That's because they don't want liability around keeping PHI.
I would disagree with A. HIPAA, while good, has its flaws, and isn't any more stringent than many of the security standards out there. B is probably true.
That's actually not clear. The DOJ has fairly consistently ruled that...