
2026 Correct Practice Tests of CIPP-US Dumps with Practice Exam
Certification Sample Questions of CIPP-US Dumps With 100% Exam Passing Guarantee
IAPP CIPP-US certification is an essential credential for anyone who is serious about working in the field of privacy and data protection. Whether you are just starting out in your career or are looking to take your skills to the next level, this certification is an important step in achieving your goals and advancing your professional development.
NEW QUESTION # 80
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A code of responsibilities for medical establishments to uphold privacy laws.
- B. A bill of rights for individuals seeking access to their personal information.
- C. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- D. An international court ruling on personal information held in the commercial sector.
Answer: B
NEW QUESTION # 81
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of
1988 (EPPA)?
- A. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits.
- B. Employers involved in the manufacture of controlled substances may terminate employees based on polygraph results if other evidence exists.
- C. The EPPA requires that employers post essential information about the Act in a conspicuous location.
- D. The EPPA includes an exception that allows polygraph tests in professions in which employee honesty is necessary for public safety.
Answer: A
Explanation:
The false statement regarding the provisions of the EPPA is C. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits. The EPPA does not regulate psychological testing, only polygraph testing. Psychological testing is a broad term that covers various types of assessments that measure cognitive abilities, personality traits, interests, values, and skills. Employers may use psychological testing for various purposes, such as hiring, promotion, training, or development, as long as they comply with other laws and regulations, such as the Americans with Disabilities Act (ADA), the Equal Employment Opportunity Commission (EEOC) guidelines, and the Uniform Guidelines on Employee Selection Procedures. However, employers should be careful to ensure that the psychological tests they use are valid, reliable, job-related, and nondiscriminatory, and that they respect the privacy and dignity of the test takers.
NEW QUESTION # 82
In what way does the "Red Flags Rule" under the Fair and Accurate Credit Transactions Act (FACTA) relate to the owner of a grocery store who uses a money wire service?
- A. It is not usually enforced in the case of a small financial institution
- B. It does not apply because the owner is not a creditor
- C. It mandates the use of updated technology for securing credit records
- D. It requires the owner to implement an identity theft warning system
Answer: B
Explanation:
The Red Flags Rule is a regulation that requires financial institutions and creditors to implement a written identity theft prevention program that is designed to detect, prevent, and mitigate identity theft in connection with the opening of a covered account or any existing covered account. A creditor is any person who regularly extends, renews, or continues credit; any person who regularly arranges for the extension, renewal, or continuation of credit; or any assignee of an original creditor who participates in the decision to extend, renew, or continue credit. A covered account is an account that a financial institution or creditor offers or maintains, primarily for personal, family, or household purposes, that involves or is designed to permit multiple payments or transactions, such as a credit card account, mortgage loan, automobile loan, margin account, cell phone account, utility account, checking account, or savings account. A money wire service is a service that allows customers to send or receive money electronically. The owner of a grocery store who uses a money wire service is not a creditor because he or she does not regularly extend, renew, or continue credit to customers. Therefore, the Red Flags Rule does not apply to the owner of a grocery store who uses a money wire service.
NEW QUESTION # 83
A company's employee wellness portal offers an app to track exercise activity via users' mobile devices.
Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?
- A. Publish a privacy policy written in clear, concise, and understandable language.
- B. Present a privacy policy to users during the wellness program registration process.
- C. Provide a link to the wellness program privacy policy at the bottom of each screen.
- D. Offer information about data collection and uses at key data entry points.
Answer: D
Explanation:
The design technique that would most effectively inform users of their data privacy rights and privileges when using the app is to offer information about data collection and uses at key data entry points. This technique is also known as "just-in-time" or "layered" notice, and it is recommended by the U.S. Federal Trade Commission (FTC) as a best practice for mobile app developers12 The idea behind this technique is to provide users with relevant and timely information about how their data is collected and used by the app, and what choices they have to control their data, at the moment when they are asked to provide or access their data. For example, if the app collects location data from the user's device, it should display a pop-up notice explaining why it needs the location data, how it will use it, and how the user can opt-out or change the settings. This way, the user can make an informed decision about whether to allow or deny the app's access to their data, and understand the consequences of their choice12 The advantage of this technique is that it avoids overwhelming the user with too much information at once, and instead provides concise and contextual information that is easy to understand and act upon. It also increases the user's trust and confidence in the app, as they feel more in control of their data and privacy12 The other design techniques are less effective because they do not provide the user with sufficient or timely information about their data privacy rights and privileges when using the app. Publishing a privacy policy written in clear, concise, and understandable language is a good practice, but it is not enough to inform the user of their data privacy rights and privileges, as many users may not read or understand the policy, or may not be aware of where to find it. Presenting a privacy policy to users during the wellness program registration process is also a good practice, but it may not capture all the data collection and uses that the app may perform, and it may not give the user enough opportunity to review and consent to the policy. Providing a link to the wellness program privacy policy at the bottom of each screen is also a good practice, but it may not be noticeable or accessible to the user, and it may not provide the user with the specific information they need at the point of data entry or access12 References:
* Mobile Privacy Disclosures: Building Trust Through Transparency: A Federal Trade Commission Staff Report (February 2013)
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 6: Privacy Program Management, Section 6.4: Privacy by Design
NEW QUESTION # 84
Which of the following best describes what a "private right of action" is?
