IAPP CIPP-US Practice Test Questions and Exam Dumps Part15 Q281-300

View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.


Question 281. What information is specifically protected by the HIPAA Security Rule?

  1. Every piece of information maintained by a hospital
  2. Only paper medical records
  3. All personally identifiable information held by any employer
  4. Electronic protected health information created, received, maintained, or transmitted by regulated entities

Correct Answer: 4. Electronic protected health information created, received, maintained, or transmitted by regulated entities

Explanation:

The HIPAA Security Rule establishes national standards for protecting electronic protected health information, commonly called ePHI. The rule applies to HIPAA covered entities and business associates and requires reasonable and appropriate safeguards for ePHI they create, receive, maintain, or transmit. The Security Rule is therefore narrower than the HIPAA Privacy Rule in one important respect: it focuses specifically on PHI in electronic form. Paper records still receive protection under the Privacy Rule and other applicable safeguards, but they are not the principal information category regulated by the Security Rule’s administrative, physical, and technical safeguard standards.

Question 282. Which three categories of safeguards form the core of the HIPAA Security Rule?

  1. Administrative, physical, and technical safeguards
  2. Marketing, financial, and advertising safeguards
  3. Federal, state, and local safeguards
  4. Civil, criminal, and contractual safeguards

Correct Answer: 1. Administrative, physical, and technical safeguards

Explanation:

The HIPAA Security Rule organizes its security requirements into administrative, physical, and technical safeguards. Administrative safeguards include areas such as risk analysis, risk management, workforce security, access management, training, incident procedures, and contingency planning. Physical safeguards address facilities, workstations, devices, and media. Technical safeguards include access controls, audit controls, integrity protections, authentication, and transmission security. These categories reinforce the idea that protecting ePHI requires more than cybersecurity software. Governance, employee practices, physical security, access management, and technology must work together to preserve confidentiality, integrity, and availability.

Question 283. What is the PRIMARY purpose of HIPAA Security Rule risk analysis?

  1. To determine which patients should receive treatment
  2. To calculate the financial value of PHI
  3. To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
  4. To create marketing profiles from health information

Correct Answer: 3. To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI

Explanation:

Risk analysis is a foundational Security Rule requirement. A regulated entity must conduct an accurate and thorough assessment of potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of the ePHI it holds. The findings then inform risk management, helping the organization determine which reasonable and appropriate security measures are necessary. Risk analysis should reflect the entity’s actual environment, including systems, devices, users, vendors, and threats, rather than being a generic compliance checklist. HHS emphasizes that organizations must also reevaluate risks and modify security measures when circumstances change.

Question 284. Under the HIPAA Security Rule, what does “availability” mean?

  1. PHI must be publicly available
  2. Information is accessible and usable on demand by an authorized person
  3. Every employee must have access to all ePHI
  4. Patients must receive records immediately in every situation

Correct Answer: 2. Information is accessible and usable on demand by an authorized person

Explanation:

The HIPAA Security Rule is built around confidentiality, integrity, and availability. Availability means that ePHI is accessible and usable on demand by an authorized person. Confidentiality focuses on preventing unauthorized access or disclosure, while integrity concerns preventing improper alteration or destruction. Security measures should therefore protect data not only from theft but also from outages, corruption, and loss that prevent authorized access when needed. Business continuity, backups, contingency planning, resilient systems, and incident response can all support availability. A system that securely encrypts data but makes it permanently inaccessible would still fail an important Security Rule objective.

Question 285. What must a HIPAA regulated entity designate as part of its administrative safeguards?

  1. A security official responsible for developing and implementing required security policies and procedures
  2. A federal judge responsible for approving access to ePHI
  3. A patient representative for every information system
  4. A public-relations employee responsible for all breach decisions

Correct Answer: 1. A security official responsible for developing and implementing required security policies and procedures

Explanation:

HIPAA’s administrative safeguards require regulated entities to assign security responsibility to an individual responsible for developing and implementing the organization’s Security Rule policies and procedures. Clear ownership helps ensure that security requirements are actively managed rather than dispersed without accountability. This responsibility works alongside requirements involving risk management, workforce security, information-access management, security training, incident procedures, contingency planning, and evaluation. The designated security official does not replace leadership, legal, compliance, or IT responsibilities, but provides an accountable focal point for implementation of the Security Rule’s requirements.

Question 286. Which item is a HIPAA physical safeguard?

  1. A privacy notice provided to a patient
  2. An advertising opt-out mechanism
  3. A consumer credit freeze
  4. Device and media controls governing hardware or electronic media containing ePHI

Correct Answer: 4. Device and media controls governing hardware or electronic media containing ePHI

Explanation:

HIPAA physical safeguards include facility access controls, workstation use, workstation security, and device and media controls. Device and media controls govern hardware and electronic media containing ePHI, including how those items are received, moved, removed, disposed of, or prepared for reuse. These protections matter because sensitive information can remain on laptops, hard drives, removable media, or other equipment even after normal business use has ended. The Security Rule requires procedures for final disposition of ePHI and for removing ePHI before electronic media is reused.

Question 287. Which HIPAA technical safeguard is intended to record and examine activity in information systems containing ePHI?

  1. Facility access controls
  2. Audit controls
  3. Workforce sanctions
  4. Device disposal procedures

Correct Answer: 2. Audit controls

Explanation:

Audit controls are a technical safeguard under the HIPAA Security Rule. Regulated entities must implement hardware, software, or procedural mechanisms capable of recording and examining activity in systems that contain or use ePHI. Audit information can help detect improper access, investigate incidents, monitor workforce activity, and validate whether security controls are functioning appropriately. Audit controls are distinct from access controls, which determine who can enter a system, and authentication, which verifies the identity of a person seeking access. Together, these technical safeguards support accountability and detection of unauthorized activity involving sensitive electronic health information.

Question 288. What is the purpose of person or entity authentication under the HIPAA Security Rule?

  1. To determine whether a marketing campaign is effective
  2. To decide whether a health plan is profitable
  3. To verify that a person or entity seeking access to ePHI is who they claim to be
  4. To automatically disclose PHI to third parties

Correct Answer: 3. To verify that a person or entity seeking access to ePHI is who they claim to be

Explanation:

Authentication helps ensure that only legitimate users or entities gain access to ePHI. The Security Rule requires procedures for verifying that a person or entity seeking access is the one claimed. Authentication can work together with unique user identification, passwords, multifactor authentication technologies, certificates, or other reasonable and appropriate controls selected by the regulated entity. Authentication is different from authorization: authentication establishes identity, while authorization determines which resources that authenticated identity may access. Strong authentication reduces risks associated with stolen credentials, impersonation, unauthorized remote access, and account sharing.

Question 289. What does HIPAA transmission security address?

  1. Protecting ePHI against unauthorized access while it is transmitted over electronic networks
  2. Restricting patients from sending emails to providers
  3. Preventing health plans from mailing paper notices
  4. Limiting the number of computers a hospital can purchase

Correct Answer: 1. Protecting ePHI against unauthorized access while it is transmitted over electronic networks

Explanation:

Transmission security is one of HIPAA’s technical safeguard standards. It requires regulated entities to implement technical security measures guarding against unauthorized access to ePHI transmitted over electronic communications networks. The appropriate controls depend on the entity’s systems, risks, technical environment, and other Security Rule factors. Technologies such as encryption can play an important role, but HIPAA’s Security Rule is designed to remain flexible and technology neutral rather than mandating one specific product. Organizations should evaluate how ePHI moves through email, networks, remote connections, applications, cloud platforms, and other communication channels.

Question 290. How long must documentation required by the HIPAA Security Rule generally be retained?

  1. One year from creation only
  2. Six years from the later of its creation date or the date it was last in effect
  3. Thirty days
  4. Permanently in every case

Correct Answer: 2. Six years from the later of its creation date or the date it was last in effect

Explanation:

HIPAA requires regulated entities to maintain required Security Rule documentation, including written policies, procedures, and documentation of required actions, activities, and assessments, for six years from the later of the document’s creation date or the date on which it was last in effect. Organizations must also make relevant documentation available to personnel responsible for implementing the procedures and periodically update it when environmental or organizational changes affect ePHI security. Good documentation provides evidence that the organization performed required risk assessments, adopted safeguards, and maintained an active security program rather than relying on undocumented practices.

Question 291. Under the FTC Telemarketing Sales Rule (TSR), how frequently must covered sellers and telemarketers generally synchronize their calling lists with the National Do Not Call Registry?

