Online Questions - Valid Practice CIPP-US Exam Dumps Test Questions [Q64-Q80]

Share

Online Questions - Valid Practice CIPP-US Exam Dumps Test Questions

100% Real CIPP-US dumps  - Brilliant CIPP-US Exam Questions PDF


The CIPP-US certification exam is designed for privacy professionals who are involved in the collection, use, and dissemination of personal data in the United States. Certified Information Privacy Professional/United States (CIPP/US) certification program is ideal for privacy professionals who work in industries such as healthcare, finance, technology, and retail, among others. CIPP-US exam covers various topics such as the U.S. legal system, the privacy framework, privacy principles and practices, and data protection technologies.


IAPP CIPP-US (Certified Information Privacy Professional/United States (CIPP/US)) Certification Exam is a highly respected certification program that recognizes individuals who possess a deep understanding of the privacy laws and regulations in the United States. CIPP-US exam is designed for professionals who work in the privacy field, including lawyers, consultants, and privacy officers. Certified Information Privacy Professional/United States (CIPP/US) certification is awarded by the International Association of Privacy Professionals (IAPP), an organization that sets the standard for privacy professionals worldwide.


The CIPP-US certification exam consists of 90 multiple-choice questions, and candidates are given 2.5 hours to complete the exam. The questions are designed to test the candidate's knowledge and understanding of the US privacy laws and regulations, as well as their ability to apply this knowledge in real-world scenarios. CIPP-US exam is administered by Pearson VUE, and candidates can take the exam at any of the Pearson VUE testing centers worldwide.

 

NEW QUESTION # 64
The Family Educational Rights and Privacy Act (FERPA) requires schools to do all of the following EXCEPT?

  • A. Provide students with access to their records within a specified amount of time.
  • B. Obtain student authorization before releasing directory information in their records.
  • C. Respond to all reasonable student requests regarding explanation of their records.
  • D. Verify the identity of students who make requests for access to their records.

Answer: A


NEW QUESTION # 65
What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?

  • A. Bill the majority of patients electronically for their health care
  • B. Make electronic health records (EHRs) part of regular care
  • C. Send health information and appointment reminders to patients electronically
  • D. Keep electronic updates about the Health Insurance Portability and Accountability Act

Answer: B


NEW QUESTION # 66
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the most likely risk of Fitness Coach, Inc. adopting Janice's first draft of the privacy policy?

  • A. Showing a lack of trust in the organization's privacy practices
  • B. Failing to meet the needs of customers who are concerned about privacy
  • C. Leaving the company susceptible to violations by setting unrealistic goals
  • D. Not being in standard compliance with applicable laws

Answer: C

Explanation:
Janice's first draft of the privacy policy may be too restrictive and impractical for Fitness Coach, Inc. to follow, given the nature of its business and the expectations of its customers. By limiting the retention of personal information to one year and requiring written consent for any third-party sharing, the policy may create operational challenges and customer dissatisfaction. For example, customers may want to resume their fitness programs after a long hiatus and expect the company to have their previous records and preferences.
Similarly, third-party contractors may need access to customer information to provide better services and tailor their classes. If the company fails to adhere to its own privacy policy, it may face legal consequences, reputational damage, and loss of trust from its customers. Therefore, the company should adopt a more realistic and flexible privacy policy that balances its business needs and its customers' privacy rights. References:
* Privacy Policy for Health Coaches
* Privacy Policies for Online Coaches
* Privacy Policy - Coaching.com


NEW QUESTION # 67
SCENARIO
Please use the following to answer the next question:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in statea.
HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo.
CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals ?ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
Which of the following would be HealthCo's best response to the attorney's discovery request?

  • A. Respond with a request for satisfactory assurances such as a qualified protective order
  • B. Turn over all of the compromised patient records to the plaintiff's attorney
  • C. Reject the request because the HIPAA privacy rule only permits disclosure for payment, treatment or healthcare operations
  • D. Respond with a redacted document only relative to the plaintiff

