Skip to content
  • Home
  • Services
    • Audit & Attest
      • Financial Statement Audits
      • Employee Benefit Plans
      • Attestation Engagements
      • Compilations & Review
      • SOC
      • Agreed-Upon Procedures
    • Advisory
      • Transaction Advisory Services
      • Cybersecurity, Technology Risk, Privacy
      • High Net Worth Services
      • Forensic Services
      • Litigation Services
      • Management Consulting
      • Technology Services
      • Valuation Services
    • Business & Tax
      • Corporate Income Tax
      • Individual Income Tax
      • International Tax
      • State and Local Tax Compliance and Tax Minimization Services
      • Tax Planning
    • T&C Family Office Group
  • Industries
    • Construction & Real Estate
    • Healthcare
    • Manufacturing & Distribution
    • Nonprofit Organizations
    • Private Equity Firms
    • Privately-held Companies
    • Technology & Energy
  • Firm
    • Overview
    • Our People
    • Our Community
    • Templeton Group
      • PracticePro 365
      • T&C Family Office Group
      • Templeton Investigative Services
  • Careers
    • Experienced
    • Students
    • Benefits
  • News
  • Pay My Bill
  • Home
  • Services
    • Audit & Attest
      • Financial Statement Audits
      • Employee Benefit Plans
      • Attestation Engagements
      • Compilations & Review
      • SOC
      • Agreed-Upon Procedures
    • Advisory
      • Transaction Advisory Services
      • Cybersecurity, Technology Risk, Privacy
      • High Net Worth Services
      • Forensic Services
      • Litigation Services
      • Management Consulting
      • Technology Services
      • Valuation Services
    • Business & Tax
      • Corporate Income Tax
      • Individual Income Tax
      • International Tax
      • State and Local Tax Compliance and Tax Minimization Services
      • Tax Planning
    • T&C Family Office Group
  • Industries
    • Construction & Real Estate
    • Healthcare
    • Manufacturing & Distribution
    • Nonprofit Organizations
    • Private Equity Firms
    • Privately-held Companies
    • Technology & Energy
  • Firm
    • Overview
    • Our People
    • Our Community
    • Templeton Group
      • PracticePro 365
      • T&C Family Office Group
      • Templeton Investigative Services
  • Careers
    • Experienced
    • Students
    • Benefits
  • News
  • Pay My Bill
CONTACT US

HIPAA and remote work: A refresher for employers

  • Audit & Attest, Blog, Employee Benefit Plan

Many employers now allow employees to work remotely, either all or part of the time. If your organization does and sponsors a health care plan, here’s a brief refresher on some of the rules regarding protected health information (PHI) and the Health Insurance Portability and Accountability Act (HIPAA).

The Privacy Rule

One major feature of HIPAA is its Privacy Rule. This is essentially a set of national standards for safeguarding PHI. Always keep in mind that PHI is much broader than details about diagnosis and treatment. It also includes demographic data such as participants’ addresses, phone numbers, email addresses and financial information, as well as details about their plan participation.

Some staff members — managers, in particular — may be able to access PHI. When working remotely, these employees should ideally:

  • Have private workspaces where others can’t overhear conversations involving PHI,
  • Use only employer-issued devices and never access electronic PHI (ePHI) on shared devices, and
  • Put hard copies of PHI in a locked filing cabinet, shredding anything they can’t store securely.

Be sure to know which remote workers can access PHI. Each should be able to verify that there are proper measures in place to protect it.

The Security Rule

Another major HIPAA feature is its Security Rule, which is essentially a set of regulations for safeguarding ePHI. Every plan sponsor should conduct an organizational risk analysis and implement a risk management plan that addresses remote work. Doing so is even more important if, in recent years, you’ve seen a substantial increase in the number of remote workers. Your risk management plan should address the three prongs of the HIPAA Security Rule. These are:

  1. Physical safeguards. Although the Security Rule applies to ePHI, physical safeguards are still important. Employers should track the location of each computer accessing ePHI. Lost or stolen computers may result in unauthorized disclosure of large amounts of ePHI, so making sure employees keep them in a secure room is critical.

In addition, employees need to report loss or theft immediately. Devices should never be left unattended in a vehicle or public space. Employees may be tempted to write down passwords and keep them near their computers. However, this practice is as unacceptable when working remotely as it is when working on-site.