- A. The right of individuals harmed by data processing to have their information deleted.
- B. The right of individuals to keep their information private.
- C. The right of individuals to submit a request to access their information.
- D. The right of individuals harmed by a violation of a law to file a lawsuit against the violation.
Answer: D
Explanation:
A private right of action is a legal provision that grants individuals the ability to bring a lawsuit against a party that has wronged them and to seek redress for the harm that they have suffered.
A private right of action is a fundamental component of the U.S. judicial system and an essential element of enforcing privacy rights. Privacy advocates argue that a private right of action is necessary to hold perpetrators of privacy violations accountable and to address the limitations of the FTC's enforcement authority. However, businesses are concerned that a private right of action would lead to a proliferation of frivolous lawsuits that would burden responsible data processors and impede innovation.
NEW QUESTION # 85
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face?
- A. Criminal fines.
- B. A jail sentence.
- C. Probation.
- D. An injunction.
Answer: D
Explanation:
An injunction is a court order that requires a party to stop or refrain from doing something. In a case of civil litigation, a defendant who is being sued for distributing an employee's private information might face an injunction that prohibits them from further disclosing or using the employee's private information. An injunction is a form of equitable relief that aims to prevent or remedy harm that cannot be adequately compensated by monetary damages. Probation, criminal fines, and jail sentences are forms of criminal sanctions that are not applicable in civil litigation, unless the defendant is also charged with a criminal offense related to the distribution of the employee's private information.
NEW QUESTION # 86
What was the original purpose of the Federal Trade Commission Act?
- A. To ensure privacy rights of U.S. citizens
- B. To enforce antitrust laws
- C. To negotiate consent decrees with companies violating personal privacy
- D. To protect consumers
Answer: B
Explanation:
The Federal Trade Commission Act (FTCA) was adopted in 1914 as part of the Progressive Era reforms that aimed to curb the power and influence of monopolies and trusts in the U.S.
economy. The FTCA created the Federal Trade Commission (FTC) as an independent agency to investigate and prevent unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce. The FTCA also gave the FTC the authority to issue cease and desist orders, seek injunctions, and impose civil penalties for violations of the law. The FTCA was intended to complement and supplement the existing antitrust laws, such as the Sherman Act and the Clayton Act, that prohibited restraints of trade, price-fixing, mergers, and other anticompetitive conduct.
NEW QUESTION # 87
SCENARIO
Please use the following to answer the next QUESTION:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data.
However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most effective kind of training CloudHealth could have given its employees to help prevent this type of data breach?
- A. Training on the difference between confidential and non-public information
- B. Training on the terms of the contractual agreement with HealthCo
- C. Training on techniques for identifying phishing attempts
- D. Training on CloudHealth's HR policy regarding the role of employees involved data breaches
Answer: C
Explanation:
Phishing is a form of social engineering that involves sending fraudulent emails or other messages that appear to come from a legitimate source, but are designed to trick recipients into revealing sensitive information, such as passwords, account numbers, or personal identifiers1. Phishing is one of the most common and effective methods of cyberattacks, and it can lead to data breaches, identity theft, ransomware infections, or other serious consequences2. Therefore, training on how to recognize and avoid phishing attempts is crucial for any organization that handles sensitive data, especially ePHI, which is subject to strict regulations under HIPAA3. Training on techniques for identifying phishing attempts can help employees to spot the signs of a phishing email, such as:
* Sender's address or domain name that does not match the expected source or contains spelling errors4
* Generic salutations or impersonal tone that do not address the recipient by name or use proper grammar4
* Urgent or threatening language that creates a sense of pressure or fear and asks the recipient to take immediate action, such as clicking on a link, opening an attachment, or providing information4
* Suspicious links or attachments that may contain malware or lead to fake websites that mimic the appearance of a legitimate site, but have a different URL or request login credentials or other data4
* Requests for sensitive information that are unusual or out of context, such as asking for passwords, account numbers, or personal identifiers that the sender should already have or should not need4 Training on techniques for identifying phishing attempts can also help employees to learn how to respond to a phishing email, such as:
* Not clicking on any links or opening any attachments in the email4
* Not replying to the email or providing any information to the sender4
* Reporting the email to the IT department or security team and deleting it from the inbox4
* Verifying the legitimacy of the email by contacting the sender directly using a different channel, such as phone or another email address4
* Updating the antivirus software and scanning the device for any malware infection4 Training on techniques for identifying phishing attempts is the most effective kind of training that CloudHealth could have given its employees to help prevent this type of data breach, because it would have enabled them to recognize the phishing email that compromised the PHI of more than 10,000 HealthCo patients, and to avoid falling victim to it. Training on the terms of the contractual agreement with HealthCo, the difference between confidential and non-public information, or CloudHealth's HR policy regarding the role of employees involved in data breaches, while important, would not have been as effective in preventing this specific type of data breach, because they would not have addressed the root cause of the breach, which was the phishing email.
References:
* 1: IAPP, Phishing, https://iapp.org/resources/glossary/phishing/
* 2: SpinOne, The Top 5 Phishing Awareness Training Providers 2023, https://spinbackup.com/blog
/phishing-awareness-training-best-providers/
* 3: IAPP, HIPAA, https://iapp.org/resources/glossary/hipaa/
* 4: Expert Insights, The Top 11 Phishing Awareness Training and Simulation Solutions,
https://expertinsights.com/insights/the-top-11-phishing-awareness-training-and-simulation-solutions/
NEW QUESTION # 88
Under the Driver's Privacy Protection Act (DPPA), which of the following parties would require consent of an individual in order to obtain his or her Department of Motor Vehicle information?
- A. Law enforcement agencies performing investigations.
- B. Attorneys gathering information related to lawsuits.
- C. Insurance companies needing to investigate claims.
- D. Marketers wishing to distribute bulk materials.
Answer: D
Explanation:
The Driver's Privacy Protection Act (DPPA) is a federal law that regulates the disclosure of personal information obtained by state departments of motor vehicles (DMVs). The DPPA prohibits DMVs and other entities that receive such information from DMVs from disclosing it to anyone without the express consent of the individual to whom the information pertains, unless the disclosure falls under one of the 14 exceptions listed in the statute.
Some of the exceptions that allow disclosure of personal information from DMV records without consent are:
For use by any government agency, including any court or law enforcement agency, in carrying out its functions, or any private person or entity acting on behalf of a government agency in carrying out its functions.
For use in connection with matters of motor vehicle or driver safety and theft; motor vehicle emissions; motor vehicle product alterations, recalls, or advisories; performance monitoring of motor vehicles, motor vehicle parts and dealers; motor vehicle market research activities, including survey research; and removal of non-owner records from the original owner records of motor vehicle manufacturers.
For use in the normal course of business by a legitimate business or its agents, employees, or contractors, but only to verify the accuracy of personal information submitted by the individual to the business or its agents, employees, or contractors; and if such information as so submitted is not correct or is no longer correct, to obtain the correct information, but only for the purposes of preventing fraud by, pursuing legal remedies against, or recovering on a debt or security interest against, the individual.
For use in connection with any civil, criminal, administrative, or arbitral proceeding in any federal, state, or local court or agency or before any self-regulatory body, including the service of process, investigation in anticipation of litigation, and the execution or enforcement of judgments and orders, or pursuant to an order of a federal, state, or local court. For use in research activities, and for use in producing statistical reports, so long as the personal information is not published, redisclosed, or used to contact individuals. For use by any insurer or insurance support organization, or by a self-insured entity, or its agents, employees, or contractors, in connection with claims investigation activities, antifraud activities, rating or underwriting.
For use in providing notice to the owners of towed or impounded vehicles. For use by any licensed private investigative agency or licensed security service for any purpose permitted under this subsection.
For use by an employer or its agent or insurer to obtain or verify information relating to a holder of a commercial driver's license that is required under chapter 313 of title 49. For use in connection with the operation of private toll transportation facilities. For any other use specifically authorized under the law of the state that holds the record, if such use is related to the operation of a motor vehicle or public safety. None of the exceptions above apply to the use of personal information from DMV records by marketers wishing to distribute bulk materials. Therefore, such use would require the consent of the individual to whom the information pertains, according to the DPPA.
NEW QUESTION # 89
Read this notice:
Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instructions on setting your Web browser to refuse cookies, click here.
What type of legal choice does not notice provide?
- A. Implied consent
- B. Mandatory
- C. Opt-out
- D. Opt-in
Answer: C
NEW QUESTION # 90
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- A. Washington.
- B. California.
- C. Vermont.
- D. New York.
Answer: C
NEW QUESTION # 91
Which federal act does NOT contain provisions for preempting stricter state laws?
- A. The Telemarketing Consumer Protection and Fraud Prevention Act
- B. The CAN-SPAM Act
- C. The Fair and Accurate Credit Transactions Act (FACTA)
- D. The Children's Online Privacy Protection Act (COPPA)
Answer: A
Explanation:
The federal act that does NOT contain provisions for preempting stricter state laws is the Telemarketing Consumer Protection and Fraud Prevention Act. This act authorizes the Federal Trade Commission (FTC) to establish and enforce rules for telemarketing practices, such as the Do Not Call Registry, the prohibition of robocalls, and the disclosure of material information.
However, the act also explicitly states that it does not "annul, alter, or affect, or exempt any person subject to the provisions of this section from complying with, the laws of any State with respect to telemarketing practices, except to the extent that those laws are inconsistent with any provision of this section, and then only to the extent of the inconsistency". This means that states can enact and enforce their own laws regarding telemarketing, as long as they are not less protective than the federal law. In contrast, the other three acts listed in the question do contain preemption clauses that limit or override the authority of states to regulate certain aspects of electronic communications, online privacy, and credit transactions.
NEW QUESTION # 92
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?
- A. Delete their personal information.
- B. Disclose their personal information to them.
- C. Refrain from selling their personal information to third parties.
- D. Correct their personal information.
Answer: D
Explanation:
The CCPA grants California residents the right to request that a business delete, disclose, or stop selling their personal information, but it does not grant them the right to request that a business correct their personal information. However, the CPRA, which will amend and expand the CCPA in 2023, will grant California residents the right to request that a business correct inaccurate personal information. References: CCPA, CPRA, IAPP CIPP/US Study Guide (p. 62)
NEW QUESTION # 93
SCENARIO
Please use the following to answer the next question:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department.
As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non- encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
What is the most likely way that Declan might directly violate the Health Insurance Portability and Accountability Act (HIPAA)?
- A. By ignoring the conversation about a potential breach
- B. By speaking to a patient without prior authorization
- C. By following through with his plans for his upcoming paper
- D. By being present when patients are checking in
Answer: C
Explanation:
Declan might directly violate the HIPAA Privacy Rule by using John's name and personal health information (PHI) in his paper without his written authorization. The Privacy Rule protects the confidentiality of PHI that is created, received, maintained, or transmitted by a covered entity or its business associate. PHI includes any information that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual. Declan, as a nursing assistant, is part of the covered entity's workforce and must comply with the Privacy Rule. He cannot disclose John's PHI to anyone, including his classmates or instructors, without John's authorization or a valid exception under the Privacy Rule. Even if he does not use John's full name, he may still reveal enough information to make John identifiable, such as his diagnosis, his father's condition, or his location. This would be an impermissible use and disclosure of PHI, and a potential HIPAA violation. Declan should either obtain John's written authorization to use his PHI in his paper, or de-identify the information according to the Privacy Rule's standards.
NEW QUESTION # 94
Under the California Consumer Privacy Act (as amended by the California Pnvacy Rights Act), a consumer may Initiate a civil action against a business for?
- A. Failure to implement and maintain reasonable security procedures and practices to protect the personal information held.
- B. Failure to implement and maintain security practices set out in regulations issued by the California Privacy Protection Agency (CPPA).
- C. Any personal information that is subject to unauthorized access or disclosure.
- D. A security breach of certain categories of personal information that is nonencrypted and nonredacted
Answer: D
Explanation:
Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), consumers have the right to initiate a civil action if a business fails to adequately protect their personal information and a security breach occurs. This right applies specifically to breaches of certain categories of personal information that are unencrypted and unredacted.
Key Details of CCPA/CPRA Civil Actions:
* Security Breaches:
* A consumer can sue a business if the breach involves personal information such as Social Security numbers, driver's license numbers, or financial account information, provided that the data was unencrypted and unredacted.
* Reasonable Security Practices:
* Businesses are required to implement and maintain reasonable security practices to protect personal information. Failure to do so may expose the business to liability in case of a breach.
