CCM Documentation & Record Management 3 — Questions and Answers
Question 1: What is the PRIMARY purpose of a records retention schedule in a compliance program?
- To reduce the number of documents employees can create
- To systematically manage the lifecycle of records from creation to final disposition (Correct answer)
- To establish the hierarchy of document approvers
- To set maximum file size limits for digital records
Correct answer: To systematically manage the lifecycle of records from creation to final disposition
A records retention schedule governs the full lifecycle of records, specifying how long each record type must be kept and how it should be disposed of.
Question 2: Under HIPAA, covered entities must retain documentation of their privacy policies for how long after the policy is in effect?
- 3 years
- 6 years (Correct answer)
- 7 years
- 10 years
Correct answer: 6 years
HIPAA requires covered entities to retain written privacy policies and related documentation for 6 years from the date of creation or the date it was last in effect, whichever is later.
Question 3: A document is marked 'Draft - Do Not Distribute.' An employee emails it externally by mistake. From a compliance standpoint, what FIRST action should be taken?
- Delete the email from the sent folder
- Report the incident per the incident response procedure and attempt recall (Correct answer)
- Wait to see if the recipient responds
- Destroy the original draft document
Correct answer: Report the incident per the incident response procedure and attempt recall
A data or document incident must be reported and an attempt made to recall the document per the organization's incident response procedure to limit exposure.
Question 4: What distinguishes a 'vital record' from other organizational records?
- It is stored on paper rather than digitally
- It is essential to resume operations after a disaster or emergency (Correct answer)
- It contains personally identifiable information
- It requires executive signature to be valid
Correct answer: It is essential to resume operations after a disaster or emergency
Vital records are those indispensable to the organization's continued operation during or after a disaster, such as incorporation documents, contracts, and financial records.
Question 5: Which of the following is the BEST control to prevent unauthorized alteration of compliance records after they are finalized?
- Password-protecting Microsoft Word files
- Implementing write-once read-many (WORM) storage (Correct answer)
- Storing records in a shared network folder
- Using email to distribute finalized records
Correct answer: Implementing write-once read-many (WORM) storage
WORM storage prevents any modification or deletion of records after they are written, providing a tamper-evident audit trail essential for compliance.
Question 6: In records management, what does 'disposition' refer to?
- The classification of records by sensitivity level
- The final action taken on a record at the end of its retention period (Correct answer)
- The process of digitizing paper records
- Assigning access permissions to a record
Correct answer: The final action taken on a record at the end of its retention period
Disposition refers to the final action taken on a record at the end of its retention period, which may include destruction, transfer to archives, or permanent preservation.
Question 7: A financial institution must retain customer transaction records for regulatory purposes. Which regulation primarily governs this requirement in the US?
- GDPR
- Bank Secrecy Act (BSA) (Correct answer)
- Fair Credit Reporting Act (FCRA)
- Electronic Communications Privacy Act (ECPA)
Correct answer: Bank Secrecy Act (BSA)
The Bank Secrecy Act requires financial institutions to retain transaction records, including Currency Transaction Reports, for five years to support anti-money laundering efforts.
What is the PRIMARY purpose of a records retention schedule in a compliance program?