ethical Principle
upvoted 1 times
...
CCNPWILL
5 months, 3 weeks ago
Selected Answer: D
Privacy regulations. D
upvoted 1 times
...
gjimenezf
9 months, 3 weeks ago
Selected Answer: B
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
gjimenezf
9 months, 3 weeks ago
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
YesPlease
11 months ago
Selected Answer: D
Answer D) Privacy regulations The ethical principle that was violated was CONSENT....and consent is legally part of privacy regulations. Informed Consent is about giving permission to have a procedure done to yourself once you get all the PROs/CONs of the procedure without being lied to...and not really about giving permission to share your records.
upvoted 1 times
...
Soleandheel
11 months, 1 week ago
Informed consent is both an ethical and legal obligation of medical practitioners in the US and originates from the patient's right to direct what happens to their body. https://www.ncbi.nlm.nih.gov/books/NBK430827/#:~:text=The%20patient%20must%20be%20competent,what%20happens%20to%20their%20body.
upvoted 1 times
...
Soleandheel
11 months, 1 week ago
B. Informed consent" is the best choice. The question is asking for an "ethical principle" rather than a "regulation". "Informed consent" aligns more closely with being an ethical principle rather than a regulation. Informed consent is a fundamental ethical principle in healthcare that emphasizes patient autonomy and their right to make decisions about their medical information and treatment. If the question was asking for what "regulation", i would have gone with D. But since it's asking for what "ethical principle", i'm going with B. informed consent.
upvoted 2 times
...
[Removed]
11 months, 2 weeks ago
Selected Answer: D
I think d. B is not information security
upvoted 1 times
...
user82652183
1 year ago
Selected Answer: D
Informed consent is a medical principle. It has nothing to do with Information Security
upvoted 1 times
...
HughJassole
1 year, 5 months ago
B is right. I first went with D but HIPAA is a law. The question asks for ethics, and informed consent is an ethical principle. "Informed consent is one of the founding principles of research ethics. " https://researchsupport.admin.ox.ac.uk/governance/ethics/resources/consent#:~:text=Informed%20consent%20is%20one%20of,before%20they%20enter%20the%20research.
upvoted 3 times
...
aleXplicitly
1 year, 7 months ago
Selected Answer: D
Consent to collect is different from privacy protection. The violation is with privacy not consent.
upvoted 2 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
sausageman
1 year, 8 months ago
Selected Answer: D
Definitely D
upvoted 2 times
...
liledag
1 year, 8 months ago
The unauthorized disclosure of protected health information (PHI) to an external marketing organization is a violation of the privacy regulations under the Health Insurance Portability and Accountability Act (HIPAA). The privacy regulations require that PHI be kept confidential and only disclosed for specific purposes, such as treatment, payment, or healthcare operations, or with the patient's explicit authorization. The unauthorized disclosure of PHI violates the patient's right to privacy and confidentiality. Therefore, option D, Privacy regulations, is the correct answer.
upvoted 2 times
...
Rollingalx
1 year, 9 months ago
I go with D The principle of informed consent is important but it pertains more to the process of obtaining a patient's consent to use or disclose their PHI, rather than the unauthorized disclosure of PHI by a medical analyst.
upvoted 4 times
Arsh_2022
1 year, 8 months ago
agree with D
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...