Category: Teleworking

  • Best Practices for Teleworking & Telehealth Involving PHI/ePHI

    by Jay Hodes, President – Colington Consulting

    With the federal public health emergency in place as of January 31 to address COVID-19, many healthcare organizations have implemented teleworking options for their workforce. Providers are also using telehealth services to interact with their patients. For some organizations, this is a whole new world. If not already in place, organizations needed to implement policies and procedures to address these critical operational topics.

    The HHS Office for Civil Rights (OCR) has issued a number of guidance documents pertaining to this emergency. Here are some excerpts I feel are important:

    February 2020: โ€œIn an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.โ€

    As further stated in the guidance regarding PHI:

    โ€œThe HIPAA Privacy Rule protects the privacy of patientsโ€™ health information (protected health information) but is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nationโ€™s public health, and for other critical purposes.โ€

    March 2020: โ€œWhile the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions of the Privacy Rule under the Project Bioshield Act of 2004 (PL 108-276) and section 1135(b)(7) of the Social Security Act.โ€

    Although OCR has indicated some discretion with its enforcement authority and waiving some requirements, the HIPAA Privacy and Security Rules are still in place with very limited exceptions.

    With the OCR guidance clearly stated, there must be an operational balance and the need to apply a commonsense approach to minimize the risks for unauthorized disclosures in order for your workforce to be able to perform their jobs while teleworking and during telehealth sessions.

    Here are some best practices to consider implementing as part of your organizationโ€™s policies to address teleworking and telehealth sessions:

    • Staff should never leave any documents containing PHI in a vehicle overnight. Even if the vehicle is locked or the documents can be secured in a trunk, all PHI must be removed. No exceptions!
    • When working from home, the staff should follow the same protocols as if in an office, practice location, or providing services face-to-face. This means following the Minimum Necessary Requirement. If working from home and there are others in the house, such as family members or roommates, only have patient conversations where others cannot hear that conversation. Staff must try to make those conversations as private as possible. This includes VTC telehealth sessions and telephone calls.
    • Always keep documents containing PHI as secure as possible so others may not see them when performing work related duties.
    • Avoid having conversations with those in the house regarding any patient.
    • Never allow family members, roommates, or others in the house to access/use any organization issued devices including cell phones and laptops, unless personal use is approved by the organization.
    • If using a personal computer for organization business, make sure others in the home do not access while performing work related duties. If a computer needs to be utilized for non-organization business during the workday or shift, always log off from organization access or VPN.
    • If staff needs to leave an area in the home that is set up as a workstation to take a break, grab a coffee, or handle non-organization issues, always make sure to lock the computer and secure documents. Even for a few minutes.
    • At the end of the business day or shift, staff should log off from any computer they are using and properly secure any documents containing PHI.
    • If HIPAA compliant bags or containers are provided by the organization, then use those to secure the documents when not needed.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Additional Resources for Telehealth:

    OCR – FAQs on Telehealth and HIPAA during the COVID-19 nationwide public health emergency

    National Consortium of Telehealth Resource Centers

    The National Counsel – Best Practices for Telehealth During COVID-19 Public Health Emergency

    American Psychiatric Association – Best Practices in Videoconferencing-Based Telemental Health

    SAMHSA Telehealth Start-Up and Resource Guide