  1. Technical safeguards.  Controlling access is key. This includes:
  • Restricting access to the minimum-necessary ePHI for each employee’s job function,
  • Requiring unique user IDs, passwords and multifactor authentication,
  • Implementing automatic log off or lock screen, and
  • Using robust encryption tools.

Advise employees to avoid downloading and storing ePHI on their computers. An individual machine often has weaker protection than a network — cloud storage may be more secure. Warn them against using portable storage media, such as thumb drives, from unknown or unauthorized sources. These items may install malware onto an employee’s computer.

  1. Administrative safeguards.  Implement procedures to supervise remote employees. Routinely monitor logins and system activity to identify potential security incidents, such as transfers or removal of large amounts of data. For new employees, or those new to remote work, mandate training on your organization’s policies and procedures.

Even with heightened awareness and safeguards, the nature of remote work increases the possibility of unauthorized use or disclosure of ePHI. Because the breach notification rules continue to apply, and you could incur HIPAA penalties if breach notification is inadequate or untimely, train employees to recognize and promptly report possible breaches.

Top of mind

Regular reminders and occasional retraining are good ways to keep HIPAA compliance top of mind for employees involved in plan administration, whether they work remotely or on-site. For help identifying and managing the costs and financial risks of your health care plan, contact us.

© 2024

Categories
  • Agribusiness
  • Assurance, Advisory & Review
  • Audit & Attest
  • Blog
  • Business and Tax
  • Business Consulting & Corporate Compliance
  • Corporate Income Tax
  • Current Opportunities
  • Cybersecurity, Technology Risk, Privacy
  • Employee Benefit Plan
  • Employee Benefit Plans / 401(k)
  • Healthcare
  • High Net Worth Individuals
  • High Net Worth Services
  • Individual Income Tax
  • Industries
  • Manufacturing & Distribution
  • Newsletter Articles
  • Newsletters
  • Nonprofit
  • Press Releases
  • Privately Held Companies
  • Professional Services
  • Real Estate & Construction
  • Retail
  • Services
  • Specialty Tax Services
  • State and Local Tax Complianc
  • T&C Family Office Group
  • Tax Planning
  • Tax Planning & Compliance
  • Technology
  • Uncategorized
  • Valuation Services
  • Valuation Services

SHARE THIS ON:

RELATED POSTS

Employees may need help recognizing, understanding mental health benefits

The Affordable Care Act generally requires mental health coverage to be included in employer health insurance plans. However, many employers offer additional benefits to help

Read More »

After a person dies, his or her debts live on

One question the family of a deceased person often asks is: What happens to debt after a person dies? It’s important to realize that a

Read More »

When corporate sponsorships raise UBIT issues

Under the Internal Revenue Code, “qualified sponsorship payments” to not-for-profits aren’t subject to unrelated business income tax (UBIT). Qualified payments refer to money, property transfers

Read More »

Contact Us

WEST PALM BEACH
Esperante Building
222 Lakeview Avenue
Suite 1200
West Palm Beach, FL 33401
(561) 798-9988
Fax: (561) 798-4053

FORT LAUDERDALE
The Main
201 East Las Olas Boulevard
Suite 1650
Fort Lauderdale, FL 33301
(954) 333-0001
Fax: (954) 765-0719

Twitter Facebook Instagram Youtube Linkedin
© 2025 Templeton & Company. All Rights Reserved. Website by Weber & Co.
Services
  • Audit & Attest
  • Advisory
  • Business & Tax
  • T&C Family Office Group
  • Pay My Bill
  • Audit & Attest
  • Advisory
  • Business & Tax
  • T&C Family Office Group
  • Pay My Bill
Industries
  • Construction & Real Estate
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit Organizations
  • Private Equity Firms
  • Privately-held Companies
  • Technology & Energy
  • Construction & Real Estate
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit Organizations
  • Private Equity Firms
  • Privately-held Companies
  • Technology & Energy
Firm
  • Overview
  • Our People
  • Our Community
  • Templeton Group
  • Terms & Conditions
  • Overview
  • Our People
  • Our Community
  • Templeton Group
  • Terms & Conditions
Careers
  • Experienced
  • Students
  • Benefits
  • Experienced
  • Students
  • Benefits