An organization's CISO presents a compliance matrix showing adherence to HIPAA, PCI DSS, and NIST CSF. The external auditor asks: "Which controls satisfy multiple frameworks, and where are the gaps?" Answering that question requires understanding what each regulation mandates, how each framework structures its requirements, and where responsibilities overlap.
AICPA Representative Tasks (verbatim). 1. Remembering & Understanding, Recall the covered entities and permitted uses and disclosures of the HIPAA Security and Privacy Rules. 2. Remembering & Understanding, Recall the scope of the General Data Protection Regulation (GDPR) and the six principles and key concepts for personal data. 3. Remembering & Understanding, Recall the requirements of the PCI DSS. 4. Remembering & Understanding, Recall the three parts of the NIST CSF (Core, Tiers, Organizational Profiles). 5.
HIGH-FREQUENCY: The Health Insurance Portability and Accountability Act (HIPAA) protects protected health information (PHI). The exam tests who is covered and what disclosures are permitted.
Covered Entities. Three categories are directly regulated:
Business Associates. Any person or entity that performs functions involving PHI on behalf of a covered entity.
Common mistakes
- Assuming HIPAA applies only to hospitals and insurers. Business associates, including cloud providers, IT consultants, and billing services, are directly regulated if they handle PHI. The exam tests whether you recognize business associate relationships.
- Confusing GDPR data controller and data processor. The controller determines purposes and means of processing; the processor acts on the controller's instructions. A SaaS vendor processing customer data is typically a processor; the customer is the controller.
- Treating PCI DSS as voluntary. While technically an industry standard rather than law, PCI DSS is contractually mandated by card brands. Merchants cannot opt out if they want to accept payment cards.
Bottom line
- HIPAA applies to covered entities (health plans, healthcare clearinghouses, healthcare providers transmitting electronically) plus business associates via BAAs; permitted disclosures cover treatment, payment, operations, and specific public interest exceptions
- GDPR applies to processing personal data of EU residents regardless of processor location; six principles: lawfulness/fairness/transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality
- PCI DSS requires twelve controls grouped into six control objectives for any entity that stores, processes, or transmits cardholder data, including firewalls, encryption, access control, and regular testing
- GLBA covers non-public personal information at financial institutions, and each functional regulator writes the security rule for the institutions it supervises; the FTC Safeguards Rule (16 CFR 314.4) binds FTC-jurisdiction institutions and requires a written program with a Qualified Individual...
Exam shortcut
HIPAA disclosure mnemonic: "TPO plus public." Treatment, Payment, Operations are always permitted; public interest exceptions (law enforcement, public health, judicial) require specific circumstances. Marketing requires authorization. GDPR principles as a data lifecycle. Lawfulness (why collect?) → Purpose limitation (for what?) → Data minimization (how much?) → Accuracy (is it right?) → Storage limitation (how long?) → Integrity/confidentiality (is it protected?). Framework hierarchy. NIST CSF = risk framework (what to manage).
The full lesson (about 7,665 words, 51 min read) adds 10 worked examples, all 8 common mistakes, a self-check, free in the app.
Learning objectives
- II.A1
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.