A business associate's workforce member snoops through a patient's records out of personal curiosity. Under HIPAA's compliance framework, the business associate must:
-
A
Do nothing, as the patient was not harmed
-
B
Investigate, apply sanctions per their sanction policy, and notify the covered entity
-
C
Only take action if the covered entity discovers the breach
-
D
Immediately notify OCR before investigating