Answer: A

Explanation:
The HIPAA privacy rule establishes national standards to protect individuals' medical records and other individually identifiable health information (collectively defined as "protected health information") and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically (collectively defined as
"covered entities")1 The rule requires appropriate safeguards to protect the privacy of protected health information and sets limits and conditions on the uses and disclosures that may be made of such information without an individual's authorization1 The rule also gives individuals rights over their protected health information, including rights to examine and obtain a copy of their health records, to direct a covered entity to transmit to a third party an electronic copy of their protected health information in an electronic health record, and to request corrections1 The HIPAA privacy rule permits a covered entity to disclose protected health information for the litigation in response to a court order, subpoena, discovery request, or other lawful process, provided the applicable requirements of 45 CFR 164.512 (e) for disclosures for judicial and administrative proceedings are met. These requirements include:
In response to a court order or administrative tribunal order, the covered entity may disclose only the protected health information expressly authorized by such order. In response to a subpoena, discovery request, or other lawful process that is not accompanied by a court order or administrative tribunal order, the covered entity must receive satisfactory assurances that the party seeking the information has made reasonable efforts to ensure that the individual who is the subject of the information has been given notice of the request, or that the party seeking the information has made reasonable efforts to secure a qualified protective order. A qualified protective order is an order of a court or administrative tribunal or a stipulation by the parties to the litigation or administrative proceeding that prohibits the parties from using or disclosing the protected health information for any purpose other than the litigation or proceeding for which such information was requested and requires the return to the covered entity or destruction of the protected health information (including all copies made) at the end of the litigation or proceeding.


NEW QUESTION # 68
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?

  • A. Mitigating harm to consumers after a security breach.
  • B. Announcing the tracking of online behavior for advertising purposes.
  • C. Integrating privacy protections during product development.
  • D. Allowing consumers to opt in before collecting any data.

Answer: C

Explanation:
According to the FTC report, the most important directive for businesses is to adopt a "privacy by design" approach, which means integrating privacy protections throughout the entire product lifecycle, from initial design to disposal. This includes implementing reasonable security measures, collecting only the data needed for a specific purpose, retaining data only as long as necessary, and safely disposing of data that is no longer needed. The FTC report also recommends that businesses provide clear and transparent privacy notices, offer consumers meaningful choices about how their data is used, and increase their accountability for data practices. References: FTC Report, IAPP CIPP/US Study Guide (p. 32-33)


NEW QUESTION # 69
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?

  • A. Decide if any enforcement actions are justified
  • B. Determine which bodies will be involved in adjudication
  • C. Appeal decisions made against it
  • D. Adhere to its industry's code of conduct

Answer: D

Explanation:
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to adhere to its industry's code of conduct. Self-regulation is a process by which an industry or a group of companies voluntarily adopts and enforces standards or guidelines to protect consumers and promote fair competition. The FTC encourages self-regulation as a way to complement its enforcement efforts and address emerging issues in the marketplace. The FTC also monitors self- regulatory programs and may take action against companies that fail to comply with their own codes of conduct or misrepresent their participation in such programs.


NEW QUESTION # 70
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?

  • A. Confirm that patients are given the privacy notice on their first visit
  • B. Post the privacy notice in a prominent location instead
  • C. State the privacy policy to the patient verbally
  • D. Direct patients to the correct area of the hospital website

Answer: A

Explanation:
HIPAA requires covered entities to provide a notice of privacy practices (NPP) to individuals who receive health care services from the covered entity. The NPP must describe how the covered entity may use and disclose protected health information (PHI), the individual's rights with respect to their PHI, and the covered entity's obligations to protect the privacy of PHI. The NPP must be provided to the individual no later than the date of the first service delivery, either in person or electronically. The covered entity must also make the NPP available on request and post it on its website if it has one. The covered entity must also make a good faith effort to obtain a written acknowledgment from the individual that they received the NPP. If the individual refuses to sign the acknowledgment, the covered entity must document the attempt and the reason for the refusal.
The other options are not sufficient to comply with HIPAA. Stating the privacy policy verbally (option A) does not provide the individual with a written or electronic copy of the NPP that they can keep for future reference. Posting the privacy notice in a prominent location (option B) does not ensure that the individual receives the NPP or has an opportunity to review it before receiving services. Directing patients to the correct area of the hospital website (option C) does not provide the individual with the NPP at the time of service delivery, unless the individual agrees to receive the NPP electronically and has access to the website at that time. References:
* Notice of Privacy Practices for Protected Health Information
* Model Notices of Privacy Practices
* Sample Notice: Availability of Notice of Privacy Practices
* Notice of Privacy Practices
* Notice of Privacy Practices (NPP) Distribution and Acknowledgement


NEW QUESTION # 71
What is the main challenge financial institutions face when managing user preferences?

