Get HIPAA Guidance

HIPAA Compliance for Remote Healthcare Workers

Secure policies and procedures for telehealth, work-from-home, and off-site healthcare professionals

Quick Answer: Remote workers must use encrypted VPN, secure home networks, implement multi-factor authentication, and follow physical security protocols for any PHI accessed outside the office.

Remote Work Risk Assessment

Remote healthcare work presents unique HIPAA risks that require specific security controls:

Essential Remote Worker Requirements

VPN and Encrypted Network Access

Multi-Factor Authentication (MFA)

Device Security

Home Network Requirements

Physical Security

Data Handling and Storage Policies

Prohibited Practices

  • Do NOT download PHI to local hard drives unless absolutely necessary
  • Do NOT store PHI in personal cloud accounts (OneDrive, Google Drive, iCloud, Dropbox)
  • Do NOT email PHI unencrypted
  • Do NOT use personal email accounts for work
  • Do NOT print PHI unless required for patient care
  • Do NOT store PHI on personal external drives or USB devices

Acceptable Data Practices

Remote Work Policy Template

REMOTE WORK AND TELEHEALTH HIPAA COMPLIANCE POLICY

Scope

This policy applies to all workforce members who access Protected Health Information (PHI) from locations outside organizational facilities.

Approved Remote Work Locations

Mandatory Security Controls

Consequences of Non-Compliance

Employee Acknowledgment

I acknowledge that I have read and understand this remote work policy. I agree to comply with all security requirements and understand the consequences for violations.

Employee Signature: _________________________ Date: _________

Telehealth-Specific Considerations

Video Conference Security

Patient Privacy During Telehealth

Incident Reporting for Remote Workers

Equipment and Access Provisioning

Organization-Provided Equipment Setup

Off-Boarding Remote Devices

Frequently Asked Questions

Q: Can employees use their personal computers for remote work with PHI?
A: Generally no. Personal devices lack the required security controls and encryption. If you have a BYOD program, personal devices must be enrolled in mobile device management (MDM), have full-disk encryption, and pass security assessments before PHI access is permitted.
Q: Is it compliant to use consumer VPN services for remote access?
A: No. Consumer VPNs don't provide necessary audit logging, don't meet encryption standards, and may route data to unknown servers. Organizations must use enterprise VPN solutions with full audit capabilities and documented security standards.
Q: What should employees do if their internet connection fails during a telehealth visit?
A: They should immediately discontinue the video call and contact the patient or clinic manager. The visit may be rescheduled or continued by phone if HIPAA-compliant. Never use personal mobile hotspot to continue a call unless it's emergency care and documented as such.
Q: Are remote workers required to have a dedicated home office space?
A: Yes, they must have a private area where PHI cannot be viewed by family members or visitors. Shared spaces like living rooms, kitchens, or bedrooms with roommates are not acceptable for PHI access. The space should be lockable and secure.

Secure Your Remote Workforce

Medcurity provides remote work policies, device security templates, and VPN/MFA configuration guidance.

Get Remote Work Policies