Module 3 - Privacy and HIPAA Flashcards

1
Q

Two laws related to PII

A

Privacy Act of 1974

HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Privacy Act of 1974 (goals)

A
  1. to limit the amount of information that is recorded,
  2. ensure that Federal agencies that collect personal records have the appropriate
    authority,
  3. protect the information that is recorded, and
  4. give citizens the opportunity to review information and a means to change
    incorrect entries.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

HIPAA

A

Health Insurance Portability and Accountability Act

  • gave the U.S. Department of Health and Human Services (HHS) the ability to establish privacy regulations.
  • The Act was designed to protect health-related information (past, present, and future), which could be used to identify individuals.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Other Documents / Guidance Documents (4)

A
  • Appendix J of NIST’s Special Publication 800-53
  • Office of Management and Budget (OMB) Memorandum M-03-22
  • Executive Office Memorandum 99-18 for posting Privacy policies on the Internet
  • The EU Privacy Directive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Privacy Act of 1974 (purpose)

A

response to the creation of databases and the impact on individual privacy

exemptions:
- government law enforcement agencies
- excuse through “routine use” exemption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
Privacy Act Definitions:
Individual
Maintain
Record
System of Records
Statistical Records
Routine Use
Matching Program
Recipient Agency
A

10 or more records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Privacy Act Accounting for Disclosures

A
  • maintain accounting of: date, nature, and purpose of each disclosure.
  • retain for at least five years, or the life of the record
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Privacy Act Access to Records

A
  • individual can gain access to his record
  • permit individual to request amendment of a record
  • permit the individual who disagrees
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

System of Records Notice

A

SORN - Federal Register

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Agency Requirements

A

Privacy Officer
Privacy Training
Privacy Act Systems of Records
System of Records Notice (SORN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Privacy Impact Assessment

A

PIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Certification & Accreditation process

A

-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

NIST 800-53 appendix J

A

Privacy Controls - best practices

risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Privacy Practices Notice

A

-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly