IAPP CIPP-US Practice Test - Questions Answers
List of questions
Related questions
The Video Privacy Protection Act of 1988 restricted which of the following?
Which purchase records of audio visual materials may be disclosed
When downloading of copyrighted audio visual materials is allowed
When a user's viewing of online video content can be monitored
Who advertisements for videos and video games may target
The Cable Communications Policy Act of 1984 requires which activity?
Delivery of an annual notice detailing how subscriber information is to be used
Destruction of personal information a maximum of six months after it is no longer needed
Notice to subscribers of any investigation involving unauthorized reception of cable services
Obtaining subscriber consent for disseminating any personal information necessary to render cable services
What is the main purpose of requiring marketers to use the Wireless Domain Registry?
To access a current list of wireless domain names
To prevent unauthorized emails to mobile devices
To acquire authorization to send emails to mobile devices
To ensure their emails are sent to actual wireless subscribers
SCENARIO
Please use the following to answer the next QUESTION:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures. A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals -- ones that exposed the PHI of public figures including celebrities and politicians. During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected. A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach. What is the most significant reason that the U.S. Department of Health and Human Services (HHS) might impose a penalty on HealthCo?
Because HealthCo did not require CloudHealth to implement appropriate physical and administrative measures to safeguard the ePHI
Because HealthCo did not conduct due diligence to verify or monitor CloudHealth's security measures
Because HIPAA requires the imposition of a fine if a data breach of this magnitude has occurred
Because CloudHealth violated its contract with HealthCo by not encrypting the ePHI
Which jurisdiction must courts have in order to hear a particular case?
Subject matter jurisdiction and regulatory jurisdiction
Subject matter jurisdiction and professional jurisdiction
Personal jurisdiction and subject matter jurisdiction
Personal jurisdiction and professional jurisdiction
Which authority supervises and enforces laws regarding advertising to children via the Internet?
The Office for Civil Rights
The Federal Trade Commission
The Federal Communications Commission
The Department of Homeland Security
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
Determine which bodies will be involved in adjudication
Decide if any enforcement actions are justified
Adhere to its industry's code of conduct
Appeal decisions made against it
Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, ''Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers''?
International data transfers
Large platform providers
Promoting enforceable self-regulatory codes
Do Not Track
The ''Consumer Privacy Bill of Rights'' presented in a 2012 Obama administration report is generally based on?
The 1974 Privacy Act
Common law principles
European Union Directive
Traditional fair information practices
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?
A consent decree
Stare decisis decree
A judgment rider
Common law judgment
Question