What is the required minimum content of a HIPAA Security Risk Analysis?
-
A
A list of all known breaches in the past three years
-
B
An accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability
-
C
A penetration test of all ePHI systems conducted by an external auditor
-
D
A comparison of current security controls against NIST SP 800-53