* Categories of Data Covered:
* The law specifies that only certain sensitive categories of personal information are actionable under a civil suit.
Explanation of Options:
* A. Any personal information that is subject to unauthorized access or disclosure:This is incorrect.
The civil action is limited to specific sensitive data categories, not all personal information.
* B. A security breach of certain categories of personal information that is nonencrypted and nonredacted:This is correct. Civil actions under the CCPA/CPRA apply to breaches involving specific sensitive data that is not encrypted or redacted.
* C. Failure to implement and maintain reasonable security procedures and practices to protect the personal information held:While this is a requirement under the law, it does not by itself provide grounds for a civil action. A security breach must occur for a consumer to sue.
* D. Failure to implement and maintain security practices set out in regulations issued by the California Privacy Protection Agency (CPPA):This is incorrect. Civil actions are tied to breaches of sensitive data, not a failure to meet specific agency guidelines.
References from CIPP/US Materials:
* CCPA/CPRA (Civil Code § 1798.150): Outlines the private right of action for security breaches involving certain unencrypted and unredacted data.
* IAPP CIPP/US Certification Textbook: Discusses the conditions under which consumers may bring civil actions under the CCPA/CPRA.
NEW QUESTION # 95
Due to cookie deprecation, businesses will be required to simplify their tracking practices by doing what?
- A. Purging existing IDs that identify visitors by browser.
- B. Ensuring only registered users are tracked.
- C. Running analytics only in dedicated sandboxes
- D. Deleting their existing data sets of any third-party cookies
Answer: D
Explanation:
With the impending deprecation of third-party cookies, businesses must simplify their tracking practices and shift to more privacy-conscious technologies. Third-party cookies are being phased out by major web browsers, such as Google Chrome, to improve user privacy and reduce cross- site tracking.
One of the most critical actions businesses need to take is deleting existing data sets of third- party cookies, as they will soon become obsolete. This action ensures compliance with emerging privacy standards and helps organizations transition to alternative methods of tracking, such as first-party data collection or consent-based tracking mechanisms.
NEW QUESTION # 96
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed.
Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
What could the company have done differently prior to the breach to reduce their risk?
- A. Looked for any persistent threats to security that could compromise the company's network.
- B. Implemented a comprehensive policy for accessing customer information.
- C. Honored the promise of its privacy policy to acquire information by using an opt-in method.
- D. Communicated requests for changes to users' preferences across the organization and with third parties.
Answer: B
Explanation:
The scenario suggests that the company lacked adequate rules about access to customer information, which increased the risk of unauthorized access and data breach. Implementing a comprehensive policy for accessing customer information would have helped the company to limit the access to only those who need it for legitimate purposes, and to protect the confidentiality, integrity, and availability of the data. This is also one of the recommendations that Roberta made in her report. References:
* CIPP/US Practice Questions (Sample Questions), Question 116, Answer A, Explanation A.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 5, Section 5.2, p. 143.
NEW QUESTION # 97
What role does the U.S. Constitution play in the area of workplace privacy?
- A. It provides significant protections to federal and state governments, but not to private-sector employment
- B. It provides contractual protections to members of labor unions, but not to employees at will
- C. It provides legal precedent for physical information security, but not for electronic security
- D. It provides enforcement resources to large employers, but not to small businesses
Answer: C
NEW QUESTION # 98
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?
- A. The impact of an organizational data breach will be more severe than if the data had been segregated.
- B. The organization will still be in compliance with most sector-specific privacy and security laws.
- C. Temporary employees will be able to find the data necessary to fulfill their responsibilities.
- D. The organization will be able to address legal discovery requests efficiently without producing more information than necessary.
Answer: D
NEW QUESTION # 99
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
- A. When providing an individual with required notice of a data breach, you must identify what personal information was actually or likely compromised.
- B. You must notify the Federal Trade Commission (FTC) in addition to affected individuals if over 500 individuals are receiving notice.
- C. When you are required to provide an individual with notice of a data breach under any state's law, you must provide the individual with an offer for free credit monitoring.
- D. The only obligations to provide data breach notification are under state law because currently there is no federal law or regulation requiring notice for the breach of personal information.
Answer: D
NEW QUESTION # 100
SCENARIO
Please use the following to answer the next QUESTION:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data.
However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
Which of the following would be HealthCo's best response to the attorney's discovery request?
