An IS auditor is reviewing a healthcare organization's EHR system. Which logical access control would BEST address the HIPAA minimum necessary standard?
-
A
Requiring strong passwords for all clinical staff
-
B
Implementing context-based access that limits record visibility to treating clinicians
-
C
Enabling full audit logging of all record accesses
-
D
Using VPN for all remote access to patient records