CRM Regulatory Compliance 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), how long must public companies retain audit workpapers?
- 3 years
- 5 years
- 7 years (Correct answer)
- 10 years
Correct answer: 7 years
SOX Section 802 requires audit workpapers to be retained for 7 years after the audit or review concludes.
Question 2: Which HIPAA rule specifically governs the safeguarding of electronic protected health information (ePHI)?
- Privacy Rule
- Security Rule (Correct answer)
- Breach Notification Rule
- Enforcement Rule
Correct answer: Security Rule
The HIPAA Security Rule establishes national standards to protect ePHI created, received, used, or maintained by covered entities.
Question 3: The Freedom of Information Act (FOIA) applies to records held by which type of entity?
- Private corporations
- Nonprofit organizations
- Federal executive branch agencies (Correct answer)
- State government offices only
Correct answer: Federal executive branch agencies
FOIA (5 U.S.C. § 552) grants the public the right to request records from federal executive branch agencies.
Question 4: A records manager discovers that a litigation hold was issued after some responsive documents were already destroyed per the normal retention schedule. What is the most appropriate immediate action?
- Re-create the documents from memory
- Document the destruction and notify legal counsel immediately (Correct answer)
- Issue a new hold and continue normal operations
- Suspend the entire records program until litigation ends
Correct answer: Document the destruction and notify legal counsel immediately
When pre-hold destruction occurs, the records manager must document the circumstances and promptly notify legal counsel to assess spoliation risk.
Question 5: Which regulation requires financial institutions to implement customer information security programs and report breaches to regulators?
- Dodd-Frank Act
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Bank Secrecy Act (BSA)
- Community Reinvestment Act
Correct answer: Gramm-Leach-Bliley Act (GLBA)
GLBA's Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program.
Question 6: Under the Federal Rules of Civil Procedure (FRCP), what term describes the process of identifying, preserving, collecting, and producing electronically stored information?
- Digital forensics
- e-Discovery (Correct answer)
- Information governance
- Data mapping
Correct answer: e-Discovery
e-Discovery refers to the discovery process as it applies to electronically stored information (ESI) under the FRCP.
Question 7: Which federal agency enforces HIPAA Privacy and Security Rules?
- Federal Trade Commission (FTC)
- Office for Civil Rights (OCR) within HHS (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
- Department of Justice (DOJ)
Correct answer: Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary enforcement agency for HIPAA Privacy and Security Rules.
Under the Sarbanes-Oxley Act (SOX), how long must public companies retain audit workpapers?