WGU D320 CORRECT EXAMS REVIEW QUESTIONS
AND ANSWERS SURE A+
✔✔Common Law - ✔✔Long-standing judicial precedents passed down through
generations. Not codified in legislation. Includes torts like negligence and invasion of
privacy.
✔✔Stare Decisis - ✔✔Legal principle meaning 'let the decision stand.' Prior court
decisions serve as precedent guiding future decisions.
✔✔Mens Rea - ✔✔Latin for 'guilty mind.' Criminal intent required for criminal liability.
Person must have intended to commit a crime.
✔✔Criminal Liability - ✔✔Violation of criminal law. Government brings charges.
Requires mens rea. Standard of proof: beyond a reasonable doubt.
✔✔Civil Liability - ✔✔One party claims another failed a legal duty. Brought by the
claimant. Standard: preponderance of the evidence (>50% likelihood).
✔✔Negligence (Tort) - ✔✔Civil violation where one party causes harm through action or
inaction. Requires: duty of care, breach of duty, damages, and causation.
✔✔Invasion of Privacy (Tort) - ✔✔Violation of reasonable expectation to be left alone.
Four types: invasion of solitude, public disclosure of private facts, false light,
appropriation.
✔✔Strict Liability - ✔✔A person is responsible for consequences of their actions even
without intent or negligence. No need to prove fault.
✔✔HIPAA (Health Insurance Portability and Accountability Act) - ✔✔1996 law
protecting PHI and ePHI. Applies to healthcare providers, health plans, clearinghouses,
and business associates. Privacy Rule + Security Rule. Enforced by HHS OCR.
, ✔✔PHI (Protected Health Information) - ✔✔Medical information pertaining to patient
health. Protected by HIPAA. Includes records, conversations, billing info.
✔✔ePHI (Electronic Protected Health Information) - ✔✔Any PHI stored or transmitted
electronically. Protected by both HIPAA Privacy Rule and Security Rule.
✔✔BAA (Business Associate Agreement) - ✔✔Required under HIPAA. Written contract
with any third party that handles PHI on behalf of a covered entity, requiring HIPAA
compliance.
✔✔HIPAA Privacy Rule - ✔✔Establishes guidelines for protecting privacy of PHI. Limits
use and disclosure without patient authorization. Gives patients right to view and correct
records.
✔✔HIPAA Security Rule - ✔✔Applies to ePHI only (not all PHI). Requires covered
entities to safeguard confidentiality, integrity, and availability of ePHI.
✔✔HITECH Act (Health Information Technology for Economic and Clinical Health Act) -
✔✔2009 law expanding HIPAA. Added Breach Notification Rule. Must notify affected
individuals within 60 days of discovering a breach.
✔✔HITECH Breach Notification Rule - ✔✔If breach affects 500+ individuals in a state,
must also notify media. If 500+ total, must notify HHS within 60 days. Business
associates must notify covered entity within 60 days.
✔✔GLBA (Gramm-Leach-Bliley Act) - ✔✔1999 law for financial institutions significantly
engaged in financial services. Three rules: Financial Privacy Rule, Safeguards Rule,
Pretexting Protection.
✔✔GLBA — Financial Privacy Rule - ✔✔Financial institutions must provide annual
privacy notices to customers explaining how their information is collected, used, and
shared.
✔✔GLBA — Safeguards Rule - ✔✔Requires financial institutions to implement an
organized information security program. Three control categories: workforce training,
securing systems, ongoing monitoring.
✔✔GLBA — Customers vs Consumers - ✔✔Customers have ongoing relationship with
institution — receive full privacy notice. Consumers conduct isolated transactions —
receive summary notice only.
AND ANSWERS SURE A+
✔✔Common Law - ✔✔Long-standing judicial precedents passed down through
generations. Not codified in legislation. Includes torts like negligence and invasion of
privacy.
✔✔Stare Decisis - ✔✔Legal principle meaning 'let the decision stand.' Prior court
decisions serve as precedent guiding future decisions.
✔✔Mens Rea - ✔✔Latin for 'guilty mind.' Criminal intent required for criminal liability.
Person must have intended to commit a crime.
✔✔Criminal Liability - ✔✔Violation of criminal law. Government brings charges.
Requires mens rea. Standard of proof: beyond a reasonable doubt.
✔✔Civil Liability - ✔✔One party claims another failed a legal duty. Brought by the
claimant. Standard: preponderance of the evidence (>50% likelihood).
✔✔Negligence (Tort) - ✔✔Civil violation where one party causes harm through action or
inaction. Requires: duty of care, breach of duty, damages, and causation.
✔✔Invasion of Privacy (Tort) - ✔✔Violation of reasonable expectation to be left alone.
Four types: invasion of solitude, public disclosure of private facts, false light,
appropriation.
✔✔Strict Liability - ✔✔A person is responsible for consequences of their actions even
without intent or negligence. No need to prove fault.
✔✔HIPAA (Health Insurance Portability and Accountability Act) - ✔✔1996 law
protecting PHI and ePHI. Applies to healthcare providers, health plans, clearinghouses,
and business associates. Privacy Rule + Security Rule. Enforced by HHS OCR.
, ✔✔PHI (Protected Health Information) - ✔✔Medical information pertaining to patient
health. Protected by HIPAA. Includes records, conversations, billing info.
✔✔ePHI (Electronic Protected Health Information) - ✔✔Any PHI stored or transmitted
electronically. Protected by both HIPAA Privacy Rule and Security Rule.
✔✔BAA (Business Associate Agreement) - ✔✔Required under HIPAA. Written contract
with any third party that handles PHI on behalf of a covered entity, requiring HIPAA
compliance.
✔✔HIPAA Privacy Rule - ✔✔Establishes guidelines for protecting privacy of PHI. Limits
use and disclosure without patient authorization. Gives patients right to view and correct
records.
✔✔HIPAA Security Rule - ✔✔Applies to ePHI only (not all PHI). Requires covered
entities to safeguard confidentiality, integrity, and availability of ePHI.
✔✔HITECH Act (Health Information Technology for Economic and Clinical Health Act) -
✔✔2009 law expanding HIPAA. Added Breach Notification Rule. Must notify affected
individuals within 60 days of discovering a breach.
✔✔HITECH Breach Notification Rule - ✔✔If breach affects 500+ individuals in a state,
must also notify media. If 500+ total, must notify HHS within 60 days. Business
associates must notify covered entity within 60 days.
✔✔GLBA (Gramm-Leach-Bliley Act) - ✔✔1999 law for financial institutions significantly
engaged in financial services. Three rules: Financial Privacy Rule, Safeguards Rule,
Pretexting Protection.
✔✔GLBA — Financial Privacy Rule - ✔✔Financial institutions must provide annual
privacy notices to customers explaining how their information is collected, used, and
shared.
✔✔GLBA — Safeguards Rule - ✔✔Requires financial institutions to implement an
organized information security program. Three control categories: workforce training,
securing systems, ongoing monitoring.
✔✔GLBA — Customers vs Consumers - ✔✔Customers have ongoing relationship with
institution — receive full privacy notice. Consumers conduct isolated transactions —
receive summary notice only.