A CDPSE is evaluating a third-party vendor that processes personal health information on behalf of the organization. Which risk management step should be performed FIRST?
-
A
Sign a data processing agreement immediately
-
B
Conduct a vendor privacy risk assessment
-
C
Audit the vendor's security controls
-
D
Terminate the relationship if any risk is found