- A. Respond with a redacted document only relative to the plaintiff
- B. Reject the request because the HIPAA privacy rule only permits disclosure for payment, treatment or healthcare operations
- C. Respond with a request for satisfactory assurances such as a qualified protective order
- D. Turn over all of the compromised patient records to the plaintiff's attorney
Answer: C
Explanation:
The HIPAA privacy rule establishes national standards to protect individuals' medical records and other individually identifiable health information (collectively defined as "protected health information") and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically (collectively defined as "covered entities")1 The rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that may be made of such information without an individual's authorization1 The rule also gives individuals rights over their protected health information, including rights to examine and obtain a copy of their health records, to direct a covered entity to transmit to a third party an electronic copy of their protected health information in an electronic health record, and to request corrections1 The HIPAA privacy rule permits a covered entity to disclose protected health information for the litigation in response to a court order, subpoena, discovery request, or other lawful process, provided the applicable requirements of 45 CFR 164.512 (e) for disclosures for judicial and administrative proceedings are met2 These requirements include:
* In response to a court order or administrative tribunal order, the covered entity may disclose only the protected health information expressly authorized by such order2
* In response to a subpoena, discovery request, or other lawful process that is not accompanied by a court order or administrative tribunal order, the covered entity must receive satisfactory assurances that the party seeking the information has made reasonable efforts to ensure that the individual who is the subject of the information has been given notice of the request, or that the party seeking the information has made reasonable efforts to secure a qualified protective order2
* A qualified protective order is an order of a court or administrative tribunal or a stipulation by the parties to the litigation or administrative proceeding that prohibits the parties from using or disclosing the protected health information for any purpose other than the litigation or proceeding for which such information was requested andrequires the return to the covered entity or destruction of the protected health information (including all copies made) at the end of the litigation or proceeding2 Option A is incorrect because the HIPAA privacy rule does not only permit disclosure for payment, treatment or healthcare operations. The rule also allows disclosure for other purposes, such as public health, research, law enforcement, judicial and administrative proceedings, as long as the applicable conditions and limitations are met1 Option B is correct because it is consistent with the HIPAA privacy rule's requirement for disclosures for judicial and administrative proceedings. By responding with a request for satisfactory assurances such as a qualified protective order, HealthCo is ensuring that the protected health information will be used only for the litigation and will be returned or destroyed afterwards2 Option C is incorrect because it is not consistent with the HIPAA privacy rule's requirement for disclosures for judicial and administrative proceedings. By turning over all of the compromised patient records to the plaintiff's attorney, HealthCo is disclosing more information than necessary and may violate the privacy rights of other individuals who are not parties to the lawsuit2 Option D is incorrect because it is not consistent with the HIPAA privacy rule's requirement for disclosures for judicial and administrative proceedings. By responding with a redacted document only relative to the plaintiff, HealthCo is not providing satisfactory assurances that the protected health information will be used only for the litigation and will be returned or destroyed afterwards2 References: 1: Summary of the HIPAA Privacy Rule | HHS.gov 2: May a covered entity use or disclose protected health information for litigation? | HHS.gov
NEW QUESTION # 101
Which of the following types of information would an organization generally NOT be required to disclose to law enforcement?
- A. Information about workspace injuries under OSHA requirements
- B. Personal health information under the HIPAA Privacy Rule
- C. Money laundering information under the Bank Secrecy Act of 1970
- D. Information about medication errors under the Food, Drug and Cosmetic Act
Answer: B
Explanation:
The HIPAA Privacy Rule generally prohibits covered entities and business associates from disclosing protected health information (PHI) to law enforcement without the individual's authorization, unless one of the exceptions in 45 CFR § 164.512 applies. These exceptions include disclosures required by law, disclosures for law enforcement purposes, disclosures about victims of abuse, neglect or domestic violence, disclosures for health oversight activities, disclosures for judicial and administrative proceedings, disclosures for research purposes, disclosures to avert a serious threat to health or safety, disclosures for specialized government functions, disclosures for workers' compensation, and disclosures to coroners and medical examiners. None of these exceptions apply to the type of information in option D, which is personal health information that is not related to any of the above purposes. Therefore, an organization would generally not be required to disclose such information to law enforcement under the HIPAA Privacy Rule. References: https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition/disclosures-third- parties
https://bing.com/search?q=information+disclosure+to+law+enforcement
https://hipaatrek.com/law-enforcement-hipaa-disclosing-phi/
NEW QUESTION # 102
......
CIPP-US Sample Practice Exam Questions 2026 Updated Verified: https://exampasspdf.testkingit.com/IAPP/latest-CIPP-US-exam-dumps.html