Module 11: Civil Litigation and Government Investigations Flashcards
List the two main sources of privacy issues that arise when a company is responding to civil litigation
- Before trial, a company may receive civil “discovery” requests (These are requests for information by each party in a lawsuit)
- At a civil trial, the tradition of public records in the United States means that additional personal information may be revealed
Explain the involvement of privacy professionals in the common company practice of disclosure of personal information in response to litigation requests
Will need to come back to this one.
Discuss the main complexity in understanding the requirements in laws concerning whether an organization can release personal information in response to a request
Sometimes the same statute requires production of information in some circumstances, such as when a judge issues a court order, but prohibits production of the same information in other circumstances, such as when no court order exists
List at least two legal avenues that require a company to release personal information
- Certain U.S. laws require disclosure of personal information held by an organization
- Outside of these regulatory systems, records sometimes must be disclosed in the course of litigation
Define the concept of discovery as it pertains to civil litigation
In litigation, discovery essentially means information disclosed to another party in a lawsuit before trial - subject to rules of civil procedure
Describe the term subpoena
Companies with information relevant to civil litigation may receive a subpoena, which is an instruction to produce a witness or records
Explain the potential consequences of failing to respond to a subpoena
The court that issued a subpoena may hold in contempt any person who fails to appropriately respond to the subpoena - without an adequate excuse (Contempt of court can result in fines or imprisonment)
Name at least two federal laws that permit, but do not require, disclosure under appropriate circumstances
Under appropriate circumstances, HIPAA and the USA PATRIOT Act permit, but do not require, disclose of personal information
Name at least two federal laws that forbid disclosure in certain circumstances
HIPAA and GLBA forbid disclose of personal information in at least certain circumstances
List common evidentiary privileges that can prohibit disclosure
Common evidentiary privileges that can prohibit disclosure include
- Attorney-client privilege
- Doctor-patient
- Priest-penitent
- Spousal privilege
Name the amendment to the U.S. Constitution that protects an accused person from self-incrimination
A person accused of a crime in state or federal court can assert the privilege against self-incrimination under the Fifth Amendment to the U.S. Constitution
Name the laws that helped to created a strong tradition of public access to government records in the U.S.
The U.S. has a strong tradition of public access to government records, including under the federal Freedom of Information Act (FOIA) and state open records laws
Explain how changes in technology led to heightened privacy concerns regarding public court records
With the growth of the Internet, court systems began to consider putting their records online, and placing court records on the Internet raised privacy issues
Explain the purpose of a protective order
With a protective order, a judge determines what personal information should not be made public and what conditions apply to those who may access the protected information
Define the term qualified protective order
A QPO prohibits the parties from using or disclosing the protected health information for any purpose other than the litigation
Discuss the meaning of the term redaction
Redaction is the practice of identifying and removing or blocking information from documents being produced pursuant to a discovery request or as evidence in a court proceeding
Describe the significance of the Sedona Conference to e-discovery
An important source of standards and best practices for managing electronic discovery compliance through data retention policies is the Sedona Conference