A health informatician conducting a HIPAA Security Risk Analysis discovers an unencrypted laptop containing ePHI was used by a remote employee. Which risk response is MOST appropriate under HIPAA's required implementation specifications?
-
A
Immediately terminate the employee to satisfy workforce sanction requirements
-
B
Implement encryption or document why encryption is not reasonable and appropriate as an equivalent alternative measure
-
C
File a self-disclosure with the HHS Office for Civil Rights within 24 hours
-
D
Destroy the laptop and notify all patients whose data was stored on it