IGP Records Management & Data Privacy 3 — Questions and Answers
Question 1: Under HIPAA, what is the minimum necessary standard?
- Covered entities must encrypt all PHI at rest
- Covered entities must limit PHI use and disclosure to the minimum necessary for the intended purpose (Correct answer)
- Covered entities must retain PHI for a minimum of six years
- Covered entities must obtain written consent before any PHI disclosure
Correct answer: Covered entities must limit PHI use and disclosure to the minimum necessary for the intended purpose
The HIPAA minimum necessary standard requires covered entities to make reasonable efforts to use, disclose, or request only the minimum amount of PHI needed to accomplish the intended purpose.
Question 2: A retention schedule assigns a seven-year retention period to financial records. When does the retention clock typically begin?
- The date the record was created
- The date the record was filed or closed (Correct answer)
- The fiscal year end in which the record was created
- The date the retention schedule was last updated
Correct answer: The date the record was filed or closed
Retention periods for most records begin when the record's active use concludes, typically upon filing or closure of the matter rather than at creation.
Question 3: Which term describes the process of converting paper records to electronic format while ensuring authenticity and reliability?
- Data migration
- Digital transformation
- Digitization with quality assurance (Correct answer)
- Electronic discovery
Correct answer: Digitization with quality assurance
Digitization with quality assurance involves scanning paper records and applying controls to verify the resulting digital copies are authentic, accurate, and complete representations of the originals.
Question 4: Under the EU-US Data Privacy Framework, what must US organizations do to lawfully receive personal data from the EU?
- Obtain explicit consent from every EU data subject
- Self-certify with the US Department of Commerce and commit to framework principles (Correct answer)
- Establish a legal entity within the EU
- Sign standard contractual clauses with every EU data exporter
Correct answer: Self-certify with the US Department of Commerce and commit to framework principles
Under the EU-US Data Privacy Framework, US organizations must self-certify their compliance with the framework's principles to the US Department of Commerce to lawfully receive EU personal data.
Question 5: What is 'information mapping' in the context of data privacy compliance?
- Creating network diagrams showing server locations
- Documenting the flow of personal data through an organization's systems and processes (Correct answer)
- Tagging records with geographic metadata
- Assigning access control permissions to data fields
Correct answer: Documenting the flow of personal data through an organization's systems and processes
Information mapping (or data mapping) documents how personal data flows into, through, and out of an organization, which is essential for privacy impact assessments and compliance.
Question 6: Which records management principle holds that records of the same origin should not be mixed with records from other origins?
- Chain of custody
- Provenance (respect des fonds) (Correct answer)
- Original order
- Authenticity
Correct answer: Provenance (respect des fonds)
Provenance, or respect des fonds, is the archival principle that records from one creator should be kept separate from those of another creator to preserve their context and meaning.
Question 7: A Privacy Impact Assessment (PIA) is most appropriately conducted at which stage of a new project involving personal data?
- After the system has been deployed to production
- Before or during the design phase of the project (Correct answer)
- Only when regulators request it
- After the first security incident occurs
Correct answer: Before or during the design phase of the project
A PIA should be conducted before or during the design phase so that privacy risks can be identified and mitigated before the system is built or deployed.
Under HIPAA, what is the minimum necessary standard?