Certified Information Privacy Professional/United States (CIPP/US) — Questions and Answers
Question 1: What does a HIPAA Notice of Privacy Practices (NPP) require?
- A financial statement of PHI processing costs
- A complete list of every employee with PHI access
- Proof that all PHI is encrypted
- A description of how the covered entity uses and discloses PHI and patients' rights (Correct answer)
Correct answer: A description of how the covered entity uses and discloses PHI and patients' rights
The NPP must inform patients how their PHI may be used and disclosed, their privacy rights, and the covered entity's legal duties regarding PHI.
Question 2: The HIPAA minimum necessary standard requires covered entities to:
- Limit PHI access and disclosure to only what is needed for the intended purpose (Correct answer)
- Encrypt all PHI at all times
- Obtain written authorization for all PHI uses
- Delete PHI after 30 days if no longer needed
Correct answer: Limit PHI access and disclosure to only what is needed for the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum needed to accomplish the intended purpose.
Question 3: FACTA's truncation requirement mandates that electronically printed receipts:
- Include the full account number for consumer verification purposes
- Contain only the consumer's name and total transaction amount
- Display only the last 4 or 5 digits of the payment card number and omit the expiration date (Correct answer)
- Show only the expiration date but not the card number
Correct answer: Display only the last 4 or 5 digits of the payment card number and omit the expiration date
FACTA requires that electronically printed receipts show no more than the last 5 digits of the card number and must not display the expiration date to reduce risk of fraud.
Question 4: Which HIPAA provision addresses the rights of parents to access their minor child's PHI?
- Parents always have full access to minor children's PHI under HIPAA
- Access is determined solely by the child's treating physician
- The Privacy Rule defers to state law and professional standards on parental access to minor PHI (Correct answer)
- Minors always control access to their own PHI under HIPAA
Correct answer: The Privacy Rule defers to state law and professional standards on parental access to minor PHI
HIPAA defers to state law and professional standards to determine parental access to minor PHI, creating variability across jurisdictions.
Question 5: Under the California Consumer Privacy Act (CCPA), which threshold triggers a business's obligation to comply?
- Having any California customer regardless of revenue
- Annual gross revenues exceeding $10 million
- Annual gross revenues exceeding $25 million, buying/selling data of 100,000+ consumers, or deriving 50%+ revenue from selling data (Correct answer)
- Processing more than 500 records of California residents per year
Correct answer: Annual gross revenues exceeding $25 million, buying/selling data of 100,000+ consumers, or deriving 50%+ revenue from selling data
CCPA applies to for-profit businesses meeting at least one of three thresholds: $25M revenue, 100,000+ consumer records, or 50%+ revenue from selling personal information.
Question 6: Under FERPA, when may a school disclose a student's education records without consent?
- To parents automatically once the student turns 18
- To any government agency that requests them
- To school officials with a legitimate educational interest, and in health or safety emergencies (Correct answer)
- To employers conducting background checks without restriction
Correct answer: To school officials with a legitimate educational interest, and in health or safety emergencies
FERPA permits disclosures without consent to school officials with a legitimate educational interest, in emergencies affecting health or safety, and in other specified exceptions.
Question 7: The GLBA Safeguards Rule primarily requires financial institutions to:
- Report security incidents to the FTC within 72 hours
- Encrypt all data at rest using AES-256
- Develop, implement, and maintain a comprehensive information security program (Correct answer)
- Conduct annual penetration testing by certified third parties
Correct answer: Develop, implement, and maintain a comprehensive information security program
The Safeguards Rule mandates that financial institutions establish and maintain a written comprehensive information security program appropriate to the size and complexity of the institution.
Question 8: Which amendment to the U.S. Constitution has courts most frequently applied to establish a constitutional right to privacy?
- Fourteenth Amendment
- First Amendment
- Fourth Amendment (Correct answer)
- Fifth Amendment
Correct answer: Fourth Amendment
The Fourth Amendment's protection against unreasonable searches and seizures is most commonly cited in constitutional privacy analysis.
Question 9: Self-regulation principally entails a company's right to what, according to Section 5 of the FTC Act?
- Appeal decisions made against it
- Decide if any enforcement actions are justified
- Adhere to its industry’s code of conduct
- Determine which bodies will be involved in adjudication (Correct answer)
Correct answer: Determine which bodies will be involved in adjudication
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to determine which bodies will be involved in adjudication.
Question 10: A company suffers a data breach exposing Social Security numbers of 600 Vermont residents. Vermont's breach notification law requires notification within 45 days. Which law governs if the federal standard differs?
- Only the FTC must be notified at the federal level
- The stricter state law applies to residents of that state (Correct answer)
- Federal law always preempts state breach laws
- The company may choose whichever standard it prefers
Correct answer: The stricter state law applies to residents of that state
In the absence of a federal breach notification standard, the stricter state law applies to residents of that state.
Question 11: Which of the following is NOT a permissible purpose for obtaining a consumer report under FCRA?
- Pre-employment background screening
- Satisfying personal curiosity about a neighbor (Correct answer)
- Insurance underwriting for a new policy
- Reviewing an existing account relationship
Correct answer: Satisfying personal curiosity about a neighbor
Personal curiosity is never a permissible purpose under FCRA; access must be tied to a legitimate business reason expressly listed in the statute.
Question 12: Which of the following is excluded from the definition of 'nonpublic personal information' (NPI) under GLBA?
- Account balances
- Transaction histories
- Social Security numbers
- Publicly available information from government records (Correct answer)
Correct answer: Publicly available information from government records
GLBA explicitly excludes publicly available information from government records from the definition of NPI, since it is already accessible to the general public.
Question 13: Under ECPA (Electronic Communications Privacy Act), employer monitoring of employee email on company systems is generally:
- Only allowed with written employee consent
- Prohibited for emails sent to personal accounts
- Permissible under the business extension exception when done in the ordinary course of business (Correct answer)
- Strictly prohibited without a court order
Correct answer: Permissible under the business extension exception when done in the ordinary course of business
ECPA's business extension exception allows employers to monitor electronic communications on company systems in the ordinary course of business without employee consent.
Question 14: Under the HIPAA Privacy Rule, which government entity receives patient complaints about HIPAA violations?
- HHS Office for Civil Rights (OCR) (Correct answer)
- Centers for Medicare & Medicaid Services
- State Attorney General offices
- FTC Bureau of Consumer Protection
Correct answer: HHS Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is the primary enforcement agency for HIPAA Privacy and Security Rule complaints and violations.
Question 15: Under HIPAA, a covered entity must provide an individual an accounting of disclosures of their PHI for a period of up to how many years?
- 6 years prior to the date of the request (Correct answer)
- 10 years prior to the date of the request
- 1 year prior to the date of the request
- 3 years prior to the date of the request
Correct answer: 6 years prior to the date of the request
Individuals have the right to an accounting of PHI disclosures made in the 6 years prior to the request, excluding disclosures for TPO.
Question 16: Which principle from the Fair Information Practice Principles (FIPPs) requires that personal data be collected only for specified purposes and not used in ways incompatible with those purposes?
- Purpose limitation (Correct answer)
- Data minimization
- Individual participation
- Accuracy
Correct answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific purposes disclosed at the time of collection.
Question 17: Under COPPA, what are the notice requirements for operators of child-directed websites?
- Post a clear privacy policy and provide direct notice to parents before collecting data (Correct answer)
- Obtain FTC approval for all data collection practices
- Display a COPPA seal of approval on the homepage
- Send annual mailings to all parents of users
Correct answer: Post a clear privacy policy and provide direct notice to parents before collecting data
COPPA requires operators to post a comprehensive privacy policy on their site and provide direct notice to parents, describing data practices, before collecting children's information.
Question 18: What federal law generally applies to privacy of employee medical information obtained through employer wellness programs?
- ADA and GINA apply; HIPAA applies only if the plan is a group health plan (Correct answer)
- HIPAA alone governs all wellness program health data
- FCRA governs all wellness program information
- No federal law protects wellness program health data
Correct answer: ADA and GINA apply; HIPAA applies only if the plan is a group health plan
ADA limits employer use of medical information from wellness programs; GINA restricts genetic information; HIPAA applies if the employer's group health plan is involved.
Question 19: Which jurisdiction must be present for a court to hear a certain case?
- Subject matter jurisdiction and regulatory jurisdiction
- Personal jurisdiction and professional jurisdiction
- Subject matter jurisdiction and professional jurisdiction
- Personal jurisdiction and subject matter jurisdiction (Correct answer)
Correct answer: Personal jurisdiction and subject matter jurisdiction
A court must have both personal jurisdiction (authority over the parties) and subject matter jurisdiction (authority over the type of dispute) to hear a case. "Professional" and "regulatory" jurisdiction are not recognized requirements for a court to exercise authority.
Question 20: Which principle from the Fair Information Practice Principles (FIPPs) states that individuals should have a right to access and correct data about themselves?
- Accountability
- Use Limitation
- Collection Limitation
- Individual Participation (Correct answer)
Correct answer: Individual Participation
The Individual Participation principle holds that individuals should have the right to know what data is held about them and to correct or challenge inaccurate records.
Question 21: Which sector-specific federal law requires telecommunications carriers to protect Customer Proprietary Network Information (CPNI)?
- Cable Communications Policy Act
- Communications Act / FCC rules (Correct answer)
- Telephone Consumer Protection Act
- CAN-SPAM Act
Correct answer: Communications Act / FCC rules
The Communications Act, enforced by the FCC, requires telecommunications carriers to protect CPNI and limits its use and disclosure.
Question 22: In its 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers," the Federal Trade Commission named five key areas. Which of those five categories was NOT one of those areas?
- Promoting enforceable self-regulatory codes
- Do Not Track
- Large platform providers
- International data transfers (Correct answer)
Correct answer: International data transfers
International data transfers" was not one of the five priority areas listed in the Federal Trade Commission's 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers.
Question 23: Under HIPAA, what is required when a covered entity engages a business associate to perform functions involving PHI?
- A Business Associate Agreement (BAA) must be in place (Correct answer)
- A federal license for the business associate
- HHS approval of the business associate
- A patient consent form for each engagement
Correct answer: A Business Associate Agreement (BAA) must be in place
Covered entities must have a Business Associate Agreement with each business associate, establishing PHI use and protection obligations.
Question 24: Under the USA PATRIOT Act, how did NSLs (National Security Letters) change government surveillance capabilities?
- Required court orders for all government data requests from businesses
- Created a new court system for reviewing all surveillance requests
- Expanded FBI authority to demand communications records from third parties without judicial approval (Correct answer)
- Limited government surveillance to terrorism investigations only with judicial oversight
Correct answer: Expanded FBI authority to demand communications records from third parties without judicial approval
The PATRIOT Act expanded NSL authority, allowing the FBI to compel businesses to provide communications records for national security investigations without prior court approval.
Question 25: Which type of entity is directly covered by HIPAA's Privacy Rule?
- Any company that collects health data
- Covered entities (health plans, providers, clearinghouses) (Correct answer)
- All employers who maintain employee health records
- All software companies handling health data
Correct answer: Covered entities (health plans, providers, clearinghouses)
HIPAA directly covers 'covered entities': health plans, healthcare providers that transmit PHI electronically, and healthcare clearinghouses.
Question 26: A hospital shares patient data with a business associate for billing purposes. Under HIPAA, what document must govern this relationship?
- Business associate agreement (Correct answer)
- Privacy notice
- Data processing addendum
- Memorandum of understanding
Correct answer: Business associate agreement
HIPAA requires a Business Associate Agreement (BAA) between a covered entity and any business associate that handles PHI.
Question 27: What is the name of the legal document that formalizes an agreement between a government agency and an opposing party and is approved by a judge?
- Common law judgment
- A consent decree (Correct answer)
- Stare decisis decree
- A judgment rider
Correct answer: A consent decree
A legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party is called a "consent decree."
Question 28: The Video Privacy Protection Act (VPPA) was enacted primarily in response to what event?
- The Sony Pictures data breach
- Congress viewing a senator's streaming history
- A cable company selling viewing data to advertisers
- Disclosure of Supreme Court nominee Robert Bork's video rental records (Correct answer)
Correct answer: Disclosure of Supreme Court nominee Robert Bork's video rental records
VPPA was passed after a newspaper published Supreme Court nominee Robert Bork's video rental records, revealing the sensitivity of such data.
Question 29: Which GLBA exception permits financial institutions to share NPI with unaffiliated third parties without offering consumers an opt-out right?
- Promotional partners exception
- Customer analytics exception
- General marketing exception
- Joint marketing agreement exception (Correct answer)
Correct answer: Joint marketing agreement exception
The joint marketing agreement exception allows sharing NPI with unaffiliated companies for joint product or service marketing purposes without triggering the opt-out requirement.
Question 30: Under the CAN-SPAM Act, commercial email senders must:
- Honor opt-out requests within 10 business days and include a physical postal address (Correct answer)
- Limit commercial emails to existing customers only
- Obtain affirmative opt-in consent before sending any commercial email
- Register with the FTC before conducting email marketing campaigns
Correct answer: Honor opt-out requests within 10 business days and include a physical postal address
CAN-SPAM requires commercial email senders to honor unsubscribe requests within 10 business days and include a valid physical postal address in every message.
Certified Information Privacy Professional/United States (CIPP/US)
The CIPP/US certifies knowledge of U.S. privacy laws and regulations, covering federal and state privacy frameworks, private-sector data collection limits, government access to information, workplace privacy, and state-level privacy laws including CCPA/CPRA.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds