{"id":20850,"date":"2026-09-24T07:56:49","date_gmt":"2026-09-24T07:56:49","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20850"},"modified":"2026-09-24T07:56:49","modified_gmt":"2026-09-24T07:56:49","slug":"iapp-cipp-us-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipp-us-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"IAPP CIPP-US Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipp-us-exam-dumps\"><b>IAPP CIPP-US Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 361. Under HIPAA, how far back can an individual generally request an accounting of disclosures of PHI?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One year<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Three years<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Up to six years preceding the request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ten years<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Up to six years preceding the request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HIPAA Privacy Rule generally gives individuals the right to obtain an accounting of certain disclosures of their protected health information made during the six years preceding the request, although an individual may request a shorter period. The accounting right does not cover every disclosure. Important exclusions include many disclosures for treatment, payment, and health care operations, disclosures made directly to the individual, disclosures made pursuant to authorization, and certain other categories. Covered entities should maintain sufficient records to respond accurately to accounting requests and should distinguish the accounting requirement from the separate HIPAA right of access to medical records.<\/span><\/p>\n<p><b>Question 362. Which disclosure is generally excluded from a HIPAA accounting of disclosures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A disclosure made for treatment, payment, or health care operations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A qualifying disclosure to a public health authority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A disclosure required by law that is otherwise subject to accounting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certain disclosures in response to legal process<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A disclosure made for treatment, payment, or health care operations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA generally does not require covered entities to include disclosures made for treatment, payment, or health care operations in an accounting of disclosures. Other excluded categories include disclosures made directly to the individual, disclosures pursuant to a valid authorization, certain facility-directory or care-involvement disclosures, limited-data-set disclosures, and specified national security and correctional activities. By contrast, some disclosures for public health, litigation, or other purposes can be subject to accounting. Privacy professionals should therefore classify the legal basis for each disclosure rather than assuming that every release of PHI must appear in the accounting.<\/span><\/p>\n<p><b>Question 363. What information must generally appear for each disclosure included in a HIPAA accounting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the recipient&#8217;s name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the date of disclosure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The entire medical record that was disclosed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Information including the date, recipient, description of PHI disclosed, and the purpose or basis for disclosure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Information including the date, recipient, description of PHI disclosed, and the purpose or basis for disclosure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A HIPAA accounting of disclosures must contain enough information to let the individual understand what occurred. The Privacy Rule generally requires the date of the disclosure, the name of the recipient and address if known, a brief description of the PHI disclosed, and a brief statement describing the purpose or legal basis for the disclosure. Special rules can simplify accounting for repeated disclosures made to the same recipient for the same purpose. The accounting is therefore more than a simple list of dates; it provides meaningful context about external disclosures of the individual&#8217;s protected health information.<\/span><\/p>\n<p><b>Question 364. When may a covered entity temporarily suspend an individual&#8217;s right to receive an accounting of certain disclosures to law enforcement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever the covered entity prefers not to respond<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> When an authorized law-enforcement official represents that providing the accounting would likely impede the agency&#8217;s activities, subject to HIPAA&#8217;s procedural requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever the individual has been arrested<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever a disclosure occurred more than 30 days earlier<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. When an authorized law-enforcement official represents that providing the accounting would likely impede the agency&#8217;s activities, subject to HIPAA&#8217;s procedural requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA permits temporary suspension of accounting rights for certain disclosures to law-enforcement or health-oversight agencies when an authorized official states that providing the accounting would be reasonably likely to impede the agency&#8217;s activities. A written statement can specify the suspension period. If the request is made orally, the covered entity must document the statement and the identity of the official, and the oral suspension generally cannot exceed 30 days unless a qualifying written statement is subsequently provided. This exception protects investigations while preserving the individual&#8217;s accounting rights once the legitimate need for secrecy ends.<\/span><\/p>\n<p><b>Question 365. A covered entity discloses PHI to a public health authority for legally authorized disease surveillance. Is individual authorization always required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> No. HIPAA can permit disclosure to an authorized public health authority without individual authorization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, in every case<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Yes, unless the information is more than one year old<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only a court may authorize the disclosure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. No. HIPAA can permit disclosure to an authorized public health authority without individual authorization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HIPAA Privacy Rule permits covered entities to disclose PHI without individual authorization to public health authorities that are legally authorized to collect or receive the information for activities such as disease surveillance, public health investigations, and public health interventions. These disclosures support functions such as responding to epidemics and other public health threats. A permissible disclosure does not mean that privacy safeguards disappear; the disclosure should still fit the applicable regulatory provision and minimum-necessary principles where they apply. Public health disclosures may also need to be reflected in an accounting of disclosures.<\/span><\/p>\n<p><b>Question 366. What is generally true of incidental disclosures under the HIPAA Privacy Rule?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every incidental disclosure automatically violates HIPAA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incidental disclosures are permitted only between physicians<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certain incidental disclosures are permitted when they result from an otherwise permitted use or disclosure and reasonable safeguards are in place<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incidental disclosures are permitted only after written patient authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Certain incidental disclosures are permitted when they result from an otherwise permitted use or disclosure and reasonable safeguards are in place<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA does not require covered entities to eliminate every possibility that another person may incidentally see or hear PHI. Certain incidental disclosures are permissible when they are a by-product of an otherwise permitted use or disclosure and the covered entity has applied reasonable safeguards and complied with the minimum necessary standard where applicable. Examples can arise in busy clinical environments where reasonable precautions are used but perfect secrecy is impractical. Permitted incidental disclosures are also excluded from the accounting-of-disclosures requirement. The rule therefore uses a reasonableness standard rather than demanding absolute prevention of every incidental exposure.<\/span><\/p>\n<p><b>Question 367. Under HIPAA, how is a legally authorized personal representative generally treated with respect to an individual&#8217;s privacy rights?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> As an unrelated third party in every circumstance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Generally as the individual for purposes within the scope of the representative&#8217;s legal authority, subject to exceptions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only as a business associate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> As a public health authority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Generally as the individual for purposes within the scope of the representative&#8217;s legal authority, subject to exceptions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA generally requires a covered entity to treat a legally authorized personal representative as though that representative were the individual, to the extent of the representative&#8217;s authority under applicable law. A personal representative may therefore exercise rights such as obtaining access to PHI, requesting certain amendments, authorizing disclosures, and requesting an accounting of disclosures. The analysis depends on state or other applicable law establishing the person&#8217;s authority, and HIPAA contains important exceptions, including situations involving abuse, neglect, or endangerment. Privacy professionals should verify both the existence and scope of the representative&#8217;s legal authority.<\/span><\/p>\n<p><b>Question 368. When may FERPA&#8217;s health or safety emergency exception permit disclosure of education-record PII without consent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever school officials believe disclosure might someday be useful<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever a student receives disciplinary action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whenever any parent requests information about another student<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> When disclosure to appropriate parties is necessary to protect the health or safety of the student or others during an actual, impending, or imminent emergency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. When disclosure to appropriate parties is necessary to protect the health or safety of the student or others during an actual, impending, or imminent emergency<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FERPA&#8217;s health or safety emergency exception allows schools to disclose personally identifiable information from education records without consent when the disclosure is necessary to protect the health or safety of the student or other individuals. The exception is designed for genuine emergencies, such as campus violence, natural disasters, terrorist threats, or epidemic disease outbreaks. It is limited to the emergency period and does not authorize blanket release of student records. The school should disclose only information relevant to addressing the emergency and only to appropriate parties capable of helping protect affected individuals.<\/span><\/p>\n<p><b>Question 369. Which circumstance would LEAST support use of FERPA&#8217;s health or safety emergency exception?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A school wants to disclose broad student records for routine administrative convenience where no actual or imminent emergency exists<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A credible campus shooting threat<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An epidemic disease outbreak affecting the school<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An impending natural disaster threatening students<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A school wants to disclose broad student records for routine administrative convenience where no actual or imminent emergency exists<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FERPA&#8217;s emergency exception is intentionally narrow. Department of Education guidance states that the disclosure must relate to an actual, impending, or imminent emergency and be necessary to protect the health or safety of students or other individuals. Routine administrative convenience, general curiosity, or speculative future risk does not justify invoking the exception. Schools should therefore resist using \u201csafety\u201d as a broad label for ordinary information sharing. When genuine emergencies exist, administrators should identify appropriate recipients, limit the information to what is relevant, and document their decision-making under applicable FERPA requirements.<\/span><\/p>\n<p><b>Question 370. When did the Kentucky Consumer Data Protection Act (KCDPA) become effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2026<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> July 1, 2024<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2023<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> January 1, 2030<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. January 1, 2026<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Kentucky Consumer Data Protection Act became effective on January 1, 2026. The statute creates consumer rights and obligations for covered controllers and processors handling personal data of Kentucky residents. Kentucky&#8217;s Office of Data Privacy within the Attorney General&#8217;s office is responsible for enforcement. Because comprehensive state privacy statutes have different effective dates and thresholds, national organizations need a current jurisdictional compliance calendar. Kentucky&#8217;s 2026 effective date means organizations serving Kentucky consumers should already have request-handling, privacy-notice, opt-out, sensitive-data, vendor, and assessment procedures in place where the statute applies.