Hard1 markMultiple Choice
Task 1: Plan and manage project complianceregulatory complianceHIPAAvendor compliancecompliance assessment

PMP · Question 34 · Task 1: Plan and manage project compliance

A healthcare project must comply with HIPAA regulations for patient data protection. During a security audit, the project manager discovers that a third-party vendor's data handling practices may not fully comply with HIPAA requirements, even though they claim to be compliant. The vendor is critical to project success and replacing them would cause significant delays. What should the project manager do FIRST?

Answer options:

A.

Continue working with the vendor while implementing additional security measures

B.

Conduct a detailed compliance assessment of the vendor's practices with legal and security teams

C.

Immediately terminate the vendor relationship to avoid compliance risks

D.

Request written certification from the vendor that they are fully HIPAA compliant

How to approach this question

When compliance issues are discovered, conduct thorough assessment with appropriate expertise before making decisions about how to proceed.

Full Answer

B.Conduct a detailed compliance assessment of the vendor's practices with legal and security teams✓ Correct
Regulatory compliance issues require thorough assessment with appropriate legal and technical expertise to understand actual compliance status and determine appropriate corrective actions.

Common mistakes

Students often choose immediate termination (C) to avoid risk, or continuation with measures (A), missing the need for proper compliance assessment first.

Practice the full PMI PMP Practice Exam 5

94 questions · hints · full answers · grading

More questions from this exam