← All CACS Flashcard Decks

Confidentiality & Privacy Standards Flashcards

7 cards from real CACS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Confidentiality & Privacy Standards flashcards as text
  1. Under the ACA's privacy rules, which federal law primarily governs the protection of personally identifiable information (PII) collected during the Health Insurance Marketplace enrollment process?

    Answer: The ACA itself and its implementing regulations

    The ACA and its implementing regulations, including 45 CFR Part 155, govern privacy protections for PII collected during Marketplace enrollment.

  2. A consumer asks a CAC to send their completed application to a family member's email address for convenience. What should the CAC do?

    Answer: Confirm the consumer understands the privacy risk and document their informed consent before proceeding

    CACs must ensure consumers understand risks of unencrypted transmission and obtain informed consent before sharing application information via email.

  3. Which of the following is NOT considered personally identifiable information (PII) in the context of Marketplace enrollment?

    Answer: The county in which the Marketplace operates

    A county name alone is publicly available geographic data and does not identify any individual consumer.

  4. A CAC's computer containing consumer enrollment files is stolen. What is the FIRST required action?

    Answer: Report the breach to the appropriate authorities and their Navigator/CAC organization per breach response protocols

    The first step is to report the breach internally and to relevant authorities per the organization's breach response plan before individual consumer notification.

  5. When a CAC assists a consumer whose application also affects household members, whose consent is needed to share household members' information with a third party?

    Answer: Each adult household member whose information would be shared must provide consent

    Each adult household member has independent privacy rights and must separately authorize disclosure of their own information.

  6. A CAC is approached by a researcher who wants anonymized enrollment data to study coverage gaps. How should the CAC respond?

    Answer: Decline, as CACs may not share any consumer data even in anonymized form without proper authorization

    CACs are not authorized to share consumer data in any form — anonymized or otherwise — without explicit authorization from the Marketplace or oversight entity.

  7. How long are CACs generally required to retain consumer records and application documentation?

    Answer: At least 3 years, or as specified by their certifying entity or state law

    HHS and most certifying entities require CACs to retain consumer records for a minimum of 3 years, though state laws or organizational policies may require longer retention.