CACs Confidentiality & Privacy Standards 2 — Questions and Answers
Question 1: Under the ACA's privacy rules, which federal law primarily governs the protection of personally identifiable information (PII) collected during the Health Insurance Marketplace enrollment process?
- HIPAA
- The Privacy Act of 1974
- The ACA itself and its implementing regulations (Correct answer)
- FERPA
Correct answer: The ACA itself and its implementing regulations
The ACA and its implementing regulations, including 45 CFR Part 155, govern privacy protections for PII collected during Marketplace enrollment.
Question 2: A consumer asks a CAC to send their completed application to a family member's email address for convenience. What should the CAC do?
- Send it since the consumer requested it
- Refuse because email is never a permitted communication channel
- Confirm the consumer understands the privacy risk and document their informed consent before proceeding (Correct answer)
- Contact the Marketplace to request a secure transfer on the consumer's behalf
Correct answer: Confirm the consumer understands the privacy risk and document their informed consent before proceeding
CACs must ensure consumers understand risks of unencrypted transmission and obtain informed consent before sharing application information via email.
Question 3: Which of the following is NOT considered personally identifiable information (PII) in the context of Marketplace enrollment?
- Social Security Number
- Date of birth
- The name of the insurance carrier a consumer enrolled in
- The county in which the Marketplace operates (Correct answer)
Correct answer: The county in which the Marketplace operates
A county name alone is publicly available geographic data and does not identify any individual consumer.
Question 4: A CAC's computer containing consumer enrollment files is stolen. What is the FIRST required action?
- Notify all affected consumers immediately by phone
- Report the breach to the appropriate authorities and their Navigator/CAC organization per breach response protocols (Correct answer)
- Wipe all other devices to prevent further exposure
- Post a public notice on the organization's website
Correct answer: Report the breach to the appropriate authorities and their Navigator/CAC organization per breach response protocols
The first step is to report the breach internally and to relevant authorities per the organization's breach response plan before individual consumer notification.
Question 5: When a CAC assists a consumer whose application also affects household members, whose consent is needed to share household members' information with a third party?
- Only the primary applicant's consent is required
- Each adult household member whose information would be shared must provide consent (Correct answer)
- The Marketplace grants blanket consent for all household members
- Only the head of household must consent
Correct answer: Each adult household member whose information would be shared must provide consent
Each adult household member has independent privacy rights and must separately authorize disclosure of their own information.
Question 6: A CAC is approached by a researcher who wants anonymized enrollment data to study coverage gaps. How should the CAC respond?
- Provide the data since it is anonymized
- Decline, as CACs may not share any consumer data even in anonymized form without proper authorization (Correct answer)
- Share only aggregate totals verbally
- Refer the researcher to the state Medicaid agency
Correct answer: Decline, as CACs may not share any consumer data even in anonymized form without proper authorization
CACs are not authorized to share consumer data in any form — anonymized or otherwise — without explicit authorization from the Marketplace or oversight entity.
Question 7: How long are CACs generally required to retain consumer records and application documentation?
- 6 months after the plan year ends
- At least 3 years, or as specified by their certifying entity or state law (Correct answer)
- Until the consumer's coverage terminates
- 10 years, in line with federal tax record rules
Correct answer: At least 3 years, or as specified by their certifying entity or state law
HHS and most certifying entities require CACs to retain consumer records for a minimum of 3 years, though state laws or organizational policies may require longer retention.
Under the ACA's privacy rules, which federal law primarily governs the protection of personally identifiable information (PII) collected during the Health Insurance Marketplace enrollment process?