  1. Once every year
  2. Every 90 days
  3. At least every 31 days
  4. Only after a consumer complaint

Correct Answer: 3. At least every 31 days

Explanation:

Covered sellers and telemarketers generally must access the National Do Not Call Registry and remove registered telephone numbers from their calling lists at least every 31 days. Calling from an outdated list can result in prohibited telemarketing calls to consumers who registered their numbers after the seller’s last update. The FTC’s safe harbor for inadvertent violations also depends partly on using a version of the Registry downloaded no more than 31 days before the call. Maintaining documented suppression procedures is therefore an important element of telemarketing compliance.

Question 292. A consumer tells a telemarketer, “Do not call me again on behalf of this company.” What must the seller generally do?

  1. Continue calling until the consumer joins the National Do Not Call Registry
  2. Honor the entity-specific do-not-call request
  3. Require the consumer to submit a notarized letter
  4. Charge an administrative fee to process the request

Correct Answer: 4. Honor the entity-specific do-not-call request

Explanation:

The Telemarketing Sales Rule separately protects consumers who tell a specific seller or charitable organization that they do not want additional calls. The seller and its telemarketers must maintain an entity-specific do-not-call list and honor the consumer’s request. A company cannot require the consumer to register on the national list, listen to another sales pitch, call a different number, or pay a fee. Interfering with the consumer’s request can itself violate the TSR. Company-specific suppression therefore remains important even when a seller also screens its calls against the National Do Not Call Registry.

Question 293. Which call is generally outside the National Do Not Call Registry’s restrictions under the FTC’s TSR?

  1. A legitimate call made solely to conduct a survey without a sales pitch
  2. A disguised survey that includes a product sales pitch
  3. A telemarketing call to sell a consumer product
  4. A sales call made after the consumer specifically told the seller not to call again

Correct Answer: 1. A legitimate call made solely to conduct a survey without a sales pitch

Explanation:

The National Do Not Call provisions generally do not apply to calls made solely for purposes such as legitimate surveys, although other laws may still apply. However, a caller cannot avoid telemarketing rules merely by labeling a sales call as a “survey.” If a supposed survey includes an offer to sell goods or services, the call can fall within the Do Not Call requirements. Political organizations and charities also receive different treatment under the Registry framework, although charitable telefunders must honor entity-specific do-not-call requests on behalf of the relevant charity.

Question 294. What must a covered telemarketer generally do before making outbound calls to consumers using a National Do Not Call list?

  1. Obtain approval from the FTC for every telephone number
  2. Maintain and use a process that suppresses numbers appearing on the Registry and entity-specific do-not-call lists
  3. Buy the consumer’s credit report
  4. Obtain the consumer’s Social Security number

Correct Answer: 3. Maintain and use a process that suppresses numbers appearing on the Registry and entity-specific do-not-call lists

Explanation:

A compliant telemarketing operation should have procedures for preventing calls to telephone numbers on the National Do Not Call Registry and the seller’s own entity-specific suppression list. FTC safe-harbor requirements include written procedures, personnel training, maintaining entity-specific records, and using an appropriately recent Registry version. A company should not rely solely on telemarketers remembering individual requests or manually checking calls one by one. Automated suppression, documented policies, training, and monitoring create a repeatable process that reduces the likelihood of prohibited calls and provides evidence of reasonable compliance practices.

Question 295. What is the significance of the Telemarketing Sales Rule’s safe harbor for inadvertent Do Not Call violations?

  1. A seller meeting specified compliance practices may avoid penalties for certain calls made in error
  2. It allows companies to ignore the Registry completely
  3. It authorizes unlimited robocalls
  4. It eliminates the need to train telemarketing personnel

Correct Answer: 1. A seller meeting specified compliance practices may avoid penalties for certain calls made inadvertently

Explanation:

The TSR includes a safe harbor for certain inadvertent Do Not Call violations when the seller or telemarketer can demonstrate routine compliance practices. Those practices include written procedures, training personnel and relevant vendors, maintaining an entity-specific do-not-call list, monitoring compliance, and using a National Registry version downloaded within the required period. The safe harbor is not permission to ignore consumer requests or operate carelessly. It protects organizations that maintain a genuine compliance program but nevertheless make an isolated error despite those safeguards. Documentation is therefore essential to demonstrating eligibility for the safe harbor.

Question 296. Under the updated TSR recordkeeping requirements, how long must covered sellers and telemarketers generally retain required records?

