{"id":1763,"date":"2020-06-30T08:00:18","date_gmt":"2020-06-30T08:00:18","guid":{"rendered":"http:\/\/72.52.228.46\/~itegriti\/?p=1763"},"modified":"2021-04-12T03:41:45","modified_gmt":"2021-04-12T03:41:45","slug":"hipaa-enforcement-relaxed-due-to-covid-19-pandemic","status":"publish","type":"post","link":"https:\/\/itegriti.com\/staging\/2020\/compliance\/hipaa-enforcement-relaxed-due-to-covid-19-pandemic\/","title":{"rendered":"HIPAA Enforcement Relaxed due to Covid-19 Pandemic"},"content":{"rendered":"<p>[fusion_builder_container hundred_percent=&#8221;no&#8221; hundred_percent_height=&#8221;no&#8221; hundred_percent_height_scroll=&#8221;no&#8221; hundred_percent_height_center_content=&#8221;yes&#8221; equal_height_columns=&#8221;no&#8221; menu_anchor=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; status=&#8221;published&#8221; publish_date=&#8221;&#8221; class=&#8221;&#8221; id=&#8221;&#8221; background_color=&#8221;&#8221; background_image=&#8221;&#8221; background_position=&#8221;center center&#8221; background_repeat=&#8221;no-repeat&#8221; fade=&#8221;no&#8221; background_parallax=&#8221;none&#8221; enable_mobile=&#8221;no&#8221; parallax_speed=&#8221;0.3&#8243; video_mp4=&#8221;&#8221; video_webm=&#8221;&#8221; video_ogv=&#8221;&#8221; video_url=&#8221;&#8221; video_aspect_ratio=&#8221;16:9&#8243; video_loop=&#8221;yes&#8221; video_mute=&#8221;yes&#8221; video_preview_image=&#8221;&#8221; border_color=&#8221;&#8221; border_style=&#8221;solid&#8221; margin_top=&#8221;&#8221; margin_bottom=&#8221;&#8221; padding_top=&#8221;&#8221; padding_right=&#8221;&#8221; padding_bottom=&#8221;&#8221; padding_left=&#8221;&#8221; type=&#8221;legacy&#8221; admin_toggled=&#8221;no&#8221;][fusion_builder_row][fusion_builder_column type=&#8221;1_1&#8243; layout=&#8221;1_1&#8243; spacing=&#8221;&#8221; center_content=&#8221;no&#8221; link=&#8221;&#8221; target=&#8221;_self&#8221; min_height=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; class=&#8221;&#8221; id=&#8221;&#8221; background_color=&#8221;&#8221; background_image=&#8221;&#8221; background_image_id=&#8221;&#8221; background_position=&#8221;left top&#8221; background_repeat=&#8221;no-repeat&#8221; hover_type=&#8221;none&#8221; border_color=&#8221;&#8221; border_style=&#8221;solid&#8221; border_position=&#8221;all&#8221; border_radius=&#8221;&#8221; box_shadow=&#8221;no&#8221; dimension_box_shadow=&#8221;&#8221; box_shadow_blur=&#8221;0&#8243; box_shadow_spread=&#8221;0&#8243; box_shadow_color=&#8221;&#8221; box_shadow_style=&#8221;&#8221; padding_top=&#8221;&#8221; padding_right=&#8221;&#8221; padding_bottom=&#8221;&#8221; padding_left=&#8221;&#8221; margin_top=&#8221;&#8221; margin_bottom=&#8221;&#8221; animation_type=&#8221;&#8221; animation_direction=&#8221;left&#8221; animation_speed=&#8221;0.3&#8243; animation_offset=&#8221;&#8221; last=&#8221;true&#8221; border_sizes_top=&#8221;0&#8243; border_sizes_bottom=&#8221;0&#8243; border_sizes_left=&#8221;0&#8243; border_sizes_right=&#8221;0&#8243; first=&#8221;true&#8221; type=&#8221;1_1&#8243;][fusion_text columns=&#8221;&#8221; column_min_width=&#8221;&#8221; column_spacing=&#8221;&#8221; rule_style=&#8221;default&#8221; rule_size=&#8221;&#8221; rule_color=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; class=&#8221;&#8221; id=&#8221;&#8221;]During the COVID-19 public health emergency, Governments, as well as public and private organizations throughout the world are taking measures to contain and mitigate COVID-19. This can involve the processing of different types of sensitive personal data, including protected health information.<\/p>\n<p>Healthcare providers subject to the HIPAA Rules may seek to communicate with patients and provide telehealth services, through remote communications technologies.\u00a0 Some of these technologies, and the manner in which they are used by HIPAA covered healthcare providers, may not fully comply with the requirements of the HIPAA Rules.<\/p>\n<h2 class=\"navy\">\u201cEmpower Medical Providers to Serve Patients\u201d<\/h2>\n<p>In an effort to \u201cempower medical providers to serve patients wherever they are during this national public health emergency\u201d the Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/special-topics\/emergency-preparedness\/notification-enforcement-discretion-telehealth\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">announced<\/a> that it \u201cwill exercise its enforcement discretion and will not impose penalties for non-compliance with the regulatory requirements under the HIPAA Rules against covered healthcare providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.\u201d<\/p>\n<p>The goal is to ensure that public health officials, working to combat the pandemic, have quick access to as much data as possible by granting hospitals the ability to pass pertinent information along without worrying about violating any HIPAA rules. By relaxing HIPAA penalties, and thus ensuring public health organizations have access to the latest metrics and developments, health organizations could better design plans to manage the pandemic and more effectively halt its spread.<\/p>\n<p>Although data security worries likely still abound among consumers \u2014 and while the suspension of data-sharing penalties could make their worries more severe, the value that new data will provide in the short-term will likely override their concerns.<\/p>\n<h2 class=\"navy\">The Use of Telepresence Tools<\/h2>\n<p>According to the OCR notice, a healthcare provider that wants to use audio or video communication technology to provide telehealth services to patients during the COVID-19 public health emergency can use any available \u201dnon-public facing remote communication product\u201d to communicate with patients.<\/p>\n<p>For example, a healthcare provider may request to examine a patient exhibiting COVID- 19 symptoms, using a video application. The provider can take advantage of the app features to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation. Likewise, a healthcare provider may provide similar telehealth services in the exercise of their professional judgment to assess or treat any other medical condition, even if not related to COVID-19, adhering to social distancing measures and limiting unnecessary movement of patients.<\/p>\n<p>The OCR Notice suggests that healthcare providers may use popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, Zoom, or Skype, to provide telehealth without risk that OCR might seek to impose a penalty for noncompliance with the HIPAA Rules. At the same time, OCR states that Facebook Live, Twitch, TikTok, and similar video communication applications are public-facing, and should not be used in the provision of telehealth.<\/p>\n<p>However, the use of such applications is not risk-free. For instance, it was only recently that the University of Toronto\u2019s <a href=\"https:\/\/citizenlab.ca\/2020\/04\/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings\/\" target=\"_blank\" rel=\"noopener noreferrer\">Citizen Lab<\/a> examined Zoom\u2019s encryption and concluded that the teleconferencing app is \u201cnot suitable for secrets.\u201d It is important to understand the security of any video teleconferencing system used. Understanding and accepting the risk is important for any outsourced service.<\/p>\n<p>Providers are encouraged to notify patients that these third-party applications potentially introduce privacy risks. In addition, healthcare providers, as well as their patients, are strongly encouraged to enable all available encryption and privacy <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2020\/04\/03\/use-zoom-here-are-7-essential-steps-you-can-take-to-secure-it\/\" target=\"_blank\" rel=\"noopener noreferrer\">best practices<\/a> when using such applications, such as:<\/p>\n<ul>\n<li>Keeping the app updated<\/li>\n<li>Using passwords and two-factor authentication to protect meetings<\/li>\n<li>Not sharing meeting details in public (i.e. pictures)<\/li>\n<li>Using waiting rooms<\/li>\n<li>Managing participants<\/li>\n<\/ul>\n<p>If healthcare providers wish to seek additional privacy protections for telehealth, they could use services from technology vendors that are HIPAA compliant by signing a business associate agreement (BAA) for the provision of their video communication products. Such products include, but are not limited to, Skype for Business, or Microsoft Teams, Zoom for Healthcare, and Cisco Webex.<\/p>\n<p>Together with the notice for the use of videoconference tools, OCR has published a <a href=\"https:\/\/www.hhs.gov\/sites\/default\/files\/february-2020-hipaa-and-novel-coronavirus.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">bulletin<\/a> advising covered entities of further flexibilities available to them as well as obligations that remain in effect under HIPAA as they respond to crises or emergencies.<\/p>\n<h2 class=\"navy\">What Happens in Europe?<\/h2>\n<p>The European Union has taken a similar approach to the US OCR. Andrea Jelinek, Chair of the European Data Protection Board (EDPB), <a href=\"https:\/\/edpb.europa.eu\/news\/news\/2020\/statement-edpb-chair-processing-personal-data-context-covid-19-outbreak_en\" target=\"_blank\" rel=\"noopener noreferrer\">has stated that<\/a> \u201cData protection rules (such as GDPR) do not hinder measures taken in the fight against the coronavirus pandemic.\u201d However, even in these exceptional times, \u201cthe data controller must ensure the protection of the personal data of the data subjects. Therefore, a number of considerations should be taken into account to guarantee the lawful processing of personal data.