2024 The Most Effective CIPP-US with 170 Questions Answers [Q59-Q78]

Share

2024 The Most Effective CIPP-US with 170 Questions Answers

Try Free and Start Using Realistic Verified CIPP-US Dumps Instantly.


The CIPP-US exam covers a wide range of privacy topics, including the US privacy legal framework, data protection regulations, data management, and privacy program management. To pass the exam, applicants must demonstrate their understanding of the essential concepts, practices, and legal requirements associated with privacy protection in the United States.


IAPP CIPP-US exam is a highly regarded certification for privacy professionals, and passing the exam is an essential step towards building a successful career in privacy. CIPP-US exam tests the candidate's knowledge of the laws and regulations governing privacy in the US, including the Federal Trade Commission Act, the Health Insurance Portability and Accountability Act, and the Children's Online Privacy Protection Act, among others. CIPP-US exam also covers data protection, data privacy management, and ethical considerations related to privacy.

 

NEW QUESTION # 59
A company's employee wellness portal offers an app to track exercise activity via users' mobile devices.
Which of the following design techniques would most effectively inform users of their data privacy rights and privileges when using the app?

  • A. Present a privacy policy to users during the wellness program registration process.
  • B. Offer information about data collection and uses at key data entry points.
  • C. Publish a privacy policy written in clear, concise, and understandable language.
  • D. Provide a link to the wellness program privacy policy at the bottom of each screen.

Answer: B

Explanation:
The design technique that would most effectively inform users of their data privacy rights and privileges when using the app is to offer information about data collection and uses at key data entry points. This technique is also known as "just-in-time" or "layered" notice, and it is recommended by the U.S. Federal Trade Commission (FTC) as a best practice for mobile app developers12 The idea behind this technique is to provide users with relevant and timely information about how their data is collected and used by the app, and what choices they have to control their data, at the moment when they are asked to provide or access their data. For example, if the app collects location data from the user's device, it should display a pop-up notice explaining why it needs the location data, how it will use it, and how the user can opt-out or change the settings. This way, the user can make an informed decision about whether to allow or deny the app's access to their data, and understand the consequences of their choice12 The advantage of this technique is that it avoids overwhelming the user with too much information at once, and instead provides concise and contextual information that is easy to understand and act upon. It also increases the user's trust and confidence in the app, as they feel more in control of their data and privacy12 The other design techniques are less effective because they do not provide the user with sufficient or timely information about their data privacy rights and privileges when using the app. Publishing a privacy policy written in clear, concise, and understandable language is a good practice, but it is not enough to inform the user of their data privacy rights and privileges, as many users may not read or understand the policy, or may not be aware of where to find it. Presenting a privacy policy to users during the wellness program registration process is also a good practice, but it may not capture all the data collection and uses that the app may perform, and it may not give the user enough opportunity to review and consent to the policy. Providing a link to the wellness program privacy policy at the bottom of each screen is also a good practice, but it may not be noticeable or accessible to the user, and it may not provide the user with the specific information they need at the point of data entry or access12 References:
* Mobile Privacy Disclosures: Building Trust Through Transparency: A Federal Trade Commission Staff Report (February 2013)
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 6: Privacy Program Management, Section 6.4: Privacy by Design


NEW QUESTION # 60
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?

  • A. Integrating privacy protections during product development.
  • B. Allowing consumers to opt in before collecting any data.
  • C. Mitigating harm to consumers after a security breach.
  • D. Announcing the tracking of online behavior for advertising purposes.

Answer: A

Explanation:
According to the FTC report, the most important directive for businesses is to adopt a "privacy by design" approach, which means integrating privacy protections throughout the entire product lifecycle, from initial design to disposal. This includes implementing reasonable security measures, collecting only the data needed for a specific purpose, retaining data only as long as necessary, and safely disposing of data that is no longer needed. The FTC report also recommends that businesses provide clear and transparent privacy notices, offer consumers meaningful choices about how their data is used, and increase their accountability for data practices. References: FTC Report, IAPP CIPP/US Study Guide (p. 32-33)


NEW QUESTION # 61
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?