  1. 30 days
  2. One year
  3. Two years in every case
  4. Five years**

Correct Answer: 4. Five years

Explanation:

The FTC’s updated Telemarketing Sales Rule recordkeeping provisions require covered sellers and telemarketers to retain specified records for five years. The updated requirements include information about calls, consent, customer transactions, scripts, service providers, Do Not Call compliance, and other relevant activities. The FTC emphasized that failure to maintain each required record can itself constitute a violation. Written agreements can allocate recordkeeping responsibilities between sellers and telemarketers, but without a clear agreement, both can face obligations. Maintaining complete records is essential for demonstrating consent, honoring opt-outs, and defending the organization’s telemarketing practices.

Question 297. Which information is among the call-detail records the updated TSR requires covered telemarketers to maintain?

  1. Only the consumer’s date of birth
  2. The calling and called numbers, date, time, duration, and disposition of the call
  3. The consumer’s complete medical history
  4. The consumer’s tax return

Correct Answer: 2. The calling and called numbers, date, time, duration, and disposition of the call

Explanation:

The updated TSR requires covered telemarketing operations to retain detailed records concerning outbound calls. These records include the identity of the telemarketer and seller, the goods or services involved, calling and called numbers, call date and time, duration, caller-ID information, and the disposition of the call, such as whether it was answered, connected, or transferred. These detailed records help regulators evaluate whether telemarketers complied with Do Not Call, consent, and other TSR obligations. Organizations should therefore ensure that dialing platforms and vendors preserve required metadata for the full retention period.

Question 298. What is generally true about most business-to-business calls under the Telemarketing Sales Rule?

  1. They are generally exempt from most TSR provisions, although important exceptions exist
  2. They are always prohibited
  3. They automatically require consumer written consent
  4. They are governed exclusively by HIPAA

Correct Answer: 3. They are generally exempt from most TSR provisions, although important exceptions exist

Explanation:

Most business-to-business telemarketing calls are exempt from the TSR, but the exemption is not absolute. The FTC identifies exceptions involving, for example, certain sales of nondurable office or cleaning supplies, and other specific categories can remain subject to particular requirements. Sellers should also remember that other federal or state laws may regulate calls even when the FTC’s TSR does not fully apply. Privacy and marketing professionals therefore should not treat “B2B” as an automatic universal exemption from every calling rule. The product, purpose, recipient, and applicable regulatory framework still matter.

Question 299. Under FCC rules, how long must a company-specific do-not-call request generally be honored?

  1. Five years from the date of the request
  2. Thirty days
  3. Six months
  4. Only until the next marketing campaign

Correct Answer: 1. Five years from the date of the request

Explanation:

FCC rules generally require companies to honor a consumer’s company-specific do-not-call request for five years from the date the request is made. This requirement exists in addition to the National Do Not Call Registry. A consumer who tells a particular company not to call should therefore be added to that company’s internal suppression list even if the telephone number is not on the national Registry. Organizations should coordinate suppression data across internal departments and telemarketing vendors because a request made during one interaction should not be defeated by another vendor continuing to call on the same seller’s behalf.

Question 300. A health care business conducts telemarketing while also maintaining large volumes of ePHI. What is the BEST privacy-compliance approach?

  1. Treat HIPAA as the only applicable federal rule
  2. Apply only the Telemarketing Sales Rule because marketing laws replace health privacy requirements
  3. Separately apply HIPAA Security Rule safeguards to ePHI and telemarketing rules to calling practices, while coordinating governance, vendors, records, and consumer preferences
  4. Assume obtaining marketing consent eliminates security duties

Correct Answer: 3. Separately apply HIPAA Security Rule safeguards to ePHI and telemarketing rules to calling practices, while coordinating governance, vendors, records, and consumer preferences

Explanation:

Different activities can trigger different legal obligations inside the same organization. Electronic PHI must be protected through appropriate administrative, physical, and technical safeguards under the HIPAA Security Rule, including risk analysis, access controls, audit mechanisms, and security documentation. Telemarketing campaigns can separately require compliance with the TSR, National Do Not Call Registry, entity-specific suppression requests, consent requirements, and recordkeeping. Neither legal framework replaces the other. A mature compliance program maps each activity to its governing law while coordinating vendor oversight, data governance, security, consent, and consumer-preference management across the organization.