\u201d<\/p>\n<p>To contain the pandemic, there is the need to share information quickly or adapt the way we work. Data protection isn\u2019t about stopping healthcare providers or civil protection workers from protecting us. \u201cIt\u2019s about being proportionate &#8211; if something feels excessive from the public\u2019s point of view, then it probably is,\u201d <a href=\"https:\/\/ico.org.uk\/for-organisations\/data-protection-and-coronavirus\/\" target=\"_blank\" rel=\"noopener noreferrer\">says the UK\u2019s Information Commissioner\u2019s Office<\/a> (ICO).<\/p>\n<p>Therefore, the ICO as well as all EU Data Protection Authorities (DPAs) have issued guidance that state the Authorities \u201cwon\u2019t penalize organizations that need to prioritize other areas or adapt their usual approach during this extraordinary period.\u201d There is a common understanding that resources, whether they are finances or people, might be diverted away from usual compliance or information governance work.<\/p>\n<p>Indeed, the GDPR provides for the legal grounds to enable the employers and the competent public health authorities to process personal data in the context of epidemics, without the need to obtain the consent of the data subject. This applies, for instance, when the processing of personal data is necessary for the employers for reasons of public interest in the area of public health or to protect vital interests (Art. 6 and 9 of the GDPR), or to comply with another legal obligation.<\/p>\n<p>However, the EU has stated implicitly that there are special precautions when it comes to the processing of electronic communication data, such as mobile location data. Governments are leveraging <a href=\"https:\/\/www.apple.com\/covid19\/contacttracing\/\" target=\"_blank\" rel=\"noopener noreferrer\">contact tracing technology<\/a> in an effort to have a cartography of the virus spread. Generalized location data trend analysis is helping to tackle the coronavirus crisis. \u201cWhere this data is properly anonymized and aggregated, it does not fall under data protection law because no individual is identified,\u201d both the <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2020\/03\/statement-in-response-to-the-use-of-mobile-phone-tracking-data-to-help-during-the-coronavirus-crisis\/\" target=\"_blank\" rel=\"noopener noreferrer\">ICO<\/a> and the <a href=\"https:\/\/edpb.europa.eu\/news\/news\/2020\/statement-edpb-chair-processing-personal-data-context-covid-19-outbreak_en\" target=\"_blank\" rel=\"noopener noreferrer\">EDPB<\/a> have stated.<\/p>\n<h2 class=\"navy\">Final thoughts<\/h2>\n<p>In extraordinary times, extraordinary measures are required. However, these measures need to be proportionate and under a lawful basis. What is more, governments and public and private organizations have to plan in advance for transitioning back into normal conditions, as far as personal and sensitive data processing is concerned. Otherwise we run the risk of abolishing all human rights and establishing an unprecedented surveillance state. Governments and agencies need to be transparent with the use of personal data gathered and processed during the COVID-19 public health crisis to avoid any misunderstandings and conspiracy theories.<\/p>\n<p>ITEGRITI can help healthcare providers navigate this emergency environment and provide high-quality services. Visit our <a href=\"http:\/\/72.52.228.46\/~itegriti\/\">website<\/a> to learn how our services can help you.[\/fusion_text][\/fusion_builder_column][\/fusion_builder_row][\/fusion_builder_container]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>During the COVID-19 public health emergency, Governments, as well as public and private organizations throughout the world are taking measures to contain and mitigate COVID-19. This can involve the processing of different types of sensitive personal data, including protected health information.<\/p>\n","protected":false},"author":10,"featured_media":1777,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2179],"tags":[],"_links":{"self":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/1763"}],"collection":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/comments?post=1763"}],"version-history":[{"count":14,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/1763\/revisions"}],"predecessor-version":[{"id":1987,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/1763\/revisions\/1987"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/media\/1777"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/media?parent=1763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/categories?post=1763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/tags?post=1763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}