An SAP is contacted by a DOT agency auditor requesting to review the SAP's case files as part of a compliance audit. The SAP should:
-
A
Provide records only after obtaining signed releases from all employees whose files will be reviewed
-
B
Cooperate with the legitimate DOT oversight process while following applicable confidentiality regulations
-
C
Refuse access since SAP records are protected under HIPAA from all government review
-
D
Provide only de-identified summary data to satisfy the audit without releasing individual files