Legal and regulatory Flashcards
HIPAA (Not HIPPA)
Health Insurance Portability and Accountability Act.
PHI
Protected Health Information
(ECPA):
Electronic Communications Privacy Act
Security Breach Notification Laws.
NOT Federal, all 50 states have individual laws, know your state.
PATRIOT Act of 2001:
Expands law enforcement electronic monitoring capabilities.
Allows search and seizure without immediate disclosure.
CFAA
Computer Fraud and Abuse Act
GLBA):
Gramm-Leach-Bliley Act
Applies to financial institutions; driven by the Federal Financial Institutions
Sarbanes-Oxley Act of 2002 (SOX):
Directly related to the accounting scandals in the late 90s
GDPR
General Data Protection Regulation.
GDPR is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA).
It does not matter where we are based, if we have customers in EU/EEA we have to adhere to the GDPR.
OECD - a guidelines
Organization for Economic Cooperation and Development (OECD) Privacy Guidelines (International): 30 member nations from around the world, including the U.S. OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, issued in 1980 Eight driving principles: 1. Collection limitation principle. 2. Data quality principle. 3. Purpose specification principle. 4. Use limitation principle. 5. Security safeguards principle. 6. Openness principle. 7. Individual participation principle. 8. Accountability principle.