Under the HIPAA Security Rule, the primary purpose of a risk analysis is to:
-
A
Evaluate the financial stability of technology vendors
-
B
Identify potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI
-
C
Assess patient satisfaction with electronic health records
-
D
Determine optimal staffing levels for the IT department