fbpx

Intersection Between HIPAA and Emerging Telehealth Practices

Telehealth is changing the way that patients can access health care, but when new technology meets decades-old federal regulation, tensions will necessarily arise.

When it comes to the intersection between telehealth and HIPAA regulation, there are many common misconceptions about how to run a telehealth practice while maintaining compliance with federal privacy and security standards.

Before we dive into some of the particularities of HIPAA as they apply to telehealth professionals, let's look at some of the basics of HIPAA regulation.

Understanding HIPAA Compliance

HIPAA regulation is composed of a series of HIPAA Rules that outline national standards for the use and distribution of protected health information (PHI). PHI is any demographic information that can potentially identify a patient. Common examples of PHI include name, address, date of birth, phone number, Social Security number, insurance ID number, medical record, or full facial photograph, to name a few.

Under the regulation, telehealth practitioners are considered covered entities. A covered entity is any health care provider, health care clearinghouse, or insurance company. As a covered entity, a telehealth practitioner is required to address all elements of the HIPAA Rules. 

Here is a list of the HIPAA Rules and what they generally require:

  • HIPAA Privacy Rule: The HIPAA Privacy Rule establishes federal standards for the use and disclosure of PHI. This includes employee access and patient authorization forms.
  • HIPAA Security Rule: The HIPAA Security Rule sets standards for how practitioners must safeguard PHI they encounter. The rule is broken up into Administrative, Physical, and Technological standards.
  • HIPAA Omnibus Rule: The HIPAA Omnibus Rule states that before any PHI can be shared with vendors, the two organizations must execute Business Associate Agreements to ensure that data is protected in transit and reduce liability in the event of a breach.
  • HIPAA Breach Notification Rule: The Breach Notification Rule identifies the different classifications of data breaches that an organization can experience. It also outlines how organizations must respond to these breaches via patient notification and HHS reporting.

These are the fundamental HIPAA Rules that all health care providers must adhere to regardless of how they conduct their business--telehealth or otherwise.

But in addition to these Rules, there are certain key areas that make telehealth practitioners potentially more vulnerable to a HIPAA violation.

HIPAA Violations and Telehealth

Because Telehealth professionals rely on telecommunications and video chat clients to serve their patients, the risk of data being exposed in the event of a health breach is significant.

In order to protect your practice from potential data breaches caused by a faulty vendor, your practice must have a robust HIPAA compliance program in place first in order to establish uniform policies. These policies will guide your practice in the event that a relationship with a vendor begins or ends. By outlining exactly who can share information with vendors and under what circumstances, your practice is already significantly reducing your risk of PHI being mishandled.

Once your organization's HIPAA compliance plan is in place, you must ensure that you execute Business Associate Agreements with all vendors BEFORE any PHI is shared. Vendors who handle PHI over the course of the work they've been hired to perform are necessarily considered business associates under HIPAA. 

Business Associate Agreements ensure that your practice will not be held liable in the event of a data breach caused by a vendor. With massive data breaches like the Equifax and Anthem examples from 2017 making headlines, Business Associate Agreements are more important than ever before.

And finally, your practice must perform due diligence investigations of vendors you decide to do business with. By assessing the security measures and security infrastructure your vendors have in place, in addition to the status of their HIPAA compliance, before doing business with them, you can save your practice from mounting HIPAA audits and fines.

These are just a few of the ways telehealth professionals can start protecting their practice right now from data breaches and ensuing HIPAA violations.

About Compliancy Group:

Compliancy Group gives telehealth professionals confidence in their HIPAA compliance with The Guard®. The Guard is a web-based HIPAA compliance solution, built by former auditors to help simplify compliance.

Compliancy Group's team of expert Compliance Coaches® field questions and guide users through the implementation process, taking the stress out of managing compliance. The Guard is built to address the full extent of HIPAA regulation, including fully automated documentation of policies, procedures, employee training, and vendor management.

With The Guard, telehealth professionals can focus on running their practice while keeping their patients' data protected and secure.

Find out more about how Compliancy Group and the HIPAA Seal of Compliance® can help simplify your HIPAA compliance today!

Because of the benefits Compliancy Group can bring to clinical practices and IT providers, Telehealth Certification Institute has an affiliation agreement with them. Follow the link above to our affiliate page on their site to receive the first three months free.

Leave a comment

Make sure you enter all the required information, indicated by an asterisk (*). HTML code is not allowed.

Oustanding presentation!!!
Michelle Collins

Helpful and inviting information to get started. Feel empowered to get this going and eager to start!

Dena Damaskinos

Well presented, easy to access and understand.

Sedonia Perrier
CEO / Steelhead LLC

This was very informative.

Wendy Pazdur
Substance Abuse Counselor / Transformation therapy
This course was full of detailed information, that I will utilize in my practice. I highly recommend this training to all interested in adding to their existing practice or transitioning to Telehealth Services.
Utopia Session
Class was informative.
Kimberly Horrell
This course was short yet informative.
Annette Cornish
Therapist / Dust 2 Destiny Counseling & Wellness
Great training!
Jacqueline Hayes, M.Ed., LPC, LMHP
Professional Counselor 4 / State of LA
Ray was a wonderful, interactive instructor who really captured the heart of counseling in the world of Telehealth. The course was thorough and beneficial. Two thumbs up!
Rachel Morales
Licensed Professional Counselor
Ray does a spectacular job presenting the ethics in technology! Thank you!
Elaine Marie Barclay
Licensed Professional Counselor/ Assistant Professor / Shorter University/ Capella University
Very beneficial and useful to the direction i am moving of providing therapy
Linda Marie Margosian, MS, NCC, LMHC
I thought the video was very informative and gave me a good back ground on Telehealth , hippa laws and things I needed to know to run an ethical and hippa complent practice .
Meg Maginn
Director /private practitioner / Eating Disorder Associates

I believe this is a good course to take because this is the new wave of society. As a therapist I would like to be able to offer clients the best tools available.

Wihletta Michelle Davis MA, LPC
Therapist / Find the Miracle Within...
This course was very informative for me as a clinician and for my profession
Roseline Ngoeh
Community Clinician / NPS

Thank you for the introduction to telemental health.

Michele Frances Purvin
Psychotherapist / Michele Frances Purvin, LCSW, LCDC

Very good.

Franklin Castillo

Really excellent training full of valuable information and resources - surpassed my expectations!

Dori Ryherd
Therapist / The Cognitive Refinery

Great information with step by step instructions

Donna Tucker
Addiction Counselor / Spectrum Health

What a superb introduction to telemental health, well organized and packed with useful tips. I so appreciate this. Thank you.

Ann P Cahouet
Owner - Clinician / Equine Assisted Solutions LLC

Awesome job! This is a very insightful presentation.

ZUNILDA CHAUDRY
Licensed Therapist, LPC / Seasons of Change Behavioral Health Services, Inc
Ray is down-to-earth, warm, pragmatic and exceptionally well-informed.
G. Reid Doster, LPC, LMFT
Director of Behavioral Health, EXCELth Inc.Primary Health Network & Private Practice Psychotherapist / www.excelth.com

An excellent course, but needs more legal information regarding where the patient needs to reside.

Barry Barmann
Clinical Psychologist / Behavior Therapy & Family Counseling Clinic
This legal course was phenomenal saturated with much detail and clarity!
Elaine Marie Barclay
Licensed Professional Counselor, Assistant Professor / Capella University and Shorter University
Great and very informative! Will help me take my skills to a new level. Gave me a great idea of how the session should go.
Jessica Latin
LPC / JL Counseling

Course provided several case scenarios regarding Interstate counseling and resource websites for further research.

Cowenda Jefferson
Clinical Director / Wise Life Choices LLC
Course provided additional information regarding the legal aspects of TeleMental Health.
Cowenda Jefferson
Clinical Director / Wise LIfe Choices LLC
I have completed prior training by Raymond and greatly appreciate his detailed and thorough trainings.
Dr Lynn Duffy, PsyD, LCPC, NCC, CCMHC, BCPCC, BC-TMH, Diplomate/CMH in Trauma
Director/Counselor/Mediator / Lighthouse Counseling & Consulting Services
This course was most helpful in helping me make my practice more compliant for me and my clients.
Marlene Small
Private Psychotherapist
This is the 4th TMH course I have taken with Ray and it is BY FAR the best TMH training out there. I've learned so much that I can use every day in my practice.
Dawn Ferrara
LPC-S, LMFT

Very Informative

Naomie Pierre
community clinician / nps
I loved this course. It was very informative and provide a great deal of information about ethics.
Tracey Marshall
Easy to learn and easy to follow. User friendly on-line course.
Kelly Johnson
Licensed Mental Health Therapist

Awesome

Melissa J Davis
LAPC- counselor
This was a phenomenal training and necessary for the continued growth of all helping professionals. This will certainly improve the manner in which I conduct counseling.
Elaine Marie Barclay
This training was extremely informative and supportive for professionals looking to gain further knowledge in Telemental health.
Marcy Abramsky
LCSW / Marcy Abramsky LCSW, InspireAmind TM Counseling and Consulting
I found this video to be very informative and helpful.
Michelle Parker
Contract Therapist

Great course, very informative!

Ashley Simmons
BCBA / Northstar Psychological Services

Love the course, worth every penny!!! Definitely helped jump start my Tele-mental health services!

Nakia Clark
Owner/ Therapist / Insightfullly You, LLC

This gave me and my staff some important insights and information regarding telehealth..

Larry Cowan
Executive Director / Samaritan Counseling and Growth

This course was easy and user friendly

Vanessa Reiser
Social Worker / JBFCS

I learned a great deal from this program and look forward to implementing telemental health in my therapy practice.

Michelle Hitchcock
Therapist

It was fantastic! Just the forms he provides are worth the cost of the course!

Mark Wagemaker, LPC, NCC, DCC, CPCS
Counselor, Clinical Supervisor / Transitions Counseling

This was an excellent class and worth my time.  Ray provided great information and is clearly an expert in TMH!

Jennifer Stuckert
Director / Restoration Counselor of Atlanta, LLC

I found these courses informative and helpful. They make establishing best practices policies and procedures for telemental health services and supervising those who provide them. so much easier. I highly recommend his courses.

Nena Rybarczyk, MA, EMBA, LPC, NCC, CPCS
Counselor / Strategies for Life Counseling, LLC

Ray's workshop was one of the most informative I have taken in years. He brought clarity to took a topic which has been intimidating and I left feeling empowered!

TRUDY POST SPRUNK, LMFT-S LPC CPCS RPT-S CPT-S EMD
Clinical Supervisor and Play Therapist / Georgia Association for Play Therapy