  • A. Ensuring they are in compliance with numerous complex state and federal privacy laws
  • B. Developing a mechanism for opting out that is easy for their consumers to navigate
  • C. Determining the legal requirements for sharing preferences with their affiliates
  • D. Ensuring that preferences are applied consistently across channels and platforms

Answer: D

Explanation:
Financial institutions (FIs) collect and process a large amount of personal data from their customers, such as name, address, account number, transaction history, credit score, etc.
Customers may have different preferences regarding how their data is used, shared, or protected by the FIs. For example, some customers may want to receive marketing offers from the FIs or their affiliates, while others may opt out of such communications. Some customers may prefer to access their accounts online, while others may use mobile apps, phone calls, or physical branches. Some customers may want to enable biometric authentication, while others may rely on passwords or PINs. Managing these diverse and dynamic user preferences is a challenge for FIs, as they need to ensure that they respect and honor the choices of their customers across all the channels and platforms they use. This requires FIs to have a robust and integrated system that can capture, store, update, and apply user preferences consistently and accurately. Failing to do so may result in customer dissatisfaction, loss of trust, regulatory fines, or legal disputes.


NEW QUESTION # 72
In which situation would a policy of "no consumer choice" or "no option" be expected?

  • A. When a customer's financial information is requested by the government
  • B. When a job applicant's credit report is provided to an employer
  • C. When a patient's health record is made available to a pharmaceutical company
  • D. When a customer's street address is shared with a shipping company

Answer: D


NEW QUESTION # 73
Under state breach notification laws, which is NOT typically included in the definition of personal information?

  • A. Social Security number
  • B. State identification number
  • C. Medical Information
  • D. First and last name

Answer: C


NEW QUESTION # 74
Which of the following best describes how federal anti-discrimination laws protect the privacy of private- sector employees in the United States?

  • A. They limit the types of information that employers can collect about employees.
  • B. They limit the amount of time a potential employee can be interviewed.
  • C. They promote a workforce of employees with diverse skills and interests.
  • D. They prescribe working environments that are safe and comfortable.

Answer: A

Explanation:
Federal anti-discrimination laws, such as Title VII of the Civil Rights Act of 1964, the Equal Pay Act of 1963, the Age Discrimination in Employment Act of 1967, and the Americans with Disabilities Act of 1990, prohibit employers from discriminating against employees or applicants based on certain protected characteristics, such as race, color, religion, sex, national origin, age, disability, and genetic information.
These laws also limit the types of information that employers can collect, use, disclose, or retain about employees or applicants, in order to prevent discrimination or invasion of privacy. For example, employers cannot ask about an applicant's medical history, disability status, genetic information, or religious beliefs, unless they are relevant to the job or a bona fide occupational qualification. Employers also cannot use such information to make adverse employment decisions, such as hiring, firing, promotion, or compensation, unless they are justified by a legitimate business necessity or a reasonable accommodation. Employers must also safeguard the confidentiality of such information and dispose of it properly when it is no longer needed. References:
* Federal Laws Prohibiting Job Discrimination Questions And Answers
* Laws Enforced by EEOC
* Employment and Anti-Discrimination Laws in the Workplace
* Protections Against Discrimination and Other Prohibited Practices
* 3. Who is protected from employment discrimination?


NEW QUESTION # 75
Which of the following laws is NOT involved in the regulation of employee background checks?

  • A. The Gramm-Leach-Bliley Act (GLBA).
  • B. The California Investigative Consumer Reporting Agencies Act (ICRAA).
  • C. The U.S. Fair Credit Reporting Act (FCRA).
  • D. The Civil Rights Act.

Answer: A


NEW QUESTION # 76
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?

  • A. The ability to investigate incidents of identity theft.
  • B. The ability to appeal negative credit-based decisions.
  • C. The ability to correct inaccurate credit information.
  • D. The ability to receive reports from multiple credit reporting agencies.

Answer: C

Explanation:
, "..Specifically, FCRA mandates accurate and relevant data collection, provides consumers with the ability to access and correct their information, and limits the use of consumer reports to defined permissible purposes".


NEW QUESTION # 77
SCENARIO -
Please use the following to answer the next question:
Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada.
Miraculous normally treats patients in person, but has recently decided to start offering telehealth appointments, where patients can have virtual appointments with on-site doctors via a phone app.
For this new initiative, Miraculous is considering a product built by MedApps, a company that makes quality telehealth apps for healthcare practices and licenses them to be usedwith the practices' branding. MedApps provides technical support for the app, which it hosts in the cloud. MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service.
Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices, as well as negotiating the terms of vendor agreements. Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.
Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps.
What HIPAA compliance issue would Miraculous have to consider before using the telehealth app?

