The HIPAA Security Rule states that covered entities and business associates must create policies and practices to protect ePHI except for: 1 confidentiality 2 availability 3 unlimited access 4 integrity. Which of the following indicates insufficient physical safeguards for ePHI?
1) To cut costs, an organization lays off all information security staff.
2) The company firewall fails to stop a hacker from holding patient or customer data hostage.
3) The server quits working, and because there is no backup system in place, all the ePHI is lost.
4) When a visitor gets lost, she enters an unlocked healthcare records room and sees ePHI on computer screens.