A healthcare organization is conducting its annual HIPAA Security Rule risk analysis. Which of the following is the PRIMARY objective of this process?
-
A
To eliminate all possible threats to electronic protected health information (ePHI).
-
B
To identify and implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
-
C
To satisfy the Meaningful Use core objective for protecting electronic health information.
-
D
To purchase a certified Electronic Health Record (EHR) technology.