WGU D485 DGN2 TASK 1 EXAM PAPER
WITH DETAILED QUESTIONS AND
RELIABLE ANSWERS
◉ HIPAA (Health Insurance Portability and Accountability Act)
Answer: 1996 law protecting PHI and ePHI. Applies to healthcare
providers, health plans, clearinghouses, and business associates.
Privacy Rule + Security Rule. Enforced by HHS OCR.
◉ PHI (Protected Health Information)
Answer: Medical information pertaining to patient health.
Protected by HIPAA. Includes records, conversations, billing info.
◉ ePHI (Electronic Protected Health Information)
Answer: Any PHI stored or transmitted electronically. Protected
by both HIPAA Privacy Rule and Security Rule.
◉ BAA (Business Associate Agreement)
Answer: Required under HIPAA. Written contract with any third
party that handles PHI on behalf of a covered entity, requiring
HIPAA compliance.
◉ HIPAA Privacy Rule
,Answer: Establishes guidelines for protecting privacy of PHI.
Limits use and disclosure without patient authorization. Gives
patients right to view and correct records.
◉ HIPAA Security Rule
Answer: Applies to ePHI only (not all PHI). Requires covered
entities to safeguard confidentiality, integrity, and availability of
ePHI.
◉ HITECH Act (Health Information Technology for Economic and
Clinical Health Act)
Answer: 2009 law expanding HIPAA. Added Breach Notification
Rule. Must notify affected individuals within 60 days of
discovering a breach.
◉ HITECH Breach Notification Rule
Answer: If breach affects 500+ individuals in a state, must also
notify media. If 500+ total, must notify HHS within 60 days.
Business associates must notify covered entity within 60 days.
◉ GLBA (Gramm-Leach-Bliley Act)
Answer: 1999 law for financial institutions significantly engaged
in financial services. Three rules: Financial Privacy Rule,
Safeguards Rule, Pretexting Protection.
◉ GLBA — Financial Privacy Rule
, Answer: Financial institutions must provide annual privacy
notices to customers explaining how their information is
collected, used, and shared.
◉ GLBA — Safeguards Rule
Answer: Requires financial institutions to implement an
organized information security program. Three control
categories: workforce training, securing systems, ongoing
monitoring.
◉ GLBA — Customers vs Consumers
Answer: Customers have ongoing relationship with institution —
receive full privacy notice. Consumers conduct isolated
transactions — receive summary notice only.
◉ SOX (Sarbanes-Oxley Act)
Answer: 2002 law for all publicly traded US corporations. Enacted
after Enron scandal. Requires accurate financial reporting and
executive accountability. Enforced by SEC.
◉ CLOUD Act (Clarifying Lawful Overseas Use of Data Act)
Answer: 2018 US law allowing law enforcement to compel US-
based cloud providers to hand over data stored overseas. Physical
location does not protect data from US government.
◉ FERPA (Family Educational Rights and Privacy Act)
WITH DETAILED QUESTIONS AND
RELIABLE ANSWERS
◉ HIPAA (Health Insurance Portability and Accountability Act)
Answer: 1996 law protecting PHI and ePHI. Applies to healthcare
providers, health plans, clearinghouses, and business associates.
Privacy Rule + Security Rule. Enforced by HHS OCR.
◉ PHI (Protected Health Information)
Answer: Medical information pertaining to patient health.
Protected by HIPAA. Includes records, conversations, billing info.
◉ ePHI (Electronic Protected Health Information)
Answer: Any PHI stored or transmitted electronically. Protected
by both HIPAA Privacy Rule and Security Rule.
◉ BAA (Business Associate Agreement)
Answer: Required under HIPAA. Written contract with any third
party that handles PHI on behalf of a covered entity, requiring
HIPAA compliance.
◉ HIPAA Privacy Rule
,Answer: Establishes guidelines for protecting privacy of PHI.
Limits use and disclosure without patient authorization. Gives
patients right to view and correct records.
◉ HIPAA Security Rule
Answer: Applies to ePHI only (not all PHI). Requires covered
entities to safeguard confidentiality, integrity, and availability of
ePHI.
◉ HITECH Act (Health Information Technology for Economic and
Clinical Health Act)
Answer: 2009 law expanding HIPAA. Added Breach Notification
Rule. Must notify affected individuals within 60 days of
discovering a breach.
◉ HITECH Breach Notification Rule
Answer: If breach affects 500+ individuals in a state, must also
notify media. If 500+ total, must notify HHS within 60 days.
Business associates must notify covered entity within 60 days.
◉ GLBA (Gramm-Leach-Bliley Act)
Answer: 1999 law for financial institutions significantly engaged
in financial services. Three rules: Financial Privacy Rule,
Safeguards Rule, Pretexting Protection.
◉ GLBA — Financial Privacy Rule
, Answer: Financial institutions must provide annual privacy
notices to customers explaining how their information is
collected, used, and shared.
◉ GLBA — Safeguards Rule
Answer: Requires financial institutions to implement an
organized information security program. Three control
categories: workforce training, securing systems, ongoing
monitoring.
◉ GLBA — Customers vs Consumers
Answer: Customers have ongoing relationship with institution —
receive full privacy notice. Consumers conduct isolated
transactions — receive summary notice only.
◉ SOX (Sarbanes-Oxley Act)
Answer: 2002 law for all publicly traded US corporations. Enacted
after Enron scandal. Requires accurate financial reporting and
executive accountability. Enforced by SEC.
◉ CLOUD Act (Clarifying Lawful Overseas Use of Data Act)
Answer: 2018 US law allowing law enforcement to compel US-
based cloud providers to hand over data stored overseas. Physical
location does not protect data from US government.
◉ FERPA (Family Educational Rights and Privacy Act)