{"id":25387,"date":"2020-11-09T13:05:33","date_gmt":"2020-11-09T07:35:33","guid":{"rendered":"https:\/\/www.syscreations.ca\/?p=25387"},"modified":"2020-12-18T13:49:40","modified_gmt":"2020-12-18T13:49:40","slug":"telehealth-hipaa","status":"publish","type":"post","link":"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/","title":{"rendered":"Telehealth HIPAA Compliance Checklist: The Easiest HIPAA Guide Available on Internet"},"content":{"rendered":"\n<p><span style=\"font-weight: 400; color: #000000;\">There is no good news. Because HIPAA does apply to all telehealth apps in the USA!<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">Even if you are not launching a telehealth app in the USA, you can make your app compliant with local privacy laws to some great extent by meeting all HIPAA requirements.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">For now, let\u2019s assume you are here to know only about HIPAA.<\/span><\/p>\n<h2><span style=\"color: #000000;\"><b>Some important things about HIPAA<\/b><\/span><\/h2>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">First of all, it is important to develop a HIPAA-compliant telehealth app to avoid a very hefty fine and legal battle with the government.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">And secondly, by being compliant with HIPAA, you are ensuring that your app does not have any privacy issues which put the important personal information of patients or users at risk.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">Now, let\u2019s understand some important definitions stated in the law.<\/span><\/p>\n<p><span style=\"color: #000000;\"><b>1) <u>Covered Entity:<\/u><\/b><\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">The covered entity is the healthcare service provider. If you are a hospital and developing a telehealth app for your in-house use, you are called a covered entity.<\/span><\/p>\n<p><span style=\"color: #000000;\"><b>2) <u>Business Associate:<\/u><\/b><\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">A business associate is a person or business that provides services to a covered entity.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">If you are a startup and providing your telehealth app to the hospital for their use, you are called a business associate.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">Both covered entities and business associates have to adhere to almost similar HIPAA requirements.<\/span><\/p>\n<h2><span style=\"color: #000000;\"><b>HIPAA Privacy Law Breakdown<\/b><\/span><\/h2>\n<p><span style=\"font-weight: 400; color: #000000;\">Understanding HIPAA requirements is a very daunting task.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">However, you can easily understand it if you break it down.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">There are major four rules described under HIPAA.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">HIPAA Security Rule<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">HIPAA Privacy Rule<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">HIPAA Breach Notification Rule<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">HIPAA Omnibus Rule<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">Each of these rules has different requirements. By combining all, you can make your telehealth app HIPAA compliant.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">That means each of these rules has a different checklist which together is called the telehealth HIPAA compliance checklist.<\/span><\/p>\n<h1><span style=\"color: #000000; font-size: x-large;\"><b>The Ultimate Telehealth HIPAA Compliance Checklist<\/b><\/span><\/h1>\n\n<h3><span style=\"color: #000000;\"><b>1. HIPAA Security Rule<\/b><\/span><\/h3>\n\n<ul>\n<li><span style=\"color: #000000;\"><b>Technical Safeguards<\/b><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you encrypt the data of patients once it leaves your internal firewalled servers?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Does your telehealth app assign a centrally-controlled unique username and PIN code for each patient or user?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you established a strategy to govern the release of the personal information of patients during an emergency?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a mechanism to confirm whether the data is altered or destroyed?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a system that catches the attempt made by even registered users to access the personal information of patients?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a mechanism that helps you know what has been done with data once it has been accessed?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Does the system automatically log off users from devices they are using for accessing the personal data of patients?<\/span><\/p>\n<ul>\n<li><span style=\"color: #000000;\"><b>Physical Safeguards<\/b><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have control over who has the physical access to the location where the data of patients is stored? (or you must ensure that the server or cloud service provider with whom you tie-up should be HIPAA compliant.)<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you implemented policies for your internal staff\u2019s workstations that do have access to personal data of patients or users?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f If your in-house team member has the access to personal information from their mobile devices, there should be policies to wipe out the data from their mobile devices when they leave your organization.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you maintain the inventory of every hardware which has the access to personal information of users?<\/span><\/p>\n<ul>\n<li><span style=\"color: #000000;\"><b>Administrative Safeguards<\/b><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you assigned a Security Officer and Privacy Officer?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you conducted a risk assessment?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you introduced a risk management policy along with the sanctions policy for employees who fail to comply with HIPAA regulations?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you developed the contingency plan to continue business operations during emergencies while protecting the integrity of the personal information of users?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you ensuring that no third-party organizations have access to the personal information of patients?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you signed a Business Associate Agreement with third-party organizations that do have access to your data?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>2. HIPAA Privacy Rule<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you asking for the patient\u2019s or user\u2019s written consent before using and sharing their data for marketing, fundraising or research purposes?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you created policies to permanently delete the personal information of users when it is no longer required?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you providing patients with copies of their data if they demand so?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you providing patients with copies of their data within 30 days of their request?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you developed policies and procedures to provide copies of data to patients?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you drafted a Notice of Privacy Practices (NPP)?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you made all users aware of your privacy practices?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you published your privacy practices on your website?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you planned a strategy to deal with failure to comply with NPP?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>3. HIPAA Breach Notification Rule<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you defined a strategy or process to deal with data breaches?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a mechanism for identifying the data breaches?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have the capability to track the investigation of data breaches?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you able to notify the patients or users when there is a breach of their personal information?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you able to notify the Department of Health and Human Services of such a data breach?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you going to share the news of the data breach with the media if the data breach is affecting the data of more than 5000 users?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f If you are a business associate, are you going to notify the covered entity of the data breach within 60 days of the incident?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>4. HIPAA Omnibus Rule<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you signed a business associate agreement with your subcontractors? ( If you are a business associate.)<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Have you identified if your signed business associate agreement has all new requirements imposed under HIPAA Omnibus rule?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you sharing personal information of the deceased person to only family members of that person or anyone who was involved in payment and healthcare before the death of a person?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Are you getting the written consent of the patients to sell the information of patients?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Train the staff on the Omnibus Rule amendments and definition changes.<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an updated privacy policy with definition changes made in the Omnibus rule?<\/span><\/p>\n<h2><span style=\"color: #000000;\"><b>Our In-house HIPAA Consultants + White-Label HIPAA Compliant Telehealth App = Your Best Investment Under $15K<\/b><\/span><\/h2>\n<p><span style=\"font-weight: 400; color: #000000;\">All of our team members have been putting our all efforts into healthcare apps especially telehealth apps. And here are what we earned:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">White-label HIPAA compliant telehealth app (<\/span><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/www.syscreations.ca\/cost-to-develop-best-telemedicine-app\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">costs under $15000<\/span><\/a><\/span><span style=\"font-weight: 400;\">)<\/span><\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">Back-office task automation for your healthcare startup\/organization<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">In-house HIPAA compliant consultants (<\/span><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/www.syscreations.ca\/healthcare-compliance-consulting\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">free consultation<\/span><\/a><\/span><span style=\"font-weight: 400;\"> with telehealth app)<\/span><\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400; color: #000000;\">Technical and business consultation for your telehealth startup<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400; color: #000000;\">In essence, we\u2019re helping you to start a telehealth startup from scratch.<\/span><\/p>\n<center><a class=\"btn btn-primary\" href=\"https:\/\/www.syscreations.ca\/contact\/\"><span style=\"font-weight: 400; color: #ffffff;\">Get Telehealth App\u2019s Free Live Demo<\/span><\/a><\/center>\n<p><span style=\"color: #000000;\"><b>CEO Note: <\/b><span style=\"font-weight: 400;\">We always wanted to prove the difference between just an app development company and a healthcare-focused app development company. And we proved it by delivering HIPAA-compliant telehealth apps along with HIPAA compliance consultation which is rare to expect from just an app development company!<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">I would love to discuss your telehealth app idea and share my earned knowledge. So, let\u2019s arrange a one-on-one meeting. Email us at <\/span><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"mailto:talk@syscreations.ca\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">talk@syscreations.ca<\/span><\/a><\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\"><b><u>Other Important Resources:<\/u><\/b><\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\"> 1) <a style=\"color: #0000ff;\" href=\"https:\/\/www.syscreations.ca\/telemedicine-startup\/\" target=\"_blank\" rel=\"noopener\">Telehealth Startup Checklist<\/a> <\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\"> 2) <a style=\"color: #0000ff;\" href=\"https:\/\/www.syscreations.ca\/telehealth-marketing\/\" target=\"_blank\" rel=\"noopener\">Telehealth Marketing Checklist<\/a> <\/span><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is no good news. Because HIPAA does apply to all telehealth apps in the USA! Even if you are not launching a telehealth app in the USA, you can make your app compliant with local privacy laws to some great extent by meeting all HIPAA requirements. For now, let\u2019s assume you are here to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25394,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[12],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.1.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Get Telehealth HIPAA Compliance Done With This Checklist<\/title>\n<meta name=\"description\" content=\"Are you struggling to understand HIPAA requirements? Get a free telehealth HIPAA compliance checklist to understand all HIPAA regulations easily.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HIPAA made Telehealth simple!\" \/>\n<meta property=\"og:description\" content=\"Telehealth HIPAA Compliance Checklist for you.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\" \/>\n<meta property=\"og:site_name\" content=\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-09T07:35:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-18T13:49:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/11\/Blog-29-10-11-20.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1140\" \/>\n\t<meta property=\"og:image:height\" content=\"554\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"HIPAA made Telehealth simple!\" \/>\n<meta name=\"twitter:description\" content=\"Telehealth HIPAA Compliance Checklist for you.\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data1\" content=\"6 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"description\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.syscreations.ca\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/11\/Blog-29-10-11-20.jpg\",\"contentUrl\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/11\/Blog-29-10-11-20.jpg\",\"width\":1140,\"height\":554,\"caption\":\"Telehealth HIPAA Compliance Checklist: The Easiest HIPAA Guide Available on Internet\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/#webpage\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\",\"name\":\"Get Telehealth HIPAA Compliance Done With This Checklist\",\"isPartOf\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/#primaryimage\"},\"datePublished\":\"2020-11-09T07:35:33+00:00\",\"dateModified\":\"2020-12-18T13:49:40+00:00\",\"author\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/58a4199dfaf1c035175e61bd9021fad3\"},\"description\":\"Are you struggling to understand HIPAA requirements? Get a free telehealth HIPAA compliance checklist to understand all HIPAA regulations easily.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/telehealth-hipaa\/\",\"name\":\"Telehealth HIPAA Compliance Checklist: The Easiest HIPAA Guide Available on Internet\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/58a4199dfaf1c035175e61bd9021fad3\",\"name\":\"test@test.com\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b642b4217b34b1e8d3bd915fc65c4452?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b642b4217b34b1e8d3bd915fc65c4452?s=96&d=mm&r=g\",\"caption\":\"test@test.com\"},\"sameAs\":[\"http:\/\/localhost\/syscreations_blogs\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25387"}],"collection":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/comments?post=25387"}],"version-history":[{"count":6,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25387\/revisions"}],"predecessor-version":[{"id":25953,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25387\/revisions\/25953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media\/25394"}],"wp:attachment":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media?parent=25387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/categories?post=25387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/tags?post=25387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}