View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 41. What does HIPAA’s “minimum necessary” standard generally require?
- Covered entities must disclose an individual’s entire medical record whenever PHI is requested
- Covered entities must make reasonable efforts to limit certain uses, disclosures, and requests for PHI to the amount necessary for the intended purpose
- PHI may never be shared outside a covered entity
- Every disclosure of PHI requires written patient authorization
Correct Answer: 2. Covered entities must make reasonable efforts to limit certain uses, disclosures, and requests for PHI to the amount necessary for the intended purpose
Explanation:
HIPAA’s minimum necessary standard generally requires covered entities to make reasonable efforts to limit protected health information used, disclosed, or requested to what is reasonably necessary to accomplish the intended purpose. The standard encourages organizations to establish role-based policies so workforce members receive access appropriate to their responsibilities. It does not mean that the smallest imaginable piece of information must always be used, nor does it apply to every HIPAA disclosure. Several exceptions exist, including certain treatment disclosures and disclosures made pursuant to an individual’s authorization. Privacy professionals should understand both the general principle and its exceptions.
Question 42. Which disclosure is generally exempt from HIPAA’s minimum necessary requirement?
- A disclosure to an advertising company for its own marketing campaign
- An internal disclosure to an employee who has no work-related need for the information
- A disclosure to an unrelated business for market research
- A disclosure to another health care provider for treatment purposes
Correct Answer: 4. A disclosure to another health care provider for treatment purposes
Explanation:
HIPAA expressly exempts disclosures to, and requests by, health care providers for treatment purposes from the minimum necessary requirement. The rule recognizes that providers may need sufficient clinical information to treat a patient properly and does not require them to reduce treatment-related exchanges to an artificially limited subset. This does not mean HIPAA permits unrestricted access for anyone who works in health care. Covered entities still need appropriate safeguards and role-based access controls internally. Other exceptions to minimum necessary include disclosures to the individual, disclosures pursuant to an authorization, certain required-by-law disclosures, and disclosures required for HIPAA enforcement.
Question 43. Under the HIPAA Privacy Rule, how quickly must a covered entity generally act on an individual’s request to access PHI?
- No later than 30 calendar days after receiving the request, subject to a permitted extension
- Within 90 business days
- Only at the end of the patient’s treatment
- Within one year
Correct Answer: 1. No later than 30 calendar days after receiving the request, subject to a permitted extension
Explanation:
HIPAA generally requires a covered entity to act on an individual’s access request no later than 30 calendar days after receiving it. If the entity cannot complete the request within that period, it may obtain one additional extension of no more than 30 calendar days, provided it gives the individual a written explanation of the delay and the expected completion date within the original period. The 30-day period is an outer limit, not a target; HHS encourages faster access when systems make that possible. The same timeline applies when a business associate maintains the requested information for the covered entity.
Question 44. Which category of information is expressly excluded from HIPAA’s individual right of access?
- Laboratory test results
- Billing records
- Psychotherapy notes maintained separately from the medical record
- Health plan enrollment records
Correct Answer: 3. Psychotherapy notes maintained separately from the medical record
Explanation:
HIPAA gives individuals a broad right to access protected health information in designated record sets, including medical records, billing records, claims information, laboratory results, and information used to make decisions about them. However, separately maintained psychotherapy notes are expressly excluded from the HIPAA access right. Information compiled in reasonable anticipation of, or for use in, certain legal proceedings is also excluded. Importantly, the underlying medical or payment information used to create excluded material can still remain part of the designated record set and be subject to access. Privacy professionals should distinguish psychotherapy notes from ordinary clinical notes contained in a patient’s medical chart.
Question 45. A patient believes information in a medical record is inaccurate. What right does HIPAA generally provide?
- The patient may request an amendment of the record
- The patient may personally delete the provider’s original record
- The patient may require the provider to destroy the entire medical file
- The patient automatically receives financial compensation
Correct Answer: 1. The patient may request an amendment of the record
Explanation:
HIPAA allows individuals to request amendment of information in their medical or billing records when they believe it is inaccurate or incomplete. The covered entity must respond to the request, although it does not have to accept every requested change. If the entity denies an amendment in circumstances permitted by the rule, the individual can generally submit a statement of disagreement that becomes associated with the relevant record. The amendment right does not mean the individual can unilaterally erase the provider’s original documentation. It instead creates a structured mechanism for correcting or contesting information used in health care decision-making.
Question 46. A pharmaceutical company wants a hospital to disclose patient PHI so the pharmaceutical company can market its own products directly to those patients. What is generally required under HIPAA?
