{"id":10218,"date":"2022-04-16T17:05:22","date_gmt":"2022-04-16T21:05:22","guid":{"rendered":"https:\/\/jolt.richmond.edu\/?p=10218"},"modified":"2022-04-16T17:05:22","modified_gmt":"2022-04-16T21:05:22","slug":"telehealths-covid-19-lack-of-privacy-where-do-we-go-from-here","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2022\/04\/16\/telehealths-covid-19-lack-of-privacy-where-do-we-go-from-here\/","title":{"rendered":"Telehealth\u2019s COVID-19 Lack of Privacy\u2014Where Do We Go From Here?"},"content":{"rendered":"<p>By Chris Jones<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>I. Introduction<\/strong><\/p>\n<p>COVID-19 sparked a \u201ctsunami of growth\u201d in the United States\u2019 telehealth industry.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> The Office for Civil Rights (\u201cOCR\u201d) <em>Notification of Enforcement Discretion for Telehealth Remote Communications During the COVID-19 Nationwide Public Health Emergency<\/em> (\u201cNotification\u201d) allowed medical providers to utilize telehealth platforms that fell short of The Health Insurance Portability and Accountability Act of 1996\u2019s (\u201cHIPAA\u201d) privacy requirements.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a><\/p>\n<p>Technology companies and governments have \u201clong shown themselves to be wolves in sheep\u2019s clothing when it comes to privacy: promising privacy while conducting widespread and illicit surveillance.\u201d<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> A recent study determined that over 70% of medical applications shared users\u2019 sensitive information with third-party data aggregators, without the user\u2019s knowledge or consent.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a><\/p>\n<p>Data aggregators can use this information to potentially damage the individual financially, physically, or psychologically.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> This data is often marketed and sold to a variety of commercial third parties including employers, advertisers, and insurers.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> In one case, a data aggregator sold the digital health-related data of approximately 3 million individuals to an insurance company.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a><\/p>\n<p>By allowing medical providers to utilize inferior privacy measures, the risk of individual privacy harm continues to increase. Privacy injuries associated with the unauthorized use of an individual\u2019s data may include reputational, discrimination, physical, psychological, economic, and relationship harms.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> Thus, telehealth platforms should be required to obtain a Telehealth Privacy Certification (\u201cCertification\u201d) of compliance prior to public market release. This Certification would strengthen security and ensure a patient\u2019s privacy rights are protected moving forward\u2014regardless of what the future holds.<\/p>\n<p style=\"text-align: center;\"><strong>II. Telehealth During COVID-19<\/strong><\/p>\n<p>During the COVID-19 pandemic, private telehealth companies and health care systems reported an increase of telehealth use ranging from 100% to 4300%.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> According to the Center for Disease Control and Prevention (\u201cCDC\u201d), 43% of medical providers had telehealth capabilities before the pandemic.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> After the pandemic began, 95% offered telehealth.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a><\/p>\n<p>Telehealth is defined as the use of electronic information and communications technologies to deliver clinical and nonclinical health care services.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a> Telehealth communications generally consist of three types: (1) Synchronous, which involves direct communication between the provider and the patient using phone, video, or data transmission such as texting; (2) Asynchronous, which involves the storage of information for the provider or patient with the expectation the other party will review it and respond back at some point in the future; and (3) Remote patient monitoring, which involves a mix of both synchronous and asynchronous telehealth that allows the provider to monitor the patient over time.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a> Prior to the pandemic, there were many barriers to utilizing telehealth such as provider licensing, insurance approval, lack of equipment, and the overall costs of complying with HIPAA.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> For example, extremely expensive devices were required for both the patient and physician with costs ranging from $799 on up.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a><\/p>\n<p>As telehealth appointments have become common events, patients confide in their providers as they would if meeting in person. Patients can be particularly susceptible to privacy harm when being videotaped. Typical telehealth sessions often contain a patient\u2019s personal disclosures of \u201cobjective and highly sensitive statements of fact\u201d that \u201cmay be inherently more revelatory\u201d than the provider\u2019s ordinary notes based on subjective impressions.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> Even when complying with HIPAA, providers are free to retain archived, stored, or transmitted data from telehealth sessions.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a><\/p>\n<p>Mental health therapist Tiffany Chhuom worries about the impact of temporarily lifting privacy protections for patient data included in video or text discussions with their doctors.<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> \u201cThe ways in which these clients who are so vulnerable on video could be exploited \u2014 I don\u2019t have the words to explain how much that concerns me,\u201d said Chhuom.<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a><\/p>\n<p style=\"text-align: center;\"><strong>III. Legal Background<\/strong><\/p>\n<p>While it is generally understood that medical providers should use the highest level of standards to assure peace of mind for their patients,<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> HIPAA regulates the use of technology to transmit certain medical data at the federal level.<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> HIPAA requires covered entities to follow data privacy, data security, and data breach notification requirements when handling applicable medical information.<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a><\/p>\n<p>The Health Information Technology for Economic and Clinical Health Act (\u201cHITECH Act\u201d) amended HIPAA in 2009 to further define the responsibilities and roles of healthcare providers and business associates.<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> The HITECH Act requires that covered entities utilize a Business Associate Agreement (\u201cBAA\u201d)<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> and demands that associates comply with the appropriate sections of HIPAA\u2019s Privacy and Security Rules.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> Absent exception, HIPAA\u2019s Privacy Rule requires patient consent in order for a covered entity to share Protected Health Information (\u201cPHI\u201d) with third parties.<a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a> HIPAA\u2019s Security Rule requires that covered entities utilize \u201cadministrative, physical, and technical safeguards to prevent threats or hazards to the security of electronic PHI.\u201d<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a><\/p>\n<p>Herein lies the broader issue\u2014under the current regulation, the use of specific telehealth equipment or technology cannot ensure an entity is HIPAA-compliant.<a href=\"#_ftn28\" name=\"_ftnref28\">[28]<\/a> Thus, the burden to utilize HIPAA-compliant telehealth platforms falls on the covered entity.<a href=\"#_ftn29\" name=\"_ftnref29\">[29]<\/a> If a covered entity utilizes telehealth involving PHI, the entity must comply with the same HIPAA requirements that it would if the patient visited the office.<a href=\"#_ftn30\" name=\"_ftnref30\">[30]<\/a> This requires the entity to have technical knowledge in order to conduct a thorough assessment of any potential risk or vulnerability that may affect the confidentiality or integrity of the patient\u2019s PHI.<a href=\"#_ftn31\" name=\"_ftnref31\">[31]<\/a> Pandemic or not, this level of technical compliance can be difficult for medical specialists to ascertain.<\/p>\n<p style=\"text-align: center;\"><strong>IV. OCR&#8217;s Notification of Enforcement Discretion<\/strong><\/p>\n<p>During the COVID-19 pandemic, patients across the country were asked to accept a trade-off between access to remote health care and protection of their sensitive health data.<a href=\"#_ftn32\" name=\"_ftnref32\">[32] \u00a0<\/a>In March 2020, the United States government further relaxed its already anemic privacy standards by enacting the Notification that allowed medical providers to utilize telehealth platforms, which fell short of HIPAA privacy requirements.<a href=\"#_ftn33\" name=\"_ftnref33\">[33]<\/a> This Notification declared the OCR would not impose penalties for noncompliance with HIPAA regulatory requirements regarding telehealth during the pandemic, as long as the activities were carried out in good faith\u2014even if the appointment was not related to COVID-19.<a href=\"#_ftn34\" name=\"_ftnref34\">[34]<\/a> Without stringent privacy and security features employed, a telehealth appointment can have devastating effects on a patient\u2019s employment status, insurance ratings, and personal reputation.