{"id":20842,"date":"2026-09-24T07:55:46","date_gmt":"2026-09-24T07:55:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20842"},"modified":"2026-09-24T07:55:46","modified_gmt":"2026-09-24T07:55:46","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 281. What information is specifically protected by the HIPAA Security Rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every piece of information maintained by a hospital<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only paper medical records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All personally identifiable information held by any employer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Electronic protected health information created, received, maintained, or transmitted by regulated entities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Electronic protected health information created, received, maintained, or transmitted by regulated entities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HIPAA Security Rule establishes national standards for protecting electronic protected health information, commonly called ePHI. The rule applies to HIPAA covered entities and business associates and requires reasonable and appropriate safeguards for ePHI they create, receive, maintain, or transmit. The Security Rule is therefore narrower than the HIPAA Privacy Rule in one important respect: it focuses specifically on PHI in electronic form. Paper records still receive protection under the Privacy Rule and other applicable safeguards, but they are not the principal information category regulated by the Security Rule&#8217;s administrative, physical, and technical safeguard standards.<\/span><\/p>\n<p><b>Question 282. Which three categories of safeguards form the core of the HIPAA Security Rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrative, physical, and technical safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Marketing, financial, and advertising safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Federal, state, and local safeguards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Civil, criminal, and contractual safeguards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Administrative, physical, and technical safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HIPAA Security Rule organizes its security requirements into administrative, physical, and technical safeguards. Administrative safeguards include areas such as risk analysis, risk management, workforce security, access management, training, incident procedures, and contingency planning. Physical safeguards address facilities, workstations, devices, and media. Technical safeguards include access controls, audit controls, integrity protections, authentication, and transmission security. These categories reinforce the idea that protecting ePHI requires more than cybersecurity software. Governance, employee practices, physical security, access management, and technology must work together to preserve confidentiality, integrity, and availability.<\/span><\/p>\n<p><b>Question 283. What is the PRIMARY purpose of HIPAA Security Rule risk analysis?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine which patients should receive treatment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To calculate the financial value of PHI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create marketing profiles from health information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk analysis is a foundational Security Rule requirement. A regulated entity must conduct an accurate and thorough assessment of potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of the ePHI it holds. The findings then inform risk management, helping the organization determine which reasonable and appropriate security measures are necessary. Risk analysis should reflect the entity&#8217;s actual environment, including systems, devices, users, vendors, and threats, rather than being a generic compliance checklist. HHS emphasizes that organizations must also reevaluate risks and modify security measures when circumstances change.<\/span><\/p>\n<p><b>Question 284. Under the HIPAA Security Rule, what does \u201cavailability\u201d mean?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PHI must be publicly available<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Information is accessible and usable on demand by an authorized person<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every employee must have access to all ePHI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Patients must receive records immediately in every situation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Information is accessible and usable on demand by an authorized person<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HIPAA Security Rule is built around confidentiality, integrity, and availability. Availability means that ePHI is accessible and usable on demand by an authorized person. Confidentiality focuses on preventing unauthorized access or disclosure, while integrity concerns preventing improper alteration or destruction. Security measures should therefore protect data not only from theft but also from outages, corruption, and loss that prevent authorized access when needed. Business continuity, backups, contingency planning, resilient systems, and incident response can all support availability. A system that securely encrypts data but makes it permanently inaccessible would still fail an important Security Rule objective.<\/span><\/p>\n<p><b>Question 285. What must a HIPAA regulated entity designate as part of its administrative safeguards?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A security official responsible for developing and implementing required security policies and procedures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A federal judge responsible for approving access to ePHI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A patient representative for every information system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A public-relations employee responsible for all breach decisions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A security official responsible for developing and implementing required security policies and procedures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA&#8217;s administrative safeguards require regulated entities to assign security responsibility to an individual responsible for developing and implementing the organization&#8217;s Security Rule policies and procedures. Clear ownership helps ensure that security requirements are actively managed rather than dispersed without accountability. This responsibility works alongside requirements involving risk management, workforce security, information-access management, security training, incident procedures, contingency planning, and evaluation. The designated security official does not replace leadership, legal, compliance, or IT responsibilities, but provides an accountable focal point for implementation of the Security Rule&#8217;s requirements.