In a recent development that has caught the attention of health law professionals, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the body in charge of enforcing the Health Insurance Portability and Accountability Act (HIPAA), advanced further into the digital health arena by issuing two new guidance documents on October 18, 2023. These documents underline privacy and security risks associated with the use of telehealth services.
The title of one of the two guidance documents is “Educating Patients about Privacy and Security Risks to Protected Health Information when Using Remote Communication Technologies for…”
This initiative by the OCR brings to light the pressing concern of security risks tied to remote healthcare services, a domain that has seen accelerated growth due to recent global events. By focusing on patient education regarding privacy and security, there is an apparent shift toward recognizing the critical role patients play in safeguarding their own health information.
This new guidance, which substantially impacts providers of telehealth services, emphasizes a proactivity approach towards HIPAA enforcement. Health law experts are encouraged to scrutinize these developments closely as they could outline the future direction of regulation for health data privacy and security.
For an elaborate read on this issue, follow this link to review the OCR’s new guidance documents in entirety and glean in-depth insights into potential implications for telehealth service providers.