decisionhealth Newsletters, Part B News - 2020 Issue 4 (April)
Be careful with HIPAA under OCR’s ‘good faith’ telehealth provision; you may face future risk
Subscribe or sign in to view the full article.
Article Overview
This article covers how OCR’s telehealth-related enforcement discretion changed the practical landscape for remote care during the COVID-19 public health emergency. It is aimed at providers, compliance staff, and advisers who need to understand the privacy and security implications of using telehealth tools, the role of business associate agreements, and the importance of documenting and safeguarding patient information even when enforcement is relaxed. The piece also discusses related concerns for staff practices, remote work, and maintaining security controls across telehealth workflows.
Why This Topic Matters
Providers using telehealth need to balance access to care with HIPAA privacy and security obligations. The article helps readers understand the compliance risks that can remain even when enforcement is relaxed, and highlights why security planning, staff training, and patient communication still matter.
Article Sections
-
Telehealth enforcement discretion during COVID-19
Introduces the federal telehealth expansion and the OCR enforcement discretion statement issued during the public health emergency. Summarizes the broader context for remote care and compliance concerns.
-
Counseling caution
Presents outside perspectives urging providers to remain cautious with telehealth technology and privacy practices. Discusses general concerns about enforcement, state law, and potential future liability.
-
Push the patient to compliance
Focuses on patient communication, technology choices, documentation, and general risk-reduction steps when using telehealth platforms. Also addresses the importance of documenting patient preferences and informed discussion about platform use.
-
5 tips for the new tech
Outlines broad security and privacy considerations for adopting telehealth tools, including platform selection, security settings, risk analysis, and patient-side precautions. Emphasizes operational safeguards rather than specific clinical guidance.
-
Don’t forget your own staff
Addresses internal practice security, remote work vulnerabilities, and employee training issues related to telehealth and electronic systems. Highlights the need for ongoing attention to staff behavior and cybersecurity.
What You Will Learn
- How OCR’s telehealth enforcement discretion affected HIPAA compliance concerns during the COVID-19 emergency
- What general privacy and security issues arise when using remote communication tools for patient care
- Why documentation, staff training, and security planning remain important in telehealth workflows
- How patient communication and internal practice policies support safer telehealth operations
Who Should Read This
- Physicians and other covered health care providers
- HIPAA compliance and privacy officers
- Practice managers
- Health care attorneys and consultants
- Health information security professionals
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com