A covered entity experiences a ransomware attack that encrypts ePHI. Under HIPAA Breach Notification Rule, what is the initial presumption regarding this incident?
-
A
It is automatically classified as a minor security incident requiring only internal logging
-
B
It is presumed to be a breach unless the entity can demonstrate low probability of PHI compromise
-
C
It requires immediate criminal referral to the DOJ before notifying patients
-
D
It is exempt from breach notification if the data was encrypted prior to the attack