6.1 C
New York
Thursday, December 19, 2024

OCR Points Steering to Suppliers and Sufferers on Telehealth Privateness and Safety


Final week, the Workplace for Civil Rights (“OCR”) issued two items of steering on the privateness and safety of protected well being data (“PHI”) when utilizing telehealth providers. One of many paperwork is meant to assist well being care suppliers clarify to sufferers, in plain language, the privateness and safety dangers of utilizing distant communication applied sciences for telehealth (the “Supplier Telehealth Steering”). The opposite offers tricks to sufferers on find out how to safeguard their PHI when utilizing video apps and different applied sciences for telehealth (the “Affected person Telehealth Steering”).

The COVID-19 public well being emergency (“PHE”) and OCR’s relaxed HIPAA enforcement and restrictions for telehealth communications throughout the PHE helped catalyze the widespread use of telehealth by well being care suppliers, resulting in extra potential threat to PHI when utilizing telehealth providers. The 2 items of steering proof OCR’s continued consideration to the HIPAA implications of utilizing telehealth providers.

The Supplier Telehealth Steering clarifies that the Well being Insurance coverage Portability and Accountability Act (collectively, with its implementing laws, “HIPAA”) doesn’t require well being care suppliers to coach sufferers about telehealth dangers. Nonetheless, because the Supplier Telehealth Steering notes, guaranteeing the privateness and safety of PHI can facilitate simpler communication, thereby bettering the standard of care. As such, the Supplier Telehealth Steering is meant to information well being care suppliers who wish to voluntarily clarify to sufferers the privateness and safety dangers of telehealth, in addition to methods to scale back these dangers.

The Supplier Telehealth Steering gives the next recommendation:

  • Previous to the telehealth session, clarify what telehealth is and the distant communication applied sciences used, which can embody phone, video conferencing apps, messaging applied sciences, and distant affected person monitoring applied sciences.
  • Clarify why well being data privateness and safety are essential, together with prevention of identification theft (medical or monetary), embarrassment, bias, and discrimination.
  • Clarify the potential dangers to PHI when utilizing distant communication applied sciences and find out how to mitigate the dangers.
  • Present details about any related distributors’ privateness and safety practices.
  • Inform sufferers that they’ll file a privateness criticism.

The Affected person Telehealth Steering is meant to supply ideas on to sufferers on find out how to defend and safe their PHI, together with:

  • Ensure you’re in a personal location on your telehealth appointment.
  • Flip off close by units which will overhear or document data.
  • Use a private laptop or cell system.
  • Set up accessible safety updates.
  • Use robust, distinctive passwords.
  • Flip in your lock display screen operate.
  • Delete well being data in your units when it’s now not wanted.
  • Activate multi-factor authentication the place accessible.
  • Activate encryption.
  • Keep away from utilizing public wi-fi networks and USB ports.

Because the Supplier Telehealth Steering notes, educating sufferers on the privateness and safety dangers of telehealth providers shouldn’t be required below HIPAA. Nonetheless, doing so might theoretically mitigate the danger of a affected person criticism within the occasion that one thing occurs to the affected person’s PHI throughout or due to a telehealth appointment. Since complaints are one of many two major pathways to an OCR investigation and potential enforcement motion, offering this training to sufferers could mitigate enforcement threat.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles