A hospital discovers that a billing employee impermissibly accessed the electronic health records of 550 patients out of curiosity. According to the HITECH Act's breach notification rule, which of the following actions is the hospital required to take?
-
A
Notify the affected individuals, the Secretary of HHS, and prominent media outlets in the state.
-
B
Notify only the affected individuals and the hospital's internal compliance officer.
-
C
Report the breach in the annual report to the Secretary of HHS and notify the affected individuals.
-
D
Notify the Secretary of HHS and local law enforcement within 60 days of discovery.