HIPAA Q&A: Taking PHI home
HIPAA Weekly Advisor, October 5, 2009
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Q. Several weeks ago, some security specialists indicated that their staff members take paper PHI home with them to get caught up on their work. Is taking PHI home to process it legal?
A. Yes, workforce members may process electronic and nonelectronic PHI remotely from their homes. The HIPAA security and privacy rules do not prohibit this practice. However, the rules do require adoption of appropriate remote access policies, procedures, and practices that include transporting the PHI securely and reasonably ensuring that it is secure when processed remotely.
Taking PHI home represents an additional security risk, as does any work performed remotely that requires access to electronic or nonelectronic PHI. A significant risk exists when organizations fail to implement appropriate remote policies, procedures, and practices and fail to monitor remote access and PHI use regularly.
CMS published remote access guidelines in 2007 that facilities and their remote workers should follow. The guidelines do not address remote use of paper PHI, but they include guidelines to minimize risk.
Taking any PHI home creates new environments that need to be secure—the mode of transportation a full- or part-time teleworker uses to carry PHI and the home where he or she accesses it.
Editor’s note: Chris Apgar, CISSP, answered this question. This is not legal advice. Consult your attorney regarding legal matters.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Billing telemetry daily monitoring
- Credentialing monthly: What is the role of the credentials committee in addressing unprofessional conduct?
- 2010 ICD-9 code updates now available online
- Master modifiers to ensure accurate reimbursement
- H1N1 hits Maine facility
- Radiologist indicted for fraudulently signing reports
- Don’t be scared into silence: Affiliation letter safeguards allow you to disclose more
- National Quality Forum creates standardized set of data for electronic health records
- New report reveals $47 billion in Medicare fraud
- Understand the H1N1 Flu and how to code it
- E-mailed
-
- Credentialing monthly: What is the role of the credentials committee in addressing unprofessional conduct?
- Q/A: Billing telemetry daily monitoring
- Radiologist indicted for fraudulently signing reports
- H1N1 hits Maine facility
- New report reveals $47 billion in Medicare fraud
- Revised MS.1.20 'huge improvement', out for comment again
- Briefings on Outpatient Rehab Reimbursement and Regulations, December 2009
- Hand hygiene rates improved through variety of reinforcement styles
- Press Ganey report: Patient satisfaction increasing across the country
- Residency Program Alert, December 2009
- Searched
