This month, the U.S. Department of Health and Human Services (“HHS”) issued guidance waiving enforcement of certain provisions of the Health Insurance Portability and Accountability Act (“HIPAA”) in response to the COVID-19 nationwide public health emergency.

Covered Health Care Providers

On March 17, 2020, the Department of Health and Human Services Office for Civil Rights (“OCR”) announced that it will exercise enforcement discretion for health care providers communicating with patients and providing telehealth services through remote communications technologies during the COVID-19 nationwide public health emergency. OCR’s Notification of Enforcement Discretion states that it will waive sanctions and penalties for HIPAA violations connected to the “good faith” provision of telehealth through the use of audio or video communication technologies. Covered health care providers may use certain technologies for telehealth services, even if the technologies or the manner in which they are used by health care providers do not comply with the HIPAA Rules.

Under the Notification, OCR permits health care providers to use non-public facing audio or video applications – i.e., those applications not accessible from the Internet but only from within the internal network – for the purpose of assessing and treating a patient exhibiting COVID-19 symptoms or other medical conditions not related to COVID-19. OCR encourages providers to enable all available encryption and privacy modes for the applications and to notify their patients that there may be privacy risks. OCR emphasizes that health care providers are not allowed to use public facing applications for the provision of telehealth.

Covered health care providers who want additional privacy protections are encouraged to use technology vendors that are HIPAA compliant and will enter into a business associate agreement (“BAA”) for their video communication products. OCR’s Notification contains a list of vendors that represent they are HIPAA-compliant, but notes that OCR has not reviewed the BAAs offered by these vendors. During the COVID-19 nationwide public health emergency, OCR will not impose penalties related to the good faith provision of telehealth services for covered health care providers that do not have a BAA with video communication vendors.

Covered Hospitals

Effective March 15, 2020, HHS will also waive sanctions and penalties for covered hospitals that do not comply with certain provisions of the HIPAA Privacy Rule. The limited waiver states that covered hospitals will not risk HIPAA violations for failing to comply with:

  • the requirement to obtain patient authorization to speak with family members or friends involved with the patient’s care;
  • the requirement to honor a patient’s request to opt out of the facility directory;
  • the requirement to distribute a notice of privacy practices;
  • the patient’s right to request additional privacy restrictions; and
  • the patient’s right to request confidential communications.

This limited waiver applies only (1) in the emergency area identified in the public health emergency declaration; (2) to covered hospitals that have instituted a disaster protocol; and (3) for up to 72 hours after the hospital implements its disaster protocol. Once the declaration of a public health emergency is terminated, covered hospitals must resume compliance with all HIPAA requirements for any patient under their care.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Anna D. Kraus Anna D. Kraus

Anna Durand Kraus has a multi-disciplinary practice advising clients on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (HHS) gives her broad experience…

Anna Durand Kraus has a multi-disciplinary practice advising clients on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (HHS) gives her broad experience with, and valuable insight into, the programs and issues within the purview of HHS, including Medicare, Medicaid, fraud and abuse, and health information privacy. Ms. Kraus regularly advises clients on Medicare reimbursement matters, the Medicaid Drug Rebate program, health information privacy issues (including under HIPAA and the HITECH Act), and the challenges and opportunities presented by the Affordable Care Act.

Photo of Tara Carrier Tara Carrier

Tara Carrier advises clients on a variety of health care compliance matters, including fraud and abuse, health information privacy and compliance with HIPAA, promotion and advertising, market access, pricing and reimbursement activities, and other related areas. She routinely advises on regulatory compliance and…

Tara Carrier advises clients on a variety of health care compliance matters, including fraud and abuse, health information privacy and compliance with HIPAA, promotion and advertising, market access, pricing and reimbursement activities, and other related areas. She routinely advises on regulatory compliance and enforcement risk, commercial transactions, and administrative and legislative policy opportunities. Tara also has experience counseling clients on investigations and compliance matters, including implementing and operating under HHS OIG Corporate Integrity Agreements.