Privacy and Security Standards Flashcards
7 cards from real CACS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privacy and Security Standards flashcards as text
A CAC's laptop containing unencrypted consumer data is stolen. Under federal guidelines, this incident is classified as:
Answer: A potential data breach requiring immediate notification to the organization's privacy officer and potentially to CMS
Theft of a device with unencrypted consumer PII is a reportable security incident that triggers breach notification protocols under CMS and HIPAA requirements.
Which of the following is a permitted use of consumer information collected by a CAC?
Answer: Using consumer data to conduct follow-up outreach regarding their enrollment status
CACs may use consumer contact information to conduct follow-up related to the enrollment assistance they provided, as this is within the scope of the original purpose.
What does 'role-based access control' mean in the context of a CAC organization's data security practices?
Answer: Access to consumer data is limited based on each staff member's specific job responsibilities
Role-based access control ensures that staff can only access consumer data that is necessary for their specific job function, limiting unnecessary exposure of PII.
A consumer who enrolled with CAC assistance later files a complaint alleging their privacy was violated. Who investigates complaints related to health information privacy violations?
Answer: The HHS Office for Civil Rights (OCR)
HHS Office for Civil Rights (OCR) is the federal agency responsible for investigating complaints and enforcing HIPAA privacy and security rules.
A CAC is conducting a home visit to assist an elderly consumer. The consumer's adult child is present and begins answering questions on behalf of the consumer. What should the CAC do?
Answer: Confirm with the consumer directly whether they want the adult child to participate, and verify if they are an authorized representative
CACs must ensure the consumer's consent and autonomy; the CAC should confirm directly with the consumer whether the third party is welcome and whether they hold authorized representative status.
Which of the following security practices is required when a CAC uses email to communicate with consumers about their applications?
Answer: Sensitive PII should be sent only through encrypted or secure messaging systems, never plain email
Standard email is not secure enough for transmitting PII; CACs must use encrypted or otherwise secured communication channels for any sensitive consumer information.
A CAC organization wants to use consumer testimonials in their marketing materials. What must they obtain first?
Answer: Written consent from each consumer whose information or story will be used
Using consumer stories or identifying information for marketing requires explicit written consent from each consumer, as this is a new use beyond the original enrollment assistance purpose.