View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps.
Question 161. Under the HIPAA Breach Notification Rule, when must a covered entity generally notify affected individuals of a breach of unsecured PHI?
- Within 10 business days in every case
- Only after HHS completes an investigation
- Without unreasonable delay and no later than 60 days after discovery
- At the end of the calendar year
Correct Answer: 3. Without unreasonable delay and no later than 60 days after discovery
Explanation:
When a breach of unsecured protected health information occurs, HIPAA generally requires the covered entity to notify affected individuals without unreasonable delay and in no event later than 60 days after discovery of the breach. The notification must include specified information, such as a description of what happened, the types of information involved, steps individuals can take to protect themselves, mitigation and investigation efforts, and contact information. The 60-day period is an outside limit rather than permission to delay unnecessarily. Covered entities should therefore begin investigation and notification planning promptly after learning of a potential breach.
Question 162. A HIPAA breach affects 600 residents of one state. Which additional notification requirement may apply?
- Notice to prominent media outlets serving the affected state or jurisdiction
- Automatic notice to every hospital in the United States
- Publication in the Federal Register
- Notice only to the organization’s insurance carrier
Correct Answer: 1. Notice to prominent media outlets serving the affected state or jurisdiction
Explanation:
For breaches of unsecured PHI involving more than 500 residents of a state or jurisdiction, HIPAA requires covered entities to provide notice to prominent media outlets serving that area in addition to required individual and HHS notifications. This requirement is intended to provide broad awareness where a breach significantly affects a geographic population. It does not replace individual notification. Privacy professionals should therefore determine not only the total number of affected individuals, but also where those individuals reside, because the geographic concentration of the affected population can trigger media-notification obligations.
Question 163. How must a HIPAA covered entity generally report a breach affecting 500 or more individuals to the HHS Secretary?
- Only as part of an annual report
- Within five years
- Only if affected individuals complain
- Without unreasonable delay and no later than 60 days following the breach**
Correct Answer: 4. Without unreasonable delay and no later than 60 days following the breach
Explanation:
A HIPAA breach affecting 500 or more individuals must be reported to the HHS Secretary without unreasonable delay and no later than 60 days following the breach. HHS provides an electronic breach-reporting mechanism for covered entities. Smaller breaches follow a different reporting schedule: they can generally be submitted to the Secretary annually, although affected individuals still must receive required notice within the ordinary breach-notification timeframe. Privacy professionals should distinguish the threshold governing HHS reporting from the separate rules concerning individual notice and media notice.
Question 164. When may HIPAA breaches affecting fewer than 500 individuals generally be reported to the HHS Secretary?
- Never
- On an annual basis, no later than 60 days after the end of the calendar year in which they were discovered
- Only after a court order
- Once every five years
Correct Answer: 2. On an annual basis, no later than 60 days after the end of the calendar year in which they were discovered
Explanation:
HIPAA permits covered entities to report breaches affecting fewer than 500 individuals to the HHS Secretary on an annual basis. These reports are due no later than 60 days after the end of the calendar year in which the breaches were discovered. This reporting schedule applies to HHS notification, not to the separate obligation to notify affected individuals. Individual notifications still generally must occur without unreasonable delay and within 60 days of discovery. Maintaining an accurate breach log is therefore important so smaller incidents are not forgotten when annual HHS reporting becomes due.
Question 165. What must a HIPAA business associate generally do after discovering a breach of unsecured PHI that it handles for a covered entity?
- Notify the covered entity without unreasonable delay and no later than 60 days after discovery
- Notify only the affected individuals and not the covered entity
- Wait until the end of the year before taking action
- Delete the data and avoid documenting the event
Correct Answer: 1. Notify the covered entity without unreasonable delay and no later than 60 days after discovery
Explanation:
When a breach occurs at or by a HIPAA business associate, the business associate generally must notify the covered entity without unreasonable delay and no later than 60 days after discovery. To the extent possible, the business associate should identify the individuals affected and provide information the covered entity needs to issue required notifications. The covered entity typically remains responsible for notifying individuals and HHS, although contractual arrangements may assign certain operational tasks. Business associate agreements should therefore establish prompt incident-escalation procedures so contractual notice does not delay statutory breach responsibilities.
Question 166. What does HIPAA mean by “unsecured” protected health information for breach-notification purposes?
- Any PHI stored outside the United States
- Any PHI kept for more than one year
- PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through recognized technology or methodology
- Only printed medical records
Correct Answer: 3. PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through recognized technology or methodology
Explanation:
HIPAA breach notification generally concerns unsecured PHI. HHS describes unsecured PHI as protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through technology or methodologies recognized in HHS guidance. Encryption and appropriate destruction are examples of methods that can render information secure for this purpose. When PHI has been secured in accordance with the guidance, breach-notification duties may not arise from the incident in the same way. Organizations should therefore understand whether their encryption and destruction practices meet the applicable HHS specifications rather than assuming any security measure creates safe-harbor treatment.
Question 167. An impermissible HIPAA disclosure occurs, but the covered entity believes there is a low probability that PHI was compromised. What should the entity do to support a conclusion that notification is not required?
- Ignore the incident because no complaint has been filed
- Perform and document the required risk assessment supporting the low-probability conclusion
- Automatically delete the affected individual’s entire record
- Wait six months before investigating
Correct Answer: 2. Perform and document the required risk assessment supporting the low-probability conclusion
Explanation:
An impermissible use or disclosure of PHI is generally presumed to be a breach unless an exception applies or the covered entity or business associate demonstrates, through a risk assessment, a low probability that the PHI was compromised. HHS places the burden on regulated entities to document why notification was or was not required. A conclusion based merely on intuition or the absence of a complaint is insufficient. Organizations should preserve the relevant facts, risk analysis, and decision-making record so they can demonstrate compliance if HHS later reviews the incident.
Question 168. A HIPAA covered entity has outdated contact information for 15 individuals affected by a breach. Which substitute-notice method may generally be required?
- No notice is required because addresses are outdated
- Notice only to law enforcement
- A note placed solely in the affected patients’ medical records
- A conspicuous website posting for at least 90 days or notice through major media where affected individuals likely reside, together with a toll-free information number**
Correct Answer: 4. A conspicuous website posting for at least 90 days or notice through major media where affected individuals likely reside, together with a toll-free information number
Explanation:
When a covered entity has insufficient or outdated contact information for 10 or more affected individuals, HIPAA requires a broader substitute-notice approach. HHS allows a conspicuous posting on the organization’s website homepage for at least 90 days or notice in major print or broadcast media where the affected individuals likely reside. The entity also must provide a toll-free number that remains active for at least 90 days so individuals can determine whether their information was involved. Different substitute-notice options apply when fewer than 10 individuals lack usable contact information.
Question 169. Under GLBA, what is “pretexting”?
- Providing a consumer with a required privacy notice
- Encrypting customer financial information
- Obtaining customer financial information through false pretenses, fraudulent statements, impersonation, or similar deceptive means
- Conducting an ordinary credit transaction with a customer
Correct Answer: 3. Obtaining customer financial information through false pretenses, fraudulent statements, impersonation, or similar deceptive means
Explanation:
Pretexting is the practice of obtaining another person’s private financial information through deception. Examples include impersonating the customer when calling a bank, using fraudulent statements, presenting false documents, or persuading someone else to obtain information through similar deceptive methods. GLBA expressly prohibits obtaining or attempting to obtain financial-institution customer information using false or fraudulent representations and also prohibits knowingly soliciting another person to obtain information in that manner. The FTC has historically pursued information brokers and others that sold confidential bank information obtained through pretexting.
Question 170. An information broker hires another person knowing that person will impersonate bank customers to obtain account balances. Which statement is MOST accurate?
- The conduct may violate GLBA’s anti-pretexting provisions even if the broker does not personally call the bank
- No violation is possible unless the broker physically enters the bank
- GLBA applies only to banks, never to information brokers
- The conduct is lawful if the broker does not publish the balances online
Correct Answer: 1. The conduct may violate GLBA’s anti-pretexting provisions even if the broker does not personally call the bank
Explanation:
GLBA’s anti-pretexting provisions do not only prohibit personally making fraudulent statements to obtain customer information. The statute also prohibits requesting another person to obtain financial-institution customer information when the requester knows that the information will be obtained using prohibited deceptive methods. The FTC has brought enforcement actions against information brokers that either conducted pretexting or hired others to do it. Organizations therefore cannot avoid liability simply by outsourcing deceptive information-gathering activities to contractors or investigative vendors.
Question 171. Under the GLBA Privacy Rule, which individual is generally considered a “consumer”?
- Only someone who already has a long-term account relationship
- Only a commercial corporation
- Only an individual who has purchased insurance
- An individual who obtains or has obtained a financial product or service primarily for personal, family, or household purposes**
Correct Answer: 4. An individual who obtains or has obtained a financial product or service primarily for personal, family, or household purposes
Explanation:
The GLBA Privacy Rule defines a consumer broadly as an individual who obtains or has obtained a financial product or service from a financial institution primarily for personal, family, or household use, or that person’s legal representative. A person may therefore be a consumer even without establishing an ongoing customer relationship—for example, someone who merely applies for a loan or conducts a one-time wire transfer. Commercial clients are generally outside this particular consumer definition. Distinguishing consumers from customers matters because GLBA notice obligations can differ depending on the relationship and disclosure practices.
Question 172. What distinguishes a GLBA “customer” from a consumer who does not become a customer?
- A customer must be a corporation
- A customer has a continuing relationship with the financial institution
- A customer must have opted out of information sharing
- A customer must be over age 65
Correct Answer: 2. A customer has a continuing relationship with the financial institution
Explanation:
Under the GLBA Privacy Rule, “consumer” and “customer” are related but distinct concepts. A consumer can interact with a financial institution through a one-time transaction or even apply for a product without establishing an ongoing relationship. A customer has a continuing relationship with the institution, such as maintaining an account or obtaining an ongoing financial product or service. This distinction matters because institutions generally must provide customers with privacy notices concerning their practices, while obligations toward consumers who never become customers depend more heavily on whether nonpublic personal information is disclosed to nonaffiliated third parties outside regulatory exceptions.
Question 173. Which information can qualify as nonpublic personal information (NPI) under GLBA?
- Information an individual provides on an application for a personal financial product, such as income or Social Security number
- Only information labeled “confidential” by a bank employee
- Only account passwords
- Only information created after an account is closed
Correct Answer: 1. Information an individual provides on an application for a personal financial product, such as income or Social Security number
Explanation:
GLBA nonpublic personal information includes personally identifiable financial information collected in connection with providing a consumer financial product or service, unless the information is otherwise lawfully publicly available under the rule’s standards. NPI can include information supplied on applications, transaction data, account balances, payment histories, customer relationship information, and information obtained from consumer reports. A list derived even partly from NPI may itself remain NPI. Privacy professionals should therefore look beyond obviously sensitive credentials and recognize that the fact of a customer’s relationship with a financial institution can itself constitute protected NPI.
Question 174. What does GLBA generally prohibit a financial institution from disclosing to a nonaffiliated third party for marketing purposes?
- The name of the institution
- An encrypted identifier that the recipient cannot decode
- The institution’s public website URL
- An account number or similar access number or code that can be used in specified marketing contexts**
Correct Answer: 4. An account number or similar access number or code that can be used in specified marketing contexts
Explanation:
GLBA contains a specific restriction on disclosure of account numbers and similar access numbers or codes to nonaffiliated third parties for telemarketing, direct-mail marketing, or email marketing. This restriction applies even if the consumer has not exercised an ordinary GLBA opt-out. Certain encrypted identifiers may fall outside the prohibition if the recipient cannot decode them, and specific agent or service-provider arrangements can receive different treatment. The rule reflects the especially sensitive nature of information that can enable direct access to or charges against financial accounts.
Question 175. Following Montana’s SB 297 amendments effective October 1, 2025, what general consumer-data threshold can bring a business within the Montana Consumer Data Privacy Act?
- Processing personal data of only 100 Montana consumers
- Controlling or processing personal data of at least 25,000 Montana consumers, subject to the statute’s applicability rules
- Processing exactly one employee record
- Having any website accessible from Montana
Correct Answer: 2. Controlling or processing personal data of at least 25,000 Montana consumers, subject to the statute’s applicability rules
Explanation:
Montana’s SB 297 amended the state’s comprehensive privacy law effective October 1, 2025. Among other changes, the general consumer-data applicability threshold was reduced from 50,000 consumers to 25,000 consumers for entities meeting the statute’s other requirements. A lower threshold applies where the business derives more than 25% of its revenue from personal-data sales. Applicability analysis must still consider where the organization conducts business or targets commercial products or services, along with statutory exemptions. Privacy professionals should therefore use the current amended thresholds rather than relying on the law’s original 2024 applicability numbers.
Question 176. Under Montana’s amended privacy law, what should a controller do when making a material change to its privacy notice or practices?
- Make the change secretly because consumers already accepted the old policy
- Delete all existing consumer accounts
- Notify consumers and provide a reasonable opportunity to withdraw consent
- Notify only the controller’s advertising vendors
Correct Answer: 3. Notify consumers and provide a reasonable opportunity to withdraw consent
Explanation:
Montana’s 2025 amendments strengthen privacy-notice obligations. When a controller makes a material change to its privacy notice or practices, the controller must notify consumers and provide a reasonable opportunity to withdraw consent. The amended law also requires privacy notices to explain consumer rights, identify the date of the last update, and be made conspicuously available online. These requirements reinforce the principle that consumer consent should not be treated as permanent authorization for materially different future processing. Organizations should therefore maintain change-management processes that flag privacy-impacting product or data-practice changes before they are implemented.
Question 177. What is one significant feature of the Minnesota Consumer Data Privacy Act’s consumer protections involving automated decision-making?
- Consumers have rights to question certain profiling and automated decisions that significantly affect them
- Automated decisions are entirely exempt from the law
- Consumers can require every algorithm to be publicly released as source code
- The law prohibits all artificial intelligence
Correct Answer: 4. Consumers have rights to question certain profiling and automated decisions that significantly affect them
Explanation:
Minnesota provides comparatively detailed rights concerning profiling and automated decision-making. Consumers can opt out of profiling used in furtherance of automated decisions producing legal or similarly significant effects, and the state’s guidance emphasizes rights to question certain automated decisions affecting important areas such as employment, housing, education, or financial services. The law does not ban artificial intelligence or require universal publication of proprietary algorithms. Instead, it provides mechanisms designed to give consumers greater transparency and control when automated systems materially influence consequential opportunities or services.
Question 178. How quickly must a Minnesota controller generally respond to a consumer rights request under the MCDPA?
- Five business days
- 45 days, subject to a possible additional 45-day extension when reasonably necessary
- Six months
- One year
Correct Answer: 2. 45 days, subject to a possible additional 45-day extension when reasonably necessary
Explanation:
Minnesota controllers generally must respond to consumer-rights requests within 45 days and explain the action taken. Where reasonably necessary, the controller may extend the response period by another 45 days, provided it informs the consumer of the delay and the reason. Minnesota also requires controllers to provide an appeals process when requests are denied. These operational obligations make privacy-rights management a continuing compliance function rather than a policy-only exercise. Organizations should track deadlines, authentication, exceptions, response status, and appeal rights systematically so requests do not become lost across customer-service or legal teams.
Question 179. Which item must a Minnesota controller’s privacy notice include?
- The private home addresses of its employees
- Its confidential legal advice
- A description of its personal-data retention policies
- Every source-code repository used by the controller
Correct Answer: 3. A description of its personal-data retention policies
Explanation:
Minnesota requires controller privacy notices to include substantial information about data practices. Among the required elements is a description of the controller’s retention policies for personal data. Other notice elements include categories of personal data processed, purposes of processing, consumer rights and how to exercise them, categories of data sold or shared, categories of third-party recipients, contact information, appeal information, and the date of the notice’s latest update. Requiring retention information gives consumers insight into how long organizations keep their personal data rather than focusing only on collection and disclosure.
Question 180. A national company handles PHI for health plans, provides financial services, and processes consumer data in Minnesota and Montana. What is the BEST compliance approach?
- Map the company’s roles, data categories, jurisdictions, incidents, and disclosures, then apply HIPAA, GLBA, and applicable state privacy requirements to each activity
- Follow HIPAA alone because health privacy law preempts all other privacy statutes
- Follow only the state law with the highest monetary penalty
- Treat all information as subject to identical notice and consent rules
Correct Answer: 1. Map the company’s roles, data categories, jurisdictions, incidents, and disclosures, then apply HIPAA, GLBA, and applicable state privacy requirements to each activity
Explanation:
U.S. privacy compliance requires layered legal analysis because one organization can operate under several frameworks simultaneously. PHI handled for covered health plans may trigger HIPAA and breach-notification obligations. Financial-service activities can implicate GLBA privacy, safeguards, and anti-pretexting provisions. Consumer-data operations in Minnesota and Montana can add comprehensive state privacy duties concerning rights, notices, consent, opt-outs, assessments, and enforcement. No single privacy law automatically governs every dataset or activity. A mature privacy program therefore maps organizational roles and data flows and applies the correct requirements to each processing context while maintaining consistent governance across the enterprise.