This article provides a guide to help therapists ensure they are HIPAA compliant regarding training, communication, record-keeping, sharing client protected health information (PHI) with third parties, recording client sessions, and reporting violations or concerns.
What does it mean to be HIPAA compliant?
HIPAA or Health Insurance Portability and Accountability Act is set in place to maintain the confidentiality and security of protected health information (PHI) in order to ensure the patient’s right to privacy.
Where can I complete HIPAA training?
All therapists complete mandatory HIPAA training during onboarding and annually after that. Occasionally, providers may be required to take remedial HIPAA privacy and security training.
How do I make sure emails, calls, and texts are HIPAA compliant?
As a covered entity, you are responsible for validating that you are practicing in alignment with HIPAA. requirements. Please note that Rula does not endorse any specific email or phone service. Your proactive, safe use and configuration of email and phone services is what truly ensures that patient PHI is protected.
All registered clients have provided consent for Rula to call, text, and email them without encryption. Details are available here. However, patients do have the ability to opt out of such unencrypted calling or texting. If a patient opts out, please cease the practice of unencrypted messaging and contact us at privacy@rula.com.
In general, traditional telephone and internet services are treated differently under HIPAA than vendors that create, receive, maintain, or transmit protected health information on behalf of a covered entity. Whether a Business Associate Agreement (BAA) is required depends on the nature of the service and the vendor's role. Organizations should assess each technology and vendor individually to determine applicable HIPAA obligations. Covered entities are responsible for implementing appropriate safeguards when transmitting ePHI. Once information has been delivered to an individual's designated device, the individual is generally responsible for the security of that device.
How can I make sure my work environment is HIPAA compliant?
Clients are entitled to the same level of privacy during telehealth sessions as they would receive in person, and therapists are ethically obligated to maintain client privacy. Therefore, you'll need to conduct telehealth sessions in a private location where client privacy is assured, and no one else will overhear the call. Household members should never hear your sessions or see client information.
As a reminder, you should ensure that you secure your devices and avoid local storage of patient information unless specifically authorized.
How can I safely collaborate with other providers?
If you need to connect with another provider for the purposes of care coordination for a mutual client, please reach out to Rula Support to make a request.
After confirming the mutual client and provider information, our team will provide you with the necessary contact details and notify the receiving provider that their information was shared for the purposes of care coordination.
What do I do if I need to request access to patient documents or information?
A medical records request is the process of requesting access to a client’s protected health information (PHI) or medical records. This requires a Release of Information (ROI).
An ROI is a document that allows a client to authorize what information is released from their medical record, who receives the information, how long it can be released, and under what guidelines.
Records can only be released through Rula’s official medical records process. Therapists are prohibited from downloading or printing client records. To request an ROI, you can do so by clicking this link.
Is it safe to share PHI information with third parties?
To ensure the integrity of Rula client records, we prohibit therapists from sharing client PHI with any third parties. This includes but is not limited to office staff, assistants, and interns. By limiting information sharing, we safeguard clients’ PHI and uphold our responsibilities to protect patient privacy.
We understand that technology plays a vital role in enhancing our services, and we want to assure you that we will communicate with you if we adopt any third-party software or launch new tools in the Rula provider portal.
Can I use AI tools or technology and remain HIPAA compliant?
Providers should only use Rula-approved AI tools and technologies (such as Rula Recap), should never enter PHI into personal or unapproved AI services, follow the HIPAA Minimum Necessary standard, and contact Privacy@rula.com before adopting new technologies.
Rula Recap is clinically validated, HIPAA-compliant, and the only note-taking tool that is fully integrated with our systems. Now that Rula has its own assisted note-taking tool, we are asking all providers who wish to use an assisted note-taking tool to only use Rula Recap for their Rula clients/sessions. Recap is strongly recommended because it’s been built with Rula providers, for Rula providers — it ensures accuracy, consistency, and quality in ways where external tools may have limitations.
Can I safely record sessions and still be HIPAA Compliant?
Rula does not allow therapists to record sessions with clients unless the provider uses Rula-approved tools, such as Rula Recap. Personal recording devices or unapproved third-party recording or transcription tools are prohibited. Rula wants clients to feel comfortable and trust that their sessions are kept confidential.
Providers who wish to use Rula Recap during a patient session must first discuss the request in accordance with Rula policies and applicable notice and consent requirements. It is important to ensure that both parties agree to and are comfortable with the arrangement before a patient records a session.
Providers should always document patient consent decisions in their notes.
How do I report any HIPAA violations or concerns?
Rula promotes a supportive and "just" culture of compliance where we constantly learn and work to improve our system and processes. To self-report any HIPAA violations or concerns, please contact privacy@rula.com or use the Compliance Hotline to file a report.
Rula appreciates your diligence in adhering to these guidelines and your continued commitment to protecting clients’ privacy. If you have any questions or need further clarification regarding the information in this article, please reach out to the Rula Privacy team at privacy@rula.com.
Updated