Under the US Health Insurance Portability and Accountability Act (HIPAA), what is a covered entity's obligation following a breach of unsecured PHI?
-
A
Only notify the affected individual if they request it
-
B
Notify affected individuals, HHS, and potentially media within 60 days of discovery
-
C
File a police report within 24 hours
-
D
Notify the FBI's IC3 within 72 hours