A healthcare AI company is subject to both HIPAA and GDPR because it serves US and EU patients. When an AI model trained on patient data is later used in a new clinical setting, which compliance obligation is MOST critical to address FIRST?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because both HIPAA (minimum necessary standard and permitted uses) and GDPR (purpose limitation principle — Article 5(1)(b)) require that personal data be used only for purposes compatible with those for which it was originally collected — making purpose assessment the foundational first step. A, C, and D may be relevant next steps but cannot be determined to be necessary before the purpose assessment.
Full explanation below image
Full Explanation
B is correct because both HIPAA (minimum necessary standard and permitted uses) and GDPR (purpose limitation principle — Article 5(1)(b)) require that personal data be used only for purposes compatible with those for which it was originally collected — making purpose assessment the foundational first step. A, C, and D may be relevant next steps but cannot be determined to be necessary before the purpose assessment.