Certified Information Privacy Professional Data Breach Notification Laws 2 — Questions and Answers
Question 1: Which type of data is most commonly excluded from triggering state breach notification requirements?
- Encrypted data where the key was not compromised (Correct answer)
- Social Security numbers
- Medical records
- Financial account numbers
Correct answer: Encrypted data where the key was not compromised
Most state breach notification laws include a safe harbor for encrypted data when the encryption key was not also compromised in the breach.
Question 2: What is the primary purpose of a 'risk of harm' threshold in breach notification laws?
- To require notification only when there is meaningful risk of harm to individuals (Correct answer)
- To eliminate all notification obligations for companies
- To allow unlimited time before notifying regulators
- To restrict notifications to government agencies only
Correct answer: To require notification only when there is meaningful risk of harm to individuals
Risk of harm thresholds help ensure notification obligations are triggered only when the breach poses meaningful risk to individuals, reducing unnecessary notifications.
Question 3: Under FTC authority, breach notification for certain health apps is governed by what rule?
- Health Breach Notification Rule (Correct answer)
- HIPAA Privacy Rule
- CCPA Regulations
- GLBA Safeguards Rule
Correct answer: Health Breach Notification Rule
The FTC's Health Breach Notification Rule covers vendors of personal health records and related entities not covered by HIPAA.
Question 4: Which notification recipient is often required when a breach affects 500 or more residents of a single state?
- Prominent media outlets in that state (Correct answer)
- The FBI
- The US Congress
- All US state attorneys general simultaneously
Correct answer: Prominent media outlets in that state
HIPAA requires notifying prominent media outlets serving a state or jurisdiction when a breach affects 500 or more residents of that state.
Question 5: What does the term 'personal information' most commonly refer to in US state breach notification laws?
- Name combined with SSN, financial account, or medical information (Correct answer)
- Any name or address alone
- Only biometric data
- Solely government-issued ID numbers
Correct answer: Name combined with SSN, financial account, or medical information
Most state laws define personal information as an individual's name combined with sensitive identifiers like SSN, financial account numbers, or medical data.
Question 6: Which best describes a 'substitute notice' under state breach notification laws?
- Notice via website posting and statewide media when direct contact is too costly (Correct answer)
- A notice sent to a substitute address when the primary address is unknown
- An internal memo circulated among employees
- A notice sent only to credit bureaus
Correct answer: Notice via website posting and statewide media when direct contact is too costly
Substitute notice is permitted when direct notification is too costly or contact information is insufficient, typically involving website posting and statewide media.
Which type of data is most commonly excluded from triggering state breach notification requirements?