HIPAA requires a covered entity to perform a risk analysis and implement standards to protect the institution's health information records. Which is one of those standards?
A) Definition of security measures that should be implemented and revised.
B) Documentation of the entity's actions, which are to be maintained for 6 years.
C) Specification of a step-by-step approach outlined in the HIPAA regulations.
D) Statutory requirements that health information professionals be credentialed.
Question 2
Which is a legal consideration that applies to the retention of health care records?
A) Available storage and methods of destruction.
B) Decision made by the health information committee.
C) Length of time required by statute and regulation.
D) Policy established by the health care institution.