FFM - Maintaining Compliance Test with
Complete Solutions 2025
What may Agents or brokers may create, collect, disclose, access, maintain, store,
and use? - ANSWER PII
Fraud or Abuse - As you provide assistance to clients seeking health coverage, you play
an important role in observing and reporting any potentially fraudulent practices
taking place in relation to the Marketplace. Examples of potential fraud or abuse
include - ANSWER A client tells you they have been contacted by an individual seeking
their personal and financial information.
An individual or agent/broker submits false documentation to the Marketplace.
An agent or broker is conducting person searches or enrolling consumers without their
consent.
An agent or broker is assisting consumers without a valid license or without
completing FFM registration.
An individual or agent/broker has disclosed a consumer's PII.
An individual or agent/broker discovers unauthorized changes were made to a
consumer's online application.
, An individual suspects a consumer or insurance company is providing false or
misleading information to the Marketplace.
What is a Breach? - ANSWER A breach is the loss of control, compromise, unauthorized
disclosure, unauthorized acquisition, or any similar occurrence where (1) a person
other than an authorized user accesses or potentially accesses PII or (2) an authorized
user accesses PII for any other reason than authorized purpose.
Agents and brokers must have written procedures for incident handling and breach
notification. These procedures must be consistent with CMS' Incident and Breach
Notification Procedures documented in Risk Management Handbook (RMH) Chapter 08:
Incident Response(opens in a new tab), and must - ANSWER Provide details regarding the
identification, response, recovery, and follow-up of incidents and breaches, which should
include information regarding the potential need for CMS to immediately suspend or
revoke access to the Federal Data Services Hub for containment purposes.
The Individual Marketplace Privacy and Security Agreement requires reporting any
Incident or Breach of PII to the CMS IT Service Desk by telephone at (410) 786-2580 or 1-
800-562-1963 or via email notification at within 24
hours of discovery.
Shortly after Open Enrollment ends, you receive a call from one of your long-time
clients, Eduardo, who explains that he was recently contacted by an individual who
claimed to work with your agency. The individual told Eduardo there was an issue
with his payment that prevented his coverage from being effectuated. The individual
asked Eduardo to provide personal and financial information over the phone so they
could effectuate his Marketplace coverage. You reassure Eduardo that his coverage is
effectuated, and this individual was not part of your agency. Since Eduardo did not
provide any of his personal or financial information, should this incident be reported?
Yes, all fraudulent activity should be reported
Complete Solutions 2025
What may Agents or brokers may create, collect, disclose, access, maintain, store,
and use? - ANSWER PII
Fraud or Abuse - As you provide assistance to clients seeking health coverage, you play
an important role in observing and reporting any potentially fraudulent practices
taking place in relation to the Marketplace. Examples of potential fraud or abuse
include - ANSWER A client tells you they have been contacted by an individual seeking
their personal and financial information.
An individual or agent/broker submits false documentation to the Marketplace.
An agent or broker is conducting person searches or enrolling consumers without their
consent.
An agent or broker is assisting consumers without a valid license or without
completing FFM registration.
An individual or agent/broker has disclosed a consumer's PII.
An individual or agent/broker discovers unauthorized changes were made to a
consumer's online application.
, An individual suspects a consumer or insurance company is providing false or
misleading information to the Marketplace.
What is a Breach? - ANSWER A breach is the loss of control, compromise, unauthorized
disclosure, unauthorized acquisition, or any similar occurrence where (1) a person
other than an authorized user accesses or potentially accesses PII or (2) an authorized
user accesses PII for any other reason than authorized purpose.
Agents and brokers must have written procedures for incident handling and breach
notification. These procedures must be consistent with CMS' Incident and Breach
Notification Procedures documented in Risk Management Handbook (RMH) Chapter 08:
Incident Response(opens in a new tab), and must - ANSWER Provide details regarding the
identification, response, recovery, and follow-up of incidents and breaches, which should
include information regarding the potential need for CMS to immediately suspend or
revoke access to the Federal Data Services Hub for containment purposes.
The Individual Marketplace Privacy and Security Agreement requires reporting any
Incident or Breach of PII to the CMS IT Service Desk by telephone at (410) 786-2580 or 1-
800-562-1963 or via email notification at within 24
hours of discovery.
Shortly after Open Enrollment ends, you receive a call from one of your long-time
clients, Eduardo, who explains that he was recently contacted by an individual who
claimed to work with your agency. The individual told Eduardo there was an issue
with his payment that prevented his coverage from being effectuated. The individual
asked Eduardo to provide personal and financial information over the phone so they
could effectuate his Marketplace coverage. You reassure Eduardo that his coverage is
effectuated, and this individual was not part of your agency. Since Eduardo did not
provide any of his personal or financial information, should this incident be reported?
Yes, all fraudulent activity should be reported