CSC CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers 2 — Questions and Answers
Question 1: What is the maximum number of days most U.S. state breach notification laws require businesses to notify affected individuals after discovering a breach?
- 30 to 90 days depending on state law (Correct answer)
- 180 days
- 7 days
- 1 year
Correct answer: 30 to 90 days depending on state law
U.S. state breach notification deadlines vary, but most fall between 30 and 90 days from discovery, with some states like Florida mandating 30 days.
Question 2: Under which federal law must covered entities notify the HHS Secretary and affected individuals within 60 days of discovering a breach of unsecured protected health information?
- HIPAA Breach Notification Rule (Correct answer)
- GLBA Safeguards Rule
- FISMA
- COPPA
Correct answer: HIPAA Breach Notification Rule
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and sometimes media within 60 days of discovering a breach.
Question 3: Which of the following would likely trigger a state data breach notification requirement in the U.S.?
- Unauthorized access to unencrypted Social Security numbers (Correct answer)
- Accidental deletion of anonymized survey data
- Loss of encrypted files where the encryption key was not compromised
- An employee viewing authorized records outside business hours
Correct answer: Unauthorized access to unencrypted Social Security numbers
Most state breach notification laws are triggered by unauthorized acquisition of unencrypted personal information such as SSNs, not encrypted data or internal authorized access.
Question 4: What is the 'safe harbor' provision in the context of U.S. data breach notification laws?
- An exemption from notification when breached data was encrypted (Correct answer)
- A grace period to delay notification by 90 additional days
- A federal preemption clause overriding all state laws
- An opt-out right for businesses with fewer than 50 employees
Correct answer: An exemption from notification when breached data was encrypted
Most state breach notification laws provide a safe harbor exempting organizations from notification duties if the breached data was encrypted and the decryption key was not also compromised.
Question 5: Which type of personal information is most commonly covered by U.S. state breach notification statutes?
- Name combined with SSN, financial account number, or driver's license number (Correct answer)
- Publicly available government records only
- Encrypted health records stored on air-gapped systems
- General demographic data such as age and zip code
Correct answer: Name combined with SSN, financial account number, or driver's license number
U.S. state breach notification laws typically protect combinations of an individual's name with sensitive identifiers like SSN, account numbers, or driver's license numbers.
Question 6: Which U.S. federal agency is responsible for overseeing breach notification compliance in the healthcare sector?
- HHS Office for Civil Rights (OCR) (Correct answer)
- Federal Trade Commission (FTC)
- CISA
- Department of Justice
Correct answer: HHS Office for Civil Rights (OCR)
The HHS Office for Civil Rights enforces the HIPAA Breach Notification Rule and can impose civil monetary penalties for non-compliance.
What is the maximum number of days most U.S. state breach notification laws require businesses to notify affected individuals after discovering a breach?