Under the Arkansas Personal Information Protection Act (PIPA), which supplements federal HIPAA with its own state breach-notification duties, how does Arkansas law define 'medical information' for breach-notification purposes?
A. Any individually identifiable information, in electronic or physical form, regarding the individual's medical history or medical treatment or diagnosis by a health care professional
B. Only information stored in an electronic health record system certified under federal meaningful-use standards
C. Only laboratory test results, excluding diagnoses or treatment notes
D. Any information a covered entity labels as 'protected health information' under HIPAA, regardless of form
Source: Ark. Code Ann. § 4-110-103(5) (Personal Information Protection Act)
Under Arkansas PIPA, an individual's first name or initial combined with their last name, plus which of the following unencrypted data elements, triggers the statutory definition of 'personal information' subject to Arkansas's separate state breach-notification duty?
A. The individual's home telephone number alone
B. Medical information, as defined in § 4-110-103(5)
C. The individual's email address alone
D. The individual's employer name alone
Source: Ark. Code Ann. § 4-110-103(7)(A)-(D)
Under Arkansas PIPA, what timing standard governs disclosure of a security breach involving Arkansas residents' unencrypted medical information, separate from HIPAA's 60-day breach-notification deadline?
A. Disclosure must occur within 5 business days regardless of any law enforcement investigation
B. Disclosure must be made within exactly 45 calendar days of discovery, mirroring most other states' fixed deadline
C. Disclosure must be made in the most expedient time and manner possible and without unreasonable delay, subject to legitimate law enforcement needs
D. Disclosure is required only if more than 500 Arkansas residents are affected
Source: Ark. Code Ann. § 4-110-105(a)(2)
Under Arkansas PIPA, is a business required to notify affected individuals of a breach involving their medical information if, after a reasonable investigation, the business determines there is no reasonable likelihood of harm to customers?
A. Yes, notification is always required regardless of harm likelihood
B. Yes, but only if the Arkansas Attorney General grants prior approval to skip notice
C. No, notice is never required for medical information breaches under Arkansas law
D. No, notice is not required if the reasonable investigation shows no reasonable likelihood of harm to customers
Source: Ark. Code Ann. § 4-110-105(d)
Under Arkansas PIPA, a business may use substitute notice instead of individual written or email notice if it demonstrates that the cost of providing notice would exceed what amount?
A. $250,000
B. $25,000
C. $100,000
D. $1,000,000
Source: Ark. Code Ann. § 4-110-105(e)(3)(A)(i)