CIPT Privacy Program Implementation and Operations 2 — Questions and Answers
Question 1: Under the US HIPAA Breach Notification Rule, how quickly must covered entities notify affected individuals of an unsecured PHI breach?
- Without unreasonable delay and no later than 60 days after discovery (Correct answer)
- Within 24 hours of discovery
- Within 14 days of discovery
- Only after completing a full forensic investigation, with no time limit
Correct answer: Without unreasonable delay and no later than 60 days after discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 days of discovering a breach of unsecured PHI.
Question 2: Which US state law, effective January 2020, grants California consumers the right to know what personal information is collected about them and to request its deletion?
- California Consumer Privacy Act (CCPA) (Correct answer)
- California Online Privacy Protection Act (CalOPPA)
- California Privacy Rights Act (CPRA)
- California Data Breach Notification Law (SB-1386)
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA, effective January 1, 2020, established rights for California consumers including access, deletion, and opt-out of sale of personal information.
Question 3: What does a 'privacy program gap analysis' involve?
- Comparing the current state of privacy practices against a target framework to identify deficiencies (Correct answer)
- Analyzing gaps in network firewall rules
- Measuring the difference between budgeted and actual privacy costs
- Reviewing employee performance reviews for privacy policy violations
Correct answer: Comparing the current state of privacy practices against a target framework to identify deficiencies
A gap analysis maps existing privacy controls against a regulatory framework or best-practice standard to identify where the program falls short and prioritize remediation.
Question 4: Which operational practice ensures that privacy controls remain effective as systems, regulations, and threats evolve over time?
- Continuous monitoring and periodic privacy program reviews (Correct answer)
- A one-time compliance audit at program launch
- Annual policy republication without control testing
- Delegating all privacy decisions to legal counsel
Correct answer: Continuous monitoring and periodic privacy program reviews
Continuous monitoring detects control failures and changing risk conditions, while periodic reviews reassess whether the program still meets current regulatory and business requirements.
Question 5: A privacy team implements a process to handle user requests to access, correct, or delete their personal data. What is this process called?
- Data Subject Rights (DSR) or Data Subject Access Request (DSAR) fulfillment process (Correct answer)
- Privacy impact assessment workflow
- Breach notification procedure
- Vendor onboarding checklist
Correct answer: Data Subject Rights (DSR) or Data Subject Access Request (DSAR) fulfillment process
A DSAR fulfillment process includes identity verification, data location, compilation, review, and timely response to requests from data subjects exercising their legal rights.
Question 6: Which element of a privacy program ensures employees know how to recognize and escalate a potential personal data breach?
- Privacy incident reporting channel and training on what constitutes a reportable event (Correct answer)
- Automated data loss prevention (DLP) only
- Annual password rotation policy
- Network segmentation controls
Correct answer: Privacy incident reporting channel and training on what constitutes a reportable event
Effective breach response depends on employees recognizing privacy incidents and knowing how to report them promptly through a clear escalation path.
Under the US HIPAA Breach Notification Rule, how quickly must covered entities notify affected individuals of an unsecured PHI breach?