← Back to CBT Library

PII Training

Personally Identifiable Information (PII) training covering PII definitions, PHI, breach reporting, safeguarding, encryption, disposal, Privacy Act of 1974, HIPAA overlap, and social engineering threats. Based on DoDI 5400.11.

40 questions and answers — updated 2025/2026
01

What is Personally Identifiable Information (PII)?

02

What DoD Instruction governs the protection of PII within the Department of Defense?

03

What is the difference between PII and Protected Health Information (PHI)?

04

Give three examples of stand-alone PII that can identify someone without additional context.

05

What is 'linked' versus 'linkable' PII?

06

What federal law requires agencies to safeguard records containing PII and gives individuals the right to access and amend their records?

07

What is a System of Records Notice (SORN)?

08

What must you do if you discover a potential PII breach?

09

What is the DoD reporting timeline for a suspected PII breach to US-CERT?

10

What encryption standard does DoD require for PII stored on mobile devices and removable media?

11

How should paper documents containing PII be disposed of?

12

How should electronic media containing PII be disposed of when no longer needed?

13

What is a Privacy Impact Assessment (PIA)?

14

What is the 'minimum necessary' rule regarding PII?

15

What is social engineering in the context of PII threats?

16

What is pretexting and how does it threaten PII?

17

How does phishing target PII?

18

What is spear phishing and why is it more dangerous than regular phishing?

19

What are 'tailgating' and 'shoulder surfing' in the context of PII protection?

20

What role does HIPAA play in DoD PII protection?

21

What are the HIPAA Privacy Rule's key requirements for PHI?

22

Can a supervisor access a service member's medical records without consent?

23

What is the penalty for willful unauthorized disclosure of PII under the Privacy Act?

24

What are common indicators that an email may be a phishing attempt targeting PII?

25

What is 'PII confidentiality impact level' and what are the three levels?

26

Give examples of PII that would be rated 'High' confidentiality impact.

27

What safeguards should be used when emailing PII?

28

What is Controlled Unclassified Information (CUI) and how does it relate to PII?

29

What should you do if you receive a misdirected email containing someone else's PII?

30

What is the DoD Breach Response Plan requirement?

31

When must individuals be notified of a PII breach?

32

What is the role of the Component Senior Official for Privacy (CSOP)?

33

How does the Freedom of Information Act (FOIA) interact with PII protections?

34

What are 'Privacy Act Statements' and when are they required?

35

What is 'data masking' and when should it be used for PII?

36

What physical safeguards protect PII in an office environment?

37

What is the 'two-person integrity' rule for handling sensitive PII?

38

How should PII be handled when teleworking?

39

What is the difference between a PII 'incident' and a PII 'breach'?

40

What should a PII breach notification letter to affected individuals include?

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Want to study these as flashcards?

Create a free study set with spaced repetition, multiple choice tests, and AI explanations.

Create Study Set