<a href=\"#_ftn35\" name=\"_ftnref35\">[35]<\/a><\/p>\n<p>Any non-public facing remote communication products were allowed to be utilized for medical appointments, regardless of the privacy and security features.<a href=\"#_ftn36\" name=\"_ftnref36\">[36]<\/a> For example, this Notification allowed a provider to examine a patient utilizing a videoconferencing application on the patient\u2019s phone.<a href=\"#_ftn37\" name=\"_ftnref37\">[37]<\/a> Additionally, it only suggested the provider notify their patients of potential third-party privacy risks and only recommended they should utilize all encryption and privacy modes available.<a href=\"#_ftn38\" name=\"_ftnref38\">[38]<\/a> This waiver applied to HIPAA\u2019s Privacy, Security, and Breach Notification Rules.<a href=\"#_ftn39\" name=\"_ftnref39\">[39]<\/a><\/p>\n<p>The OCR provided a list of potential video communication platforms that claimed to be HIPAA-compliant and were willing to enter into a BAA;<a href=\"#_ftn40\" name=\"_ftnref40\">[40]<\/a> yet did not specifically endorse them.<a href=\"#_ftn41\" name=\"_ftnref41\">[41]<\/a> This Notification recommended that providers concerned about additional privacy protections for their patients continue to utilize services through HIPAA-compliant vendors.<a href=\"#_ftn42\" name=\"_ftnref42\">[42]<\/a><\/p>\n<p>For example, this Notification allowed medical providers to utilize the consumer version of Zoom for confidential telehealth visits.<a href=\"#_ftn43\" name=\"_ftnref43\">[43]<\/a> Zoom experienced a 10-fold increase in usage since the COVID-19 pandemic began, including increased use in healthcare.<a href=\"#_ftn44\" name=\"_ftnref44\">[44]<\/a> According to a study by Sermo, Zoom was the most common telehealth platform in use during the COVID-19 pandemic.<a href=\"#_ftn45\" name=\"_ftnref45\">[45]<\/a><\/p>\n<p>Zoom has come under fire as a myriad of articles and lawsuits exposed its privacy flaws.<a href=\"#_ftn46\" name=\"_ftnref46\">[46]<\/a> Zoom users encountered Zoom Bombing, which occurs when someone joins a meeting they weren\u2019t invited to and \u201cdrops gross or disturbing images.\u201d<a href=\"#_ftn47\" name=\"_ftnref47\">[47]<\/a> Confidential secrets are easily revealed when random people join private videoconferences.<a href=\"#_ftn48\" name=\"_ftnref48\">[48]<\/a> For example, online classes at UCLA were disrupted by a Zoom Bomber shouting slurs and insulting individuals.<a href=\"#_ftn49\" name=\"_ftnref49\">[49]<\/a> Zoom Bombers have even posted pornographic content during video chats like AA meetings.<a href=\"#_ftn50\" name=\"_ftnref50\">[50]<\/a><\/p>\n<p>As this Notification allowed for any non-public teleconferencing platform to be used,<a href=\"#_ftn51\" name=\"_ftnref51\">[51]<\/a> the privacy issues exposed here are not unique to Zoom alone\u2014Zoom likely only scratches the surface.<a href=\"#_ftn52\" name=\"_ftnref52\">[52]<\/a><\/p>\n<p>This Notification of Enforcement Discretion was inadequate as it essentially stripped consumers of their right to privacy by allowing providers to utilize random videoconferencing applications with no guarantees of confidentiality or security. The importance of privacy and security concerns surrounding telehealth cannot be overlooked as medical data necessitates a higher standard of security due to its personal and sensitive nature.<a href=\"#_ftn53\" name=\"_ftnref53\">[53]<\/a> The effects of this Notification may be felt for years or decades to come if the medical data makes its way into the hands of data brokers,<a href=\"#_ftn54\" name=\"_ftnref54\">[54]<\/a> unscrupulous actors, or onto the Dark Web.<\/p>\n<p style=\"text-align: center;\"><strong>V. Two Years In &#8211; Where Do We Go From Here?<\/strong><\/p>\n<p>For the past two years, medical providers and patients have become accustomed to utilizing telehealth without the safety of regulatory oversight. As the state of emergency declarations are lifted, this compliance waiver will likely end. Covered entities will no longer be allowed to utilize whatever nonpublic telehealth modality patients have chosen, and will be required to resume utilizing only telehealth platforms that comply with HIPAA.<\/p>\n<p>In October 2021, the American Medical Association (\u201cAMA\u201d) called on the OCR to extend this Notification for yet another year, in order to provide its members with more time to adapt to HIPAA-compliant technologies.<a href=\"#_ftn55\" name=\"_ftnref55\">[55]<\/a> The AMA has requested that the OCR assist providers by establishing \u201cguidance documents that specifically speak to telemedicine platforms and what HIPAA requires for use of such technology.\u201d<a href=\"#_ftn56\" name=\"_ftnref56\">[56]<\/a> As the AMA explained, \u201cmany clinicians are using telemedicine for the first time and may not be well-versed in the unique risks and vulnerabilities associated with the new tools they are using.\u201d<a href=\"#_ftn57\" name=\"_ftnref57\">[57]<\/a><\/p>\n<p>This chain of events is taking Americans\u2019 privacy concerns even further off track.\u00a0 As the AMA confirmed, medical providers are not technologists and do not specialize in decrypting the intricate privacy concerns involved with third-party applications.<\/p>\n<p>In order to protect both health and privacy, Congress should enact a comprehensive federal regulation to require Telehealth Privacy Certification (\u201cCertification\u201d), administered by the OCR, for all platforms prior to public market release. The OCR already has a trained staff of technologists currently tasked with HIPAA auditing and enforcement. Thus, the OCR should implement a new system to standardize and simplify the necessary HIPAA-compliant technological requirements for telehealth platforms and control how personal telehealth data is maintained.<a href=\"#_ftn58\" name=\"_ftnref58\">[58]<\/a> This Certification should also implement one standardized BAA required for use with all approved telehealth platforms.<\/p>\n<p>By requiring telehealth platforms to meet or exceed HIPAA regulations upfront, entities that specialize in medicine would no longer be tasked with attempting to analyze whether or not technology platforms comply with the applicable laws. Instead, medical providers can confidently focus their resources on treating patients\u2019 health concerns\u2014the true purpose of telehealth.<\/p>\n<p>With Certification, it is possible to leverage the public health benefits of telehealth without subjecting unsuspecting patients to abusive or illicit surveillance. This long-term solution would safeguard the privacy rights of telehealth users and ensure that patients\u2019 medical data is protected\u2014both during a pandemic and beyond.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>See<\/em> Marie Fishpaw &amp; Stephanie Zawada, <em>Telehealth in the Pandemic and Beyond: The Policies That Made It Possible, and the Policies That Can Expand Its Potential<\/em>, Heritage Found. (July 20, 2020), https:\/\/www.heritage.org\/health-care-reform\/report\/telehealth-the-pandemic-and-beyond-the-policies-made-it-possible-and-the.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See<\/em> <em>Notification of Enforcement Discretion for Telehealth Remote Communications During the COVID-19 Nationwide Public Health Emergency<\/em>, U.S. Dep\u2019t Health &amp; Hum. Servs., https:\/\/www.hhs.gov\/hipaa\/for-professionals\/special-topics\/emergency-preparedness\/notification-enforcement-discretion-telehealth\/index.html (last updated Mar. 30, 2020) [hereinafter <em>Notification of Enforcement Discretion<\/em>]; <em>Telehealth and Telemedicine: Frequently Asked Questions<\/em>, Cong. Research Serv. (Mar. 12, 2020), https:\/\/crsreports.congress.gov\/product\/pdf\/R\/R46239.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> Jake Goldenfein, Ben Green, &amp; Salome Viljoen, <em>Privacy Versus Health Is a False Trade-Off<\/em>, Jacobin, https:\/\/jacobinmag.com\/2020\/4\/privacy-health-surveillance-coronavirus-pandemic-technology (last visited Sept. 19, 2020).<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> Lori Andrews, <em>A New Privacy Paradigm in the Age of Apps<\/em>, 53 Wake Forest L. Rev. 421, 421 (2018).<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>Id.<\/em> at 424.<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>Id. <\/em>at 421.<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>Id.<\/em> at 461.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>See<\/em> Daniel J. Solove &amp; Danielle Keats Citron, <em>Privacy Harms, <\/em>GW L. Fac. Publ\u2019n &amp; Other Works, 1534, (2021), https:\/\/scholarship.law.gwu.edu\/faculty_publications\/1534\/.<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> Fishpaw, <em>supra<\/em> note 1.<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> Hanna B. Demeke, Sharifa Merali, Suzanne Marks, et al., <em>Trends in Use of Telehealth Among Health Centers During the COVID-19 Pandemic \u2014 United States<\/em>, <em>June 26\u2013November 6, 2020 (Morbidity and Mortality Weekly Report)<\/em>, CDC (Feb. 19, 2021), https:\/\/www.cdc.gov\/mmwr\/volumes\/70\/wr\/mm7007a3.htm.<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>Telehealth and Telemedicine: Frequently Asked Questions<\/em>, Cong. Research Serv. (Mar. 12, 2020), <a href=\"https:\/\/crsreports.congress.gov\/product\/pdf\/R\/R46239\">https:\/\/crsreports.congress.gov\/product\/pdf\/R\/R46239<\/a>. While the World Health Organization limits the term \u201ctelemedicine to services provided by doctors,\u201d whereas \u201ctelehealth is broader, including services from other health providers such as nurses, psychologists and pharmacists;\u201d the terms telehealth and telemedicine are often used interchangeably. Dana Shilling, <em>Telemedicine in the age of COVID-19<\/em>, 35 Elder L. Advisory NL 1, 1 (2020).