Section 2 Flashcards
(116 cards)
What year was COPPA enacted?
1998
Who does COPPA apply to?
Online services that specifically design for children under 13 or know that children under 13 use their services AND online services that knowingly collect children’s personal info from another online service or website targeted at children
Does COPPA apply to governments and non profits?
No except in limited circumstances where nonprofit websites are operated for the commercial benefit of their members
What additional kinds of PII apply for COPPA?
screen names, geolocation data, any media of a child’s image or voice and phone numbers AND any info collected from the child that is combined with any personal information
What rights do parents have under COPPA?
to approve of the collection and use of personal information, to revoke that consent and require the deletion of the information, and to approve of collection ONLY as necessary to use the service
What are COPPA’s general requirements?
Privacy policy, parental notification, consent and control, information security
What does a COPPA information security program have to have?
Reasonable steps to protect against unauthorized access to children’s data and procedures to delete data when it is no longer needed
What must a parental notification of a change in an organization’s practices include under COPPA?
The notice must: explain the consent process, detail the information the service intends to collect, and provide a link to the privacy policy and assure that any data collected, including contact data, will be deleted if parental consent isn’t granted.
What services must be available to parents under COPPA?
To view the personal information collected, revoke any previous consent, restrict the online service form further use of their information and have personal information deleted
Which agency(ies) enforce COPPA?
FTC. It may be enforced by states and some agencies like Department of Transportation.
What is a COPPA fine?
up to $43,280 for each violation
What happened with YouTube and COPPA?
In 2019 the FTC got a judgment against YouTube. They weren’t complying with COPPA because they didn’t think they were within its scope because the content is crowdsourced social media and not centrally managed. This helps to affirm COPPA’s application to social media companies.
Who does HIPAA apply to?
Health insurance plans, healthcare clearinghouses and healthcare providers
Plus third party businesses associates if they meet certain conditions
What are the requirements for third party individuals or organizations under HIPAA?
They must have business associate agreements that require the business associate to conform with HIPAA
What kind of records are not covered under HIPAA?
personnel records for employees, academic records covered by FERPA, and information that has been properly anonymized so it cannot be used to identify a patient
What are some HIPAA covered transactions from HHS’ guidance that aren’t on their face healthcare information?
payment and remittance advice, claims status, eligibility, coordination of benefits, claims and encounter information, enrollment and disenrollment, referrals and authorizations, and premium payments
What year was the HIPAA privacy rule established?
2000
What does the HIPAA Privacy Rule require?
- implementation of information privacy practices
- limits use and disclosure of data without patient authorization
- gives patients additional rights including the right to view and correct their medical records
Who enforces the HIPAA Privacy Rule?
HHS Office of Civil Rights (OCR)
For how long are HIPAA covered entities required to retain records related to their privacy policies (like complaints or public notices)?
Six years
Can HIPAA covered entities ask patients to waive their rights under the Privacy Rule as a condition of care or coverage?
No
What are exceptions to the HIPAA requirement that patients have access to their PHI?
- psychotherapy notes
- information gathered for legal actions
- lab results specifically restricted by the Clinical Lab Improvement Amendments
- circumstances if the entity thinks may cause the person to harm themselves or others
What are the exceptions of HIPAA for states to make use of PHI without patient consent?
- Reporting health information (birth, death records)
- Public health (reporting vital stats or enforcing regulations)
- Reporting information about health plans for oversight purpose
What is the range of fines for the OCR?
$100 up to $50K per violation
For repeated violations, up to $1.5M per year (per provision)