  • A. HIPAA does not permit healthcare providers to use cloud hosting services.
  • B. HIPAA does not permit in-person appointment data to be hosted in the cloud.
  • C. HIPAA would require Miraculous and MedApps to enter into a Business Associate Agreement.
  • D. HIPAA would require Miraculous to obtain patient consent before in-person appointment data can be shared with third parties.

Answer: C

Explanation:
According to HIPAA, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) on behalf of, or provides services to, a covered entity. A business associate agreement (BAA) is a written contract between a covered entity and a business associate that establishes the permitted and required uses and disclosures of PHI by the business associate, as well as the safeguards that the business associate must implement to protect the PHI. In this scenario, MedApps is a business associate of Miraculous, since it provides a telehealth app that involves the use or disclosure of PHI on behalf of Miraculous. Therefore, HIPAA would require Miraculous and MedApps to enter into a BAA before using the telehealth app. The other options are incorrect because HIPAA does not prohibit the use of cloud hosting services or the hosting of in-person appointment data in the cloud, as long as the appropriate safeguards and agreements are in place. HIPAA also does not require patient consent for the sharing of PHI with third parties for treatment, payment, or health care operations purposes, which would include the use of the telehealth app. References:
* HIPAA and Telehealth - Office for Civil Rights
* HIPAA Rules for telehealth technology - Telehealth.HHS.gov
* Notification of Enforcement Discretion for Telehealth - Office for Civil Rights
* Guidance: How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Provide Audio-Only Telehealth - Office for Civil Rights
* HIPAA Compliant App - Telehealth.org
* IAPP CIPP/US Certified Information Privacy Professional Study Guide - Chapter 3: HIPAA and HITECH, pages 75-76, 81-82, 86-87.


NEW QUESTION # 78
Which two FCRA rules were added with the Fair and Accurate Credit Transitions Act in 2003?

  • A. Privacy Rule and Red Flags Rule
  • B. Privacy Rule and Safeguards Rule
  • C. Disposal Rule and Safeguards Rule
  • D. Disposal Rule and Red Flags Rule

Answer: D

Explanation:
FACTA has introduced measures for identity theft protection, together with a Disposal Rule and a Red Flags Rule.


NEW QUESTION # 79
Under the Telemarketing Sales Rule, what characteristics of consent must be in place for an organization to acquire an exception to the Do-Not-Call rules for a particular consumer?

  • A. The consent must be in writing, must contain the number to which calls can be made and must have an end date
  • B. The consent must be in writing, must state the times when calls can be made to the consumer and must be signed
  • C. The consent must be in writing, must contain the number to which calls can be made and must be signed
  • D. The consent must be in writing, must have an end data and must state the times when calls can be made

Answer: C

Explanation:
The Telemarketing Sales Rule (TSR) is a federal regulation that applies to telemarketing calls, which are defined as "a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call." The TSR requires telemarketers to make specific disclosures, prohibit misrepresentations, limit the times and number of calls, and set payment restrictions for the sale of certain goods and services. The TSR also gives consumers the right to opt out of receiving telemarketing calls by registering their phone numbers on the National Do Not Call Registry. The TSR applies to both for-profit and not-for-profit organizations, but there are some exemptions and partial exemptions for certain types of entities, calls, and transactions. For example, the TSR does not apply to nonprofit organizations calling on their own behalf, as they are not considered to be engaged in telemarketing. However, if a nonprofit organization hires a for-profit telemarketer or telefunder to solicit charitable contributions on its behalf, the for-profit entity must comply with the TSR, as it is engaged in telemarketing. Similarly, the TSR does not apply to for-profit organizations calling businesses when a binding contract exists between them, as they are not considered to be inducing the purchase of goods or services. However, if a for-profit organization calls businesses to sell additional services to established customers, the TSR applies, as it is considered to be inducing the purchase of goods or services.
Therefore, among the four options, only for-profit organizations and for-profit telefunders regarding charitable solicitations must comply with the TSR, as they are engaged in telemarketing and do not fall under any of the exemptions or partial exemptions.


NEW QUESTION # 80
......

CIPP-US Exam PDF [2026] Tests Free Updated Today with Correct 228 Questions: https://www.examcollectionpass.com/IAPP/CIPP-US-practice-exam-dumps.html

IAPP CIPP-US Exam Preparation Guide and PDF Download: https://drive.google.com/open?id=18SOoc6UQN5OZDPhWJDTnY_sLGMnf84dU