Can you give me any information on working from your home, and obeying all the HIPAA rules and regulations?
HIPAA Weekly Advisor, February 24, 2004
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Question: I work at a plastic surgery office. My manager is going to be on maternity leave for a few months and needs information on HIPAA regulations for working at home. Can you give me any information on working from your home, and obeying all the HIPAA rules and regulations?
Answer: The security rule indicates that working from home requires security policies and practices--just as working in the office. But it gives no specifics. It's up to each covered entity to establish these documents based on their security risk assessment.
Security measures should address the technical setup. A typical security policy might stipulate that the telecommuter use a computer--preferably dedicated--with a virtual private network (VPN) solution, antivirus software and a firewall, assuming the computer's connected to the Internet and the office. The policy might also address the management of work papers and disks, and the computer work environment (protected from family and visitors).
As to privacy compliance, privacy policies should apply just the same at home.
Editor's note: Answered by Kate Borten, CISSP, president of The Marblehead Group, in Marblehead, MA. This is not legal advice. Be sure to consult with your facility's legal counsel for legal matters.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- HIPAA Q&A: Level of encryption needed for email
- What does case-mix index mean to you?
- Identify potential Medicaid RAC target areas
- QA:Coding multiple initial infusions
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched