Data Breach Response & Incident Management Flashcards
6 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Breach Response & Incident Management flashcards as text
Under HIPAA, covered entities must notify affected individuals of a breach affecting their protected health information within how many days of discovering the breach?
Answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Under the GDPR (applicable to US companies with EU data subjects), a personal data breach must be reported to the supervisory authority within how many hours of becoming aware?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Which US federal law requires financial institutions to notify customers of a security breach involving their personal financial information?
Answer: Gramm-Leach-Bliley Act (GLBA)
The GLBA Safeguards Rule requires financial institutions to notify affected customers when their personal financial information is breached.
A company discovers that an employee accidentally emailed a spreadsheet containing 500 customers' Social Security numbers to the wrong recipient. What is the FIRST step in proper incident response?
Answer: Contain the incident and assess its scope
Incident response best practice dictates that containment and assessment of scope must occur first before notifications or external reporting.
Which of the following is NOT typically required in a state breach notification letter to affected individuals?
Answer: The name of the employee responsible for the breach
State breach notification laws do not require naming the responsible employee; they require a description of the incident, data types involved, and remediation steps.
Under the California Consumer Privacy Act (CCPA), businesses that suffer a data breach exposing consumers' unencrypted personal information may face statutory damages of how much per consumer, per incident?
Answer: $100 to $750
The CCPA allows affected consumers to seek statutory damages between $100 and $750 per consumer per incident for data breaches of unencrypted personal information.