View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 321. What type of organization is generally subject to 42 CFR Part 2’s substance use disorder confidentiality requirements?
- Every employer that knows an employee has a substance use disorder
- A federally assisted program that provides substance use disorder diagnosis, treatment, or referral for treatment
- Every pharmacy selling prescription medications
- Every health-related mobile application
Correct Answer: 2. A federally assisted program that provides substance use disorder diagnosis, treatment, or referral for treatment
Explanation:
42 CFR Part 2 provides specialized confidentiality protections for patient records associated with qualifying substance use disorder programs. It generally applies to federally assisted programs that provide SUD diagnosis, treatment, or referral for treatment. Part 2 can therefore apply alongside HIPAA when a program also qualifies as a HIPAA covered entity, but the two frameworks are not identical. Certain requirements can also affect recipients of Part 2 records. Privacy professionals should first determine whether the organization is a Part 2 program and whether the records at issue qualify as protected Part 2 records before analyzing disclosure requirements.
Question 322. Under the updated 42 CFR Part 2 framework, what may a patient generally provide for future treatment, payment, and health care operations uses and disclosures?
- Only a new consent for every individual disclosure
- An oral authorization with no documentation
- A standing court order
- A single consent covering future treatment, payment, and health care operations uses and disclosures**
Correct Answer: 4. A single consent covering future treatment, payment, and health care operations uses and disclosures
Explanation:
The updated Part 2 rules allow patients to provide a single consent for future uses and disclosures of Part 2 records for treatment, payment, and health care operations. This is often referred to as a TPO consent. The change, implemented following the CARES Act, aligns Part 2 more closely with HIPAA and is intended to reduce unnecessary barriers to care coordination while retaining specialized protections for substance use disorder records. Privacy teams should still ensure that the consent satisfies Part 2 requirements and should distinguish ordinary TPO redisclosures from uses in legal proceedings against the patient, which remain subject to stronger limitations.
Question 323. A HIPAA covered entity receives Part 2 records pursuant to a patient’s valid TPO consent. What is generally true of subsequent redisclosures?
- The covered entity may generally redisclose the records as permitted by HIPAA, subject to important Part 2 limitations
- Redisclosure is always prohibited
- Every redisclosure requires a new court order
- The records automatically lose all federal confidentiality protection
Correct Answer: 1. The covered entity may generally redisclose the records as permitted by HIPAA, subject to important Part 2 limitations
Explanation:
Under the modernized Part 2 framework, a HIPAA covered entity or business associate that receives Part 2 records pursuant to a valid TPO consent can generally redisclose those records in ways permitted by the HIPAA Privacy Rule. This significantly improves care coordination compared with older consent structures. However, Part 2 continues to impose special restrictions, particularly regarding use or disclosure of SUD records in civil, criminal, administrative, or legislative proceedings against the patient. The records therefore do not simply become ordinary unrestricted health information after the first disclosure.
Question 324. What special protection does 42 CFR Part 2 provide regarding the use of SUD patient records in legal proceedings against the patient?
- The records may always be used if a prosecutor requests them
- The records become public after treatment ends
- Their use or disclosure against the patient is restricted unless appropriate consent or qualifying legal process requirements are satisfied
- Part 2 imposes no restrictions once records are disclosed to another provider
Correct Answer: 3. Their use or disclosure against the patient is restricted unless appropriate consent or qualifying legal process requirements are satisfied
Explanation:
Part 2 contains strong protections against using substance use disorder treatment records against the patient in legal proceedings. HHS explains that Part 2 records generally may not be used or disclosed in civil, criminal, administrative, or legislative proceedings against a patient without the patient’s consent or an appropriate court order and subpoena or similar legal mandate meeting applicable requirements. These protections reflect concern that fear of prosecution, discrimination, or legal consequences could discourage people from seeking SUD treatment. They remain important even after the 2024 modernization of Part 2.
Question 325. Beginning February 16, 2026, which federal office administers the civil enforcement program for 42 CFR Part 2?
- Federal Trade Commission
- Federal Communications Commission
- Consumer Financial Protection Bureau
- HHS Office for Civil Rights**
Correct Answer: 4. HHS Office for Civil Rights
Explanation:
HHS delegated enforcement authority for Part 2 to the Office for Civil Rights, which also administers and enforces major HIPAA privacy and security requirements. Beginning February 16, 2026, OCR began accepting Part 2 complaints and breach reports under the updated enforcement framework. OCR can conduct investigations and compliance reviews and may resolve violations through corrective action, settlements, resolution agreements, or civil money penalties. This enforcement alignment reflects the CARES Act’s effort to bring the confidentiality rules for substance use disorder records closer to HIPAA’s compliance and enforcement structure.
