A researcher publishes a study using de-identified HIPAA data. Later, a third party uses publicly available voter registration records to re-identify individuals in the dataset. Who bears HIPAA liability?
-
A
The researcher bears liability because they published the data
-
B
The covered entity that originally de-identified the data bears liability if de-identification was improper
-
C
The third party who performed re-identification bears all liability under HIPAA
-
D
No one bears liability since the data was de-identified before publication