Search the practice set
275 questions, 991 terms and 600 topics in 30 areas.
60 results for “Healthcare Data Protection”
Minimum Necessary Access
Restricting each user to the health information required for their specific role and, in the strong form, to the patients they are actually treating.
Obligation Mapping
Translating each legal or regulatory requirement into the specific design constraints it imposes, so that compliance becomes a set of testable properties rather than a document.
Purpose-Based Access
Granting access for a stated and recorded purpose rather than by role alone, which is what several data protection regimes actually require.
Re-Identification Risk
The probability that pseudonymised data can be linked back to individuals, which is what keeps such data within the scope of data protection law.
Capital One's Data Centre Exit
A major US bank closed all eight of its data centres and moved fully to public cloud, treating governance automation as the enabling technology rather than a constraint.
Change Data Capture
Publishing a stream of a database's row-level changes by reading its replication log, without modifying the application that owns it.
Control Plane and Data Plane
The separation between the machinery that makes changes to a system and the machinery that serves its traffic.
Cross-Zone Data Transfer
Charges incurred when data moves between availability zones within a region — invisible on architecture diagrams and a recurring surprise on cloud bills.
Data Catalog
A searchable inventory of datasets with their schema, owner, meaning, freshness, quality and classification.
Data Contract
An explicit, versioned, enforced agreement between a data producer and its consumers about schema, semantics, quality and change policy.
Data Discovery
Automatically scanning stores to find where sensitive data actually resides, as distinct from where the documentation says it should.
Data Lakehouse
A pattern that puts warehouse-style transactions, schema and governance on top of cheap open-format object storage.
Data Lineage
A record of where each dataset came from, what transformed it, and what depends on it — traced at table and ideally column level.
Product wants to add a recommendation feature using browsing history. Legal asks for a data protection impact assessment. What does architecture need to supply?
What the assessment actually needs from architecture Legal cannot assess a feature description. They need the data facts, which only the design supplies: A data
A CDO proposes moving to a data mesh because the central data team is a bottleneck with a nine-month backlog. How do you assess the proposal?
Agree with the diagnosis, examine the prescription The bottleneck is real and it is structural rather than a matter of capacity. A central team receives data fr
A GDPR erasure request arrives for a customer. Where does their data actually live, and what makes this expensive to retrofit?
Where the data lives Longer than people expect, and enumerating it is most of the work: Primary database · read replicas · caches · search indexes · analytical
A business sponsor asks for a real-time data platform because "the competition has one". Reporting is currently a nightly batch that lands at 06:00 and nobody has complained. How do you handle this?
Do not answer the technology question "Real time platform" is a solution, and it has arrived without a problem attached. Answering it directly leads either to a
A new platform must serve a public partner API, three internal front-ends with different data needs, and high-volume service-to-service traffic. Choose the API styles and defend the choice.
Resist "pick one" These are three different problems with three different consumers. Standardising on one style optimises for architectural tidiness at the expe
A query that ran in 50ms for two years now takes 90 seconds. Nothing was deployed and the data volume grew normally. What happened?
The most likely cause: a plan flip The optimiser's choice is a function of estimated row counts. As the data grows or its distribution shifts, an estimate cross
A regulated client requires that no traffic between their data centre and your SaaS platform traverses the public internet. Design the connectivity and justify the cost.
Two distinct requirements hiding in one sentence Traffic must not traverse the public internet — a routing requirement. The client must be able to demonstrate i
A regulator asks whether customer data is encrypted. The team says yes, disks are encrypted. Is that a sufficient answer?
What disk encryption actually protects against Someone obtaining the physical medium or a raw storage snapshot. In a cloud context that means a provider employe
Choose storage for four workloads: a Postgres data directory, user-uploaded images, a shared build cache, and seven years of audit records.
Postgres data directory — block storage It needs low latency random reads and writes and a filesystem, and it attaches to one instance. That is precisely block
Healthcare Data Protection
PHI handling, minimum necessary access, and audit expectations in clinical systems.
Regulatory & Data Protection Architecture
General material on designing under legal and regulatory obligation.
Data Residency
Keeping data within a jurisdiction, including backups, logs and support access.
Data Subject Rights
Access, correction, portability and erasure across systems that never planned for them.
Consent Architecture
Capturing, versioning and propagating consent to every system that acts on the data.
Cross-Border Transfer
The legal mechanism that permits data to leave, and the architecture that respects it.
Digital Sovereignty
Control over data, operations and the operator, beyond where the bytes physically sit.
Erasure vs Immutability
Deletion obligations against event logs, backups and ledgers designed never to forget.
Exit & Concentration Risk
Being able to leave a provider, and what the regulator asks when you cannot.
Financial Services Regulation
Operational resilience, payment rules and supervisory expectations as design inputs.
Geo-Restriction & Sanctions
Blocking access by jurisdiction, and the accuracy and evasion problems that come with it.
Lawful Basis & Purpose Limitation
Why you may hold the data, and why that forbids the second use somebody proposed.
PCI-DSS Scoping
Segmentation and tokenisation to shrink what is in scope, because scope is the cost.
Privacy by Design
Data minimisation, default protection and purpose binding as structural decisions.
Privacy-Enhancing Technologies
Differential privacy, secure enclaves and federated computation, and what each buys.
Pseudonymisation
Separating identity from record, and the re-identification risk that remains.
Records Retention & Legal Hold
Keeping what must be kept, deleting what must go, and freezing both on demand.
Regulatory Reporting Pipelines
Submissions with fixed deadlines, fixed formats, and a regulator who audits the lineage.
Sector Cloud Rules
Regulator expectations for cloud use, exit plans and material outsourcing notification.
Third-Party Risk
Assessing, contracting and monitoring the vendors your architecture now depends on.
Change Data Capture
Turning a database's replication log into a stream, and its coupling risk.
Client Caching & Data Layer
Stale-while-revalidate, invalidation and optimistic updates on the client.
Data Access Models
Role, attribute and purpose-based access over analytical data, and how they compose.
Data Architecture
General material on structuring, storing and governing data.
Data Catalog
Discovery, ownership and technical metadata, and why catalogues go stale.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Data Contracts
Producers committing to schema, semantics and freshness, and breaking builds when they do not.
Data Governance
Ownership, lineage, quality, catalogues and who may see what.
Data Governance & Semantics
General material on ownership, meaning, quality and control of data at enterprise scale.
Data Lakes & Lakehouses
Open formats on object storage with transactional metadata on top.
Data Lifecycle & Retention
How long data is kept, where it ages to, and how it is actually deleted.
Regulatory & Data Protection Architecture
The obligations that constrain a design before a single quality attribute is discussed.
Data Architecture
Where state lives, how it is modelled, replicated, partitioned and governed.
Data Governance & Semantics
Who owns data, what it means, whether it can be trusted, and who may see it.