Question 326. What new breach-related obligation applies under the modernized Part 2 framework?
- Part 2 records are excluded from all breach reporting
- Qualifying breaches of unsecured Part 2 records are subject to breach-notification requirements aligned with the HIPAA framework
- Breaches need only be reported to law enforcement
- Only paper-record breaches require notification
Correct Answer: 2. Qualifying breaches of unsecured Part 2 records are subject to breach-notification requirements aligned with the HIPAA framework
Explanation:
The CARES Act and HHS’s 2024 Part 2 final rule added breach-notification requirements for Part 2 records and aligned those requirements more closely with HIPAA’s Breach Notification Rule. Part 2 programs must report qualifying breaches of unsecured Part 2 records, including required notification to affected individuals, the HHS Secretary, and, in some circumstances, the media. This represents a major modernization of the SUD confidentiality regime. Programs should therefore integrate Part 2 records into incident-response procedures rather than assuming only HIPAA-designated PHI needs formal breach analysis and reporting.
Question 327. What compliance date applied to the requirements of HHS’s 2024 final rule updating 42 CFR Part 2?
- February 16, 2026
- January 1, 2024
- July 1, 2027
- January 1, 2030
Correct Answer: 1. February 16, 2026
Explanation:
HHS’s 2024 Part 2 final rule became effective on April 16, 2024, but regulated entities were given until February 16, 2026, to comply with the updated requirements. That distinction between an effective date and a compliance date is important. By February 16, 2026, regulated entities needed to implement the revised consent, notice, breach, redisclosure, patient-rights, and other applicable requirements. OCR’s civil enforcement program also became operational for Part 2 at that time, including acceptance of complaints and breach reports.
Question 328. A Part 2 program is also a HIPAA covered entity. How may it address patient privacy notices under the updated rules?
- It must maintain two entirely unrelated notices in every circumstance
- It may omit Part 2 information from all notices
- It may use a combined notice that satisfies both HIPAA and Part 2 notice requirements
- It may provide notice only after a patient requests records
Correct Answer: 3. It may use a combined notice that satisfies both HIPAA and Part 2 notice requirements
Explanation:
HHS permits a Part 2 program that also qualifies as a HIPAA covered entity to use a combined privacy notice, provided the document satisfies both HIPAA Notice of Privacy Practices requirements and the Part 2 patient-notice requirements. This can reduce duplicative paperwork while still communicating how SUD records may be used and disclosed, the entity’s responsibilities, and patients’ privacy rights. HHS has provided model notice materials to assist regulated entities. Combining notices does not merge the laws entirely; the organization must still comply with substantive protections specific to Part 2.
Question 329. Before an employer obtains a consumer report for employment purposes under the FCRA, what must it generally do?
- Provide the applicant or employee with a clear disclosure and obtain written authorization
- Obtain a search warrant
- Notify the applicant only after the hiring decision
- Obtain permission from the applicant’s current employer
Correct Answer: 2. Provide the applicant or employee with a clear disclosure and obtain written authorization
Explanation:
Employers using third-party consumer reports for employment purposes must satisfy FCRA requirements before obtaining the report. They generally must clearly inform the applicant or employee that a consumer report may be obtained and used for employment decisions and obtain the person’s written permission. Employment purposes under the FCRA include decisions concerning hiring, promotion, reassignment, and retention. State laws can impose additional background-check restrictions, so federal FCRA compliance may not be the end of the analysis. Employers should coordinate authorization, permissible-purpose certification, and state-specific requirements before ordering the report.
Question 330. Before taking an adverse employment action based on information in a consumer report, what must an employer generally provide?
- Nothing until after the decision becomes final
- Only the name of the hiring manager
- A copy of the consumer report and a copy of the Summary of Rights under the FCRA
- A free year of credit monitoring in every case
Correct Answer: 1. A copy of the consumer report and a copy of the Summary of Rights under the FCRA
Explanation:
Before taking adverse action based on a consumer report, an employer generally must provide the applicant or employee with a pre-adverse-action notice that includes a copy of the report relied upon and the Summary of Rights under the FCRA. Providing the materials before the final decision gives the individual an opportunity to review the information and identify inaccuracies. This is distinct from the post-adverse-action notice required after the employer actually makes the unfavorable decision. Employers should build both steps into their background-screening process rather than treating them as one notice.
