A small dental practice is conducting its annual risk analysis as required by the HIPAA Security Rule. Which of the following is a required implementation specification they must address under the Administrative Safeguards?
-
A
Implementing automatic logoff procedures for all workstations.
-
B
Encrypting all electronic protected health information (ePHI) at rest.
-
C
Conducting a thorough assessment of potential risks and vulnerabilities to ePHI.
-
D
Assigning unique user IDs to every member of the workforce.