CIPT Privacy Incident Response and Breach Management 2 — Questions and Answers
Question 1: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals within how many days of discovering a breach?
- 30 calendar days
- 45 calendar days
- 90 calendar days
- 60 calendar days (Correct answer)
Correct answer: 60 calendar days
The HIPAA Breach Notification Rule requires notification to affected individuals without unreasonable delay and no later than 60 calendar days of breach discovery.
Question 2: Which US federal rule requires financial institutions to notify the FTC and customers following certain data breaches affecting 500 or more customers?
- COPPA Safe Harbor Rule
- CAN-SPAM Enforcement Rule
- GLBA Safeguards Rule (Correct answer)
- FERPA Disclosure Rule
Correct answer: GLBA Safeguards Rule
The FTC's updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to report qualifying breaches affecting 500+ customers to the FTC.
Question 3: What is the 'risk of harm' standard primarily used for in breach notification decisions?
- Determining the financial penalties owed to regulators after a breach
- Calculating compensation amounts owed to individual data subjects
- Setting the regulatory reporting timeline after a breach is discovered
- Establishing whether the severity of potential harm to individuals triggers mandatory notification (Correct answer)
Correct answer: Establishing whether the severity of potential harm to individuals triggers mandatory notification
The risk of harm standard acts as a threshold test—notification is required only when a breach creates a sufficient risk of real harm to affected individuals.
Question 4: Which element is generally NOT required in a breach notification sent directly to affected individuals?
- Description of the types of personal information involved in the breach
- Steps individuals can take to protect themselves from potential harm
- A list of all employees who handled the breached data internally (Correct answer)
- Contact information for the notifying organization
Correct answer: A list of all employees who handled the breached data internally
Breach notifications must help individuals protect themselves but do not require disclosing internal personnel details, which would not aid the affected person.
Question 5: When reporting a data breach to a supervisory authority under GDPR Article 33, what information must be included?
- The full names of all data subjects whose data was affected
- A complete audit trail of all prior data processing activities
- The nature of the breach, categories of data affected, likely consequences, and measures taken (Correct answer)
- Proof of active cyber insurance coverage at the time of the breach
Correct answer: The nature of the breach, categories of data affected, likely consequences, and measures taken
GDPR Article 33(3) specifies the notification must describe the breach nature, data categories, approximate number affected, likely consequences, and remediation measures.
Question 6: The FTC's Health Breach Notification Rule applies primarily to which type of entity?
- HIPAA-covered entities such as hospitals and health insurers
- Vendors of personal health records and related apps not subject to HIPAA (Correct answer)
- All businesses that collect or process any health-related data
- State health departments and public health agencies
Correct answer: Vendors of personal health records and related apps not subject to HIPAA
The FTC's Health Breach Notification Rule fills the gap left by HIPAA, applying to vendors of personal health records and PHR-related entities that HIPAA does not cover.
Question 7: What is 'substitute notice' in the context of breach notification laws?
- Using a third-party vendor to send breach notifications on behalf of the organization
- Notifying regulators in lieu of notifying affected individuals
- Sending a condensed summary notice rather than a full breach disclosure document
- Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive (Correct answer)
Correct answer: Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive
Substitute notice allows organizations to satisfy notification obligations via media notices or website postings when direct individual notification is infeasible due to cost or missing contact information.
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals within how many days of discovering a breach?