CEC Privacy and Security Standards 3 — Questions and Answers
Question 1: A Certified Enrollment Counselor discovers a colleague is accessing applicant files out of curiosity, not for work purposes. The counselor should:
- Ignore it as it is an internal matter
- Report it to a supervisor or compliance officer (Correct answer)
- Confront the colleague directly and then drop the matter
- Share the concern only with coworkers
Correct answer: Report it to a supervisor or compliance officer
Unauthorized access to applicant records is a privacy violation that must be reported through proper compliance channels.
Question 2: Which of the following best describes a 'Business Associate Agreement' (BAA) under HIPAA?
- A contract between an insurer and a policyholder
- A written agreement ensuring vendors protect PHI appropriately (Correct answer)
- An enrollment agreement signed by the applicant
- A federal registration form for healthcare navigators
Correct answer: A written agreement ensuring vendors protect PHI appropriately
A BAA is a contract requiring business associates who handle PHI to safeguard it in compliance with HIPAA rules.
Question 3: Which type of security safeguard involves using physical measures such as locks, badge readers, and security cameras to protect data?
- Technical safeguards
- Administrative safeguards
- Physical safeguards (Correct answer)
- Operational safeguards
Correct answer: Physical safeguards
Physical safeguards under HIPAA include physical measures, policies, and procedures to protect electronic information systems and related buildings from unauthorized access.
Question 4: An enrollment counselor is helping an applicant over the phone. Before discussing account details, the counselor should:
- Ask for the applicant's plan preference first
- Verify the applicant's identity using security questions or a PIN (Correct answer)
- Request the applicant's SSN immediately
- Proceed without verification to avoid delays
Correct answer: Verify the applicant's identity using security questions or a PIN
Identity verification before disclosing account information prevents unauthorized disclosure to impostors.
Question 5: Under the ACA Marketplace rules, which of the following is a permitted use of applicant data collected during enrollment?
- Selling the data to insurance brokers for marketing
- Using it to determine eligibility for coverage and financial assistance (Correct answer)
- Sharing it with employers to verify employment status without consent
- Providing it to political campaigns for outreach
Correct answer: Using it to determine eligibility for coverage and financial assistance
Applicant data collected through Marketplace enrollment may only be used for purposes directly related to determining eligibility and enrollment.
Question 6: Which encryption standard is commonly recommended for protecting data transmitted over the internet in healthcare enrollment systems?
- FTP (File Transfer Protocol)
- TLS (Transport Layer Security) (Correct answer)
- HTTP (Hypertext Transfer Protocol)
- Telnet
Correct answer: TLS (Transport Layer Security)
TLS encrypts data in transit and is the standard protocol for securing sensitive information transmitted over the internet.
Question 7: If an applicant withdraws their consent to share data with a third-party assister, the enrollment counselor must:
- Continue using the data since consent was originally given
- Stop sharing the applicant's data with that third party immediately (Correct answer)
- Require the applicant to submit a written request before acting
- Notify the third party to continue for 30 more days
Correct answer: Stop sharing the applicant's data with that third party immediately
Consent can be revoked at any time, and data sharing must cease promptly upon withdrawal of consent.
A Certified Enrollment Counselor discovers a colleague is accessing applicant files out of curiosity, not for work purposes.
The counselor should: