Certified Information Privacy Professional Data Breach Notification Laws 1 — Questions and Answers
Question 1: Which US federal law requires covered entities to notify individuals of breaches involving unsecured protected health information?
- HITECH Act (Correct answer)
- COPPA
- GLBA
- FERPA
Correct answer: HITECH Act
The HITECH Act established the HIPAA Breach Notification Rule requiring covered entities to notify affected individuals, HHS, and sometimes the media of PHI breaches.
Question 2: Under most US state breach notification laws, what triggers the notification obligation?
- Unauthorized acquisition of personal information (Correct answer)
- Any access to a database
- Loss of encrypted data
- Internal employee data sharing
Correct answer: Unauthorized acquisition of personal information
Notification is typically triggered when personal information is acquired by an unauthorized person, not merely accessed or viewed.
Question 3: Which state enacted the first US data breach notification law in 2003?
- California (Correct answer)
- New York
- Texas
- Florida
Correct answer: California
California's SB 1386, effective in 2003, was the first state data breach notification law and served as a model for other states.
Question 4: The SEC requires publicly traded companies to disclose material cybersecurity incidents within how many business days?
- 4 business days (Correct answer)
- 10 business days
- 30 calendar days
- 72 hours
Correct answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to file Form 8-K disclosing material incidents within four business days of determining materiality.
Question 5: Which element is commonly required in a breach notification letter to consumers?
- Description of the type of information involved (Correct answer)
- The company's annual revenue
- Names of all employees who had access
- The attacker's identity
Correct answer: Description of the type of information involved
State breach notification laws typically require the letter to describe the type of personal information that was involved in the breach.
Question 6: Under the HIPAA Breach Notification Rule, large breaches affecting 500 or more individuals must be reported to HHS within what timeframe?
- 60 days of discovery (Correct answer)
- 30 days of discovery
- 72 hours of discovery
- 1 year of discovery
Correct answer: 60 days of discovery
Covered entities must notify HHS of breaches affecting 500 or more residents of a state or jurisdiction within 60 days of discovery.
Which US federal law requires covered entities to notify individuals of breaches involving unsecured protected health information?