4.2 Regulatory Standards: The Big Three
-
GDPR (EU – General Data Protection Regulation):
-
Scope: Any data related to EU citizens.
-
Key Concept: “Privacy by Design.”
-
Penalty: Up to €20 Million or 4% of global annual turnover (whichever is higher).
-
-
HIPAA (US – Health Insurance Portability and Accountability Act):
-
Scope: Protected Health Information (PHI).
-
Key Concept: Minimum Necessary Rule (only access what you need to treat the patient).
-
Penalty: Up to $1.5 Million/year; criminal charges for willful neglect.
-
-
ISO 27001:
-
Scope: International standard for Information Security Management Systems (ISMS).
-
Key Concept: Continuous improvement of the security posture. It is a commercial differentiator in B2B contracts.
-