  • A. Direct patients to the correct area of the hospital website
  • B. Post the privacy notice in a prominent location instead
  • C. State the privacy policy to the patient verbally
  • D. Confirm that patients are given the privacy notice on their first visit

Answer: D

Explanation:
HIPAA requires covered entities to provide a notice of privacy practices (NPP) to individuals who receive health care services from the covered entity. The NPP must describe how the covered entity may use and disclose protected health information (PHI), the individual's rights with respect to their PHI, and the covered entity's obligations to protect the privacy of PHI. The NPP must be provided to the individual no later than the date of the first service delivery, either in person or electronically. The covered entity must also make the NPP available on request and post it on its website if it has one. The covered entity must also make a good faith effort to obtain a written acknowledgment from the individual that they received the NPP. If the individual refuses to sign the acknowledgment, the covered entity must document the attempt and the reason for the refusal.
The other options are not sufficient to comply with HIPAA. Stating the privacy policy verbally (option A) does not provide the individual with a written or electronic copy of the NPP that they can keep for future reference. Posting the privacy notice in a prominent location (option B) does not ensure that the individual receives the NPP or has an opportunity to review it before receiving services. Directing patients to the correct area of the hospital website (option C) does not provide the individual with the NPP at the time of service delivery, unless the individual agrees to receive the NPP electronically and has access to the website at that time. References:
* Notice of Privacy Practices for Protected Health Information
* Model Notices of Privacy Practices
* Sample Notice: Availability of Notice of Privacy Practices
* Notice of Privacy Practices
* Notice of Privacy Practices (NPP) Distribution and Acknowledgement


NEW QUESTION # 62
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the main problem with Cheryl's suggested method of communicating the new privacy policy?

  • A. Employees might not understand how the documents relate to the policy as a whole.
  • B. The policy would not be considered valid if not communicated in full.
  • C. Employees would not be comfortable with a policy that is put into action over time.
  • D. The policy might not be implemented consistency across departments.

Answer: D


NEW QUESTION # 63
What is the most likely reason that states have adopted their own data breach notification laws?

  • A. Many large businesses have intentionally breached the personal information of their customers
  • B. Many lawmakers believe that federal enforcement of current laws has not been effective
  • C. Many states have unique types of businesses that require specific legislation
  • D. Many types of organizations are not currently subject to federal laws regarding breaches

Answer: B


NEW QUESTION # 64
SCENARIO -
Please use the following to answer the next question:
Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to the U.S. Department of Defense and other U.S. federal agencies. Jane's manager, Patrick, is a French citizen who has been living in California for over a decade. Patrick has recently begun to suspect that Jane is an insider secretly transmitting trade secrets to foreign intelligence. Unbeknownst to Patrick, the FBI has already received a hint from anonymous whistleblower, and jointly with the National Security Agency is investigating Jane's possible implication in a sophisticated foreign espionage campaign.
Ever since the pandemic, Jane has been working from home. To complete her daily tasks she uses her corporate laptop, which after each login conspicuously provides notice that the equipment belongs to Jones Labs and may be monitored according to the enacted privacy policy and employment handbook. Jane also has a corporate mobile phone that she uses strictly for business, the terms of which are defined in her employment contract and elaborated upon in her employee handbook. Both the privacy policy and the employee handbook are revised annually by a reputable California law firm specializing in privacy law. Jane also has a personal iPhone that she uses for private purposes only.
Jones Labs has its primary data center in San Francisco, which is managed internally by Jones Labs engineers.
The secondary data center, managed by Amazon AWS, is physically located in the UK for disaster recovery purposes. Jones Labs' mobile devices backup is managed by a mid-sized mobile defense company located in Denver, which physically stores the data in Canada to reduce costs. Jones Labs MS Office documents are securely stored in a Microsoft Office 365 data center based in Ireland. Manufacturing data of Jones Labs is stored in Taiwan and managed by a local supplier that has no presence in the U.S.
Before inspecting any GPS geolocation data from Jane's corporate mobile phone, Patrick should first do what?

  • A. Obtain a subpoena from law enforcement, or a court order, directing Jones Labs to collect the GPS geolocation data.
  • B. Ensure that such activity is permitted under Jane's employment contract or the company's employee privacy policy.
  • C. Revise emerging workplace privacy best practices with a reputable advocacy organization.
  • D. Obtain prior consent from Jane pursuant to the Telephone Consumer Protection Act

Answer: B

Explanation:
Patrick should first ensure that inspecting GPS geolocation data from Jane's corporate mobile phone is permitted under Jane's employment contract or the company's employee privacy policy. This is because Jane has a reasonable expectation of privacy in her location information, even if she uses a corporate-owned device for business purposes. The Fourth Amendment protects individuals from unreasonable searches and seizures by the government, and the Electronic Communications Privacy Act (ECPA) prohibits unauthorized interception or access to electronic communications by private parties. Therefore, Patrick cannot inspect Jane's GPS data without a valid legal basis, such as consent, contract, or court order. Obtaining prior consent from Jane pursuant to the Telephone Consumer Protection Act (A) is not relevant, as this law regulates unsolicited calls and text messages, not location tracking. Revising emerging workplace privacy best practices with a reputable advocacy organization (B) is not sufficient, as Patrick still needs to comply with the existing legal obligations and contractual terms. Obtaining a subpoena from law enforcement, or a court order, directing Jones Labs to collect the GPS geolocation data is not necessary, as Patrick is not acting on behalf of the government or in response to a legal request. However, if Patrick does obtain such a legal order, he should also comply with it and notify Jane of the disclosure, unless prohibited by law. References:
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.1.2, p. 115-116
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.1, p. 118-119
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.2, p. 120-121
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.3, p. 122-123
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.1, p. 124-125
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.2, p. 126-127
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.3, p. 128-129
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.4, p. 130-131
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.5, p. 132-133
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.6, p. 134-135
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.7, p. 136-137
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.8, p. 138-139
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.9, p. 140-141
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.10, p. 142-143
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.11, p. 144-145
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.12, p. 146-147
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.13, p. 148-149
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.14, p. 150-151
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.15, p. 152-153
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.16, p. 154-155
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.17, p. 156-157


NEW QUESTION # 65
All of the following organizations are specified as covered entities under the Health Insurance Portability and Accountability Act (HIPAA) EXCEPT?

  • A. Health plans
  • B. Healthcare providers
  • C. Pharmaceutical companies
  • D. Healthcare information clearinghouses

Answer: B

Explanation:
* The Privacy Act of 1974 is a federal law that regulates the collection, use, and disclosure of personal information by federal agencies.
* The Privacy Act of 1974 applies to records that are maintained in a system of records, which is defined as a group of records under the control of an agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifier assigned to the individual.
* The Privacy Act of 1974 grants individuals the right to access and amend their records, and requires agencies to provide notice of their systems of records, establish safeguards for the protection of the records, and limit the disclosure of the records to certain authorized purposes.
* The Privacy Act of 1974 also establishes civil and criminal penalties for violations of the law, such as unauthorized disclosure, failure to publish a notice, or refusal to grant access or amendment.
* The Privacy Act of 1974 does NOT require agencies to obtain the consent of the individual before collecting their personal information. However, the Privacy Act of 1974 does require agencies to inform the individual of the authority for the collection, the purpose and use of the collection, and the effects of not providing the information.
References: : [Overview of the Privacy Act of 1974]


NEW QUESTION # 66
SCENARIO
Please use the following to answer the next QUESTION :
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
Which of the following would be HealthCo's best response to the attorney's discovery request?

  • A. Respond with a request for satisfactory assurances such as a qualified protective order
  • B. Turn over all of the compromised patient records to the plaintiff's attorney
  • C. Reject the request because the HIPAA privacy rule only permits disclosure for payment, treatment or healthcare operations
  • D. Respond with a redacted document only relative to the plaintiff

Answer: A


NEW QUESTION # 67
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?

  • A. Washington.
  • B. California.
  • C. Vermont.
  • D. New York.

Answer: C


NEW QUESTION # 68
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S.
and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?

  • A. Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.
  • B. Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.
  • C. Request that the Board sign off in a written document on the choice of cloud provider.
  • D. Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.

Answer: D

Explanation:
The best way for Otto to minimize the privacy risks involved in using a cloud provider for the HR data is to ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit. This would allow Otto to verify that the cloud provider has implemented adequate security measures, such as encryption, access controls, and backup systems, to protect the HR data from unauthorized access, use, or disclosure. It would also allow Otto to check that the cloud provider is complying with the applicable privacy laws and regulations, such as the CCPA, the APEC Privacy Framework, and the breach notification requirements. By conducting an on-site audit, Otto can identify any gaps or weaknesses in the cloud provider's privacy practices and address them promptly. This would also demonstrate due diligence and accountability on the part of Filtration Station, which could mitigate the legal and reputational consequences of a data breach. References:
* [IAPP CIPP/US Study Guide], Chapter 3: Data Assessments, pp. 77-78.
* IAPP CIPP/US Body of Knowledge, Section III: Government and Court Access to Private-sector Information, Subsection B: Cross-Border Data Transfer, Topic 2: APEC Privacy Framework.
* IAPP CIPP/US Practice Questions, Question 125.


