Chapter 5: Private Sector Data Collection Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

COPPA applies to… (3)

A

Online services intended for children
General online services where the operator knows they are gathering childrens data
Online services knowingly collecting children’s data from other online services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

COPPA Online Services examples

A

Websites
Mobile apps
Smart Devices
etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who enforces COPPA?

A

FTC
States
Specific agencies in their context

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

COPPA PI

A

Names
Addresses
SSN
Phone numbers
Screen names
geolocation
Media of a child’s image or voice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

COPPA protects…

A

PI and any info combined with PI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Parents rights under COPPA

A

Consent
Revoking consent
Deletion
Limit collection to necessary information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

COPPA 3rd party restriction

A

Parents can’t be forced to allow collection by 3rd parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

COPPA requirements for online services

A

Privacy Policies that meet COPPA requirements
Parental notification
Parental consent
Maintain way for parents to exercise their rights
Information security program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COPPA consent requirements

A

Consent form (including paper)
Validate parents identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

COPPA maximum fine

A

$43,280 per violation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data Brokers

A

Buy datasets to be resold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Machine learning

A

Computer learns without human interaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

PHI

A

Personal Health Information. Medical info including records by insurance companies and billing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ePHI

A

Medical records transferred electronically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HIPAA applies to…

A

Covered entities and covered transactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

HIPAA covered entities (3)

A

Insurance plans
Clearinghouses
Healthcare providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Healthcare clearinghouse

A

Manages the sharing of healthcare info by standardizing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

HIPAA business associates

A

3rd party of a covered entity that works with PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

HIPAA Business Associate Agreements

A

Agreements between covered entities and 3rd parties ensuring conformance with HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

HIPAA doesn’t cover

A

Personel records
Academic records
Anonymized records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

HIPAA privacy rule (3)

A

Requires privacy practices
Limites use and disclosure of data without authorization.
Gives patients rights, including right to view and correct records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Who enforces HIPAA

A

HHS OCR (Office of Civil Rights)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Where are privacy standards and practices documented for HIPAA

A

Privacy policy and procedures document

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

HIPAA compliance retention period

A

6 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

HIPAA privacy rule requires…

A

Privacy official
Process for privacy complaints
Training
Implementing reasonable safeguards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

PHI Disclosure (3)

A

Sharing with 3rd parties
Only to provide services
Patients must consent (with a few exceptions)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

HIPAA Authorizations requests must be specific

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

HIPAA Privacy Notice

A

Describes how data is used and shared
Privacy practices
Patients rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

HIPAA Acknowledgment or receiving privacy notice

A

Good faith effort required

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Patients may access their records except…

A

Psychotherapy notes
Info regarding legal action
Certain restricted lab results covered by CLIA
If it will cause a person to harm themselves or others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

HIPAA Hybrid entities

A

Only part of a business is covered by HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

HIPAA personal representatives

A

Basically, healthcare proxies. Also, parents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

HIPAA Preemption

A

State laws may not be weaker than HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

HIPAA Voluntary Compliance

A

30 days to remediate as long as there wasn’t willful neglect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

HIPAA fines range

A

$100-$50,000 per violation
$1.5 million/year for repeated violations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

HIPAA criminal penalties

A

Up to 1 year in prison or up to 10 years
Up to $50K or up to $250K

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

HIPAA Security Rule protects…

A

ePHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

HIPAA Security Rule purpose

A

Information security framework for HIPAA compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

HIPAA RIsk analysis

A

Required to find risks, severity of risks, and probability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

EHR

A

Electronic Health Records (HITECH)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

HITECH encourages implementing…

A

EHR’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

HITECH Breach notification rule

A

Triggered when any unauthorized use or access of PHI occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

HITECH breach notification factors (4)

A

Type of information and if patients are identified
Who the data was disclosed to. (Hacker vs. wrong doctor)
Likelihood that data was accessed/shared. (Unread email scenario)
How PHI is secured. (Inaccessible due to encryption)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

HITECH breach notification thresholds

A

60 days
The media if it’s more than 500 people in a state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

HITECH breach notification to HHS requirements

A

60 days for more than 500 people
Annually for less than 500 people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

HITECH Business Associate breach notification requirements

A

60 days. Then covered entity notifies patients

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Information blocking (21st century Cures Act)

A

Attempts to block lawful sharing of data between doctors or with patients

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

CURES act benefits

A

Exempts medical data from FOIA
Easier remote access of medical data
Increased confidentiality for research participants

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Confidentiality of substance use disorder patient rule

A

Protects records from law enforcement with a few exceptions
Fines and possible criminal prosecution for violators

50
Q

FCRA regulates…

A

Consumer reporting agencies

51
Q

CRA’s are

A

agency that provides reports about individual consumers

52
Q

What are these a factor of?

Creditworthiness
Credit standing
Credit capacity
Character
General reputation
Personal characteristics
Mode of living

A

Credit report

53
Q

3 well known CRA’s

A

Experian
Equifax
Transunion

54
Q

FCRA requires CRA’s to…

A

Maintain accurate reports
Determining when reports can be shared
Properly managing information in credit reports

55
Q

FCRA grants rights…

A

Right to requests reports
Right to be told about anything negative to make unfavorable decisions
Rights to control how report is shared

56
Q

Unfavorable credit reports must include…

A

Contact info for the CRA
Explanation of consumer rights
Right to dispute anything incorrect

57
Q

Who enforces FCRA?

A

FTC , CFPB, state AG’s

58
Q

FACTA

A

2003 update to FCRA

59
Q

FACTA’s most famous benefit

A

Free annual credit report

60
Q

FACTA benefits (4)

A

Free credit reports
Fraud alerts placed on reports
Creditors must verify identity before checking credit.
Enhanced dispute rights

61
Q

Financial Services Modernization Act of 1999 aka

A

GLBA

62
Q

What qualifies as a “financial institution” under GLBA?

A

“Significantly involved” in financial services.

63
Q

GLBA privacy rule

A

Financial institutions must share privacy notice annually

64
Q

GLBA privacy notice requirements

A

Privacy policy
Disclose how consumer info is collected, used, and shared.
List of 3rd parties with access to data

65
Q

GLBA customer vs. consumers

A

Customers have an ongoing relationship.
Consumers conduct isolated transactions (one offs like cashing checks)

66
Q

GLBA customer vs. consumers notification requirements

A

Customers get full privacy notice
Consumers get pointed to privacy notice

67
Q

GLBA Safeguards rule

A

Covers security practices

68
Q

GLBA Safeguards rule requires

A

Security program
Anticipate threats and take actions to prevent them
Risk management
3rd Party Risk Management
Designated security personnel

69
Q

GLBA 3 catagories of security controls

A

Training
Security Information Systems
Monitoring

70
Q

GLBA Red Flags Rule

A

Creditors monitor consumer data for identity theft red flags

71
Q

Red Flags Rule enforcement

A

SEC and CFTC for entities they regulate. Otherwise, FTC, CFPB, State AG

72
Q

Law that is a good example of shared regulatory authority

A

Red Flag Rule

73
Q

Dodd Frank centralized rulemaking for GLBA, FCRA/FACTA under what agency?

A

CFPB

74
Q

Abusive practices

A

Practices that abuse misunderstanding by consumers.
Material interference with consumers ability to understand terms of a consumer financial product

75
Q

FERPA applies to which records for what institutions?

A

Academic records for schools receiving federal funding

76
Q

FERPA protects which records (2)

A

Student
3rd party records about a student

77
Q

FERPA protected records (6)

A

Grades
Class rosters
Schedules
Health records
Financial info for higher ed students
Disciplinary records

78
Q

FERPA excludes… (3)

A

Law enforcement records
Some application data
Applicant data from non-students

79
Q

FERPA data disclosure requires…

A

Consent or anonymization

80
Q

TCPA
TSR

A

Telephone consumer protection act
Telemarketing Sales Rule

81
Q

TCPA regulates

A

Unsolicited sales and marketing calls (including autodialers and robocalls)
Texts

82
Q

Which agency issued TSR?

A

FTC

83
Q

TSR regulated by

A

FTC and FCC since FCC has jurisdiction for telemarketing

84
Q

UDAAP’s

A

Unfair, Deceptive, Abusive Acts

85
Q

Established Business Relationship Exemption (EBR)

A

Customer that has completed a purchase in last 18 months

86
Q

TSR applies to…

A

Telemarketing firms

87
Q

TSR Exemptions

A

Financial institutions
Non-profits
Airlines
Long distance phone providers
Certain insurance and investment sales activities

88
Q

TSR calling rules

A

8AM-9PM
Valid caller ID
Connect to a live person within 2 seconds
Must identify as a sales call
Written permission for robocalls

89
Q

DNC

A

Do Not Call Registry

90
Q

DNC prohibits…

A

Sales and marketing calls

91
Q

DNC exceptions

A

Politics
Charities
some non-profit
Surveys
Existing customers

92
Q

How often must DNC be updated?

A

31 days at telemarketers expense

93
Q

What is required to call someone on the DNC list?

A

Written permission

94
Q

Who enforces DNC? (3)

A

FTC
FCC
States

95
Q

DNC fines (FTC/FCC and States)

A

Fed: Up to $43,000
States: Up to $25,000

96
Q

JFPA

A

Junk Fax Prevention Act

97
Q

JFPA fine

A

$500-$1500 per page

98
Q

CAN-SPAM Act commercial messages

A

Advertising or promitional

99
Q

CAN-SPAM message “primary purpose”

A

If a reasonable person thinks the primary purpose is commercial, CAN-SPAM applies

100
Q

CAN-SPAM electronic messages

A

Not limited to email. Ex. Facebook messenger

101
Q

CAN-SPAM applies to:

A

All senders (not just businesses)

102
Q

CAN-SPAM sender requirements

A

Inform about advertising purpose
Identify sender
Share senders physical location
Prohibits deceiving recipients
Simple opt-out

103
Q

CAN-SPAM Opt-out requirements

A

Opt out up to 30 days from sending the message
10 days to cease all commercial messages
Not selling email address (keeping it private)

104
Q

rCAN-SPAM enforced by…

A

FTC

105
Q

CAN-SPAM ISP Rights

A

May take action if they are harmed

106
Q

CAN-SPAM federal pre-emption

A

Doesn’t allow stricter laws

107
Q

Wireless domain registry

A

Domain names that may not receive unsolicited email because they go to handheld devices

108
Q

Wireless domain registry update time requirement

A

Within 30 days by wireless carriers

109
Q

CPNI

A

Telephone call metadata

110
Q

Consent requirement for sharing CPNI

A

Consent required

111
Q

CPNI breach reporting

A

7 days to Law Enforcement
Then subscribers

112
Q

FCC excludes what from CPNI?

A

Text messages (information services)

113
Q

Cable Communications Policy Act

A

Consent required to collect PII (except to deliver services and block theft)

114
Q

Cable Comms Policy act notification requirements

A

At sign up and then annually

115
Q

Cable Communications Policy Act enforced by…

A

Multiple agencies
Private right of Action

116
Q

VPPA

A

Video Privacy Protection Act

117
Q

VPPA protects

A

PII collected by a Videotape Service Provider

118
Q

Videotape service provider includes…

A

Streamers

119
Q

Videotape service providers are allowed to share…

A

Customer names and addresses

120
Q

VPPA enforced by…

A

Private right of action