<\/span><\/p>\n<p><b>Question 371. Which right is expressly granted to Kentucky consumers under the KCDPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to force a business to disclose its trade secrets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to prevent all fraud-prevention processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to confirm whether a controller processes their personal data and access qualifying data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The right to erase every legally required business record<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The right to confirm whether a controller processes their personal data and access qualifying data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kentucky consumers have several rights under the KCDPA. These include confirming whether a controller processes their personal data, accessing qualifying personal data, correcting inaccuracies, deleting personal data provided by or obtained about them, and obtaining a portable copy where feasible. Consumers can also opt out of specified forms of processing. These rights remain subject to statutory exceptions and do not require controllers to reveal trade secrets. Privacy professionals should implement an authenticated request process capable of identifying the applicable consumer, locating responsive information, applying valid exceptions, and communicating the result clearly.<\/span><\/p>\n<p><b>Question 372. Which processing may Kentucky consumers generally opt out of under the KCDPA?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every activity needed to fulfill a requested transaction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Targeted advertising, sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All cybersecurity monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every legally required disclosure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Targeted advertising, sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The KCDPA gives Kentucky consumers the right to opt out of three major categories of processing: targeted advertising, sale of personal data, and profiling performed in furtherance of decisions producing legal or similarly significant effects. This structure resembles several other U.S. comprehensive state privacy statutes. The opt-out right does not mean a consumer can prohibit every internal use of personal data, such as processing necessary to provide a requested product, maintain security, or comply with law. Controllers should therefore map each processing purpose so they can distinguish opt-out-eligible activities from ordinary operational uses.<\/span><\/p>\n<p><b>Question 373. What must a Kentucky controller&#8217;s privacy notice generally disclose?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Categories of personal data processed, purposes, categories shared, categories of third-party recipients, rights procedures, and relevant sale or targeted-advertising practices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every employee&#8217;s personal home address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All proprietary source code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the controller&#8217;s company name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Categories of personal data processed, purposes, categories shared, categories of third-party recipients, rights procedures, and relevant sale or targeted-advertising practices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kentucky requires controllers to provide an accessible, clear, and meaningful privacy notice. The notice should identify categories of personal data processed, processing purposes, categories of personal data shared with third parties, categories of third parties receiving the data, and procedures for exercising and appealing consumer rights. If the controller sells personal data or processes it for targeted advertising, the notice should explain those practices and how consumers can opt out. A notice therefore must communicate substantive operational information rather than simply make general statements about respecting privacy.<\/span><\/p>\n<p><b>Question 374. Who has enforcement authority under the Kentucky Consumer Data Protection Act?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every consumer through an automatic statutory private right of action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Federal Communications Commission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local county governments only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Kentucky Attorney General&#8217;s Office of Data Privacy**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The Kentucky Attorney General&#8217;s Office of Data Privacy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kentucky created an Office of Data Privacy within the Attorney General&#8217;s office to enforce the KCDPA. The Office has exclusive authority to enforce the statute and may seek remedies including injunctive relief, civil penalties, reasonable attorneys&#8217; fees, and investigative costs. Consumers can exercise statutory rights and report concerns, but enforcement of the KCDPA itself is assigned to the Attorney General rather than being structured as a broad private damages action. Understanding who can enforce a privacy statute is as important as knowing the underlying consumer rights because state laws differ substantially in their enforcement mechanisms.<\/span><\/p>\n<p><b>Question 375. Which Kentucky consumer right concerns inaccurate personal data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A right to correct inaccuracies in qualifying personal data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A right to rewrite every business record regardless of accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A right to require deletion instead of correction in every case<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No correction right exists under the KCDPA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A right to correct inaccuracies in qualifying personal data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kentucky consumers have a right to correct inaccuracies in personal data covered by the KCDPA, taking into account the nature of the data and the purposes for which it is processed. Correction rights help reduce harms that can occur when inaccurate information influences consumer profiles, services, or other processing. The right does not permit consumers to rewrite accurate records according to preference or require controllers to falsify historical documentation. Controllers need procedures for assessing claimed inaccuracies, making appropriate corrections, and documenting the disposition of the request.<\/span><\/p>\n<p><b>Question 376. Which statement BEST describes Kentucky&#8217;s data portability right?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controllers must disclose proprietary algorithms with every portability response<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Consumers can obtain a portable and readily usable copy of qualifying personal data where feasible, without requiring disclosure of trade secrets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data portability applies only to paper records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Portability requires the controller to transfer ownership of its databases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Consumers can obtain a portable and readily usable copy of qualifying personal data where feasible, without requiring disclosure of trade secrets<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kentucky&#8217;s KCDPA provides consumers with a right to obtain a portable copy of qualifying personal data where feasible. The purpose is to allow consumers to receive their information in a usable form without forcing controllers to reveal trade secrets or transfer ownership of proprietary systems. Portability is related to, but distinct from, ordinary access. A privacy program should therefore consider the format and usability of the response, not merely whether data can be displayed on a screen. Controllers should also apply statutory exceptions and appropriate authentication before releasing portable copies.