Minimization - Disclosure, v1.0

Defines privacy requirements related to limitations on disclosure of sensitive information.

Assessment Step

1
Minimization - Disclosure (Minimization-Disclosure)
Does the organization require sensitive information to be disclosed only to the extent necessary to accomplish a specified purpose(s) and to never discriminate inappropriately?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Individually identifiable health information should be disclosed only to the extent necessary to accomplish a specified purpose(s) and never to discriminate inappropriately.
Citation
HHS-PSF
Section II, Collection Use and Disclosure Limitation