The HIPAA Omnibus Rule of 2013 modified the Breach Notification Rule by replacing the subjective "harm threshold." An impermissible use or disclosure of PHI is now presumed to be a breach unless the covered entity or business associate demonstrates what?
-
A
The individuals affected have been notified and offered credit monitoring.
-
B
A formal risk of harm analysis shows no significant financial impact.
-
C
There is a low probability that the protected health information has been compromised.
-
D
The data was encrypted after the impermissible disclosure was discovered.