An unencrypted company laptop containing the electronic protected health information (ePHI) of 650 patients is stolen. After conducting a risk assessment, the practice administrator confirms this is a reportable breach. According to the HIPAA Breach Notification Rule, which of the following actions is required?
-
A
Notify only the affected individuals and the local police department.
-
B
Notify the affected individuals, the Secretary of HHS, and prominent media outlets.
-
C
Notify the Secretary of HHS on an annual basis and offer all patients credit monitoring.
-
D
Notify only the patients whose data was confirmed to have been opened and viewed.