← All CACS Flashcard Decks

Confidentiality & Privacy Standards Flashcards

7 cards from real CACS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Confidentiality & Privacy Standards flashcards as text
  1. A CAC assists consumers at a community event where multiple booths are set up in close proximity. What is the MOST important privacy precaution to take?

    Answer: Collect only names and phone numbers at the event and complete full applications later in a private setting

    Collecting sensitive PII in a public, non-private setting creates unacceptable privacy risks; limiting data collection to non-sensitive items and completing full applications privately is the correct approach.

  2. Under CMS training requirements, how often must CACs complete privacy and security training to maintain their certification?

    Answer: Annually, as part of the required re-certification process each plan year

    CACs must complete privacy and security training annually as part of the yearly re-certification process required by CMS.

  3. A consumer is applying for coverage and reveals undocumented family members in the household. How should a CAC handle this information?

    Answer: Use it solely to correctly calculate household size and eligibility, keeping it strictly confidential

    Immigration status information may only be used for eligibility determinations and is strictly protected — CACs are prohibited from reporting it to immigration enforcement.

  4. Which of the following BEST describes the concept of 'need-to-know' as applied to CAC access to consumer records?

    Answer: Only the CAC directly assisting a consumer should access that consumer's records

    Need-to-know limits record access to only those individuals directly involved in providing assistance to a specific consumer, minimizing unnecessary exposure of sensitive data.

  5. A CAC who suspects a consumer is a victim of domestic violence notices the consumer's abuser is listed as an authorized representative on the account. The CAC should:

    Answer: Privately inform the consumer of their right to update or remove authorized representatives and connect them with appropriate resources

    CACs must respect consumer autonomy while ensuring they are informed of their rights regarding account access; connecting them with resources protects safety without overriding their decisions.

  6. When a CAC leaves an enrollment session at a shared workstation, what is the required action to protect consumer data?

    Answer: Log out of all Marketplace systems and lock or secure the workstation

    Logging out and locking the workstation prevents unauthorized access to open sessions containing consumer PII whenever the CAC steps away.

  7. A CAC wants to take notes about a consumer's situation using a personal smartphone for convenience. This practice is:

    Answer: Generally prohibited unless the personal device is enrolled in the organization's mobile device management (MDM) program

    Using personal devices to store consumer PII requires the device to meet organizational security standards, typically through enrollment in an MDM program.