PMP · Question 34 · Task 1: Plan and manage project compliance
A healthcare project must comply with HIPAA regulations for patient data protection. During a security audit, the project manager discovers that a third-party vendor's data handling practices may not fully comply with HIPAA requirements, even though they claim to be compliant. The vendor is critical to project success and replacing them would cause significant delays. What should the project manager do FIRST?
Answer options:
Continue working with the vendor while implementing additional security measures
Conduct a detailed compliance assessment of the vendor's practices with legal and security teams
Immediately terminate the vendor relationship to avoid compliance risks
Request written certification from the vendor that they are fully HIPAA compliant
94 questions · hints · full answers · grading