Which of the following best describes the 'minimum necessary' standard under HIPAA's Privacy Rule?
-
A
Covered entities must encrypt the minimum required fields when transmitting PHI
-
B
Covered entities must make reasonable efforts to limit PHI use and disclosure to the minimum needed for the intended purpose
-
C
Business associates must obtain minimum security certifications before accessing PHI
-
D
Covered entities must collect only the minimum amount of PHI during patient registration