Question 331. After an employer takes an adverse action based on a consumer report, which information must generally be included in the notice?
- The employer’s complete hiring algorithm
- The consumer reporting agency’s internal source code
- The applicant’s complete personnel file
- The CRA’s contact information, a statement that the CRA did not make the decision, and notice of dispute and free-report rights**
Correct Answer: 4. The CRA’s contact information, a statement that the CRA did not make the decision, and notice of dispute and free-report rights
Explanation:
After an adverse employment decision based on a consumer report, the employer must provide a post-adverse-action notice. The notice generally identifies the consumer reporting agency, explains that the CRA did not make the employment decision and cannot explain the employer’s reasons, and informs the individual of rights to dispute inaccurate or incomplete information and to obtain an additional free report if requested within 60 days. The notice helps consumers identify the source of potentially inaccurate information and provides a path for correction.
Question 332. What additional FCRA obligation arises when an employer obtains an investigative consumer report based on personal interviews about an individual’s character, reputation, personal characteristics, or lifestyle?
- The employer must publish the report
- Additional written notice and disclosure rights concerning the investigative report and its scope apply
- No FCRA requirements apply to investigative reports
- The report may only be requested after employment begins
Correct Answer: 3. Additional written notice and disclosure rights concerning the investigative report and its scope apply
Explanation:
Investigative consumer reports involve information obtained through personal interviews about a person’s character, general reputation, personal characteristics, or mode of living. Employers using these reports have obligations beyond ordinary consumer-report requirements. They must provide specified notice that an investigative consumer report may be or has been requested and explain the individual’s right to request additional information about the nature and scope of the investigation. The rules recognize that interview-based reporting can contain especially subjective information and therefore give consumers additional transparency rights.
Question 333. What is a core duty of an information furnisher under the FCRA?
- Provide information to credit bureaus even when known to be inaccurate
- Delete all consumer accounts after one year
- Refuse to investigate disputes submitted through a CRA
- Furnish information accurately and investigate qualifying disputes concerning information it supplied**
Correct Answer: 1. Furnish information accurately and investigate qualifying disputes concerning information it supplied
Explanation:
Businesses that furnish information to consumer reporting agencies have important FCRA duties. They should provide information that is accurate and complete and investigate consumer disputes regarding information they reported. Depending on the dispute process, furnishers may receive disputes directly from consumers or indirectly through CRAs. The legal framework aims to improve the accuracy and integrity of consumer-report information because inaccurate data can affect credit, insurance, housing, and other important decisions. Furnishers should therefore maintain documented dispute procedures rather than assuming accuracy is solely the CRA’s responsibility.
Question 334. An insurer wants a consumer report containing medical information for underwriting. What does the FCRA generally require before the CRA supplies that medical information?
- Nothing if the insurer already knows the consumer’s name
- The consumer’s permission
- Consent from the consumer’s employer
- Approval from HHS
Correct Answer: 4. The consumer’s permission
Explanation:
The FCRA places additional restrictions on consumer reports containing medical information. FTC guidance states that when an insurer needs a consumer report containing medical information, the consumer’s permission is generally required before the CRA can issue the report. The insurer must also have a permissible purpose for obtaining the consumer report, such as underwriting insurance involving the consumer. Medical information obtained through this process is further restricted in how it may be shared. These requirements demonstrate how the FCRA can protect health-related information even when HIPAA does not govern the specific transaction.
Question 335. An insurer increases a consumer’s premium partly because of information in a consumer report. Which FCRA requirement is likely triggered?
- An adverse action notice to the consumer
- A HIPAA breach notice
- A COPPA parental-consent notice
- A FERPA annual notice
Correct Answer: 3. An adverse action notice to the consumer
Explanation:
Under the FCRA, adverse action in the insurance context can include denying coverage, terminating a policy, increasing charges, or making another unfavorable change based partly or entirely on information in a consumer report. When such action occurs, the consumer must generally receive an adverse action notice identifying the CRA and explaining relevant consumer rights. The notice allows the individual to obtain a free copy of the report within the applicable period and dispute inaccurate information. Insurance underwriting therefore represents another important FCRA use case beyond lending and employment background checks.
Question 336. A lender approves a consumer for credit but offers materially less favorable terms because of information in the consumer’s credit report. Which requirement may apply?
