Final Answer:
The three true statements about HIPAA are: Complaints about breaches must be tracked and investigated, All PHI should be kept confidential, and Access to PHI is based on a "need to know" basis. Option A is the answer.
Step-by-step explanation:
Complaints about breaches must be tracked and investigated: HIPAA (Health Insurance Portability and Accountability Act) mandates that covered entities track and investigate complaints related to breaches of Protected Health Information (PHI) to ensure compliance with privacy and security regulations.
All PHI should be kept confidential: HIPAA strictly requires the confidentiality of PHI. Covered entities must implement measures to safeguard patient information and prevent unauthorized disclosure.
Access to PHI is based on a "need to know" basis: HIPAA emphasizes the principle of the "minimum necessary" standard, allowing access to PHI only to individuals or entities that require the information for legitimate purposes.
Option A is the answer.