Tuesday, February 27, 2024
HomeHealth LawOCR points HIPAA steerage on audio-only telehealth companies

OCR points HIPAA steerage on audio-only telehealth companies

[ad_1]

On June 13, 2022, the U.S. Division of Well being and Human Providers, Workplace for Civil Rights (“OCR”), issued steerage on how lined entities and enterprise associates can use distant communication applied sciences for audio-only telehealth in a HIPAA-compliant method following the top of the nationwide COVID-19 public well being emergency (“PHE”).  OCR had beforehand issued steerage in 2020 informing the general public that it might not impose penalties towards well being care suppliers for noncompliance with the HIPAA guidelines in reference to the nice religion provision of telehealth companies in the course of the COVID-19 PHE. The brand new steerage is issued to assist the continuation of expanded entry to care through audio-only telehealth companies.

The brand new steerage contains responses to 4 ceaselessly requested questions (“FAQs”) relating to compliance with the HIPAA privateness and safety guidelines in reference to audio-only telehealth companies. These FAQs cowl the next matters:

  1. Whether or not the HIPAA Privateness Rule permits well being care suppliers and well being plans to make use of distant communication applied sciences to offer audio-only telehealth companies?
    • The OCR clarified that such apply is permissible supplied that affordable safeguards for shielding the privateness of protected well being data (“PHI”) from impermissible makes use of or disclosures are utilized when offering telehealth companies. Examples of such safeguards embody the availability of telehealth companies in non-public settings, not utilizing speakerphone and utilizing lowered voices to restrict incidental makes use of or disclosures of PHI. As well as, verification of the affected person’s identification is required, which can be carried out both orally or in writing (together with utilizing digital strategies).
  2. Whether or not well being care suppliers and well being plans have to fulfill HIPAA Safety Rule necessities to make use of distant communication applied sciences to offer audio-only telehealth companies?
    • The OCR clarified that the HIPAA Safety Rule doesn’t apply to audio-only telehealth companies supplied utilizing a phone landline as a result of the data transmitted isn’t digital. Nonetheless, the HIPAA Safety Rule does apply to the usage of digital communication applied sciences, similar to communication apps on a smartphone or different computing system, Voice over Web Protocol (VoIP) applied sciences, applied sciences that electronically document or transcribe a telehealth session, and messaging companies that electronically retailer audio messages. Thus, lined entities want to handle safety dangers and vulnerabilities to digital PHI when utilizing these applied sciences as a part of the chance evaluation and danger administration processes.
  3. Whether or not a well being care supplier or a well being plan might conduct audio-only telehealth utilizing distant communication applied sciences and not using a enterprise affiliate settlement (“BAA”) with the seller?
    • In keeping with its prior place on the difficulty, the OCR said that HIPAA doesn’t require a BAA between a supplier and vendor the place the seller solely has transient entry to PHI it transmits throughout a name as a result of the seller is merely appearing as a conduit for the PHI and isn’t creating, receiving, or sustaining PHI on behalf of the supplier. As an illustration, a BAA isn’t required the place a supplier conducts an audio-only telehealth session with a affected person utilizing a smartphone and the seller’s sole function is connecting the decision. Nonetheless, a supplier must enter right into a BAA with a vendor that’s greater than a mere conduit for PHI. For instance, a BAA is required the place the seller’s smartphone app shops PHI (e.g., recordings, transcripts) or interprets oral communications to a different language (and due to this fact creates and receives PHI) to offer significant entry to people with restricted English proficiency.
  4. Whether or not well being care suppliers might use distant communication applied sciences to offer audio-only telehealth if a person’s well being plan doesn’t present protection for these companies?
    • OCR famous that suppliers might provide audio-only telehealth companies utilizing distant communication applied sciences in keeping with the necessities of the HIPAA Guidelines, no matter whether or not any well being plan covers or pays for these service.

OCR’s new HIPAA steerage on utilizing distant communication applied sciences for audio-only telehealth could be discovered right here.

Milada Goturi and Kevin Kifer are members of Thompson Coburn’s well being care apply.

[ad_2]

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments