Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 408 discussion

Actual exam question from ISC's CISSP
Question #: 408
Topic #: 1
[All CISSP Questions]

If a medical analyst independently provides protected health information (PHI) to an external marketing organization, which ethical principal is this a violation of?

  • A. Higher ethic in the worst case
  • B. Informed consent
  • C. Change of scale test
  • D. Privacy regulations
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
l00t
Highly Voted 1 year, 4 months ago
Selected Answer: B
The ethical principle that is violated by a medical analyst who independently provides protected health information (PHI) to an external marketing organization is informed consent. Informed consent is the principle that every medical professional should allow the patient to retain control over their body and their data, and that the patient should be informed of and agree to any use or disclosure of their PHI. By providing PHI to an external organization without the patient’s knowledge and consent, the medical analyst is violating the patient’s right to privacy and autonomy.
upvoted 6 times
...
Chris
Most Recent 16 hours, 22 minutes ago
Selected Answer: B
Based on the CISSP Official Study Guide, the violation of providing PHI to an external marketing organization without patient consent touches upon several ethical principles. Let's clarify the key principles involved: Informed Consent: This principle emphasizes that individuals must be informed about how their personal data will be used and must give explicit permission for its use. Providing PHI without the patient’s consent directly violates this principle. Privacy Regulations: Legal frameworks like HIPAA in the U.S. strictly regulate the handling and sharing of PHI. Sharing PHI without proper authorization is a direct violation of these regulations. Considering both points, your selected answer, B. Informed consent, is indeed valid as it directly addresses the ethical principle of ensuring that patients are aware of and agree to any use or disclosure of their PHI. However, it is also closely tied to privacy regulations (answer D), which legally enforce this ethical principle.
upvoted 1 times
...
50e940e
1 week, 1 day ago
Selected Answer: B
D is not a Principle
upvoted 1 times
...
Skittle4710
3 weeks, 1 day ago
Selected Answer: B
Answer: B - Informed Consent. Key word: Ethical Principle. Privacy Regulations - Laws Informed Consent - Ethical Principle
upvoted 1 times
...
CCNPWILL
1 month ago
Selected Answer: D
Privacy regulations. D
upvoted 1 times
...
gjimenezf
5 months, 1 week ago
Selected Answer: B
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
gjimenezf
5 months, 1 week ago
Ethical principal: Informed Conset Law: Privacy regulations
upvoted 1 times
...
YesPlease
6 months, 2 weeks ago
Selected Answer: D
Answer D) Privacy regulations The ethical principle that was violated was CONSENT....and consent is legally part of privacy regulations. Informed Consent is about giving permission to have a procedure done to yourself once you get all the PROs/CONs of the procedure without being lied to...and not really about giving permission to share your records.
upvoted 1 times
...
Soleandheel
6 months, 3 weeks ago
Informed consent is both an ethical and legal obligation of medical practitioners in the US and originates from the patient's right to direct what happens to their body. https://www.ncbi.nlm.nih.gov/books/NBK430827/#:~:text=The%20patient%20must%20be%20competent,what%20happens%20to%20their%20body.
upvoted 1 times
...
Soleandheel
6 months, 3 weeks ago
B. Informed consent" is the best choice. The question is asking for an "ethical principle" rather than a "regulation". "Informed consent" aligns more closely with being an ethical principle rather than a regulation. Informed consent is a fundamental ethical principle in healthcare that emphasizes patient autonomy and their right to make decisions about their medical information and treatment. If the question was asking for what "regulation", i would have gone with D. But since it's asking for what "ethical principle", i'm going with B. informed consent.
upvoted 2 times
...
[Removed]
7 months ago
Selected Answer: D
I think d. B is not information security
upvoted 1 times
...
user82652183
7 months, 2 weeks ago
Selected Answer: D
Informed consent is a medical principle. It has nothing to do with Information Security
upvoted 1 times
...
HughJassole
1 year ago
B is right. I first went with D but HIPAA is a law. The question asks for ethics, and informed consent is an ethical principle. "Informed consent is one of the founding principles of research ethics. " https://researchsupport.admin.ox.ac.uk/governance/ethics/resources/consent#:~:text=Informed%20consent%20is%20one%20of,before%20they%20enter%20the%20research.
upvoted 3 times
...
aleXplicitly
1 year, 2 months ago
Selected Answer: D
Consent to collect is different from privacy protection. The violation is with privacy not consent.
upvoted 2 times
jackdryan
1 year, 1 month ago
D is correct
upvoted 1 times
...
...
sausageman
1 year, 3 months ago
Selected Answer: D
Definitely D
upvoted 2 times
...
liledag
1 year, 3 months ago
The unauthorized disclosure of protected health information (PHI) to an external marketing organization is a violation of the privacy regulations under the Health Insurance Portability and Accountability Act (HIPAA). The privacy regulations require that PHI be kept confidential and only disclosed for specific purposes, such as treatment, payment, or healthcare operations, or with the patient's explicit authorization. The unauthorized disclosure of PHI violates the patient's right to privacy and confidentiality. Therefore, option D, Privacy regulations, is the correct answer.
upvoted 2 times
...
Rollingalx
1 year, 4 months ago
I go with D The principle of informed consent is important but it pertains more to the process of obtaining a patient's consent to use or disclose their PHI, rather than the unauthorized disclosure of PHI by a medical analyst.
upvoted 4 times
Arsh_2022
1 year, 4 months ago
agree with D
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in