โ† All CEC Flashcard Decks

Privacy and Security Standards Flashcards

7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privacy and Security Standards flashcards as text
  1. What is the primary purpose of a Notice of Privacy Practices (NPP) in healthcare enrollment?

    Answer: To inform individuals how their health information may be used and disclosed

    An NPP informs individuals of their privacy rights and how covered entities may use or disclose their protected health information.

  2. Multi-factor authentication (MFA) in enrollment systems provides security by:

    Answer: Verifying identity using two or more independent credentials

    MFA requires users to provide two or more verification factors, significantly reducing the risk of unauthorized account access.

  3. An applicant's income information collected for APTC eligibility may NOT be shared with:

    Answer: A commercial lender without the applicant's consent

    Income data collected for Marketplace eligibility determinations cannot be shared with commercial lenders, as that falls outside the permitted uses of enrollment data.

  4. Which of the following actions violates the principle of 'data minimization' during enrollment?

    Answer: Recording an applicant's favorite hobbies for a future marketing campaign

    Data minimization requires collecting only what is necessary for the specific purpose; collecting personal data for marketing violates this principle.

  5. A counselor's work laptop is stolen. What is the FIRST step the counselor should take?

    Answer: Report the theft to their supervisor and IT/security team promptly

    Immediately reporting device theft allows the security team to remotely wipe the device and begin breach assessment procedures.

  6. Under HIPAA Security Rule, which of the following is an example of a technical safeguard?

    Answer: Installing automatic logoff on workstations after inactivity

    Automatic logoff is a technical safeguard that prevents unauthorized access to systems left unattended.

  7. An individual asks to inspect their enrollment records. Under applicable privacy rules, the covered entity must respond:

    Answer: Within 30 days, with a possible 30-day extension

    HIPAA requires covered entities to provide access to records within 30 days, with one 30-day extension allowed if needed.