A hospital discovers that an unencrypted laptop containing the protected health information (PHI) of 600 patients was stolen. After a risk assessment, it is determined there is a significant risk of harm to the individuals. According to the HIPAA Breach Notification Rule, which of the following actions is required?
-
A
Notify the Secretary of HHS annually and publish a notice in a local newspaper.
-
B
Notify only the affected individuals within 90 days of discovering the breach.
-
C
Notify the affected individuals without unreasonable delay, notify the Secretary of HHS, and notify prominent media outlets.
-
D
Report the theft to local law enforcement and wait for their investigation to conclude before taking further action.