Chapter 5: Private Sector Data Collection Flashcards

1
Q

COPPA applies to… (3)

A

Online services intended for children
General online services where the operator knows they are gathering childrens data
Online services knowingly collecting children’s data from other online services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

COPPA Online Services examples

A

Websites
Mobile apps
Smart Devices
etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who enforces COPPA?

A

FTC
States
Specific agencies in their context

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

COPPA PI

A

Names
Addresses
SSN
Phone numbers
Screen names
geolocation
Media of a child’s image or voice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

COPPA protects…

A

PI and any info combined with PI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Parents rights under COPPA

A

Consent
Revoking consent
Deletion
Limit collection to necessary information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

COPPA 3rd party restriction

A

Parents can’t be forced to allow collection by 3rd parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

COPPA requirements for online services

A

Privacy Policies that meet COPPA requirements
Parental notification
Parental consent
Maintain way for parents to exercise their rights
Information security program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COPPA consent requirements

A

Consent form (including paper)
Validate parents identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

COPPA maximum fine

A

$43,280 per violation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data Brokers

A

Buy datasets to be resold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Machine learning

A

Computer learns without human interaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

PHI

A

Personal Health Information. Medical info including records by insurance companies and billing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ePHI

A

Medical records transferred electronically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HIPAA applies to…

A

Covered entities and covered transactions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

HIPAA covered entities (3)

A

Insurance plans
Clearinghouses
Healthcare providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Healthcare clearinghouse

A

Manages the sharing of healthcare info by standardizing data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

HIPAA business associates

A

3rd party of a covered entity that works with PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

HIPAA Business Associate Agreements

A

Agreements between covered entities and 3rd parties ensuring conformance with HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

HIPAA doesn’t cover

A

Personel records
Academic records
Anonymized records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

HIPAA privacy rule (3)

A

Requires privacy practices
Limites use and disclosure of data without authorization.
Gives patients rights, including right to view and correct records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Who enforces HIPAA

A

HHS OCR (Office of Civil Rights)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Where are privacy standards and practices documented for HIPAA

A

Privacy policy and procedures document

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

HIPAA compliance retention period

A

6 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
HIPAA privacy rule requires...
Privacy official Process for privacy complaints Training Implementing reasonable safeguards
26
PHI Disclosure (3)
Sharing with 3rd parties Only to provide services Patients must consent (with a few exceptions)
27
HIPAA Authorizations requests must be specific
True
28
HIPAA Privacy Notice
Describes how data is used and shared Privacy practices Patients rights
29
HIPAA Acknowledgment or receiving privacy notice
Good faith effort required
30
Patients may access their records except...
Psychotherapy notes Info regarding legal action Certain restricted lab results covered by CLIA If it will cause a person to harm themselves or others
31
HIPAA Hybrid entities
Only part of a business is covered by HIPAA
32
HIPAA personal representatives
Basically, healthcare proxies. Also, parents
33
HIPAA Preemption
State laws may not be weaker than HIPAA
34
HIPAA Voluntary Compliance
30 days to remediate as long as there wasn't willful neglect
35
HIPAA fines range
$100-$50,000 per violation $1.5 million/year for repeated violations
36
HIPAA criminal penalties
Up to 1 year in prison or up to 10 years Up to $50K or up to $250K
37
HIPAA Security Rule protects...
ePHI
38
HIPAA Security Rule purpose
Information security framework for HIPAA compliance
39
HIPAA RIsk analysis
Required to find risks, severity of risks, and probability.
40
EHR
Electronic Health Records (HITECH)
41
HITECH encourages implementing...
EHR's
42
HITECH Breach notification rule
Triggered when any unauthorized use or access of PHI occurs
43
HITECH breach notification factors (4)
Type of information and if patients are identified Who the data was disclosed to. (Hacker vs. wrong doctor) Likelihood that data was accessed/shared. (Unread email scenario) How PHI is secured. (Inaccessible due to encryption)
44
HITECH breach notification thresholds
60 days The media if it's more than 500 people in a state
45
HITECH breach notification to HHS requirements
60 days for more than 500 people Annually for less than 500 people
46
HITECH Business Associate breach notification requirements
60 days. Then covered entity notifies patients
47
Information blocking (21st century Cures Act)
Attempts to block lawful sharing of data between doctors or with patients
48
CURES act benefits
Exempts medical data from FOIA Easier remote access of medical data Increased confidentiality for research participants
49
Confidentiality of substance use disorder patient rule
Protects records from law enforcement with a few exceptions Fines and possible criminal prosecution for violators
50
FCRA regulates...
Consumer reporting agencies
51
CRA's are
agency that provides reports about individual consumers
52
What are these a factor of? Creditworthiness Credit standing Credit capacity Character General reputation Personal characteristics Mode of living
Credit report
53
3 well known CRA's
Experian Equifax Transunion
54
FCRA requires CRA's to...
Maintain accurate reports Determining when reports can be shared Properly managing information in credit reports
55
FCRA grants rights...
Right to requests reports Right to be told about anything negative to make unfavorable decisions Rights to control how report is shared
56
Unfavorable credit reports must include...
Contact info for the CRA Explanation of consumer rights Right to dispute anything incorrect
57
Who enforces FCRA?
FTC , CFPB, state AG's
58
FACTA
2003 update to FCRA
59
FACTA's most famous benefit
Free annual credit report
60
FACTA benefits (4)
Free credit reports Fraud alerts placed on reports Creditors must verify identity before checking credit. Enhanced dispute rights
61
Financial Services Modernization Act of 1999 aka
GLBA
62
What qualifies as a "financial institution" under GLBA?
"Significantly involved" in financial services.
63
GLBA privacy rule
Financial institutions must share privacy notice annually
64
GLBA privacy notice requirements
Privacy policy Disclose how consumer info is collected, used, and shared. List of 3rd parties with access to data
65
GLBA customer vs. consumers
Customers have an ongoing relationship. Consumers conduct isolated transactions (one offs like cashing checks)
66
GLBA customer vs. consumers notification requirements
Customers get full privacy notice Consumers get pointed to privacy notice
67
GLBA Safeguards rule
Covers security practices
68
GLBA Safeguards rule requires
Security program Anticipate threats and take actions to prevent them Risk management 3rd Party Risk Management Designated security personnel
69
GLBA 3 catagories of security controls
Training Security Information Systems Monitoring
70
GLBA Red Flags Rule
Creditors monitor consumer data for identity theft red flags
71
Red Flags Rule enforcement
SEC and CFTC for entities they regulate. Otherwise, FTC, CFPB, State AG
72
Law that is a good example of shared regulatory authority
Red Flag Rule
73
Dodd Frank centralized rulemaking for GLBA, FCRA/FACTA under what agency?
CFPB
74
Abusive practices
Practices that abuse misunderstanding by consumers. Material interference with consumers ability to understand terms of a consumer financial product
75
FERPA applies to which records for what institutions?
Academic records for schools receiving federal funding
76
FERPA protects which records (2)
Student 3rd party records about a student
77
FERPA protected records (6)
Grades Class rosters Schedules Health records Financial info for higher ed students Disciplinary records
78
FERPA excludes... (3)
Law enforcement records Some application data Applicant data from non-students
79
FERPA data disclosure requires...
Consent or anonymization
80
TCPA TSR
Telephone consumer protection act Telemarketing Sales Rule
81
TCPA regulates
Unsolicited sales and marketing calls (including autodialers and robocalls) Texts
82
Which agency issued TSR?
FTC
83
TSR regulated by
FTC and FCC since FCC has jurisdiction for telemarketing
84
UDAAP's
Unfair, Deceptive, Abusive Acts
85
Established Business Relationship Exemption (EBR)
Customer that has completed a purchase in last 18 months
86
TSR applies to...
Telemarketing firms
87
TSR Exemptions
Financial institutions Non-profits Airlines Long distance phone providers Certain insurance and investment sales activities
88
TSR calling rules
8AM-9PM Valid caller ID Connect to a live person within 2 seconds Must identify as a sales call Written permission for robocalls
89
DNC
Do Not Call Registry
90
DNC prohibits...
Sales and marketing calls
91
DNC exceptions
Politics Charities some non-profit Surveys Existing customers
92
How often must DNC be updated?
31 days at telemarketers expense
93
What is required to call someone on the DNC list?
Written permission
94
Who enforces DNC? (3)
FTC FCC States
95
DNC fines (FTC/FCC and States)
Fed: Up to $43,000 States: Up to $25,000
96
JFPA
Junk Fax Prevention Act
97
JFPA fine
$500-$1500 per page
98
CAN-SPAM Act commercial messages
Advertising or promitional
99
CAN-SPAM message "primary purpose"
If a reasonable person thinks the primary purpose is commercial, CAN-SPAM applies
100
CAN-SPAM electronic messages
Not limited to email. Ex. Facebook messenger
101
CAN-SPAM applies to:
All senders (not just businesses)
102
CAN-SPAM sender requirements
Inform about advertising purpose Identify sender Share senders physical location Prohibits deceiving recipients Simple opt-out
103
CAN-SPAM Opt-out requirements
Opt out up to 30 days from sending the message 10 days to cease all commercial messages Not selling email address (keeping it private)
104
rCAN-SPAM enforced by...
FTC
105
CAN-SPAM ISP Rights
May take action if they are harmed
106
CAN-SPAM federal pre-emption
Doesn't allow stricter laws
107
Wireless domain registry
Domain names that may not receive unsolicited email because they go to handheld devices
108
Wireless domain registry update time requirement
Within 30 days by wireless carriers
109
CPNI
Telephone call metadata
110
Consent requirement for sharing CPNI
Consent required
111
CPNI breach reporting
7 days to Law Enforcement Then subscribers
112
FCC excludes what from CPNI?
Text messages (information services)
113
Cable Communications Policy Act
Consent required to collect PII (except to deliver services and block theft)
114
Cable Comms Policy act notification requirements
At sign up and then annually
115
Cable Communications Policy Act enforced by...
Multiple agencies Private right of Action
116
VPPA
Video Privacy Protection Act
117
VPPA protects
PII collected by a Videotape Service Provider
118
Videotape service provider includes...
Streamers
119
Videotape service providers are allowed to share...
Customer names and addresses
120
VPPA enforced by...
Private right of action