<\/span><\/p>\n<p><b>Question 377. Which statement BEST describes the relationship between HIPAA&#8217;s right of access and right to an accounting of disclosures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are the same right<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accounting replaces the right to inspect medical records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access concerns obtaining one&#8217;s PHI, while accounting generally concerns specified disclosures of PHI to others<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Neither right applies to individuals<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Access concerns obtaining one&#8217;s PHI, while accounting generally concerns specified disclosures of PHI to others<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA provides several separate individual rights. The right of access allows an individual to inspect or obtain copies of PHI contained in designated record sets, subject to limited exclusions. The accounting right is different: it provides information about certain disclosures of PHI made by a covered entity or business associate during the applicable period. Many routine disclosures, including those for treatment, payment, and health care operations, are excluded from accounting. Privacy teams should maintain separate operational procedures for access requests and accounting requests because they require different searches, records, exceptions, and response content.<\/span><\/p>\n<p><b>Question 378. A covered entity receives an oral request from law enforcement to suspend accounting disclosures because notification would impede an investigation. What should the covered entity generally do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Document the oral statement and official&#8217;s identity and limit the temporary suspension to no more than 30 days unless a qualifying written statement follows<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanently eliminate the individual&#8217;s accounting right<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the request because only courts may request suspension<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the disclosure records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Document the oral statement and official&#8217;s identity and limit the temporary suspension to no more than 30 days unless a qualifying written statement follows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA accommodates urgent law-enforcement and health-oversight concerns by allowing a temporary accounting suspension based initially on an oral representation. The covered entity must document the statement and the identity of the requesting official. An oral request generally supports suspension for no more than 30 days unless the official provides the written statement required for a longer specified period. The accounting records themselves should not be destroyed; the right is only temporarily suspended. This preserves both investigative confidentiality and the individual&#8217;s ultimate privacy rights.<\/span><\/p>\n<p><b>Question 379. Why should a school document its basis for a FERPA health or safety emergency disclosure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FERPA requires schools to publish all emergency records publicly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Documentation helps demonstrate that the disclosure was tied to a genuine emergency and made to appropriate parties for safety-related purposes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Documentation automatically makes the information directory information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Documentation eliminates all future FERPA obligations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Documentation helps demonstrate that the disclosure was tied to a genuine emergency and made to appropriate parties for safety-related purposes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FERPA&#8217;s health or safety emergency exception is narrow and depends on the circumstances existing at the time of disclosure. Schools should document why administrators concluded that an actual, impending, or imminent threat existed, what information was disclosed, and which parties received it. This creates an accountable record showing that the exception was used to address a real emergency rather than as a general information-sharing mechanism. Documentation is especially important because the exception is temporary and does not authorize blanket disclosure of education records beyond what the emergency requires.<\/span><\/p>\n<p><b>Question 380. A university experiences an infectious-disease emergency, runs a HIPAA-covered health clinic, and also processes Kentucky residents&#8217; consumer data through a separate commercial service. What is the BEST privacy approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply FERPA to every dataset because the organization is a university<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify each legal role and data context separately, applying FERPA emergency rules to education records, HIPAA to covered clinic PHI, and the KCDPA to qualifying Kentucky consumer-data processing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply only HIPAA because health information is involved somewhere in the organization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat all records as public during the emergency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Identify each legal role and data context separately, applying FERPA emergency rules to education records, HIPAA to covered clinic PHI, and the KCDPA to qualifying Kentucky consumer-data processing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A single institution can be subject to multiple privacy frameworks because legal obligations depend on the data, organizational role, individual relationship, and processing purpose. Education records can fall under FERPA, including its health or safety emergency exception. A university clinic that is a HIPAA covered entity can separately handle PHI under HIPAA. Commercial services directed to Kentucky consumers may create KCDPA obligations if statutory applicability requirements are met. Privacy professionals should classify each data flow independently rather than assuming the institution&#8217;s identity as a university causes one law to govern every information practice.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPP-US Exam Dumps and Practice Test Dumps. Question 361. Under HIPAA, how far back can an individual generally request an accounting of disclosures of PHI? One year Three years Up to six years preceding the request Ten years Correct Answer: 3. Up to six years preceding the request Explanation: The HIPAA Privacy [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20850"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20850"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20850\/revisions"}],"predecessor-version":[{"id":20851,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20850\/revisions\/20851"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}