Privacy and Security Standards Flashcards
7 cards from real CACS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privacy and Security Standards flashcards as text
A consumer asks their CAC to email a copy of their completed Marketplace application to a family member. What is the correct response?
Answer: Decline unless the consumer provides written authorization and the family member is an authorized representative
CACs must obtain written authorization before sharing application information with anyone other than the consumer, even family members, unless they are an authorized representative.
Which federal law primarily governs the privacy protections that CACs must follow when handling consumers' health information?
Answer: The Health Insurance Portability and Accountability Act (HIPAA)
HIPAA establishes the baseline privacy and security standards for protected health information (PHI) that CACs must comply with.
A CAC discovers that a co-worker has been accessing consumer application files without a business need. What should the CAC do first?
Answer: Report the incident to their supervisor or privacy officer immediately
Unauthorized access to consumer data is a potential breach that must be escalated to a supervisor or privacy officer immediately per standard incident response protocols.
When a consumer calls a CAC's office and wants to discuss their application over the phone, what should the CAC do first?
Answer: Verify the caller's identity using established authentication questions before discussing any PII
CACs must verify caller identity through security questions or other authentication methods before discussing any personally identifiable information over the phone.
A CAC prints a consumer's application summary and accidentally leaves it on a shared printer. This is an example of what type of privacy risk?
Answer: An inadvertent disclosure of PII
Leaving printed PII unattended in a shared space constitutes an inadvertent disclosure, which is a privacy incident that must be reported and remediated.
Under Marketplace privacy rules, for how long are CAC organizations generally required to retain records of their consumer assistance activities?
Answer: 5 years
CMS generally requires certified entities like CAC programs to retain records related to their Navigator/CAC activities for a minimum of 5 years.
A consumer provides their Social Security Number during an enrollment session. How should a CAC handle this information after the session ends?
Answer: Ensure it is stored only in approved, secured systems and any physical notes are shredded
SSNs are highly sensitive PII and must be stored exclusively in approved secure systems; physical copies must be securely destroyed immediately after use.