<\/span><\/p>\n<p><b>Question 286. Which item is a HIPAA physical safeguard?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A privacy notice provided to a patient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An advertising opt-out mechanism<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A consumer credit freeze<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device and media controls governing hardware or electronic media containing ePHI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Device and media controls governing hardware or electronic media containing ePHI<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA physical safeguards include facility access controls, workstation use, workstation security, and device and media controls. Device and media controls govern hardware and electronic media containing ePHI, including how those items are received, moved, removed, disposed of, or prepared for reuse. These protections matter because sensitive information can remain on laptops, hard drives, removable media, or other equipment even after normal business use has ended. The Security Rule requires procedures for final disposition of ePHI and for removing ePHI before electronic media is reused.<\/span><\/p>\n<p><b>Question 287. Which HIPAA technical safeguard is intended to record and examine activity in information systems containing ePHI?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Facility access controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Audit controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Workforce sanctions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device disposal procedures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Audit controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit controls are a technical safeguard under the HIPAA Security Rule. Regulated entities must implement hardware, software, or procedural mechanisms capable of recording and examining activity in systems that contain or use ePHI. Audit information can help detect improper access, investigate incidents, monitor workforce activity, and validate whether security controls are functioning appropriately. Audit controls are distinct from access controls, which determine who can enter a system, and authentication, which verifies the identity of a person seeking access. Together, these technical safeguards support accountability and detection of unauthorized activity involving sensitive electronic health information.<\/span><\/p>\n<p><b>Question 288. What is the purpose of person or entity authentication under the HIPAA Security Rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine whether a marketing campaign is effective<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To decide whether a health plan is profitable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To verify that a person or entity seeking access to ePHI is who they claim to be<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically disclose PHI to third parties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To verify that a person or entity seeking access to ePHI is who they claim to be<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication helps ensure that only legitimate users or entities gain access to ePHI. The Security Rule requires procedures for verifying that a person or entity seeking access is the one claimed. Authentication can work together with unique user identification, passwords, multifactor authentication technologies, certificates, or other reasonable and appropriate controls selected by the regulated entity. Authentication is different from authorization: authentication establishes identity, while authorization determines which resources that authenticated identity may access. Strong authentication reduces risks associated with stolen credentials, impersonation, unauthorized remote access, and account sharing.<\/span><\/p>\n<p><b>Question 289. What does HIPAA transmission security address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Protecting ePHI against unauthorized access while it is transmitted over electronic networks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restricting patients from sending emails to providers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preventing health plans from mailing paper notices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Limiting the number of computers a hospital can purchase<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Protecting ePHI against unauthorized access while it is transmitted over electronic networks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transmission security is one of HIPAA&#8217;s technical safeguard standards. It requires regulated entities to implement technical security measures guarding against unauthorized access to ePHI transmitted over electronic communications networks. The appropriate controls depend on the entity&#8217;s systems, risks, technical environment, and other Security Rule factors. Technologies such as encryption can play an important role, but HIPAA&#8217;s Security Rule is designed to remain flexible and technology neutral rather than mandating one specific product. Organizations should evaluate how ePHI moves through email, networks, remote connections, applications, cloud platforms, and other communication channels.<\/span><\/p>\n<p><b>Question 290. How long must documentation required by the HIPAA Security Rule generally be retained?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year from creation only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Six years from the later of its creation date or the date it was last in effect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Thirty days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanently in every case<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Six years from the later of its creation date or the date it was last in effect<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA requires regulated entities to maintain required Security Rule documentation, including written policies, procedures, and documentation of required actions, activities, and assessments, for six years from the later of the document&#8217;s creation date or the date on which it was last in effect. Organizations must also make relevant documentation available to personnel responsible for implementing the procedures and periodically update it when environmental or organizational changes affect ePHI security. Good documentation provides evidence that the organization performed required risk assessments, adopted safeguards, and maintained an active security program rather than relying on undocumented practices.<\/span><\/p>\n<p><b>Question 291. Under the FTC Telemarketing Sales Rule (TSR), how frequently must covered sellers and telemarketers generally synchronize their calling lists with the National Do Not Call Registry?