Check Real IAPP CIPP-US Exam Question for Free (2022) [Q71-Q88]

Rate this post

Check Real IAPP CIPP-US Exam Question for Free (2022)

Get Ready to Boost your Prepare for your CIPP-US Exam with 152 Questions

How much IAPP CIPP-US: Certified Information Privacy Professional/United States (CIPP/US) Exam cost

IAPP CIPP-US: Certified Information Privacy Professional/United States (CIPP/US) exam cost is $550 USD and retake fees is $375 USD, for more information please visit the official website.

 

NEW QUESTION 71
Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?

 
 
 
 

NEW QUESTION 72
All of the following organizations are specified as covered entities under the Health Insurance Portability and Accountability Act (HIPAA) EXCEPT?

 
 
 
 

NEW QUESTION 73
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?

 
 
 
 

NEW QUESTION 74
What do the Civil Rights Act, Pregnancy Discrimination Act, Americans with Disabilities Act, Age Discrimination Act, and Equal Pay Act all have in common?

 
 
 
 

NEW QUESTION 75
What was the original purpose of the Foreign Intelligence Surveillance Act?

 
 
 
 

NEW QUESTION 76
What is the most likely reason that states have adopted their own data breach notification laws?

 
 
 
 

NEW QUESTION 77
What role does the U.S. Constitution play in the area of workplace privacy?

 
 
 
 

NEW QUESTION 78
What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require?

 
 
 
 

NEW QUESTION 79
What are banks required to do under the Gramm-Leach-Bliley Act (GLBA)?

 
 
 
 

NEW QUESTION 80
Which action is prohibited under the Electronic Communications Privacy Act of 1986?

 
 
 
 

NEW QUESTION 81
SCENARIO
Please use the following to answer the next question:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo’s business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth’s security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals – ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual’s ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient’s attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most significant reason that the U.S. Department of Health and Human Services (HHS) might impose a penalty on HealthCo?

 
 
 
 

NEW QUESTION 82
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track information about its patients. Recently, SMH suffered a data breach where a third-party hacker was able to gain access to the SMH internal network.
Because it is a HIPPA-covered entity, SMH made a notification to the Office of Civil Rights at the U.S. Department of Health and Human Services about the breach.
Which statement accurately describes SMH’s notification responsibilities?

 
 
 
 

NEW QUESTION 83
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?

 
 
 
 

NEW QUESTION 84
Under the Telemarketing Sales Rule, what characteristics of consent must be in place for an organization to acquire an exception to the Do-Not-Call rules for a particular consumer?

 
 
 
 

NEW QUESTION 85
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?

 
 
 
 

NEW QUESTION 86
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?

 
 
 
 

NEW QUESTION 87
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?

 
 
 
 

NEW QUESTION 88
An organization self-certified under Privacy Shield must, upon request by an individual, do what?

 
 
 
 

For more info visit:

The IAPP CIPP-US: Certified Information Privacy Professional/United States (CIPP/US)

 

Use Free CIPP-US Exam Questions that Stimulates Actual EXAM : https://www.actualpdf.com/CIPP-US_exam-dumps.html

         

Related Links: www.stes.tyc.edu.tw learn.csisafety.com.au www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below