The HIPAA Breach Notification Rule defines 'unsecured PHI' as PHI that has NOT been:
-
A
Stored in a locked cabinet or encrypted server room
-
B
Rendered unusable, unreadable, or indecipherable through approved methods such as encryption or destruction
-
C
Accessed exclusively by workforce members with proper credentials
-
D
Anonymized using the Safe Harbor method