Chapter 04: Privacy
Which act included strong privacy provisions for electronic health records and bans the sale of health information, promotes the use of audit trails and encryption, and provides rights of access for patients?
American Recovery and Reinvestment Act
Although the Constitution does not contain the word privacy, the U.S. Supreme Court has ruled that the concept of privacy is protected by which of the following?
Bill of Rights
Under which act did the Federal Communications Commission respond to appeals from the Department of Justice by requiring providers of Internet phone services and broadband services to ensure that their equipment accommodated the use of law enforcement wiretaps?
Communications Assistance for Law Enforcement Act
Which of the following acts restricted the government's ability to intercept electronic communications such as email, fax, and text messages?
ECPA
Title I of which of the following acts extends the protections offered under the Wiretap Act to electronic communications, such as fax and messages sent over the Internet?
Electronic Communications Privacy Act
Which act prohibits unauthorized access to stored wire and electronic communications, such as the contents of email inboxes, instant messages, message boards, and social networking sites?
Electronic Communications Privacy Act
Which act bars the export of data to countries that do not have data privacy protection standards comparable to those of its member countries?
European Union Data Protection Directive
Which act outlines who may access a user's credit information, how users can find out what is in their file, how to dispute inaccurate data, and how long data is retained?
Fair Credit Reporting Act
Which act allows consumers to request and obtain a free credit report each year from each of the three primary credit reporting companies?
Fair and Accurate Credit Transactions Act
A National Security Letter is subject to judicial review and oversight.
False
A pen register is a device that records the originating number of incoming calls for a particular phone number.
False
American citizens are protected by the Fourth Amendment even when there is no reasonable expectation of privacy.
False
Online marketers can capture personal information, such as names, addresses, and Social Security numbers without requiring consent.
False
The Privacy Act of 1974 extends to the actions of the CIA, U.S. law enforcement agencies, and the private industry.
False
The U.S. has a single, overarching national data privacy policy.
False
The USA PATRIOT Act grants citizens the right to access certain information and records of federal, state, and local governments upon request.
False
The rights assigned to parents by the Family Educational Rights and Privacy Act transfer to the student once the student reaches the age of 21.
False
There is virtually no way to limit the deposit of cookies on a user's hard drive.
False
Title III of the Wiretap Act allows state and federal law enforcement officials to use wiretapping without requiring them to obtain warrants.
False
Under the Right to Financial Privacy Act, a financial institution can release a customer's financial records without the customer's authorization as long as it is a government authority that is seeking the records.
False
Which act presumes that a student's records are private and not available to the public without the consent of the student?
Family Educational Rights and Privacy Act
In Doe v. Holder, the courts ruled that the NSL gag provision violates which of the following?
First Amendment
In 2008, which act granted expanded authority to collect, without court-approved warrants, international communications as they flow through U.S. telecom network equipment and facilities?
Foreign Intelligence Surveillance Act Amendments Act
Which act protects citizens from unreasonable government searches and is often invoked to protect the privacy of government employees?
Fourth Amendment
Which act enables the public to gain access to certain government records?
Freedom of Information Act
Which act requires that financial institutions must provide a privacy notice to each consumer that explains what data about the consumer is gathered, with whom that data is shared, how the data is used, and how the data is protected?
Gramm-Leach-Bliley Act
Which of the following is an act that repealed a depression-era law known as Glass-Steagall?
Gramm-Leach-Bliley Act
Which act prohibits the government from concealing the existence of any personal data record-keeping systems?
Privacy Act
Which of the following rules requires each financial institution to document a data security plan describing the company's preparation and plans for the ongoing protection of clients' personal data?
Safeguards Rule
A vehicle event data recorder (EDR) is a device that records vehicle and occupant data for a few seconds before, during, and after any vehicle crash that is severe enough to deploy the vehicle's air bags.
True
Electronic discovery is the collection, preparation, review, and production of electronically stored information for use in criminal and civil actions and proceedings.
True
Electronically stored information includes any form of digital information stored on any form of electronic storage device.
True
Information privacy is the combination of communications privacy and data privacy.
True
The Constitution does not contain the word privacy, but the Supreme Court has ruled that the concept of privacy is protected by the Bill of Rights.
True
The European Union Data Protection Directive requires member countries to ensure that data transferred to non-European Union countries is protected.
True
The Foreign Intelligence Surveillance Act describes procedures for the electronic surveillance of communications between foreign powers and the agents of foreign powers.
True
The Gramm-Leach-Bliley Act includes three key rules that affect personal privacy: financial privacy rule, safeguards rule, and pretexting rule.
True
The Health Insurance Portability and Accountability Act requires healthcare organizations to employ standardized electronic transactions, codes, and identifiers to enable them to fully digitize medical records thus making it possible to exchange medical records over the Internet.
True
The cost of a data breach can be quite expensive, by some estimates nearly $200 for each record lost.
True
The use of cookies and tracking software is controversial because companies can collect information about consumers without their explicit permission.
True
The use of information technology in business requires balancing the needs of those who use the information that is collected against the rights and desires of the people whose information is being used.
True
Through the use of cookies, a Web site is able to identify visitors on subsequent visits.
True
Under the USA PATRIOT Act, the FBI can issue a National Security Letter to compel banks, Internet service providers, and credit reporting companies to turn over information about their customers without a court order simply on the basis that the information is needed for an ongoing investigation.
True
Which of the following acts gave sweeping new powers both to domestic law enforcement and international intelligence agencies, including increasing the ability of law enforcement agencies to search telephone, email, medical, financial, and other records?
USA PATRIOT Act
The Foreign Intelligence Surveillance Act:
allows surveillance, without court order, within the United States for up to a year unless the "surveillance will acquire the contents of any communication to which a U.S. person is a party."
In the context of tenets of the European Union Data Protection Directive, which of the following terms refers to an individual's right to challenge the accuracy of the data and provide the corrected data?
correction
The Organisation for Economic Co-operation and Development's requirement that personal data collected should be accurate, complete, current, and relevant to the purpose for which it is used is based on which principle?
data quality
The Children's Online Privacy Protection Act:
does not cover the dissemination of information to children
In the context of tenets of The European Union Data Protection Directive, which of the following terms refers to an individual's right to seek legal relief through appropriate channels to protect privacy rights?
enforcement
One purpose of which of the following is to capture and record data that can be used by the manufacturer to make future changes to improve vehicle performance in the case of a crash?
event data recorder
Discovery is part of the pretrial phase of a lawsuit in which each party can obtain which of the following from the other party by various means?
evidence
Established in 1980, The Organisation for Economic Co-operation and Development's created which of the following, which are often held up as the model of ethical treatment of consumer data?
fair information practices
A device that records the originating number of incoming calls for a particular phone number is known as which of the following?
trap and trace
In the context of the Fourth Amendment, the courts have ruled that:
without a reasonable expectation of privacy, there is no privacy right
The Health Insurance Portability and Accountability Act requires healthcare providers to obtain which of the following from patients prior to disclosing any information in their medical records?
written consent