HIPAA Q&A: Taking PHI home
HIM-HIPAA Insider, October 5, 2009
Q. Several weeks ago, some security specialists indicated that their staff members take paper PHI home with them to get caught up on their work. Is taking PHI home to process it legal?
A. Yes, workforce members may process electronic and nonelectronic PHI remotely from their homes. The HIPAA security and privacy rules do not prohibit this practice. However, the rules do require adoption of appropriate remote access policies, procedures, and practices that include transporting the PHI securely and reasonably ensuring that it is secure when processed remotely.
Taking PHI home represents an additional security risk, as does any work performed remotely that requires access to electronic or nonelectronic PHI. A significant risk exists when organizations fail to implement appropriate remote policies, procedures, and practices and fail to monitor remote access and PHI use regularly.
CMS published remote access guidelines in 2007 that facilities and their remote workers should follow. The guidelines do not address remote use of paper PHI, but they include guidelines to minimize risk.
Taking any PHI home creates new environments that need to be secure—the mode of transportation a full- or part-time teleworker uses to carry PHI and the home where he or she accesses it.
Editor’s note: Chris Apgar, CISSP, answered this question. This is not legal advice. Consult your attorney regarding legal matters.
Related Products
Most Popular
- Articles
-
- Five tips for an effective hospital patient safety program
- Jury sides with blood lab technician in New Jersey whistleblower case
- Note from Hugh
- Note from the instructor: CMS clarifies payment amount to be applied to payment caps and manual review thresholds for outpatient therapy services provided by critical access hosptials
- Q/A: Should we use modifier -Q0 to override edits for ICDs?
- Questions surround when time starts for proposed inpatient presumption
- Overnight physicians in ICU show little effect on outcomes
- Recent Recovery Auditor activity
- QAPI is coming: Is your facility preparing for its arrival?
- Latest scores show incremental progress in hospital safety
- E-mailed
-
- Questions surround when time starts for proposed inpatient presumption
- Q/A: Should we use modifier -Q0 to override edits for ICDs?
- Jury sides with blood lab technician in New Jersey whistleblower case
- Overnight physicians in ICU show little effect on outcomes
- Five tips for an effective hospital patient safety program
- Note from the instructor: CMS clarifies payment amount to be applied to payment caps and manual review thresholds for outpatient therapy services provided by critical access hosptials
- Tip: Review codes that are now packaged
- QAPI is coming: Is your facility preparing for its arrival?
- ACDIS/AHIMA brief provides guidance on query best practices
- CMS recommends use of AHRQ Common Formats for hospital adverse event reporting
- Searched