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Once every year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every 90 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> At least every 31 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after a consumer complaint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. At least every 31 days<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Covered sellers and telemarketers generally must access the National Do Not Call Registry and remove registered telephone numbers from their calling lists at least every 31 days. Calling from an outdated list can result in prohibited telemarketing calls to consumers who registered their numbers after the seller&#8217;s last update. The FTC&#8217;s safe harbor for inadvertent violations also depends partly on using a version of the Registry downloaded no more than 31 days before the call. Maintaining documented suppression procedures is therefore an important element of telemarketing compliance.<\/span><\/p>\n<p><b>Question 292. A consumer tells a telemarketer, \u201cDo not call me again on behalf of this company.\u201d What must the seller generally do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continue calling until the consumer joins the National Do Not Call Registry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Honor the entity-specific do-not-call request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require the consumer to submit a notarized letter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Charge an administrative fee to process the request<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Honor the entity-specific do-not-call request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Telemarketing Sales Rule separately protects consumers who tell a specific seller or charitable organization that they do not want additional calls. The seller and its telemarketers must maintain an entity-specific do-not-call list and honor the consumer&#8217;s request. A company cannot require the consumer to register on the national list, listen to another sales pitch, call a different number, or pay a fee. Interfering with the consumer&#8217;s request can itself violate the TSR. Company-specific suppression therefore remains important even when a seller also screens its calls against the National Do Not Call Registry.<\/span><\/p>\n<p><b>Question 293. Which call is generally outside the National Do Not Call Registry&#8217;s restrictions under the FTC&#8217;s TSR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A legitimate call made solely to conduct a survey without a sales pitch<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A disguised survey that includes a product sales pitch<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A telemarketing call to sell a consumer product<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A sales call made after the consumer specifically told the seller not to call again<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A legitimate call made solely to conduct a survey without a sales pitch<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The National Do Not Call provisions generally do not apply to calls made solely for purposes such as legitimate surveys, although other laws may still apply. However, a caller cannot avoid telemarketing rules merely by labeling a sales call as a \u201csurvey.\u201d If a supposed survey includes an offer to sell goods or services, the call can fall within the Do Not Call requirements. Political organizations and charities also receive different treatment under the Registry framework, although charitable telefunders must honor entity-specific do-not-call requests on behalf of the relevant charity.<\/span><\/p>\n<p><b>Question 294. What must a covered telemarketer generally do before making outbound calls to consumers using a National Do Not Call list?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Obtain approval from the FTC for every telephone number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maintain and use a process that suppresses numbers appearing on the Registry and entity-specific do-not-call lists<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Buy the consumer&#8217;s credit report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Obtain the consumer&#8217;s Social Security number<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Maintain and use a process that suppresses numbers appearing on the Registry and entity-specific do-not-call lists<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compliant telemarketing operation should have procedures for preventing calls to telephone numbers on the National Do Not Call Registry and the seller&#8217;s own entity-specific suppression list. FTC safe-harbor requirements include written procedures, personnel training, maintaining entity-specific records, and using an appropriately recent Registry version. A company should not rely solely on telemarketers remembering individual requests or manually checking calls one by one. Automated suppression, documented policies, training, and monitoring create a repeatable process that reduces the likelihood of prohibited calls and provides evidence of reasonable compliance practices.<\/span><\/p>\n<p><b>Question 295. What is the significance of the Telemarketing Sales Rule&#8217;s safe harbor for inadvertent Do Not Call violations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A seller meeting specified compliance practices may avoid penalties for certain calls made in error<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows companies to ignore the Registry completely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It authorizes unlimited robocalls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need to train telemarketing personnel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A seller meeting specified compliance practices may avoid penalties for certain calls made inadvertently<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The TSR includes a safe harbor for certain inadvertent Do Not Call violations when the seller or telemarketer can demonstrate routine compliance practices. Those practices include written procedures, training personnel and relevant vendors, maintaining an entity-specific do-not-call list, monitoring compliance, and using a National Registry version downloaded within the required period. The safe harbor is not permission to ignore consumer requests or operate carelessly. It protects organizations that maintain a genuine compliance program but nevertheless make an isolated error despite those safeguards. Documentation is therefore essential to demonstrating eligibility for the safe harbor.<\/span><\/p>\n<p><b>Question 296. Under the updated TSR recordkeeping requirements, how long must covered sellers and telemarketers generally retain required records?