A telehealth company markets its platform as 'HIPAA compliant' but has not signed BAAs with its vendors. This situation represents:
-
A
A minor administrative oversight with no legal consequence
-
B
A potential HIPAA violation and deceptive marketing claim
-
C
Acceptable if the platform uses end-to-end encryption
-
D
A violation of the FTC Act only, not HIPAA