medium
Single Answer
0

Greg has data that is classified as health information that his organization uses as part of their company’s HR data. Which of the following statements is true for his company’s secu- rity policy?

Answer Options

A

The health information must be encrypted.

B

Greg should review relevant law to ensure the health information is handled properly.

C

Companies are prohibited from storing health information and must outsource to third parties.

D

All of the above.

Correct Answer: B

Explanation

Personal health information (PHI) may be covered by state, local, or federal law, and Greg’s organization should ensure that they understand any applicable laws before storing, processing, or handling health information.