Q&A: Processing PHI at home
Compliance Monitor, May 27, 2009
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Q: Is taking PHI home to process it legal?
A: Yes, work force members may process electronic and nonelectronic PHI remotely from their homes. The HIPAA security and privacy rules do not prohibit this practice. However, the rules do require adoption of appropriate remote access policies, procedures, and practices that include transporting the PHI securely and reasonably ensuring that it is secure when processed remotely.
This practice represents an additional security risk, as does any work performed remotely that requires access to electronic or nonelectronic PHI. A significant risk exists when organizations fail to implement appropriate remote policies, procedures, and practices and fail to monitor remote access and PHI use regularly.
CMS published remote access guidelines in 2007 (available at www.cms.hhs.gov/SecurityStandard), which facilities and their remote workers should follow. The guidelines do not address remote use of paper PHI, but they include guidelines to minimize risk. Taking any PHI home creates new environments that need to be secure (e.g., the mode of transportation a full- or part-time teleworker uses to carry PHI and the home where he or she accesses it).
This question was answered by Chris Apgar, CISSP in the June 2009 issue of the HCPro newsletter Briefings on HIPAA. For more information about this newsletter visit the HCMarketplace.
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- HIPAA Q&A: Level of encryption needed for email
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- Capturing all necessary codes for IUD insertion and removal can be challenging
- Topic: CMS, OESS post new security compliance review information, checklist
- What does case-mix index mean to you?
- Q&A: Acute respiratory failure diagnosis does not require intubation
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- HIPAA Q&A: Level of encryption needed for email
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- CMS has reformulated payments for some bilateral procedures
- Oxygen Cylinder Storage Requirements
- Q&A: Follow CMS' coding guidelines when using modifier -25
- Understand the spine to code back procedures correctly
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Searched
