PrepSolution
PHRHigh-YieldHR Information Management 10%
access, encryption, audit, response

Data Security and Privacy

4

Pillars

Access, Encryption, Audit, Response

60

Days

HIPAA breach notification

1

Principle

Least privilege

picture HR data as a castle

Four-Layer Defense

Concentric defenses around HR data. Each ring stops a different attacker. Skip a ring and the attacker walks past it untouched.

ring 1 · access controlwho gets in?ring 2 · encryptioneven if read, unreadablering 3 · audit trailswho saw what, whenthe dataHRrecordsring 4 · breach response · 60-day clockattackvector4 layers · 4 different blocks
#1

Access Control

Role-based perms. MFA. Least privilege. Quarterly reviews.

#2

Encryption

AES-256 at rest and in transit. Key management.

#3

Audit Trails

Logs of access. Required for compliance + investigation.

#4

Breach Response

Detect → contain → assess → notify → remediate.

when the wall comes down

Breach Response — Five Beats

A documented playbook from the moment the alarm goes off. Each step has a clock attached.

1Detectmonitoring · alert2Containisolate systems3Assessscope · individuals4Notifyaffected · regs · media5Remediatepatch · train · improvealarmstronger castle

Privacy Laws Affecting HR Data

HIPAA

60 days

Group health plan data — breach notice

CCPA / CPRA

CA only

Employee rights to know, delete, correct

GDPR

72 hours

EU employees · DPO · breach notice

BIPA

consent first

IL biometric data · no after-the-fact fix

State breach laws

30-90 days

All 50 states · varying deadlines

SOX

ongoing

Public-company financial integrity

Exam Traps

Least privilege applies even within HR

Only the minimum access needed for the role. Quarterly access reviews are the audit standard.

State breach deadlines vary

Federal HIPAA gives 60 days. Some states require 30 days or less. The strictest applicable rule controls.

GDPR applies to EU employees regardless of HQ

A US company with EU staff must comply. The exam tests jurisdictional reach.

BIPA requires consent BEFORE collection

After-the-fact consent does not save the violation. Illinois statutory damages are significant.

Strictest rule wins

When multiple deadlines apply (federal HIPAA + state breach laws), the shortest applicable timeline controls.

Need-to-know operating standard

Least privilege is the default. Quarterly access reviews remove permissions for role changes and departures.

1
Outer wall — Access Control

Only authorized people get past the gate. Role-based keys. Least privilege. MFA.

2
Inner moat — Encryption

Even if attackers get past the wall, the documents are written in cipher.

3
Watchtower — Audit Trails

Logs of who entered, when, and what they touched.

4
Drawbridge — Breach Response

When the wall is breached, raise the bridge, count the loss, notify the village.

Wall, moat, tower, bridge. Four defenses. Least privilege at every gate.
reading is not enough, you gotta practice

Ready to test your PHR knowledge?

1,700+ practice questions written by certified professionals.

Start Practicing PHR
Reviewed by Sarah L., PrepSolution Content Editor, HR
Sources verified against HRCI 2026 standards
Updated May 2026