decisionhealth Newsletters, Part B News - 2023 Issue 4 (April)
As PHE nears end, know when audio-only care becomes ePHI — and stay compliant
Subscribe or sign in to view the full article.
Article Overview
This article covers HIPAA compliance issues for audio-only telehealth services, with emphasis on when remote communication technologies create security obligations and how that affects covered entities as the public health emergency enforcement discretion ends. It is relevant to medical practices, compliance staff, and telehealth providers who need a high-level understanding of OCR guidance, privacy and security safeguards, and the operational considerations tied to phone-based care.
Why This Topic Matters
As telehealth policies evolve after the public health emergency, practices need to understand which audio-only workflows may trigger HIPAA security requirements and what safeguards OCR expects. This helps organizations reduce privacy risk and prepare staff and systems for ongoing compliance.
Article Sections
-
HIPAA compliance for audio-only telehealth
Introduces the compliance focus for phone-based care and the role of OCR guidance as enforcement discretion changes. It frames the topic around telehealth operations and HIPAA obligations.
-
How OCR guidance applies to remote communication technologies
Summarizes the federal guidance on audio-only telehealth and the broader categories of communication technologies discussed by OCR. It explains the article’s focus on when telehealth remains within HIPAA’s scope.
-
Is the ePHI just passing through?
Discusses the distinction between transient transmission and situations where electronic information is retained or otherwise handled in a way that affects security obligations. It highlights the importance of understanding what happens to patient information during the call.
-
Review HIPAA requirements for audio-only care
Covers general privacy and security preparedness steps for audio-only care as practices approach the end of the temporary enforcement flexibility. It also addresses operational safeguards and organizational readiness.
What You Will Learn
- How OCR guidance addresses audio-only telehealth under HIPAA
- What broad factors affect whether phone-based care raises security obligations
- What types of operational safeguards practices should consider for audio-only services
- How the end of temporary enforcement discretion affects telehealth compliance planning
Who Should Read This
- Medical practices
- Telehealth providers
- Compliance officers
- Privacy and security staff
- Practice managers
Codes Discussed
Code Ranges Discussed
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com