- Nothing, because all health-related marketing is a treatment activity
- Only oral approval from a hospital employee
- A business associate agreement always eliminates the need for patient permission
- The individual’s prior written authorization, unless a specific exception applies
Correct Answer: 4. The individual’s prior written authorization, unless a specific exception applies
Explanation:
HIPAA generally requires an individual’s authorization before a covered entity uses or discloses PHI for marketing as defined by the Privacy Rule. HHS specifically distinguishes permissible communications from disclosures that enable another company to market its own goods or services. A covered entity cannot simply provide patient information to an outside marketer for that marketer’s independent commercial purposes. Certain limited communications fall outside the marketing definition or receive special treatment, but privacy professionals should not assume that a business associate agreement converts third-party marketing into an unrestricted health care operation. Marketing involving PHI requires careful classification and authorization analysis.
Question 47. Under GLBA Regulation P, what does a consumer opt-out right generally concern?
- All internal uses of information by a financial institution
- Certain disclosures of nonpublic personal information to nonaffiliated third parties
- Every disclosure required by law
- All information shared with regulators
Correct Answer: 2. Certain disclosures of nonpublic personal information to nonaffiliated third parties
Explanation:
Regulation P implements important GLBA privacy requirements for covered financial institutions. Among other provisions, it addresses privacy notices, limits on disclosure of nonpublic personal information to nonaffiliated third parties, and circumstances in which consumers must receive notice and an opportunity to opt out before certain disclosures occur. The opt-out right is not an absolute right to stop every transfer of financial information. Numerous exceptions and permitted disclosures exist. Privacy professionals therefore need to understand the type of information involved, the recipient’s relationship to the institution, and whether a regulatory exception applies before deciding that an opt-out must be offered.
Question 48. What does Regulation P specifically restrict concerning account numbers?
- Financial institutions may never assign account numbers
- Account numbers may not be stored electronically
- Certain disclosures of account-number information for marketing purposes are restricted
- Consumers must choose their own account numbers
Correct Answer: 3. Certain disclosures of account-number information for marketing purposes are restricted
Explanation:
Regulation P contains specific limits on sharing certain account-number information for marketing purposes. This requirement reflects the heightened sensitivity and fraud risk associated with account numbers and similar access information. GLBA privacy compliance therefore involves more than providing a privacy notice or offering an opt-out in some circumstances. Covered institutions also must consider restrictions on redisclosure, reuse, and specified marketing uses of account identifiers. Privacy professionals evaluating financial-information flows should identify not only whether information is nonpublic personal information, but also whether particularly sensitive identifiers are involved and whether a specific regulatory restriction applies to the contemplated disclosure.
Question 49. What is the PRIMARY purpose of the FTC Red Flags Rule?
- To require covered organizations to maintain written programs for detecting, preventing, and mitigating identity theft
- To establish requirements for children’s online advertising
- To govern patient medical records
- To regulate cable viewing history
Correct Answer: 1. To require covered organizations to maintain written programs for detecting, preventing, and mitigating identity theft
Explanation:
The Red Flags Rule requires covered businesses and organizations to develop and implement a written Identity Theft Prevention Program. The program should help identify patterns, practices, or specific activities indicating possible identity theft, establish procedures for responding appropriately, and provide for updating the program as risks evolve. Examples of warning signs can include suspicious identification documents, inconsistent personal information, unusual account activity, and notices from customers or law enforcement. The Red Flags Rule is associated with the FCRA identity-theft framework and should not be confused with data-breach notification or general information-security laws.
Question 50. Which event is an example of a possible “red flag” of identity theft?
- A customer makes their normal monthly payment
- A business updates its privacy policy
- An employee receives routine cybersecurity training
- A customer’s identification information conflicts with other information supplied during account opening
Correct Answer: 4. A customer’s identification information conflicts with other information supplied during account opening
Explanation:
The Red Flags Rule focuses on warning signs indicating that identity theft may be occurring. Inconsistent personal information is a classic example. A submitted address may conflict with a credit report, an identification document may not match the person presenting it, a Social Security number may already be associated with another fraudulent account, or an application may appear altered. Covered organizations should identify the red flags relevant to their covered accounts and operating environment, establish appropriate detection methods, and define responses that prevent or mitigate identity theft. A useful program should reflect the organization’s actual risks rather than simply copying a generic checklist.
Question 51. What is the general rule of the Driver’s Privacy Protection Act (DPPA) regarding personal information held by state motor vehicle departments?
- The information must always be publicly available
- Disclosure is generally restricted unless a statutory permissible use or other authorization applies
- Only insurance companies may receive the information
- The information may be disclosed for any commercial purpose without restriction
Correct Answer: 2. Disclosure is generally restricted unless a statutory permissible use or other authorization applies
Explanation:
The DPPA restricts disclosure and use of personal information obtained from state motor vehicle records, while providing a series of statutory permissible uses. Those uses include certain government functions, motor vehicle safety activities, litigation-related purposes, fraud prevention, and uses supported by the individual’s written consent. Privacy analysis under the DPPA therefore requires examining both the source of the information and the purpose for which it will be obtained or used. The law does not make driver-record information universally confidential in every situation, but neither does it allow unrestricted commercial access simply because a requester can obtain the data technically.
Question 52. Under the DPPA, when may a legitimate business use motor vehicle record information to verify information supplied by an individual?
- Never
- Only if the business is a motor vehicle manufacturer
- In the normal course of business to verify accuracy, with further use of corrected information limited to specified purposes such as fraud prevention or debt recovery
- For any unrelated advertising purpose
Correct Answer: 3. In the normal course of business to verify accuracy, with further use of corrected information limited to specified purposes such as fraud prevention or debt recovery
Explanation:
The DPPA provides a permissible-use provision allowing a legitimate business, or its agents, employees, or contractors, to use motor vehicle record information in the normal course of business to verify the accuracy of personal information submitted by an individual. If the information supplied is incorrect or outdated, the business may obtain corrected information for specified purposes such as preventing fraud, pursuing legal remedies, or recovering a debt or security interest. This is not a general authorization to repurpose driver information for unrelated advertising. The specific statutory purpose remains central to determining whether the use is permitted.
Question 53. Under the DPPA, an authorized recipient that resells or rediscloses covered personal information generally must keep records of recipients and permitted purposes for how long?
- 30 days
- One year
- Three years
- Five years
Correct Answer: 4. Five years
Explanation:
The DPPA imposes recordkeeping obligations on many authorized recipients that resell or redisclose personal information obtained under the statute. Covered recipients generally must retain records identifying each person or entity that received the information and the permitted purpose for which it was provided for five years, and those records must be available to the motor vehicle department upon request. This requirement supports accountability after the initial disclosure and helps ensure downstream use remains tied to statutory permissible purposes. Privacy programs dealing with regulated government-source data should therefore address not only initial collection but also redisclosure controls and record-retention requirements.
Question 54. What is the PRIMARY focus of the federal Right to Financial Privacy Act (RFPA)?
- Restricting federal government access to customers’ financial records held by financial institutions unless statutory procedures or exceptions are satisfied
- Regulating private companies’ marketing emails
- Governing children’s banking accounts
- Requiring all financial institutions to publish customer transactions
Correct Answer: 1. Restricting federal government access to customers’ financial records held by financial institutions unless statutory procedures or exceptions are satisfied
Explanation:
The Right to Financial Privacy Act generally restricts federal government authorities from obtaining customers’ financial records from financial institutions unless they use an authorized statutory mechanism or an exception applies. The law responds to government access to financial records rather than functioning as a comprehensive consumer privacy law for all financial-sector data processing. Depending on the circumstances, permitted mechanisms can include customer authorization, qualifying subpoenas or summonses, search warrants, judicial subpoenas, and formal written requests. CIPP/US candidates should distinguish the RFPA’s government-access focus from GLBA, which regulates privacy and information-sharing practices of covered financial institutions.
Question 55. Which is a recognized mechanism under the RFPA through which a federal government authority may obtain qualifying customer financial records?
- An employee’s informal telephone request
- A search warrant meeting statutory requirements
- An anonymous social media message
- An unrestricted marketing request
Correct Answer: 2. A search warrant meeting statutory requirements
Explanation:
The RFPA specifies mechanisms through which a government authority may obtain qualifying customer financial records. These include customer authorization and specified forms of legal process, such as an administrative subpoena or summons, a search warrant, a judicial subpoena, or a formal written request meeting statutory requirements. The records also must generally be reasonably described. The existence of defined mechanisms prevents federal government access from resting solely on an informal request to a financial institution. Privacy professionals should recognize, however, that the RFPA contains exceptions, so each request must be assessed according to the statute’s detailed provisions rather than one simplified rule.
Question 56. What privacy notice must a covered cable operator generally provide to a subscriber under 47 U.S.C. § 551?
- Only a one-time oral notice when service begins
- A notice only if the subscriber complains
- A separate written privacy notice when the relationship begins and at least annually thereafter
- No privacy notice is required
Correct Answer: 3. A separate written privacy notice when the relationship begins and at least annually thereafter
Explanation:
Federal cable subscriber privacy law generally requires a cable operator to provide a separate, written privacy notice when entering into the subscriber relationship and at least once annually afterward. The notice must address subjects such as the nature of personally identifiable information collected, how it is used, disclosure practices, retention periods, subscriber access rights, and applicable privacy limitations. This requirement illustrates that U.S. privacy law contains industry-specific notice obligations beyond the better-known health, financial, and consumer-reporting statutes. Privacy professionals should identify sector-specific rules when evaluating organizations that offer regulated communications or media services.
Question 57. When may a cable operator generally collect personally identifiable subscriber information through the cable system without prior subscriber consent?
- When the information is necessary to provide the cable or related service, or to detect unauthorized reception
- Whenever the operator intends to sell the information to advertisers
- Only after obtaining a federal search warrant
- For any unrelated business purpose selected by the operator
Correct Answer: 1. When the information is necessary to provide the cable or related service, or to detect unauthorized reception
Explanation:
Federal cable privacy law generally restricts collection of personally identifiable information through the cable system without prior written or electronic consent. However, it allows collection when needed to provide the cable service or another service supplied by the operator, as well as to detect unauthorized reception of cable communications. This illustrates a common privacy-law structure: broad restrictions accompanied by purpose-specific exceptions necessary to provide the underlying service or protect it from misuse. Organizations should avoid treating a service-delivery exception as permission to collect additional subscriber information for unrelated commercial purposes.
Question 58. What right does federal cable subscriber privacy law provide concerning personally identifiable information maintained by a cable operator?
- Subscribers may require all cable records to be posted publicly
- Subscribers may access their personally identifiable information and receive a reasonable opportunity to correct errors
- Subscribers may modify other subscribers’ records
- Subscribers may require that every record be retained permanently
Correct Answer: 4. Subscribers may access their personally identifiable information and receive a reasonable opportunity to correct errors
Explanation:
Federal cable privacy law gives subscribers access to personally identifiable information about them that the cable operator collects and maintains. The information must be made available at reasonable times and at a convenient place designated by the operator, and the subscriber must receive a reasonable opportunity to correct errors. The statute also includes a destruction principle requiring personally identifiable information to be destroyed when it is no longer necessary for the purpose for which it was collected, subject to specified pending requests or orders. These provisions reflect access, correction, and retention concepts familiar across many privacy frameworks.
Question 59. Which conduct can fall within the federal Computer Fraud and Abuse Act (CFAA)?
- Intentionally accessing a protected computer without authorization and obtaining information
- Sending an ordinary commercial email containing an unsubscribe mechanism
- Requesting one’s own health records from a physician
- Exercising a state consumer deletion right
Correct Answer: 3. Intentionally accessing a protected computer without authorization and obtaining information
Explanation:
The CFAA is a federal computer-crime statute addressing specified unauthorized computer access and related conduct. Among its provisions, it prohibits intentionally accessing a computer without authorization or exceeding authorized access and thereby obtaining certain protected categories of information, including information from a protected computer. Other provisions address conduct such as computer-related fraud, unauthorized damage, and certain trafficking in passwords. Although the CFAA is not a general privacy statute, it is relevant to U.S. information law because unauthorized access can involve personal or confidential information. Privacy professionals should distinguish unlawful access questions from ordinary data-processing or notice obligations.
Question 60. A national company operates a health plan, a consumer-lending service, and a website that uses customer information for marketing. What is the BEST privacy-compliance approach?
- Apply only the company’s general privacy policy to every activity
- Determine the entity, information, purpose, and information flow for each activity and map the applicable sector-specific and general privacy requirements
- Apply HIPAA to all information collected by every business unit
- Assume financial privacy law overrides all other privacy requirements
Correct Answer: 2. Determine the entity, information, purpose, and information flow for each activity and map the applicable sector-specific and general privacy requirements
Explanation:
U.S. privacy compliance often requires several legal regimes to be analyzed simultaneously. A health plan may have HIPAA obligations, qualifying financial operations may be governed by GLBA and related regulations, marketing activities may involve FTC requirements or communications laws, and state privacy or breach laws may apply as well. The correct approach is therefore to map the organization, data categories, affected individuals, processing purposes, disclosures, and jurisdictions before determining which requirements apply. Applying one law universally can create both compliance gaps and unnecessary restrictions because U.S. privacy statutes frequently have different scopes, definitions, exceptions, rights, and enforcement mechanisms.