- HIPAA minimum necessary
- A risk-based pricing notice
- FERPA consent
- COPPA Safe Harbor certification
Correct Answer: 2. A risk-based pricing notice
Explanation:
The FCRA’s Risk-Based Pricing Rule generally applies when a creditor uses a consumer report to grant credit on terms that are materially less favorable than terms offered to a substantial proportion of other consumers. Instead of simply denying credit, the creditor may charge a higher rate or impose less favorable terms because of report information. In qualifying circumstances, the consumer must receive a risk-based pricing notice. This differs from the adverse-action notice required when credit is denied or otherwise adversely changed within the FCRA’s adverse-action framework.
Question 337. A lender denies an application for credit because of information in a consumer report. Which consumer right should the adverse action notice explain?
- The right to obtain a free copy of the report from the CRA if requested within 60 days and to dispute inaccurate information
- The right to have the debt automatically canceled
- The right to require the lender to approve the application
- The right to delete every negative item from the report
Correct Answer: 4. The right to obtain a free copy of the report from the CRA if requested within 60 days and to dispute inaccurate information
Explanation:
An FCRA adverse action notice helps consumers understand how to investigate information that contributed to an unfavorable credit decision. Among other things, it must inform the consumer of the right to obtain a free copy of the report from the CRA if requested within 60 days and the right to dispute inaccurate or incomplete information. The CRA did not make the lender’s business decision and is not required to reverse accurate negative information. The purpose is transparency and correction of inaccurate reporting, not a guaranteed approval of the requested credit.
Question 338. Under the FCRA, why must a person requesting a consumer report have a permissible purpose?
- Consumer reports are regulated information and generally may be furnished only for purposes authorized by the statute
- Permissible purpose is required only for government agencies
- Anyone may obtain a report if they know the consumer’s address
- Consumer reports are public records
Correct Answer: 1. Consumer reports are regulated information and generally may be furnished only for purposes authorized by the statute
Explanation:
The FCRA limits access to consumer reports by requiring users to have a permissible purpose recognized by the statute. Permissible purposes can include qualifying credit transactions, insurance underwriting, employment uses with required procedures, tenant screening, certain account reviews, and other specified circumstances. A person cannot lawfully obtain another individual’s consumer report merely out of curiosity or because identifying information is available. This access limitation is a central FCRA privacy protection, ensuring that consumer reporting agencies furnish reports only where an authorized legal purpose exists.
Question 339. A consumer reporting agency receives a dispute about information in a consumer’s report. What core policy objective of the FCRA does the dispute process support?
- Maximizing advertising revenue
- Protecting report accuracy and allowing consumers to challenge inaccurate or incomplete information
- Preventing consumers from seeing their files
- Eliminating all negative financial information
Correct Answer: 2. Protecting report accuracy and allowing consumers to challenge inaccurate or incomplete information
Explanation:
Accuracy is one of the central objectives of the FCRA. Consumer reports can affect access to credit, housing, employment, insurance, and other opportunities, so inaccurate information can cause serious harm. The FCRA gives consumers rights to dispute inaccurate or incomplete information, while CRAs and furnishers have corresponding investigation responsibilities. The law does not require accurate negative information to be removed simply because the consumer dislikes it. Instead, the dispute system is designed to identify and correct information that is erroneous, incomplete, or otherwise improperly reported.
Question 340. A health care organization operates a Part 2 substance use disorder program and also uses third-party background reports when hiring employees. What is the BEST privacy-compliance approach?
- Apply only HIPAA because health care laws override employment screening requirements
- Apply only the FCRA because employee screening is the organization’s primary business risk
- Separately apply Part 2 confidentiality and breach requirements to SUD records and FCRA authorization, pre-adverse, and adverse-action procedures to employment consumer reports
- Use one general employee consent form to satisfy every privacy law
Correct Answer: 3. Separately apply Part 2 confidentiality and breach requirements to SUD records and FCRA authorization, pre-adverse, and adverse-action procedures to employment consumer reports
Explanation:
An organization can operate under several privacy regimes simultaneously because each law regulates different information and activities. Part 2 protects qualifying substance use disorder patient records and now includes updated consent, redisclosure, breach, notice, and enforcement requirements. The FCRA separately regulates the employer’s use of third-party consumer reports for hiring, promotion, reassignment, and retention. Appropriate authorization, pre-adverse-action procedures, and post-adverse notices are required when applicable. A mature privacy program maps the information, legal role, affected individual, and processing purpose instead of trying to satisfy every obligation through one generic form or policy.