The 'minimum necessary' standard under HIPAA requires covered entities to:
-
A
Share all patient records when requested by any provider
-
B
Disclose only the PHI needed to accomplish the intended purpose
-
C
Encrypt all PHI regardless of intended use
-
D
Obtain written consent for every internal use of PHI