CCB CCB Data Privacy & Information Security Compliance 2 — Questions and Answers
Question 1: Under HIPAA's Security Rule, which type of safeguard includes workforce training and security policies?
- Physical safeguards
- Technical safeguards
- Administrative safeguards (Correct answer)
- Environmental safeguards
Correct answer: Administrative safeguards
HIPAA's Administrative Safeguards include policies, procedures, workforce training, and security management processes designed to protect electronic protected health information (ePHI).
Question 2: What is the primary purpose of a Privacy Impact Assessment (PIA) in a compliance program?
- To calculate the financial cost of a data breach
- To evaluate privacy risks of a new project or system before implementation (Correct answer)
- To audit employees' personal device usage
- To certify compliance with PCI DSS
Correct answer: To evaluate privacy risks of a new project or system before implementation
A Privacy Impact Assessment (PIA) systematically identifies and evaluates privacy risks associated with a new project, system, or process before it is deployed.
Question 3: Which term refers to the contractual obligation requiring a vendor who processes personal data on behalf of a company to follow the company's privacy requirements?
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Business Associate Agreement (BAA)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) legally binds a third-party vendor (data processor) to handle personal data in accordance with the data controller's privacy obligations and applicable law.
Question 4: What is 'pseudonymization' as used in data privacy compliance?
- Permanently deleting personal data
- Replacing identifying fields with artificial identifiers so data cannot be attributed to an individual without additional information (Correct answer)
- Encrypting data with a public key
- Publishing anonymized data publicly
Correct answer: Replacing identifying fields with artificial identifiers so data cannot be attributed to an individual without additional information
Pseudonymization replaces direct identifiers with artificial codes, reducing privacy risk while still allowing data to be re-linked if needed with separately held key information.
Question 5: A company experiences a ransomware attack that encrypts customer data. Under the FTC's data security expectations, which response is most appropriate first?
- Pay the ransom immediately
- Activate the incident response plan and contain the breach (Correct answer)
- Delete all affected systems
- Notify the press before regulators
Correct answer: Activate the incident response plan and contain the breach
Best practice and regulatory expectation require activating the incident response plan to contain the breach, assess the impact, and follow proper notification protocols before other actions.
Question 6: Which principle requires organizations to implement data protection measures from the outset of designing a product or service?
- Privacy by Accident
- Privacy by Default
- Privacy by Design (Correct answer)
- Security by Obscurity
Correct answer: Privacy by Design
Privacy by Design mandates that data protection and privacy are built into systems and processes from the earliest design stage, rather than added as an afterthought.
Under HIPAA's Security Rule, which type of safeguard includes workforce training and security policies?