by Catherine Wanjau and Jay Hodes, President โ Colington Consulting
While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.
Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.
HIPAA Guidelines on Telehealth
The U.S. Department of Health and Human Services (HHS) defines telehealth as โthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:
- Only authorized users should have access to electronic Protected Health Information (ePHI).
- A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
- The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโs platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.
The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโt last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโs becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโs time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.
Colington Consulting | HIPAA Compliance, Risk Assessment & Management
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.