Skip to main content

14.2.3 Data Regulation

Learn how to properly handle sensitive user data according to the law.

Mishandling sensitive user data like financial, personal, and healthcare information puts your organization at risk to legal action from the government.

Finances

Organizations are (mostly, hopefully) required to adhere to the Payment-Card-Industry-Data-Security-Standards.

Personal Information

This includes personally identifiable information like:

  • driver's license
  • social security number
  • address history
  • credit score
  • student loans
  • employment records

Educational institutes are required to abide by the Family Educational Rights and Privacy Act. California enforces the California Consumer Privacy Act, and the EU enforces the General-Data-Protection-Regulation.

Healthcare Information

Healthcare data is regulated by the Health Insurance Portability and Accountability Act, better known as HIPAA. HIPAA is split into two rules, the Privacy Rule and the Security Rule.

  • The Privacy Rule defines how to generally secure health information.
  • The Security Rule defines how to protect electronic health information specifically.

#XIV

#Aplus