CSL CSL Legal, Regulatory & Ethical Frameworks 1 — Questions and Answers
Question 1: Under the US Health Insurance Portability and Accountability Act (HIPAA), what is a covered entity's obligation following a breach of unsecured PHI?
- Only notify the affected individual if they request it
- Notify affected individuals, HHS, and potentially media within 60 days of discovery (Correct answer)
- File a police report within 24 hours
- Notify the FBI's IC3 within 72 hours
Correct answer: Notify affected individuals, HHS, and potentially media within 60 days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals and HHS within 60 days, and media outlets if the breach affects more than 500 residents of a state.
Question 2: Which US federal law governs cybersecurity requirements for financial institutions and requires a Safeguards Rule?
- SOX (Sarbanes-Oxley Act)
- GLBA (Gramm-Leach-Bliley Act) (Correct answer)
- FISMA (Federal Information Security Management Act)
- CFAA (Computer Fraud and Abuse Act)
Correct answer: GLBA (Gramm-Leach-Bliley Act)
The GLBA Safeguards Rule requires financial institutions to implement comprehensive security programs to protect customer financial information.
Question 3: What does the SEC's cybersecurity disclosure rule (effective 2023) require of publicly traded companies?
- Annual submission of penetration test results to the SEC
- Disclosure of material cybersecurity incidents within 4 business days and annual disclosure of cybersecurity risk management programs (Correct answer)
- Appointment of a CISO who reports directly to the SEC
- Mandatory cyber insurance coverage above $10 million
Correct answer: Disclosure of material cybersecurity incidents within 4 business days and annual disclosure of cybersecurity risk management programs
The SEC's 2023 rule requires public companies to disclose material cybersecurity incidents on Form 8-K within 4 business days and to describe their cybersecurity risk management annually on Form 10-K.
Question 4: Under the Computer Fraud and Abuse Act (CFAA), which activity can create criminal liability for security professionals?
- Running approved vulnerability scans on internal systems
- Accessing computer systems without authorization, even for research purposes (Correct answer)
- Reporting discovered vulnerabilities to vendors
- Conducting authorized penetration tests under a signed contract
Correct answer: Accessing computer systems without authorization, even for research purposes
The CFAA criminalizes unauthorized computer access — security professionals must have explicit written authorization before testing any systems they do not own.
Question 5: Which principle from the GDPR gives individuals the right to request deletion of their personal data?
- Right of access
- Right to erasure (right to be forgotten) (Correct answer)
- Right to data portability
- Right to restriction of processing
Correct answer: Right to erasure (right to be forgotten)
GDPR Article 17 grants individuals the right to request that organizations delete their personal data under specific circumstances.
Question 6: A US company operates in California and collects consumer data. Which state law imposes GDPR-like privacy rights on those consumers?
- Illinois Biometric Information Privacy Act (BIPA)
- California Consumer Privacy Act (CCPA) / CPRA (Correct answer)
- New York SHIELD Act
- Virginia Consumer Data Protection Act (CDPA)
Correct answer: California Consumer Privacy Act (CCPA) / CPRA
The CCPA (amended by CPRA) is the most comprehensive US state privacy law, granting California consumers rights to know, delete, and opt out of the sale of their personal data.
Under the US Health Insurance Portability and Accountability Act (HIPAA), what is a covered entity's obligation following a breach of unsecured PHI?