1. C: The HIPAA privacy rule demands that covered entities protect their patients' health information whether it is living
in their offices or with a business associate!
2. B: If you must outsource your patients' PHI, make sure you've done your homework. If you're comfortable with a contractor's history and reputation, you can use the BAA to further ensure privacy rule compliance.
3. A: Apply all the HIPAA privacy rule standards to your BAs, but remember -- if there's a violation, it's your organization on the line!
4. C: Being upfront and honest with your patients about your mistakes might just endear them to you. Dishonesty could ruin your business!