A healthcare organization discovers that an employee inappropriately accessed 500 patient records out of curiosity with no malicious intent. Under HIPAA, this is:
-
A
Not a reportable breach because there was no malicious intent
-
B
A breach that must be evaluated using the four-factor risk assessment
-
C
Automatically a reportable breach requiring notification to all 500 patients
-
D
An internal workforce issue only requiring OSHA reporting