HIPAA Compliance for Remote Healthcare Workers
Secure policies and procedures for telehealth, work-from-home, and off-site healthcare professionals
Quick Answer: Remote workers must use encrypted VPN, secure home networks, implement multi-factor authentication, and follow physical security protocols for any PHI accessed outside the office.
Remote Work Risk Assessment
Remote healthcare work presents unique HIPAA risks that require specific security controls:
- Uncontrolled Environments: Home networks and public Wi-Fi lack organizational security controls
- Physical Security Gaps: Patient information may be visible on shared home screens or devices
- Network Interception: Unencrypted data transmission over consumer internet is vulnerable
- Device Sharing: Family members may access devices containing PHI
- Backup & Storage: PHI may be downloaded to unsecured personal computers or cloud accounts
Essential Remote Worker Requirements
VPN and Encrypted Network Access
- Require use of organization-provided VPN for all PHI access
- VPN must use strong encryption (AES-256 or equivalent)
- Disable split tunneling to prevent unencrypted connections
- Implement certificate-based VPN authentication
- Monitor VPN connections and access logs
- Disconnect VPN when not actively using PHI
Multi-Factor Authentication (MFA)
- Require MFA for all system access from remote locations
- Use authenticator apps (not SMS when possible)
- Prohibit reuse of authentication codes
- Enforce session timeouts (30 minutes or less)
- Require re-authentication for sensitive functions
Device Security
- Use only organization-issued devices for PHI access
- Prohibit personal device access to PHI (unless in approved BYOD program)
- Enable full-disk encryption on all devices
- Install and maintain antivirus/anti-malware software
- Enable firewall protection
- Install security patches and OS updates promptly
- Enable remote wipe capability
Home Network Requirements
- Use secure home Wi-Fi network with WPA3 or WPA2 encryption
- Change default router passwords and settings
- Disable WPS (Wi-Fi Protected Setup)
- Use complex, unique network password
- Keep router firmware updated
- Restrict network access to household members only
- Do not use public Wi-Fi for PHI access
Physical Security
- Maintain private, locked workspace when accessing PHI
- Position monitor away from windows and shared spaces
- Use privacy screens to prevent screen viewing
- Prevent unauthorized access to devices during breaks
- Lock devices when stepping away
- Store paper documents securely (locked drawer/cabinet)
- Shred or securely destroy paper containing PHI
Data Handling and Storage Policies
Prohibited Practices
- Do NOT download PHI to local hard drives unless absolutely necessary
- Do NOT store PHI in personal cloud accounts (OneDrive, Google Drive, iCloud, Dropbox)
- Do NOT email PHI unencrypted
- Do NOT use personal email accounts for work
- Do NOT print PHI unless required for patient care
- Do NOT store PHI on personal external drives or USB devices
Acceptable Data Practices
- Access PHI through organization's secure web portal only
- Use organization-approved secure file transfer services
- Utilize secure EHR systems through encrypted VPN connection
- Store necessary documents in organization's encrypted cloud storage
- Use organization-provided file sharing platforms only
- Keep minimal copies of PHI; delete when no longer needed
Remote Work Policy Template
REMOTE WORK AND TELEHEALTH HIPAA COMPLIANCE POLICY
Scope
This policy applies to all workforce members who access Protected Health Information (PHI) from locations outside organizational facilities.
Approved Remote Work Locations
- Employee's primary residence (approved by manager)
- Secondary residences (must be approved in advance)
- Satellite office locations (must meet security standards)
- Public locations (hospitals, clinics - only for telehealth if secure connection available)
- Prohibited: Public Wi-Fi locations without VPN, vehicles, shared spaces
Mandatory Security Controls
- Organization-provided device with full-disk encryption
- Current antivirus and anti-malware software
- VPN connection for all PHI access
- Multi-factor authentication enabled
- Secure Wi-Fi network (home) with WPA2/WPA3 encryption
- Private workspace away from unauthorized viewers
Consequences of Non-Compliance
- First violation: Written warning and mandatory retraining
- Second violation: Suspension of remote work privileges
- Third violation: Disciplinary action up to termination
- Security breaches: Immediate investigation and disciplinary action
Employee Acknowledgment
I acknowledge that I have read and understand this remote work policy. I agree to comply with all security requirements and understand the consequences for violations.
Employee Signature: _________________________ Date: _________
Telehealth-Specific Considerations
Video Conference Security
- Use only HIPAA-compliant video conferencing platforms (Zoom for Healthcare, Cisco Webex, Microsoft Teams with compliance features)
- Enable meeting password protection
- Disable screen sharing unless necessary
- Disable recording by participants (only organization may record with consent)
- Use waiting rooms to screen participants
- Inform patients call may be recorded for quality purposes
Patient Privacy During Telehealth
- Schedule calls in private space
- Ensure no unauthorized persons are present
- Minimize background noise
- Verify patient identity before beginning visit
- Confirm consent to use video communication
- Document consent in medical record
Incident Reporting for Remote Workers
- Immediately report any suspected security incidents
- Include details of what, when, where, and who was affected
- Contact manager and Security/Privacy Officer within 1 hour
- Preserve evidence (don't close applications or clear logs)
- Follow guidance for breach notification if warranted
- Cooperate fully with incident investigation
Equipment and Access Provisioning
Organization-Provided Equipment Setup
- All devices pre-configured with encryption and security software
- VPN client pre-installed and tested
- MFA configured before distribution
- Device inventory tracking and asset tags
- Setup instructions and security training provided
- Device support and patching procedures documented
Off-Boarding Remote Devices
- Remote wipe of all data when employee terminates
- Revoke VPN and system access credentials
- Retrieve all organization-issued equipment
- Verify return of all logins and access tokens
- Document equipment return and data deletion
- Conduct exit interview regarding data handling
Frequently Asked Questions
Q: Can employees use their personal computers for remote work with PHI?
A: Generally no. Personal devices lack the required security controls and encryption. If you have a BYOD program, personal devices must be enrolled in mobile device management (MDM), have full-disk encryption, and pass security assessments before PHI access is permitted.
Q: Is it compliant to use consumer VPN services for remote access?
A: No. Consumer VPNs don't provide necessary audit logging, don't meet encryption standards, and may route data to unknown servers. Organizations must use enterprise VPN solutions with full audit capabilities and documented security standards.
Q: What should employees do if their internet connection fails during a telehealth visit?
A: They should immediately discontinue the video call and contact the patient or clinic manager. The visit may be rescheduled or continued by phone if HIPAA-compliant. Never use personal mobile hotspot to continue a call unless it's emergency care and documented as such.
Q: Are remote workers required to have a dedicated home office space?
A: Yes, they must have a private area where PHI cannot be viewed by family members or visitors. Shared spaces like living rooms, kitchens, or bedrooms with roommates are not acceptable for PHI access. The space should be lockable and secure.
Secure Your Remote Workforce
Medcurity provides remote work policies, device security templates, and VPN/MFA configuration guidance.
Get Remote Work Policies