NEW QUESTION # 69
Under the Driver's Privacy Protection Act (DPPA), which of the following parties would require consent of an individual in order to obtain his or her Department of Motor Vehicle information?

  • A. Insurance companies needing to investigate claims.
  • B. Law enforcement agencies performing investigations.
  • C. Attorneys gathering information related to lawsuits.
  • D. Marketers wishing to distribute bulk materials.

Answer: D

Explanation:
The Driver's Privacy Protection Act (DPPA) is a federal law that regulates the disclosure of personal information obtained by state departments of motor vehicles (DMVs). The DPPA prohibits DMVs and other entities that receive such information from DMVs from disclosing it to anyone without the express consent of the individual to whom the information pertains, unless the disclosure falls under one of the 14 exceptions listed in the statute.
Some of the exceptions that allow disclosure of personal information from DMV records without consent are:
* For use by any government agency, including any court or law enforcement agency, in carrying out its functions, or any private person or entity acting on behalf of a government agency in carrying out its functions.
* For use in connection with matters of motor vehicle or driver safety and theft; motor vehicle emissions; motor vehicle product alterations, recalls, or advisories; performance monitoring of motor vehicles, motor vehicle parts and dealers; motor vehicle market research activities, including survey research; and removal of non-owner records from the original owner records of motor vehicle manufacturers.
* For use in the normal course of business by a legitimate business or its agents, employees, or contractors, but only to verify the accuracy of personal information submitted by the individual to the business or its agents, employees, or contractors; and if such information as so submitted is not correct or is no longer correct, to obtain the correct information, but only for the purposes of preventing fraud by, pursuing legal remedies against, or recovering on a debt or security interest against, the individual.
* For use in connection with any civil, criminal, administrative, or arbitral proceeding in any federal, state, or local court or agency or before any self-regulatory body, including the service of process, investigation in anticipation of litigation, and the execution or enforcement of judgments and orders, or pursuant to an order of a federal, state, or local court.
* For use in research activities, and for use in producing statistical reports, so long as the personal information is not published, redisclosed, or used to contact individuals.
* For use by any insurer or insurance support organization, or by a self-insured entity, or its agents, employees, or contractors, in connection with claims investigation activities, antifraud activities, rating or underwriting.
* For use in providing notice to the owners of towed or impounded vehicles.
* For use by any licensed private investigative agency or licensed security service for any purpose permitted under this subsection.
* For use by an employer or its agent or insurer to obtain or verify information relating to a holder of a commercial driver's license that is required under chapter 313 of title 49.
* For use in connection with the operation of private toll transportation facilities.
* For any other use specifically authorized under the law of the state that holds the record, if such use is related to the operation of a motor vehicle or public safety.
None of the exceptions above apply to the use of personal information from DMV records by marketers wishing to distribute bulk materials. Therefore, such use would require the consent of the individual to whom the information pertains, according to the DPPA. Hence, option D is the correct answer.
Option A is incorrect, as law enforcement agencies performing investigations are exempt from the consent requirement under the first exception.
Option B is incorrect, as insurance companies needing to investigate claims are exempt from the consent requirement under the sixth exception.
Option C is incorrect, as attorneys gathering information related to lawsuits are exempt from the consent requirement under the fourth exception.
References:
* [IAPP CIPP/US Study Guide], Chapter 8: Federal Privacy Laws, pp. 181-182.
* CIPP/US Practice Questions (Sample Questions), Question 31.


NEW QUESTION # 70
Which of the following best describes private-sector workplace monitoring in the United States?

  • A. Employers have broad authority to monitor their employees
  • B. Most employees are protected from workplace monitoring by the U.S. Constitution
  • C. U.S. federal law restricts monitoring only to industries for which it is necessary
  • D. Judgments in private lawsuits have severely limited the monitoring of employees

Answer: A


NEW QUESTION # 71
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
What is the most likely way that Declan might directly violate the Health Insurance Portability and Accountability Act (HIPAA)?

  • A. By speaking to a patient without prior authorization
  • B. By ignoring the conversation about a potential breach
  • C. By following through with his plans for his upcoming paper
  • D. By being present when patients are checking in

Answer: B


NEW QUESTION # 72
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the best reason for Cheryl to follow Janice's suggestion about classifying customer data?

