New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPT Exam - Topic 1 Question 41 Discussion

Actual exam question for IAPP's CIPT exam
Question #: 41
Topic #: 1
[All CIPT Questions]

SCENARIO

Please use the following to answer the next question:

Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile application that collects personal health information from electronic patient health records. The application will use machine learning to recommend potential medical treatments and medications based on information collected from anonymized electronic health records. Patient users may also share health data collected from other mobile apps with the LBH app.

The application requires consent from the patient before importing electronic health records into the application and sharing it with their authorized physicians or healthcare provider. The patient can then review and share the recommended treatments with their physicians securely through the app. The patient user may also share location data and upload photos in the app. The patient user may also share location data and upload photos in the app for a healthcare provider to review along with the health record. The patient may also delegate access to the app.

LBH's privacy team meets with the Application development and Security teams, as well as key business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the application development process.

The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during development of the application. The team must assess whether the application is collecting descriptive, demographic or any other user related data from the electronic health records that are not needed for the purposes of the application. The team is also reviewing whether the application may collect additional personal data for purposes for which the user did not provide consent.

Regarding the app, which action is an example of a decisional interference violation?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Gwen
4 months ago
Not sure if the app will really keep my data safe, though.
upvoted 0 times
...
Brandon
5 months ago
Totally agree, unnecessary questions can lead to privacy issues.
upvoted 0 times
...
Albina
5 months ago
Wait, can they really ask about family medical history? Seems sketchy.
upvoted 0 times
...
Keneth
5 months ago
I think selling data without consent is way worse!
upvoted 0 times
...
Stephen
5 months ago
The app shouldn't ask for income level, that's unnecessary.
upvoted 0 times
...
Juliana
5 months ago
I agree with D, but I wonder if asking about income level in A could also be seen as influencing treatment decisions.
upvoted 0 times
...
Twanna
5 months ago
I feel like option B could also be a violation, but it seems more about consent rather than direct interference.
upvoted 0 times
...
Pauline
5 months ago
I remember we discussed decisional interference violations in class, but I'm not entirely sure which option fits best.
upvoted 0 times
...
Bo
5 months ago
I think option D is the most likely choice since asking for unnecessary family medical history seems to interfere with the patient's decision-making.
upvoted 0 times
...
Farrah
5 months ago
Easy peasy! Splunk is all about indexing data by timestamp, so A is the clear answer here. I feel good about this one.
upvoted 0 times
...
Fredric
5 months ago
This seems like a straightforward question about supply chain design. I think the key is to focus on the core elements of the supply chain, like the physical flow of goods and supporting information systems.
upvoted 0 times
...
Glen
5 months ago
I'm a little confused on this one. I think the SSID and radio name need to match, but I'm not positive. I'll have to review my notes before answering.
upvoted 0 times
...
Marguerita
5 months ago
Hmm, I'm a bit unsure about this one. The question is asking for the amount to be reported as related party disclosures, but the information given seems to be just the individual company amounts. I'll need to think through how to consolidate those figures.
upvoted 0 times
...

Save Cancel