An ophthalmic practice manager discovers that a technician has been using a personal, unencrypted USB drive to transfer patient diagnostic images between the testing room and a physician's review station. According to HIPAA incident response protocols, what is the MOST critical and immediate action required?
-
A
Immediately retrain all staff on the practice's HIPAA policies.
-
B
Report a potential breach to the Department of Health and Human Services (HHS) within 24 hours.
-
C
Confiscate the drive, secure the device, and perform a formal risk assessment to determine if a breach of Protected Health Information (PHI) occurred.
-
D
Draft a notification letter to all potentially affected patients.