CEC Privacy and Security Standards 5 — Questions and Answers
Question 1: Which of the following is an example of a 'social engineering' attack that enrollment counselors should be trained to recognize?
- A software update notification from IT
- A caller claiming to be a government official and requesting an applicant's SSN (Correct answer)
- An automated password reset email from the enrollment platform
- A routine reminder to complete annual compliance training
Correct answer: A caller claiming to be a government official and requesting an applicant's SSN
Social engineering involves manipulating individuals into divulging confidential information by impersonating trusted authorities.
Question 2: When disposing of paper records containing applicant PII, enrollment counselors must:
- Place them in the recycling bin to be environmentally responsible
- Shred or otherwise render the documents unreadable before disposal (Correct answer)
- Return them to the applicant by mail
- Archive them indefinitely in a storage unit
Correct answer: Shred or otherwise render the documents unreadable before disposal
Documents containing PII must be destroyed in a manner that makes the information unreadable, such as cross-cut shredding, to prevent unauthorized access.
Question 3: The HITECH Act strengthened HIPAA by:
- Eliminating the requirement for Business Associate Agreements
- Extending HIPAA privacy and security obligations to business associates and increasing breach penalties (Correct answer)
- Replacing HIPAA with a new federal privacy framework
- Reducing the timeframe for breach notification to 10 days
Correct answer: Extending HIPAA privacy and security obligations to business associates and increasing breach penalties
HITECH directly subjected business associates to HIPAA requirements and significantly increased civil and criminal penalties for violations.
Question 4: A phishing email sent to an enrollment counselor's work account asks them to click a link and log in to 'verify their credentials.' The counselor should:
- Click the link to verify it is legitimate before deciding
- Delete the email and report it to the IT security team (Correct answer)
- Forward it to all colleagues as a warning
- Reply to the sender requesting more information
Correct answer: Delete the email and report it to the IT security team
Phishing emails should never be clicked on; they should be deleted and reported so the IT team can investigate and protect other users.
Question 5: Which of the following scenarios represents an appropriate use of an applicant's email address collected during enrollment?
- Sending promotional offers from partnered insurance products
- Sending enrollment confirmation and plan-related notifications (Correct answer)
- Sharing it with employers to verify the applicant's insurance status
- Adding it to a mailing list for a community newsletter
Correct answer: Sending enrollment confirmation and plan-related notifications
Email addresses collected during enrollment may only be used for purposes directly related to the enrollment process, such as sending confirmations.
Question 6: What is the significance of the 'right to amend' under HIPAA for enrollment applicants?
- Applicants can change their plan selection at any time without a qualifying event
- Applicants may request corrections to inaccurate PHI in their records (Correct answer)
- Applicants can amend their subsidy amount after enrollment closes
- Applicants have the right to delete all records after coverage ends
Correct answer: Applicants may request corrections to inaccurate PHI in their records
The right to amend allows individuals to request corrections to inaccurate or incomplete PHI held by a covered entity.
Question 7: An enrollment counselor finishes assisting an applicant at a shared workstation. What should the counselor do before leaving?
- Minimize all open windows to keep the data accessible for the next session
- Log out of all systems and clear any cached applicant data (Correct answer)
- Leave the session open so the applicant can review their information later
- Transfer the session to a supervisor's account for safekeeping
Correct answer: Log out of all systems and clear any cached applicant data
Logging out and clearing session data on shared workstations prevents unauthorized access to applicant information by subsequent users.
Which of the following is an example of a 'social engineering' attack that enrollment counselors should be trained to recognize?