IAPP CIPP-US Practice Test Questions and Exam Dumps Part11 Q201-220

View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.


Question 201. Under HIPAA, what is a limited data set?

  1. PHI from which specified direct identifiers have been removed, but which may still contain certain information such as dates and limited geographic data
  2. Any health information stored on fewer than 500 individuals
  3. Fully anonymous data containing no possible identifiers whatsoever
  4. Only information contained in paper medical records

Correct Answer: 1. PHI from which specified direct identifiers have been removed, but which may still contain certain information such as dates and limited geographic data

Explanation:

A HIPAA limited data set is still protected health information, but certain direct identifiers of the individual and specified relatives, household members, and employers must be removed. Unlike fully de-identified information, a limited data set may retain some useful information, including certain dates and geographic details. Covered entities may disclose limited data sets for research, public health, and health care operations when the recipient signs an appropriate data use agreement. Because limited data sets remain PHI, they should not be treated as unrestricted information merely because many identifiers have been removed.

Question 202. What agreement is generally required when a covered entity discloses a HIPAA limited data set to a recipient?

  1. A consumer credit agreement
  2. A data use agreement
  3. A FERPA consent form
  4. A search warrant

Correct Answer: 2. A data use agreement

Explanation:

HIPAA generally requires a data use agreement before a covered entity discloses a limited data set for permitted purposes such as research, public health, or health care operations. The agreement establishes permitted uses and disclosures, limits who may use or receive the data, requires appropriate safeguards, restricts re-identification and contact with individuals, and obligates the recipient to report unauthorized uses or disclosures. A data use agreement is not the same as a business associate agreement, although the two can sometimes be combined when both sets of requirements apply.

Question 203. Which method can a covered entity use to de-identify PHI under the HIPAA Privacy Rule?

  1. Simply removing the patient’s name
  2. Replacing the record with a customer number while keeping all other identifiers
  3. Using either the Safe Harbor method or the Expert Determination method
  4. Obtaining a business associate agreement from the recipient

Correct Answer: 3. Using either the Safe Harbor method or the Expert Determination method

Explanation:

HIPAA recognizes two principal methods for de-identifying protected health information: Safe Harbor and Expert Determination. Safe Harbor requires removal of specified identifiers and no actual knowledge that the remaining information could identify an individual. Expert Determination relies on a qualified expert applying generally accepted statistical and scientific principles to determine that the risk of re-identification is very small. Merely removing a person’s name is not necessarily sufficient because other data elements can still identify the individual. Once information is properly de-identified, HIPAA generally no longer treats it as PHI.

Question 204. A cloud service provider receives only information that has been properly de-identified under HIPAA. Is the provider a business associate solely because it stores that information?

  1. Yes, every cloud provider is automatically a business associate
  2. Yes, but only if the data originated at a hospital
  3. Yes, whenever the data relates to health
  4. No, not if it receives and maintains only properly de-identified information**

Correct Answer: 4. No, not if it receives and maintains only properly de-identified information

Explanation:

HHS states that a cloud service provider is not a HIPAA business associate when it receives and maintains only information that has been de-identified in accordance with the HIPAA Privacy Rule. Properly de-identified information is not considered PHI, so ordinary HIPAA Privacy and Security Rule obligations applicable to PHI do not attach solely because the data originated from a covered entity. The analysis changes if the provider also receives identifiable PHI or performs functions that otherwise make it a business associate. Proper classification of the data therefore matters before determining contractual and security obligations.

Question 205. Which statement BEST describes HIPAA research use of PHI without an individual’s authorization?

  1. It can be permitted in specified circumstances, such as with documented IRB or Privacy Board waiver approval
  2. It is never permitted
  3. It is permitted whenever a researcher promises confidentiality orally
  4. It requires publication of the research protocol in the Federal Register

Correct Answer: 1. It can be permitted in specified circumstances, such as with documented IRB or Privacy Board waiver approval

Explanation:

HIPAA permits certain research uses and disclosures of PHI without individual authorization when specific conditions are satisfied. One important pathway is a documented waiver or alteration of authorization approved by an Institutional Review Board or Privacy Board. Other pathways include certain activities preparatory to research and research involving decedents. A limited data set may also be used for research pursuant to a data use agreement. These exceptions are structured and conditional, so researchers cannot simply rely on a promise of confidentiality as a substitute for HIPAA’s requirements.

Question 206. A researcher receives only a HIPAA limited data set from a covered entity for research purposes. What is generally required?

  1. A search warrant
  2. A data use agreement, rather than individual HIPAA authorization for that limited-data-set disclosure
  3. A court-approved subpoena in every case
  4. A full business associate agreement in every case

Correct Answer: 2. A data use agreement, rather than individual HIPAA authorization for that limited-data-set disclosure

Explanation:

HIPAA allows a covered entity to disclose a limited data set for research without obtaining individual authorization, provided the recipient enters into a compliant data use agreement. The agreement restricts permitted uses and disclosures, requires safeguards, limits downstream access, and prohibits identifying or contacting the individuals. HHS also explains that a researcher receiving PHI for research is not automatically a business associate merely because the covered entity engages the researcher. The legal basis for research disclosure must still be established under the Privacy Rule.

Question 207. Under FERPA’s school-official exception, when may a school disclose education records to an outside contractor without prior consent?

  1. Whenever the contractor pays the school
  2. Whenever the contractor signs any confidentiality agreement
  3. When the contractor performs an institutional service, is under the school’s direct control regarding records, follows FERPA redisclosure restrictions, and meets the school’s school-official criteria
  4. Only when the contractor is a government employee

Correct Answer: 3. When the contractor performs an institutional service, is under the school’s direct control regarding records, follows FERPA redisclosure restrictions, and meets the school’s school-official criteria

Explanation:

FERPA permits schools to treat certain contractors, consultants, volunteers, and other outside parties as school officials for disclosure purposes. To qualify, the outside party must perform a service or function the school would otherwise use employees to perform, remain under the school’s direct control regarding use and maintenance of education records, comply with restrictions on use and redisclosure, and satisfy the criteria identified in the school’s annual FERPA notice for legitimate educational interest. The exception therefore requires meaningful institutional control rather than merely calling a vendor a “school official.”

Question 208. Can a school law-enforcement-unit official ever qualify as a FERPA “school official” with a legitimate educational interest?

  1. No, law-enforcement personnel are categorically excluded
  2. Only if the official is also a teacher
  3. Only if the student gives written consent in every instance
  4. Yes, if the official satisfies FERPA’s applicable school-official conditions**

Correct Answer: 4. Yes, if the official satisfies FERPA’s applicable school-official conditions

Explanation:

A school law-enforcement-unit official can qualify as a school official with a legitimate educational interest if the relevant FERPA requirements are met. The official must perform an institutional function the school would otherwise use employees to perform, be under the school’s direct control regarding education records, comply with use and redisclosure restrictions, and satisfy the school’s published criteria for school officials with legitimate educational interests. This does not make every law-enforcement disclosure automatically permissible. Schools must distinguish access in the official’s school role from disclosures made to outside law enforcement for other purposes.

Question 209. Under FERPA, what limits generally apply after a school discloses education-record PII to a qualifying school official?

  1. The recipient may use the information only for the purpose for which the disclosure was made and remains subject to applicable redisclosure restrictions
  2. The recipient may sell the information to advertisers
  3. FERPA ceases to apply after the first disclosure
  4. The recipient may publish the records if names are removed

Correct Answer: 1. The recipient may use the information only for the purpose for which the disclosure was made and remains subject to applicable redisclosure restrictions

Explanation:

FERPA’s school-official exception does not turn education-record information into unrestricted data. Contractors and other school officials receiving PII must remain subject to the rule’s restrictions on use and redisclosure. Information generally should be used only for the institutional purpose supporting the original disclosure. This principle is particularly important with education technology vendors, security contractors, and consultants because access may be operationally broad even though legally permitted purposes are narrow. Schools should reinforce these limitations through contracts, access controls, training, and vendor oversight.

Question 210. Under HIPAA, what is true when a covered entity uses or discloses PHI for treatment, payment, or health care operations?

  1. Individual authorization is always required
  2. The Privacy Rule generally permits such uses and disclosures without individual authorization, subject to applicable conditions
  3. Only a court can approve these activities
  4. Treatment disclosures are prohibited between separate providers

Correct Answer: 2. The Privacy Rule generally permits such uses and disclosures without individual authorization, subject to applicable conditions

Explanation:

HIPAA permits covered entities to use and disclose PHI for treatment, payment, and health care operations without obtaining individual authorization in many circumstances. These activities are central to the functioning of the health care system. Treatment can include communication among providers, payment includes activities needed to obtain reimbursement, and health care operations include specified administrative and quality-related functions. Other HIPAA requirements still apply, and the minimum necessary standard does not apply identically to every category—for example, disclosures for treatment receive special treatment under the rule.

Question 211. What is one purpose of the FCRA’s affiliate-marketing provisions implemented through Regulation V?

  1. To regulate federal government public records
  2. To create HIPAA medical records
  3. To limit certain uses of eligibility information received from an affiliate for marketing solicitations unless applicable notice and opt-out requirements are satisfied
  4. To ban all corporate affiliates from sharing information

Correct Answer: 3. To limit certain uses of eligibility information received from an affiliate for marketing solicitations unless applicable notice and opt-out requirements are satisfied

Explanation:

Regulation V implements several FCRA requirements, including affiliate-marketing restrictions. In general, the rules address circumstances in which a company uses specified eligibility information received from an affiliate to make marketing solicitations to consumers. Depending on the circumstances, consumers must receive appropriate notice and an opportunity to opt out before such information is used for affiliate marketing. The rules do not categorically prohibit information sharing among affiliates; rather, they regulate certain downstream marketing uses of shared eligibility information. This distinction is important in large financial or corporate groups with multiple affiliated businesses.

Question 212. Regulation V implements which federal statute?

  1. HIPAA
  2. COPPA
  3. FERPA
  4. The Fair Credit Reporting Act**

Correct Answer: 4. The Fair Credit Reporting Act

Explanation:

Regulation V implements the Fair Credit Reporting Act. It covers topics including consumer reporting agencies, users of consumer reports, furnishers of information, identity theft, affiliate marketing, file disclosures, and use of certain medical information. Understanding Regulation V is important because many FCRA duties appear in implementing regulations and official interpretations rather than only in the statutory text. Privacy professionals dealing with credit, employment background screening, affiliate marketing, or information furnished to consumer reporting agencies should therefore understand both the FCRA and Regulation V.

Question 213. Why might a financial institution use the model privacy form in Regulation P?

  1. To obtain a regulatory safe harbor for the form of its privacy notice when used in accordance with the instructions
  2. To avoid all GLBA obligations permanently
  3. To eliminate the need for any data-security controls
  4. To convert customers into affiliates

Correct Answer: 1. To obtain a regulatory safe harbor for the form of its privacy notice when used in accordance with the instructions

Explanation:

Regulation P includes a model privacy form that financial institutions can use to satisfy specified privacy-notice requirements. Institutions that use the form consistently with the regulatory instructions can obtain a safe harbor for the notice format. The model form is designed to present sharing practices in a standardized and understandable manner. It does not eliminate other GLBA obligations, such as safeguarding customer information or complying with restrictions on account-number disclosures. Institutions must also ensure the substantive information included in the model form accurately reflects their actual practices.

Question 214. What should a financial institution consider if it discloses information from a consumer reporting agency to affiliates?

  1. Only CAN-SPAM
  2. Potential FCRA obligations in addition to GLBA privacy requirements
  3. Only HIPAA marketing rules
  4. No additional law because affiliates are part of the same corporate family

Correct Answer: 2. Potential FCRA obligations in addition to GLBA privacy requirements

Explanation:

Regulation P’s model privacy form instructions expressly note that disclosures involving certain information—such as information obtained from a consumer reporting agency—may trigger Fair Credit Reporting Act obligations in addition to GLBA requirements. Depending on the disclosure and subsequent use, the institution may need to consider affiliate-sharing opt-outs, affiliate-marketing rules, or even whether conduct could implicate consumer-reporting-agency status. Privacy professionals should therefore avoid analyzing financial privacy solely under GLBA when consumer-report information is involved. Multiple sector-specific rules can overlap in one information-sharing arrangement.

Question 215. What is a core FTC advertising-law requirement that applies to privacy-related marketing claims?

  1. Advertising claims must be truthful and not deceptive or unfair
  2. Every privacy claim must be preapproved by the FTC
  3. Companies may make any claim if it appears in small print
  4. Advertising law never applies to statements about data practices

Correct Answer: 1. Advertising claims must be truthful and not deceptive or unfair

Explanation:

FTC advertising law requires marketing claims to be truthful, nondeceptive, and not unfair. This principle can apply directly to privacy and security representations. A company that markets a product as “anonymous,” “private,” “secure,” or “never shared” should ensure the claim is accurate and adequately supported by actual practices. Fine print or technical disclosures may not cure a misleading overall impression. Privacy teams therefore should review advertising and product claims alongside legal and marketing teams so consumer-facing promises align with operational data practices.

Question 216. An influencer promotes a privacy-focused mobile application but fails to disclose that the developer paid for the endorsement. Which FTC concern is MOST relevant?

  1. HIPAA minimum necessary
  2. The Stored Communications Act
  3. Endorsement and testimonial disclosure requirements under FTC advertising principles
  4. FERPA directory information

Correct Answer: 3. Endorsement and testimonial disclosure requirements under FTC advertising principles

Explanation:

FTC advertising guidance requires endorsements and testimonials to comply with truth-in-advertising principles. When a material connection exists between an endorser and the advertiser—such as payment, free products, or another relationship that could affect the credibility consumers give the endorsement—the connection generally should be clearly disclosed. The fact that the product being promoted is privacy-focused does not change the basic advertising rule. Privacy professionals should recognize that privacy products and services remain subject to ordinary consumer-protection standards governing marketing claims, endorsements, influencers, and reviews.

Question 217. Which HIPAA research disclosure would generally NOT require a business associate agreement solely because the recipient is a researcher?

  1. A permissible disclosure of PHI to a researcher for research purposes under the Privacy Rule
  2. A vendor performing billing functions on behalf of a covered entity
  3. A consultant conducting health care operations using PHI on behalf of the covered entity
  4. A cloud service maintaining identifiable PHI for the covered entity

Correct Answer: 1. A permissible disclosure of PHI to a researcher for research purposes under the Privacy Rule

Explanation:

HHS explains that a researcher is not automatically a business associate merely because a covered entity discloses PHI to the researcher for research. A business associate relationship generally exists when the outside party performs a covered function or service on behalf of the covered entity, such as payment, health care operations, legal, or administrative services involving PHI. Research disclosures still need an independent HIPAA basis, such as individual authorization, an IRB or Privacy Board waiver, or a limited data set with a data use agreement.

Question 218. Under HIPAA research rules, what is generally true of a disclosure made pursuant to an individual’s valid research authorization?

  1. It automatically requires a separate Privacy Board waiver
  2. It generally does not require an IRB or Privacy Board waiver of authorization for that disclosure
  3. It may never identify the research study
  4. It must expire within 30 days

Correct Answer: 2. It generally does not require an IRB or Privacy Board waiver of authorization for that disclosure

Explanation:

When an individual provides a valid HIPAA authorization for research use or disclosure of PHI, the covered entity generally does not need a separate IRB or Privacy Board waiver of authorization for that same disclosure. HIPAA research authorizations have some special flexibility; for example, an authorization may state that it has no expiration date or continues until the end of the research study. An authorization can also be combined with other legal permissions relating to study participation, provided applicable requirements are satisfied.

Question 219. What is generally true of disclosures of a HIPAA limited data set made under a data use agreement for research?

  1. They are generally exempt from the ordinary HIPAA accounting-of-disclosures requirement
  2. They must always appear in the individual’s accounting of disclosures
  3. They automatically trigger breach notification
  4. They require prior approval from the FTC

Correct Answer: 4. They are generally exempt from the ordinary HIPAA accounting-of-disclosures requirement

Explanation:

HHS explains that certain research disclosures are excluded from the HIPAA accounting-of-disclosures requirement. These include disclosures made pursuant to an individual’s authorization and disclosures of limited data sets to researchers under compliant data use agreements. Other research disclosures may need to be included in an accounting, depending on the legal basis and applicable rules. Privacy professionals should therefore distinguish the legal basis for each research disclosure rather than treating all research activity identically. The accounting rules are separate from whether the underlying disclosure itself was permitted.

Question 220. A health system conducts research, uses outside education contractors, shares consumer-report information within a financial affiliate, and advertises privacy features to consumers. What is the BEST compliance approach?

  1. Apply HIPAA to every activity because health organizations are always governed solely by HIPAA
  2. Use one general consent form for every data practice
  3. Map each activity to its applicable legal framework, including HIPAA research rules, FERPA where education records are involved, FCRA/Regulation V for consumer-report information, and FTC advertising standards for public claims
  4. Assume vendor contracts replace all statutory requirements

Correct Answer: 3. Map each activity to its applicable legal framework, including HIPAA research rules, FERPA where education records are involved, FCRA/Regulation V for consumer-report information, and FTC advertising standards for public claims

Explanation:

Complex organizations often operate under several privacy and consumer-protection regimes at once. HIPAA governs covered health information in defined contexts, FERPA can apply to qualifying education records, FCRA and Regulation V regulate consumer-report information and specified affiliate uses, and FTC advertising law governs consumer-facing claims. Vendor contracts can support compliance but do not replace statutory requirements. The correct approach is to identify each data flow, legal role, purpose, recipient, and individual population, then apply the relevant rules rather than forcing every activity into one privacy framework.