  • A. It will help employees stay better organized
  • B. It will prevent the company from collecting too much personal information (PI)
  • C. It will help the company meet a federal mandate
  • D. It will increase the security of customers' personal information (PI)

Answer: D

Explanation:
Data classification systematically categorizes information based on sensitivity and importance to determine its level of confidentiality. This process helps apply appropriate security and compliance measures to ensure each category receives proper protection1. This process also helps to identify which personal data is subject to specific GDPR requirements, such as obtaining explicit consent from data subjects, or notifying data subjects in the event of a data breach2. By classifying data, Cheryl can also make more informed decisions about where to store the information on her computer system and the nature of controls that are required based on classification3. This way, she can protect her customers' privacy while maintaining the highest level of service. References:
* Data Classification for GDPR Explained
* A guide to data classification: confidential data vs. sensitive data vs. public information
* Why Is Data Classification Important?


NEW QUESTION # 73
SCENARIO
Please use the following to answer the next QUESTION:
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking Questions about my opinions."
"Let me see," Matt said, and began reading the list of Questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer Questions about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
Based on the incident, the FTC's enforcement actions against the marketer would most likely include what violation?

  • A. Collecting information from a child under the age of thirteen.
  • B. Failing to notify of a breach of children's private information.
  • C. Intruding upon the privacy of a family with young children.
  • D. Disregarding the privacy policy of the children's marketing industry.

Answer: D


NEW QUESTION # 74
Which jurisdiction must courts have in order to hear a particular case?

  • A. Subject matter jurisdiction and professional jurisdiction
  • B. Personal jurisdiction and subject matter jurisdiction
  • C. Personal jurisdiction and professional jurisdiction
  • D. Subject matter jurisdiction and regulatory jurisdiction

Answer: B

Explanation:
Reference:
~klett/chapter%25202%2520bl281%2520judicial%2520review%2520new.htm
+&cd=1&hl=en&ct=clnk&gl=pk&client=firefox-b-e


NEW QUESTION # 75
More than half of U.S. states require telemarketers to?

  • A. Identify themselves at the beginning of a call
  • B. Register with the state before conducting business
  • C. Obtain written consent from potential customers
  • D. Provide written contracts for customer transactions

Answer: D


NEW QUESTION # 76
What practice do courts commonly require in order to protect certain personal information on documents, whether paper or electronic, that is involved in litigation?

  • A. Encryption
  • B. Redaction
  • C. Hashing
  • D. Deletion

Answer: B

Explanation:
Redaction is the permanent removal of sensitive data-the digital equivalent of "blacking out" text in printed material. Redaction can be accomplished by simply deleting characters from a file or database record, or by replacing characters with asterisks or other placeholders. Redaction is often used to protect personal information, such as names, addresses, social security numbers, or financial data, on documents that are disclosed in litigation, such as pleadings, exhibits, or discovery responses. Redaction is required by courts to comply with privacy laws and rules, such as the Federal Rules of Civil Procedure (FRCP), which mandate that parties must redact certain types of personal information from documents filed with the court or produced to the other party. Redaction is also a best practice to minimize the risk of unauthorized access, identity theft, or reputational harm that may result from exposing personal information in litigation. References:
* When to redact, or not, disclosable documents in litigation - Stewarts
* The approach to redaction - High Court guidance - Lexology
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 3: Federal Privacy Laws and Regulations, Section 3.2: Federal Rules of Civil Procedure (FRCP).


NEW QUESTION # 77
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the General Data Protection Regulation (GDPR), how would the U.S.-based startup company most likely be classified?

  • A. As a data supervisor
  • B. As a data processor
  • C. As a data manager
  • D. As a data controller

Answer: B

Explanation:
The data privacy leader needs to identify all the personal data that the Company has received from the retailer, as well as the purposes, retention periods, and sharing practices of such data. Since the data inventory is obsolete, the data privacy leader cannot rely on it to provide accurate and complete information. Therefore, the next best source of information is to interview the key marketing personnel who are responsible for the partnership with the retailer and the use of the personal data. The marketing personnel can provide insights into the data flows, the data categories, the data processing activities, and the data protection measures that the Company has implemented. They can also help the data privacy leader to locate the relevant documents, contracts, and records that can support the investigation. References: [IAPP CIPP/US Study Guide], Chapter 5:
Data Management, p. 97-98; IAPP Privacy Tech Vendor Report, Data Mapping and Inventory, p. 9-10.


NEW QUESTION # 78
......

Download Free Latest Exam CIPP-US Certified Sample Questions: https://exam-hub.prepawayexam.com/IAPP/braindumps.CIPP-US.ete.file.html