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 30 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two years in every case<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Five years**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Five years<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FTC&#8217;s updated Telemarketing Sales Rule recordkeeping provisions require covered sellers and telemarketers to retain specified records for five years. The updated requirements include information about calls, consent, customer transactions, scripts, service providers, Do Not Call compliance, and other relevant activities. The FTC emphasized that failure to maintain each required record can itself constitute a violation. Written agreements can allocate recordkeeping responsibilities between sellers and telemarketers, but without a clear agreement, both can face obligations. Maintaining complete records is essential for demonstrating consent, honoring opt-outs, and defending the organization&#8217;s telemarketing practices.<\/span><\/p>\n<p><b>Question 297. Which information is among the call-detail records the updated TSR requires covered telemarketers to maintain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the consumer&#8217;s date of birth<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The calling and called numbers, date, time, duration, and disposition of the call<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The consumer&#8217;s complete medical history<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The consumer&#8217;s tax return<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The calling and called numbers, date, time, duration, and disposition of the call<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The updated TSR requires covered telemarketing operations to retain detailed records concerning outbound calls. These records include the identity of the telemarketer and seller, the goods or services involved, calling and called numbers, call date and time, duration, caller-ID information, and the disposition of the call, such as whether it was answered, connected, or transferred. These detailed records help regulators evaluate whether telemarketers complied with Do Not Call, consent, and other TSR obligations. Organizations should therefore ensure that dialing platforms and vendors preserve required metadata for the full retention period.<\/span><\/p>\n<p><b>Question 298. What is generally true about most business-to-business calls under the Telemarketing Sales Rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are generally exempt from most TSR provisions, although important exceptions exist<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are always prohibited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They automatically require consumer written consent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are governed exclusively by HIPAA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. They are generally exempt from most TSR provisions, although important exceptions exist<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Most business-to-business telemarketing calls are exempt from the TSR, but the exemption is not absolute. The FTC identifies exceptions involving, for example, certain sales of nondurable office or cleaning supplies, and other specific categories can remain subject to particular requirements. Sellers should also remember that other federal or state laws may regulate calls even when the FTC&#8217;s TSR does not fully apply. Privacy and marketing professionals therefore should not treat \u201cB2B\u201d as an automatic universal exemption from every calling rule. The product, purpose, recipient, and applicable regulatory framework still matter.<\/span><\/p>\n<p><b>Question 299. Under FCC rules, how long must a company-specific do-not-call request generally be honored?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Five years from the date of the request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Thirty days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Six months<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only until the next marketing campaign<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Five years from the date of the request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FCC rules generally require companies to honor a consumer&#8217;s company-specific do-not-call request for five years from the date the request is made. This requirement exists in addition to the National Do Not Call Registry. A consumer who tells a particular company not to call should therefore be added to that company&#8217;s internal suppression list even if the telephone number is not on the national Registry. Organizations should coordinate suppression data across internal departments and telemarketing vendors because a request made during one interaction should not be defeated by another vendor continuing to call on the same seller&#8217;s behalf.<\/span><\/p>\n<p><b>Question 300. A health care business conducts telemarketing while also maintaining large volumes of ePHI. What is the BEST privacy-compliance approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat HIPAA as the only applicable federal rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only the Telemarketing Sales Rule because marketing laws replace health privacy requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separately apply HIPAA Security Rule safeguards to ePHI and telemarketing rules to calling practices, while coordinating governance, vendors, records, and consumer preferences<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume obtaining marketing consent eliminates security duties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Separately apply HIPAA Security Rule safeguards to ePHI and telemarketing rules to calling practices, while coordinating governance, vendors, records, and consumer preferences<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Different activities can trigger different legal obligations inside the same organization. Electronic PHI must be protected through appropriate administrative, physical, and technical safeguards under the HIPAA Security Rule, including risk analysis, access controls, audit mechanisms, and security documentation. Telemarketing campaigns can separately require compliance with the TSR, National Do Not Call Registry, entity-specific suppression requests, consent requirements, and recordkeeping. Neither legal framework replaces the other. A mature compliance program maps each activity to its governing law while coordinating vendor oversight, data governance, security, consent, and consumer-preference management across the organization.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 281. What information is specifically protected by the HIPAA Security Rule? Every piece of information maintained by a hospital Only paper medical records All personally identifiable information held by any employer Electronic protected health information created, received, maintained, or transmitted by regulated entities Correct [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20842"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20842"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20842\/revisions"}],"predecessor-version":[{"id":20843,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20842\/revisions\/20843"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}