C838 – Mid-Term Exam Questions with
100% Correct Answers.
Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009
Provided financial incentives for medical practices and hospitals to convert paper record-
keeping systems to digital
GLBA
Requires financial institutions to have a written Information Security Plan. Later FDIC revisions
require an Information Security Officer be named and given adequate resources to implement the
ISP.
Who enforces SOX?
The SEC
Jurisdiction
The land and people belonging to a country in which laws are being enforced.
EU Data Protection Directive 95/46 EC
This was the first major EU data privacy Law. This regulation describes the appropriate
handling of personal and private information of all EU citizens. Anyone gathering PII is subject
to this law.
OECD (Organization for Economic Cooperation and Development)
A standards organization made up of reps from many countries which publishes policy
suggestions (not legally binding and not laws, just suggestions)
Safe harbor privacy rules (Part of Data Directive)
Outline what American companies must do in order to comply with EU laws. These
rules outlined the handling of storage and transmission of private information belonging
to EU citizens.
, Administered by the department of Commerce for most, and for airlines and shipping
companies, the program is administered by the Department of Transportation.
Audited and enforced by FTC for the DOC, and by the DOT for it's program.
Australian Privacy Act of 1988
Meets all the directives of the EU Data Directive.
Requires transparency in the handling of PII
Outlines the rules on collecting information from solicitation.
Requires correctness and integrity of collected data.
Canada's Person Information Protection and Electronic Documents Act (PIPEDA)
Satisfactorily addresses the principles of the EU Data Directive.
Provides for protection of PII collected, used or disclosed in certain circumstances by providing
for the use of electronic means to communicate or record information or transactions. Includes
filing complaints as how and with whom they are filed and the remedies.
Argentina's Personal Data Protection Act
Passed in 2000 with the explicit intent of ensuring adherence and compliance with the EU
Directive. The EU treats them like they are part of the EU and allows them to collect PII
for European citizens.
The EFTA and Switzerland
The EU considers their laws stringent enough to protect EU citizens' PII so they are
considered part of the EU in regard to privacy information.
Asian Pacific Economic Cooperation (APEC) Privacy Framework
Less consumer friendly but still provides protection of PII. The privacy principles rest on:
Individuals knowing when their data is used, transmitted, or stored.
Limitations on usage are based on what is known to the individuals.
The entity collecting or creating PII has responsibilities toward maintaining data accuracy
and integrity.
100% Correct Answers.
Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009
Provided financial incentives for medical practices and hospitals to convert paper record-
keeping systems to digital
GLBA
Requires financial institutions to have a written Information Security Plan. Later FDIC revisions
require an Information Security Officer be named and given adequate resources to implement the
ISP.
Who enforces SOX?
The SEC
Jurisdiction
The land and people belonging to a country in which laws are being enforced.
EU Data Protection Directive 95/46 EC
This was the first major EU data privacy Law. This regulation describes the appropriate
handling of personal and private information of all EU citizens. Anyone gathering PII is subject
to this law.
OECD (Organization for Economic Cooperation and Development)
A standards organization made up of reps from many countries which publishes policy
suggestions (not legally binding and not laws, just suggestions)
Safe harbor privacy rules (Part of Data Directive)
Outline what American companies must do in order to comply with EU laws. These
rules outlined the handling of storage and transmission of private information belonging
to EU citizens.
, Administered by the department of Commerce for most, and for airlines and shipping
companies, the program is administered by the Department of Transportation.
Audited and enforced by FTC for the DOC, and by the DOT for it's program.
Australian Privacy Act of 1988
Meets all the directives of the EU Data Directive.
Requires transparency in the handling of PII
Outlines the rules on collecting information from solicitation.
Requires correctness and integrity of collected data.
Canada's Person Information Protection and Electronic Documents Act (PIPEDA)
Satisfactorily addresses the principles of the EU Data Directive.
Provides for protection of PII collected, used or disclosed in certain circumstances by providing
for the use of electronic means to communicate or record information or transactions. Includes
filing complaints as how and with whom they are filed and the remedies.
Argentina's Personal Data Protection Act
Passed in 2000 with the explicit intent of ensuring adherence and compliance with the EU
Directive. The EU treats them like they are part of the EU and allows them to collect PII
for European citizens.
The EFTA and Switzerland
The EU considers their laws stringent enough to protect EU citizens' PII so they are
considered part of the EU in regard to privacy information.
Asian Pacific Economic Cooperation (APEC) Privacy Framework
Less consumer friendly but still provides protection of PII. The privacy principles rest on:
Individuals knowing when their data is used, transmitted, or stored.
Limitations on usage are based on what is known to the individuals.
The entity collecting or creating PII has responsibilities toward maintaining data accuracy
and integrity.