โ† All CSC Flashcard Decks

CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers Flashcards

6 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers flashcards as text
  1. What is the maximum number of days most U.S. state breach notification laws require businesses to notify affected individuals after discovering a breach?

    Answer: 30 to 90 days depending on state law

    U.S. state breach notification deadlines vary, but most fall between 30 and 90 days from discovery, with some states like Florida mandating 30 days.

  2. Under which federal law must covered entities notify the HHS Secretary and affected individuals within 60 days of discovering a breach of unsecured protected health information?

    Answer: HIPAA Breach Notification Rule

    The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and sometimes media within 60 days of discovering a breach.

  3. Which of the following would likely trigger a state data breach notification requirement in the U.S.?

    Answer: Unauthorized access to unencrypted Social Security numbers

    Most state breach notification laws are triggered by unauthorized acquisition of unencrypted personal information such as SSNs, not encrypted data or internal authorized access.

  4. What is the 'safe harbor' provision in the context of U.S. data breach notification laws?

    Answer: An exemption from notification when breached data was encrypted

    Most state breach notification laws provide a safe harbor exempting organizations from notification duties if the breached data was encrypted and the decryption key was not also compromised.

  5. Which type of personal information is most commonly covered by U.S. state breach notification statutes?

    Answer: Name combined with SSN, financial account number, or driver's license number

    U.S. state breach notification laws typically protect combinations of an individual's name with sensitive identifiers like SSN, account numbers, or driver's license numbers.

  6. Which U.S. federal agency is responsible for overseeing breach notification compliance in the healthcare sector?

    Answer: HHS Office for Civil Rights (OCR)

    The HHS Office for Civil Rights enforces the HIPAA Breach Notification Rule and can impose civil monetary penalties for non-compliance.

CSC - Cybersecurity Compliance Data Privacy and Breach Notification Laws Questions and Answers Flashcards โ€” CSC Study Cards with Answers