Under the HIPAA Security Rule, what is the PRIMARY purpose of conducting a risk analysis?
-
A
To document which workforce members currently have access to ePHI
-
B
To satisfy mandatory annual reporting requirements to the Office for Civil Rights
-
C
To determine which workforce members require HIPAA Security Rule training
-
D
To identify and evaluate potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI