Chapter 5: Private Sector Data Collection Flashcards
COPPA applies to… (3)
Online services intended for children
General online services where the operator knows they are gathering childrens data
Online services knowingly collecting children’s data from other online services
COPPA Online Services examples
Websites
Mobile apps
Smart Devices
etc.
Who enforces COPPA?
FTC
States
Specific agencies in their context
COPPA PI
Names
Addresses
SSN
Phone numbers
Screen names
geolocation
Media of a child’s image or voice
COPPA protects…
PI and any info combined with PI
Parents rights under COPPA
Consent
Revoking consent
Deletion
Limit collection to necessary information
COPPA 3rd party restriction
Parents can’t be forced to allow collection by 3rd parties
COPPA requirements for online services
Privacy Policies that meet COPPA requirements
Parental notification
Parental consent
Maintain way for parents to exercise their rights
Information security program
COPPA consent requirements
Consent form (including paper)
Validate parents identity
COPPA maximum fine
$43,280 per violation
Data Brokers
Buy datasets to be resold
Machine learning
Computer learns without human interaction
PHI
Personal Health Information. Medical info including records by insurance companies and billing.
ePHI
Medical records transferred electronically
HIPAA applies to…
Covered entities and covered transactions
HIPAA covered entities (3)
Insurance plans
Clearinghouses
Healthcare providers
Healthcare clearinghouse
Manages the sharing of healthcare info by standardizing data
HIPAA business associates
3rd party of a covered entity that works with PHI
HIPAA Business Associate Agreements
Agreements between covered entities and 3rd parties ensuring conformance with HIPAA
HIPAA doesn’t cover
Personel records
Academic records
Anonymized records
HIPAA privacy rule (3)
Requires privacy practices
Limites use and disclosure of data without authorization.
Gives patients rights, including right to view and correct records
Who enforces HIPAA
HHS OCR (Office of Civil Rights)
Where are privacy standards and practices documented for HIPAA
Privacy policy and procedures document
HIPAA compliance retention period
6 years