CIPP-US - Limits on Private-Sector Collection and Use of Data (31% of the exam) - Section 2.2

Explain HIPAA's Privacy Rule and Security Rule requirements, permissible uses and disclosures, and the HITECH Act's breach notification obligations.

Describe the HIPAA Privacy Rule's framework for permissible uses and disclosures of protected health information (PHI) by covered entities and business associates, and the Security Rule's administrative, physical, and technical safeguards for electronic PHI. Apply HITECH breach notification requirements to determine when and to whom a covered entity must report an impermissible disclosure.

HIPAA Privacy RulePHICovered entityHITECH breach notification

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datahard

A compliance officer at a covered clinic is structuring the clinic's protections for electronic protected health information so that they map cleanly onto the categories of safeguards the HIPAA Security Rule requires. Which three categories of safeguards does the Security Rule require the clinic to implement for electronic PHI? (Select THREE.)

  • AAdministrative safeguards, such as a security management process, workforce training, and assignment of a security official. Correct
  • BPhysical safeguards, such as facility access controls and rules for workstation use and device and media disposal. Correct
  • CTechnical safeguards, such as access controls, audit controls, integrity controls, and transmission security. Correct
  • DFinancial safeguards, such as cyber-insurance coverage and a funded reserve sized to the cost of a notifiable breach.
  • EContractual safeguards, such as business associate agreements that by themselves satisfy the Rule's safeguard obligations for the clinic.
The HIPAA Security Rule organises protection of electronic PHI into three required categories: administrative, physical, and technical safeguards. The Security Rule structures its standards into administrative, physical, and technical safeguards, each addressing a distinct layer of protection for electronic PHI; financial and contractual safeguards are not categories the Rule defines, so options invoking insurance reserves or treating a business associate agreement as a standalone safeguard misstate the framework.

Why A is correct: Administrative safeguards are one of the three required categories and cover the policies, risk management, and personnel measures that govern security.

Why B is correct: Physical safeguards are a required category covering protection of facilities, workstations, and the devices and media that hold electronic PHI.

Why C is correct: Technical safeguards are a required category governing the technology that controls and monitors access to electronic PHI.

Why D is wrong: The Security Rule defines administrative, physical, and technical safeguards; it does not establish a financial safeguards category or mandate insurance reserves.

Why E is wrong: Business associate agreements are required where applicable but are not one of the Security Rule's three safeguard categories and do not discharge the clinic's own safeguard duties.

See more CIPP-US practice questions, answers explained.

Exam traps in Limits on Private-Sector Collection and Use of Data

Answers that look right on this material and are not. Each one is a distractor from a different question in the CIPP-US bank for this domain.

  • It governs PHI in every form, including paper and oral communications, and requires a single uniform technology stack that every covered entity must deploy identically.

    Why it is wrong: Tempting because security feels all-encompassing, but the Security Rule applies only to electronic PHI and is technology-neutral and scalable rather than prescribing one identical stack, so both clauses are wrong.

  • New written authorisations are required from every affected patient before the acquirer may use any of the acquired protected health information, because a change of ownership voids all prior permissions to use the records.

    Why it is wrong: This is tempting because authorisation is the default for many uses, but the Privacy Rule treats treatment, payment, and operations as permitted without authorisation, so a blanket re-authorisation requirement misstates the rule.

  • It relied on a notice of privacy practices instead of obtaining patient authorisations for each electronic disclosure of records.

    Why it is wrong: This conflates Privacy Rule concepts with the Security Rule; the gap here concerns securing electronic PHI, not authorisations for disclosure.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.