CGRC CGRC Privacy and Data Protection 2 — Questions and Answers
Question 1: Which federal law requires healthcare organizations to protect the privacy of patients' health information and is frequently referenced in CGRC study materials?
- FISMA
- HIPAA (Correct answer)
- SOX
- FERPA
Correct answer: HIPAA
HIPAA's Privacy Rule and Security Rule establish national standards for protecting individually identifiable health information held by covered entities.
Question 2: What is a Privacy Continuous Monitoring (PCM) program designed to do?
- Conduct annual penetration tests on systems storing PII
- Provide ongoing awareness of privacy risks and control effectiveness across the system lifecycle (Correct answer)
- Assign privacy officers to each federal department
- Replace the need for privacy impact assessments
Correct answer: Provide ongoing awareness of privacy risks and control effectiveness across the system lifecycle
Privacy Continuous Monitoring provides real-time or near-real-time visibility into privacy controls, enabling organizations to detect and respond to privacy risks as they evolve.
Question 3: Which role is responsible for ensuring that privacy requirements are integrated into the organization's programs and that privacy risks are managed?
- System Owner
- Chief Privacy Officer (CPO) / Senior Agency Official for Privacy (SAOP) (Correct answer)
- Information System Security Officer (ISSO)
- Authorizing Official (AO)
Correct answer: Chief Privacy Officer (CPO) / Senior Agency Official for Privacy (SAOP)
The Senior Agency Official for Privacy (SAOP) is responsible for agency-wide privacy policy, compliance, and risk management under the Privacy Act and E-Government Act.
Question 4: Under NIST SP 800-122, what is the recommended approach for assessing privacy risk associated with PII?
- Calculate risk solely based on the number of PII records stored
- Evaluate the likelihood of a PII breach and the impact on affected individuals (Correct answer)
- Classify all PII as High impact by default
- Delegate all PII risk decisions to legal counsel
Correct answer: Evaluate the likelihood of a PII breach and the impact on affected individuals
NIST SP 800-122 recommends assessing PII confidentiality risk by evaluating both the likelihood of a breach and the potential harm to affected individuals.
Question 5: What is the purpose of a data retention schedule in a privacy program?
- To specify how long PII and other records must be kept before secure disposal (Correct answer)
- To prioritize which systems receive security patches first
- To schedule employee privacy training intervals
- To define backup frequency for databases
Correct answer: To specify how long PII and other records must be kept before secure disposal
A data retention schedule establishes how long each type of record, including PII, must be retained to meet legal requirements and when it must be securely destroyed.
Question 6: Which technique renders PII useless to unauthorized parties if a breach occurs while still allowing data to be used for its intended purpose?
- Data masking / de-identification (Correct answer)
- Data archiving
- Data normalization
- Data replication
Correct answer: Data masking / de-identification
De-identification and masking techniques remove or obscure direct and indirect identifiers so that data cannot reasonably be linked back to a specific individual.
Which federal law requires healthcare organizations to protect the privacy of patients' health information and is frequently referenced in CGRC study materials?