HHS Issues Guidance on HIPAA and Audio-Only Telehealth
HHS Issues Guidance on HIPAA and Audio-Only Telehealth
Today,
the U.S. Department of Health and Human Services (HHS), through its
Office for Civil Rights (OCR), is issuing guidance on how covered health
care providers and health plans can use remote communication
technologies to provide audio-only telehealth services when such
communications are conducted in a manner that is consistent with the
applicable requirements of the Health Insurance Portability and
Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach
Notification Rules, including when OCR’s Notification of Enforcement Discretion for Telehealth - PDF is no longer in effect.
This guidance will help individuals to continue to benefit from
audio-only telehealth by clarifying how covered entities can provide
these services in compliance with the HIPAA Rules and by improving
public confidence that covered entities are protecting the privacy and
security of their health information.
While telehealth can significantly expand access to health care,
certain populations may have difficulty accessing or be unable to access
technologies used for audio-video telehealth because of various
factors, including financial resources, limited English proficiency,
disability, internet access, availability of sufficient broadband, and
cell coverage in the geographic area. Audio-only telehealth, especially
using technologies that do not require broadband availability, can help
address the needs of some of these individuals.
“Audio telehealth is an important tool to reach patients in rural
communities, individuals with disabilities, and others seeking the
convenience of remote options. This guidance explains how the HIPAA
Rules permit health care providers and plans to offer audio telehealth
while protecting the privacy and security of individuals’ health
information,” said OCR Director Lisa J. Pino.
The Guidance on How the HIPAA Rules Permit Health Plans and Covered
Health Care Providers to Use Remote Communication Technologies for
Audio-Only Telehealth
| Can a covered entity use existing aspects of the HIPAA Privacy Rule to give individuals the right to decide whether sensitive information about them may be disclosed to or through a health information organization (HIO)? Yes. To the extent a covered entity is using a process either to obtain consent or act on an individual’s right to request restrictions under the Privacy Rule as a method for effectuating individual choice, policies can be developed for obtaining consent or honoring restrictions on a granular level, based on the type of information involved. For example, specific consent and restriction policies could ...read more |
| Wednesday, November 9, 2022 A federal grand jury in Newark, New Jersey, returned an indictment today charging an Indian national for fraudulently obtaining millions of dollars in Paycheck Protection Program (PPP) loans guaranteed by the Small Business Administration (SBA) under the Coronavirus Aid, Relief, and Economic Security (CARES) Act. According to court documents, Abhishek Krishnan, 40, previously resided in Wake County, North Carolina, before returning to his home country of India. After returning to India, Krishnan allegedly submitted numerous fraudulent PPP loan applications to federally insured banks, including on behalf of purported companies that were not registered business entities. ...read more |
| Pharmacy Chain Revises Process for Disclosures to Law Enforcement Covered Entity: Pharmacies Issue: Impermissible Uses and Disclosures A chain pharmacy disclosed protected health information to municipal law enforcement officials in a manner that did not conform to the provisions of the Privacy Rule. Among other corrective actions to resolve the specific issues in the case, OCR required this chain to revise its national policy regarding law enforcement's access to patient protected health information to comply with the Privacy Rule requirements, including that disclosures of protected health information to law enforcement only be made in response to written requests from ...read more |
| Mental Health Center Corrects Process for Providing Notice of Privacy Practices Covered Entity: Outpatient Facility Issue: Notice A mental health center did not provide a notice of privacy practices (notice) to a father or his minor daughter, a patient at the center. In response to OCR’s investigation, the mental health center acknowledged that it had not provided the complainant and his daughter with a notice prior to her mental health evaluation. To resolve this matter, the mental health center revised its intake assessment policy and procedures to specify that the notice will be provided and the clinician will attempt to ...read more |
|
January 2026
| Su | Mo | Tu | We | Th | Fr | Sa |
| | | | 1 | 2 | 3 |
| 4 | 5 | 6 | 7 | 8 | 9 | 10 |
| 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| 18 | 19 | 20 | 21 | 22 | 23 | 24 |
| 25 | 26 | 27 | 28 | 29 | 30 | 31 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
January 2025 (1) November 2022 (54)
Blog Labels
BAA (4) Covered Entity (40) HIPAA (2) EHR Fraud (1) PPP Fraud (1) Telehealth (1) Data Breach (1) HIPAA Enforcement (3) ePHI (2)
|