GRC Regulatory and Legal Compliance 4 — Questions and Answers
Question 1: Under the Americans with Disabilities Act (ADA), which title specifically prohibits discrimination by private employers with 15 or more employees?
- Title I (Correct answer)
- Title II
- Title III
- Title IV
Correct answer: Title I
ADA Title I prohibits private employers with 15 or more employees from discriminating against qualified individuals with disabilities in employment.
Question 2: A healthcare organization receives a subpoena for patient records. Under HIPAA, what should be the organization's first step before disclosing the records?
- Immediately comply with the subpoena and produce all records
- Notify the patient and provide an opportunity to object (Correct answer)
- Consult with the Department of Health and Human Services
- Encrypt the records before transmitting them
Correct answer: Notify the patient and provide an opportunity to object
HIPAA requires covered entities to notify the patient and give them a chance to object before disclosing PHI in response to a subpoena not accompanied by a court order.
Question 3: The concept of 'privacy by design' in regulatory compliance requires that privacy protections be integrated at which stage of system development?
- During post-deployment audits
- Only when handling sensitive data categories
- From the earliest design phase onward (Correct answer)
- After regulatory approval is obtained
Correct answer: From the earliest design phase onward
Privacy by design mandates that privacy protections be embedded into systems and processes from the beginning of development, not added as an afterthought.
Question 4: Which regulatory body oversees compliance with the Fair Credit Reporting Act (FCRA) for most entities?
- Securities and Exchange Commission (SEC)
- Consumer Financial Protection Bureau (CFPB) (Correct answer)
- Federal Reserve Board
- Office of the Comptroller of the Currency (OCC)
Correct answer: Consumer Financial Protection Bureau (CFPB)
The Consumer Financial Protection Bureau (CFPB) has primary enforcement authority over the FCRA for most entities that use or furnish consumer reports.
Question 5: An organization implements a compliance training program but employees later repeat the same violations. According to the DOJ's guidance on effective compliance programs, what is the most likely deficiency?
- Insufficient training frequency
- Lack of tone at the top
- Training that is not reinforced through consistent enforcement and discipline (Correct answer)
- Failure to use e-learning platforms
Correct answer: Training that is not reinforced through consistent enforcement and discipline
The DOJ emphasizes that training must be supported by consistent disciplinary action; without enforcement, employees learn that policies are not seriously enforced.
Question 6: Under the EU's NIS2 Directive, which sector is newly included compared to the original NIS Directive?
- Energy
- Transport
- Public administration (Correct answer)
- Water supply
Correct answer: Public administration
NIS2 expanded coverage to include public administration, among other new sectors, broadening the scope of cybersecurity obligations across the EU.
Question 7: A company subject to SEC regulations discovers a material cybersecurity incident. Under the SEC's 2023 cybersecurity disclosure rules, within how many business days must it file a Form 8-K disclosure?
- 2 business days
- 4 business days (Correct answer)
- 10 business days
- 30 business days
Correct answer: 4 business days
The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.
Under the Americans with Disabilities Act (ADA), which title specifically prohibits discrimination by private employers with 15 or more employees?