Under HIPAA, which of the following is considered a permissible disclosure of PHI without patient authorization?
-
A
Marketing a new telehealth app to the patient
-
B
Sharing PHI with a business associate under a signed BAA
-
C
Posting de-identified data that still includes zip code and birthdate
-
D
Selling PHI to a third-party analytics firm