Under HIPAA, what is the minimum necessary standard?
-
A
Covered entities must encrypt all PHI at rest
-
B
Covered entities must limit PHI use and disclosure to the minimum necessary for the intended purpose
-
C
Covered entities must retain PHI for a minimum of six years
-
D
Covered entities must obtain written consent before any PHI disclosure