Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 408 discussion

Actual exam question from ISC's CISSP
Question #: 408
Topic #: 1
[All CISSP Questions]

If a medical analyst independently provides protected health information (PHI) to an external marketing organization, which ethical principal is this a violation of?

  • A. Higher ethic in the worst case
  • B. Informed consent
  • C. Change of scale test
  • D. Privacy regulations
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
l00t
Highly Voted 1 year, 2 months ago
Selected Answer: B
The ethical principle that is violated by a medical analyst who independently provides protected health information (PHI) to an external marketing organization is informed consent. Informed consent is the principle that every medical professional should allow the patient to retain control over their body and their data, and that the patient should be informed of and agree to any use or disclosure of their PHI. By providing PHI to an external organization without the patient’s knowledge and consent, the medical analyst is violating the patient’s right to privacy and autonomy.
upvoted 6 times
...
gjimenezf
Most Recent 2 months, 3 weeks ago
Selected Answer: B
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
gjimenezf
2 months, 3 weeks ago
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
YesPlease
4 months ago
Selected Answer: D
Answer D) Privacy regulations The ethical principle that was violated was CONSENT....and consent is legally part of privacy regulations. Informed Consent is about giving permission to have a procedure done to yourself once you get all the PROs/CONs of the procedure without being lied to...and not really about giving permission to share your records.
upvoted 1 times
...
Soleandheel
4 months, 1 week ago
Informed consent is both an ethical and legal obligation of medical practitioners in the US and originates from the patient's right to direct what happens to their body. https://www.ncbi.nlm.nih.gov/books/NBK430827/#:~:text=The%20patient%20must%20be%20competent,what%20happens%20to%20their%20body.
upvoted 1 times
...
Soleandheel
4 months, 1 week ago
B. Informed consent" is the best choice. The question is asking for an "ethical principle" rather than a "regulation". "Informed consent" aligns more closely with being an ethical principle rather than a regulation. Informed consent is a fundamental ethical principle in healthcare that emphasizes patient autonomy and their right to make decisions about their medical information and treatment. If the question was asking for what "regulation", i would have gone with D. But since it's asking for what "ethical principle", i'm going with B. informed consent.
upvoted 2 times
...
[Removed]
4 months, 2 weeks ago
Selected Answer: D
I think d. B is not information security
upvoted 1 times
...
user82652183
5 months ago
Selected Answer: D
Informed consent is a medical principle. It has nothing to do with Information Security
upvoted 1 times
...
HughJassole
10 months, 2 weeks ago
B is right. I first went with D but HIPAA is a law. The question asks for ethics, and informed consent is an ethical principle. "Informed consent is one of the founding principles of research ethics. " https://researchsupport.admin.ox.ac.uk/governance/ethics/resources/consent#:~:text=Informed%20consent%20is%20one%20of,before%20they%20enter%20the%20research.
upvoted 3 times
...
aleXplicitly
1 year ago
Selected Answer: D
Consent to collect is different from privacy protection. The violation is with privacy not consent.
upvoted 2 times
jackdryan
11 months, 2 weeks ago
D is correct
upvoted 1 times
...
...
sausageman
1 year, 1 month ago
Selected Answer: D
Definitely D
upvoted 2 times
...
liledag
1 year, 1 month ago
The unauthorized disclosure of protected health information (PHI) to an external marketing organization is a violation of the privacy regulations under the Health Insurance Portability and Accountability Act (HIPAA). The privacy regulations require that PHI be kept confidential and only disclosed for specific purposes, such as treatment, payment, or healthcare operations, or with the patient's explicit authorization. The unauthorized disclosure of PHI violates the patient's right to privacy and confidentiality. Therefore, option D, Privacy regulations, is the correct answer.
upvoted 2 times
...
Rollingalx
1 year, 1 month ago
I go with D The principle of informed consent is important but it pertains more to the process of obtaining a patient's consent to use or disclose their PHI, rather than the unauthorized disclosure of PHI by a medical analyst.
upvoted 4 times
Arsh_2022
1 year, 1 month ago
agree with D
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...