PLC Data Breach Response & Incident Management 1 — Questions and Answers
Question 1: Under HIPAA, covered entities must notify affected individuals of a breach affecting their protected health information within how many days of discovering the breach?
- 30 days
- 60 days (Correct answer)
- 45 days
- 90 days
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Question 2: Under the GDPR (applicable to US companies with EU data subjects), a personal data breach must be reported to the supervisory authority within how many hours of becoming aware?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 96 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 3: Which US federal law requires financial institutions to notify customers of a security breach involving their personal financial information?
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Sarbanes-Oxley Act
- Fair Credit Reporting Act
- Electronic Communications Privacy Act
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The GLBA Safeguards Rule requires financial institutions to notify affected customers when their personal financial information is breached.
Question 4: A company discovers that an employee accidentally emailed a spreadsheet containing 500 customers' Social Security numbers to the wrong recipient. What is the FIRST step in proper incident response?
- Immediately notify all 500 affected customers
- Contain the incident and assess its scope (Correct answer)
- File a police report
- Notify the FTC within 24 hours
Correct answer: Contain the incident and assess its scope
Incident response best practice dictates that containment and assessment of scope must occur first before notifications or external reporting.
Question 5: Which of the following is NOT typically required in a state breach notification letter to affected individuals?
- Description of what happened
- The name of the employee responsible for the breach (Correct answer)
- Types of information involved
- Contact information for further inquiries
Correct answer: The name of the employee responsible for the breach
State breach notification laws do not require naming the responsible employee; they require a description of the incident, data types involved, and remediation steps.
Question 6: Under the California Consumer Privacy Act (CCPA), businesses that suffer a data breach exposing consumers' unencrypted personal information may face statutory damages of how much per consumer, per incident?
- $100 to $750 (Correct answer)
- $500 to $5,000
- $1,000 to $10,000
- $250 to $2,500
Correct answer: $100 to $750
The CCPA allows affected consumers to seek statutory damages between $100 and $750 per consumer per incident for data breaches of unencrypted personal information.
Under HIPAA, covered entities must notify affected individuals of a breach affecting their protected health information within how many days of discovering the breach?