Report It
Artificial Intelligence
Name that Law
Know Your Data
Spot the Violation
100

This icon appears on ISD employees' desktops and is utilized to report breaches.

What is the HPS Icon?

100

This is the only AI tool UPMC employees are approved to use.

What is Copilot?

100

This U.S. healthcare privacy law, passed in 1996, protects personal health information (PHI), and includes both a Privacy Rule and a Security Rule.

What is HIPAA (Health Insurance Portability and Accountability Act)?

100

This role is responsible for ensuring data quality, integrity and proper usage of data within a specific domain.

What is a data steward?

100

This must be in the subject line or assigned to all emails that contain PHI.

What is a "Secure" tagline or sensitivity label?

200

This is the first step upon discovery of a known or suspected breach.

What is notify the privacy department as soon as possible?

200

This type of data must never be entered into unsanctioned AI tools, as it could be stored or reused.

What is Protected Health Information (PHI)?

200

This federal regulation increases protections for records related to substance use disorder (SUD) treatment.

What is 42 CFR Part 2?

200

Aside from legal, IT Security, and privacy, this data governance role is responsible for approving data being shared outbound.

What is the information owner?

200

This action must be taken whenever an employee steps away from their desk to keep sensitive information secure. 

What is locking their computer?

300

In addition to the HPS Icon, this UPMC Privacy Office page can be used to report incidents.

What is Viva Engage?

300

UPMC employees must follow this overarching set of principles when posting online.

What is the Code of Conduct?

300

This California law, passed in 2018, was the first major U.S. consumer privacy law giving residents rights over their personal data.

What is the CCPA (California Consumer Privacy Act)?

300

This department is responsible for managing offsite records storage and retention schedules.

What is records management?

300

This is the proper place for employees to dispose of any paper PHI.

What is a shred bin?

400

This term describes the process of informing affected individuals after a data breach.

What is a breach notification? 

400

This UPMC page is where you can locate policy HS-IS0243, which outlines the acceptable use of AI technology. 

What is the Infonet?

400

This law restricts telemarketing calls, robocalls, and text messages, and requires businesses to get consent before contacting consumers.

What is the TCPA (Telephone Consumer Protection Act)?

400

Commonly referred to as a DTA, this approves and documents the use of any data classified as Business Confidential or higher.

What is a data transfer authorization?

400

This document must be reviewed and approved before any data is shared.

What is a data transfer authorization?

500

This federal agency enforces consumer privacy protections and investigates data breaches.

What is the Federal Trade Commission (FTC)?

500

This UPMC division establishes standards regarding the adoption and acceptable use of AI.

What is the Information Technology division?

500

This European law, enacted in 2018, set a global standard for data privacy and includes rights like data portability and the right to be forgotten.

What is the GDPR (General Data Protection Regulation)?

500

To prevent unauthorized access to sensitive business information, this method must be used when disposing of physical UPMC documents.

What is shredding?

500

This form is necessary for an employee to send out information to a member.

What is a member request to use/disclose PHI form?

M
e
n
u