HHS Issues Guidance on HIPAA and Audio-Only Telehealth
HHS Issues Guidance on HIPAA and Audio-Only Telehealth
Today,
the U.S. Department of Health and Human Services (HHS), through its
Office for Civil Rights (OCR), is issuing guidance on how covered health
care providers and health plans can use remote communication
technologies to provide audio-only telehealth services when such
communications are conducted in a manner that is consistent with the
applicable requirements of the Health Insurance Portability and
Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach
Notification Rules, including when OCR’s Notification of Enforcement Discretion for Telehealth - PDF is no longer in effect.
This guidance will help individuals to continue to benefit from
audio-only telehealth by clarifying how covered entities can provide
these services in compliance with the HIPAA Rules and by improving
public confidence that covered entities are protecting the privacy and
security of their health information.
While telehealth can significantly expand access to health care,
certain populations may have difficulty accessing or be unable to access
technologies used for audio-video telehealth because of various
factors, including financial resources, limited English proficiency,
disability, internet access, availability of sufficient broadband, and
cell coverage in the geographic area. Audio-only telehealth, especially
using technologies that do not require broadband availability, can help
address the needs of some of these individuals.
“Audio telehealth is an important tool to reach patients in rural
communities, individuals with disabilities, and others seeking the
convenience of remote options. This guidance explains how the HIPAA
Rules permit health care providers and plans to offer audio telehealth
while protecting the privacy and security of individuals’ health
information,” said OCR Director Lisa J. Pino.
The Guidance on How the HIPAA Rules Permit Health Plans and Covered
Health Care Providers to Use Remote Communication Technologies for
Audio-Only Telehealth
| Health Sciences Center Revises Process to Prevent Unauthorized Disclosures to Employers Covered Entity: General Hospitals Issue: Impermissible Uses and Disclosures; Authorizations A state health sciences center disclosed protected health information to a complainant's employer without authorization. Among other corrective actions to resolve the specific issues in the case, including mitigation of harm to the complainant, OCR required the Center to revise its procedures regarding patient authorization prior to release of protected health information to an employer. All staff was trained on the revised procedures. ...read more |
| Private Practice Revises Access Procedure to Provide Access Despite an Outstanding Balance Covered Entity: Private Practice Issue: Access A complainant alleged that a private practice physician denied her access to her medical records, because the complainant had an outstanding balance for services the physician had provided. During OCR’s investigation, the physician confirmed that the complainant was not given access to her medical record because of the outstanding balance. OCR provided technical assistance to the physician, explaining that, in general, the Privacy Rule requires that a covered entity provide an individual access to their medical record within 30 days of ...read more |
| Issued by: Office for Civil Rights (OCR) What if a HIPAA covered entity (or business associate) uses a CSP to maintain ePHI without first executing a business associate agreement with that CSP? Answer: If a covered entity (or business associate) uses a CSP to maintain (e.g., to process or store) electronic protected health information (ePHI) without entering into a BAA with the CSP, the covered entity (or business associate) is in violation of the HIPAA Rules. 45 C.F.R §§164.308(b)(1) and §164.502(e). OCR has entered into a resolution agreement and corrective action plan with a covered entity that OCR determined ...read more |
| State Hospital Sanctions Employees for Disclosing Patient's PHI Covered Entity: Health Care Provider / General Hospital Issue: Impermissible Disclosure A nurse and an orderly at a state hospital discussed the HIV/AIDS status of a patient and the patient's spouse within earshot of other patients without making reasonable efforts to prevent the disclosure. Upon learning of the incident, the hospital placed both employees on leave; the orderly resigned his employment shortly thereafter. Among other actions taken to satisfactorily resolve this matter, the hospital took further disciplinary action with the nurse, which included: documenting the employee record with a memo of ...read more |
|
May 2026
| Su | Mo | Tu | We | Th | Fr | Sa |
| | | | | 1 | 2 |
| 3 | 4 | 5 | 6 | 7 | 8 | 9 |
| 10 | 11 | 12 | 13 | 14 | 15 | 16 |
| 17 | 18 | 19 | 20 | 21 | 22 | 23 |
| 24 | 25 | 26 | 27 | 28 | 29 | 30 |
| 31 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
January 2025 (1) November 2022 (54)
Blog Labels
BAA (4) HIPAA (2) PPP Fraud (1) HIPAA Enforcement (3) EHR Fraud (1) Telehealth (1) Data Breach (1) ePHI (2) Covered Entity (40)
|