HHS Issues Guidance on HIPAA and Audio-Only Telehealth
HHS Issues Guidance on HIPAA and Audio-Only Telehealth
Today,
the U.S. Department of Health and Human Services (HHS), through its
Office for Civil Rights (OCR), is issuing guidance on how covered health
care providers and health plans can use remote communication
technologies to provide audio-only telehealth services when such
communications are conducted in a manner that is consistent with the
applicable requirements of the Health Insurance Portability and
Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach
Notification Rules, including when OCR’s Notification of Enforcement Discretion for Telehealth - PDF is no longer in effect.
This guidance will help individuals to continue to benefit from
audio-only telehealth by clarifying how covered entities can provide
these services in compliance with the HIPAA Rules and by improving
public confidence that covered entities are protecting the privacy and
security of their health information.
While telehealth can significantly expand access to health care,
certain populations may have difficulty accessing or be unable to access
technologies used for audio-video telehealth because of various
factors, including financial resources, limited English proficiency,
disability, internet access, availability of sufficient broadband, and
cell coverage in the geographic area. Audio-only telehealth, especially
using technologies that do not require broadband availability, can help
address the needs of some of these individuals.
“Audio telehealth is an important tool to reach patients in rural
communities, individuals with disabilities, and others seeking the
convenience of remote options. This guidance explains how the HIPAA
Rules permit health care providers and plans to offer audio telehealth
while protecting the privacy and security of individuals’ health
information,” said OCR Director Lisa J. Pino.
The Guidance on How the HIPAA Rules Permit Health Plans and Covered
Health Care Providers to Use Remote Communication Technologies for
Audio-Only Telehealth
When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials? Answer: The Privacy Rule is balanced to protect an individual’s privacy while allowing important law enforcement functions to continue. The Rule permits covered entities to disclose protected health information (PHI) to law enforcement officials, without the individual’s written authorization, under specific circumstances summarized below. For a complete understanding of the conditions and requirements for these disclosures, please review the exact regulatory text at the citations provided. Disclosures for law enforcement purposes are permitted as follows: To comply with a court order or ...read more |
Mental Health Center Provides Access and Revises Policies and Procedures Covered Entity: Mental Health Center Issue: Access, Restrictions The complainant alleged that a mental health center (the "Center") refused to provide her with a copy of her medical record, including psychotherapy notes. OCR’s investigation revealed that the Center provided the complainant with an opportunity to review her medical record, including the psychotherapy notes, with her therapist, but the Center did not provide her with a copy of her records. The Privacy Rule requires covered entities to provide individuals with access to their medical records; however, the Privacy Rule exempts ...read more |
HMO Revises Process to Obtain Valid Authorizations Covered Entity: Health Plans / HMOs Issue: Impermissible Uses and Disclosures; Authorizations A complaint alleged that an HMO impermissibly disclosed a member’s PHI, when it sent her entire medical record to a disability insurance company without her authorization. An OCR investigation indicated that the form the HMO relied on to make the disclosure was not a valid authorization under the Privacy Rule. Among other corrective actions to resolve the specific issues in the case, the HMO created a new HIPAA-compliant authorization form and implemented a new policy that directs staff to obtain patient signatures ...read more |
Hospital Implements New Minimum Necessary Polices for Telephone Messages Covered Entity: General Hospital Issue: Minimum Necessary; Confidential Communications A hospital employee did not observe minimum necessary requirements when she left a telephone message with the daughter of a patient that detailed both her medical condition and treatment plan. An OCR investigation also indicated that the confidential communications requirements were not followed, as the employee left the message at the patient’s home telephone number, despite the patient’s instructions to contact her through her work number. To resolve the issues in this case, the hospital developed and implemented several new procedures. ...read more |
|
October 2025
Su | Mo | Tu | We | Th | Fr | Sa |
| | | 1 | 2 | 3 | 4 |
5 | 6 | 7 | 8 | 9 | 10 | 11 |
12 | 13 | 14 | 15 | 16 | 17 | 18 |
19 | 20 | 21 | 22 | 23 | 24 | 25 |
26 | 27 | 28 | 29 | 30 | 31 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
November 2022 (54) January 2025 (1)
Blog Labels
Data Breach (1) EHR Fraud (1) Telehealth (1) PPP Fraud (1) BAA (4) ePHI (2) HIPAA (2) HIPAA Enforcement (3) Covered Entity (40)
|