ARTICLE
1 November 2023

Telehealth Privacy And Security Risk Mitigation: Office For Civil Rights Provides Guidance To Providers, Patients

GT
Greenberg Traurig, LLP

Contributor

Greenberg Traurig, LLP has more than 2750 attorneys in 47 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 500. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.
On Oct. 18, 2023, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued two resources for health care providers and patients regarding...
United States Food, Drugs, Healthcare, Life Sciences
To print this article, all you need is to be registered or login on Mondaq.com.

On Oct. 18, 2023, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued two resources for health care providers and patients regarding the potential risks of using telehealth services. Although HIPAA does not require regulated entities to educate patients about these risks, OCR published these guidance documents to assist providers that wish to voluntarily inform patients of potential privacy and security exposures stemming from the use of telehealth tools.

The first resource, Educating Patients about Privacy and Security Risks to Protected Health Information when Using Remote Communication Technologies for Telehealth, is intended to assist providers in educating patients on how to use telehealth technologies safely. This guidance includes suggestions for how to explain the applicability of HIPAA to remote communication vendors, how telehealth may be used in practice, and how to prepare patients for the use of such technologies. The guidance also includes a non-exhaustive list of risks associated with remote communications (e.g., the chance that health information could inadvertently be disclosed if the patient participates in a telehealth session in a public location) and emphasizes the importance of implementing software updates to avoid potential exploitation of software weaknesses. Finally, the guidance reminds providers that patients have a right to file a privacy complaint if they feel there has been a violation of their privacy rights. Patients can make such complaints via the OCR complaint portal.

The second guidance document, Telehealth Privacy and Security Tips for Patients, provides suggestions for patients to better control and improve the security of their devices when accessing telehealth services and transmitting their protected health information. These recommendations include traditional electronic security approaches, such as using strong unique passwords, using encryption tools when possible, and avoiding public wi-fi connections. The guidance also encourages patients to delete health information from personal devices once the patient no longer needs to retain such information, and to turn off devices that may be listening to telehealth meetings, such as smart devices. Further, the guidance encourages patients to note agency guidance related to protecting cell phone privacy and security, improving security when using telehealth services, and ensuring cybersecurity in patients' personal devices.

* Special thanks to Tyler Strobel˘ for his valuable contributions to this GT Alert.
˘ Not admitted to the practice of law.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More