On Monday, June 14th the U.S. Department of Health and Human Services (HHS), issued guidance on how the HIPAA rules permit covered health plans to use remote communication technologies for audio-only telehealth.
The guidance is in the form of FAQs and clarifies the following:
-
A covered entity does not need to apply the Security Rule safeguards to telehealth services that they provide using such traditional landlines (regardless of the type of telephone technology the individual uses, because the information transmitted is not electronic.
-
Communication of Personal Health Information (PHI) via apps on a smart phone or other device, VoIP technology, technologies that transcribe or record a telehealth session or messaging services that store audio messages will require compliance with the Security Rule.
-
A covered health care provider may conduct an audio-only telehealth session with a patient using a smartphone without a Business Associate Agreement (BAA) between the covered health care provider and the telecommunication service provider where that service provider does not create, receive, or maintain any PHI from the session and is only connecting the call.


