Under North Carolina's Identity Theft Protection Act, within what specific timeframe must a business notify affected individuals after discovering a security breach involving personal information?
A. Within 30 days of discovery
B. Within 45 days of discovery
C. Within 60 days of discovery
D. There is no fixed number of days; notice must be given without unreasonable delay
Source: N.C.G.S. 75-65
In addition to notifying affected individuals, North Carolina's Identity Theft Protection Act requires a business to notify which state entity about a security breach?
A. The Consumer Protection Division of the NC Attorney General's Office
B. The NC Department of Health and Human Services
C. The NC Medical Board
D. The NC Insurance Commissioner
Source: N.C.G.S. 75-65
Under North Carolina's Identity Theft Protection Act, when must a business also notify nationwide consumer reporting agencies of a breach?
A. Whenever any breach occurs, regardless of size
B. Only if the breach involves Social Security numbers
C. When the business must notify more than 1,000 persons at one time
D. Never - NC law does not require notifying consumer reporting agencies
Source: N.C.G.S. 75-65(e)
A hospital's business office in North Carolina experiences unauthorized access to a database containing patient diagnosis codes and treatment histories, but no Social Security numbers, driver's license numbers, or financial account numbers. Does this trigger notice obligations under North Carolina's general Identity Theft Protection Act (G.S. Chapter 75)?
A. Yes, because medical diagnosis and treatment information is expressly listed as 'personal information' under the statute
B. No, because the Identity Theft Protection Act's definition of 'personal information' is built around identity-theft data elements (like SSNs, driver's license numbers, and financial account numbers) and does not itself include medical or health insurance information
C. Yes, but only if the patient is a minor
D. No, because HIPAA entirely preempts North Carolina from having any breach notification law
Source: N.C.G.S. 75-61, 14-113.20(b)
Under North Carolina's Identity Theft Protection Act, if personal information is encrypted and the decryption key was NOT also compromised, how is this generally treated?
A. It is automatically still treated as a reportable security breach regardless of encryption
B. It generally falls outside the statute's definition of 'security breach,' since that definition is built around unauthorized access to unencrypted and unredacted data (or encrypted data plus the key)
C. It must be reported to HHS OCR but not to the NC Attorney General
D. North Carolina law prohibits the use of encryption for personal information
Source: N.C.G.S. 75-61