Under HIPAA, which cloud storage configuration violates the minimum necessary standard?
-
A
Granting read-only access to audit logs for the security team
-
B
Allowing all employees to access the full patient database for any reason
-
C
Encrypting PHI at rest using AES-256
-
D
Logging all access attempts to PHI containers