<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>See<\/em> David A. Hoffman, <em>Increasing Access to Care: Telehealth During COVID-19<\/em>, 7 <em>J. L. &amp; Biosciences<\/em> 1, 3 (2020).<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> <em>See <\/em>Miranda A. Moore &amp; Dominique D. Monroe, <em>COVID-19 Brings About Rapid Changes in the Telehealth Landscape<\/em>, Mary Ann Liebert, Inc., Publishers (Aug. 14, 2020), https:\/\/www.liebertpub.com\/doi\/10.1089\/TMJ.2020.0228.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> Josh Sherman, <em>Double Secret Protection:\u00a0 Bridging Federal and State Law to Protect Privacy Rights for Telemental and Mobile Health Users<\/em>, 67 Duke L. J. 1115, 1143 (2018).<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>See id.<\/em> at 1141\u201343.<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> Kate Kaye, <em>HHS Notice on Telehealth Penalties Raises Privacy Concerns<\/em>, Int\u2019l Ass\u2019n of Privacy Prof\u2019ls (Mar. 20, 2020), https:\/\/iapp.org\/news\/a\/hhs-notice-on-telehealth-penalties-raises-privacy-concerns\/. Chhuom worked with the Washington State Health Care Authority to utilize digital technology in its response to the COVID-19 pandemic. Chhuom has first-hand experience with patient technology as she owns Eth Tech, a digital training firm. <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>See <\/em>Geoffrey Lottenberg, <em>COVID-19 Telehealth Boom Demands Better Privacy Practices<\/em>, Lexis Law 360 (July 2, 2020), https:\/\/www.law360.com\/articles\/1287404\/covid-19-telehealth-boom-demands-better-privacy-practices-.<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>HIPAA, Telehealth, and COVID-19<\/em>, Cong. Res. Serv. (June 5, 2020), https:\/\/crsreports.congress.gov\/product\/pdf\/LSB\/LSB10490.<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>See id<\/em>. (A Covered Entity is one that is (1) A health plan, (2) A health care clearinghouse, or (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by 45 CFR \u00a7 160.103). HIPAA imposes obligations on covered entities, those that have entered into a Business Associate Agreement (\u201cBAA\u201d) with a covered entity, and subcontractors of covered entities or business associates. <em>See<\/em> <em>Business Associate Contracts<\/em>, U.S. Dep\u2019t of Health &amp; Hum. Servs., https:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/sample-business-associate-agreement-provisions\/index.html (last reviewed June 16, 2017).<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>See<\/em> <em>Business Associate Contracts<\/em>, <em>supra <\/em>note 22. (A Business Associate is a person or entity, including subcontractors, who \u201cperform[s] functions or activities on behalf of, or provides certain services to, a covered entity that involve access by the business associate to protected health information.\u201d).<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> A covered entity may share PHI with another entity only after a BAA has been entered into that provides \u201csatisfactory assurances\u201d the business will appropriately safeguard the information. Therefore, the business associates themselves are directly liable for breaches of HIPAA. <em>See<\/em> <em>HIPAA, Telehealth, and COVID-19<\/em>, <em>supra<\/em> note 21.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> <em>See<\/em> Leslie Lenert &amp; Brooke Yeager McSwain, <em>Balancing Health Privacy, Health Information Exchange, and Research in the Context of the COVID-19 Pandemic<\/em>, J. Am. Med. Infomatics Ass\u2019n (Apr. 26, 2020), https:\/\/academic.oup.com\/jamia\/article\/27\/6\/963\/5814212.<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>See<\/em> <em>HIPAA, Telehealth, and COVID-19<\/em>, <em>supra<\/em> note 21.<\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[27]<\/a> <em>See<\/em> <em>HIPAA, Telehealth, and COVID-19<\/em>, <em>supra<\/em> note 21.<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[28]<\/a> <em>HIPAA and Telehealth<\/em>, Ctr. for Connected Health Policy, https:\/\/www.cchpca.org\/sites\/default\/files\/2018-09\/HIPAA%20and%20Telehealth.pdf (last visited Dec. 18, 2020).<\/p>\n<p><a href=\"#_ftnref29\" name=\"_ftn29\">[29]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref30\" name=\"_ftn30\">[30]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref31\" name=\"_ftn31\">[31]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref32\" name=\"_ftn32\">[32]<\/a> Goldenfein, Green, &amp; Viljoen, <em>supra <\/em>note 3.<\/p>\n<p><a href=\"#_ftnref33\" name=\"_ftn33\">[33]<\/a> <em>See Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref34\" name=\"_ftn34\">[34]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref35\" name=\"_ftn35\">[35]<\/a> <em>See <\/em>Lothar Determann, <em>Healthy Data Protection<\/em>, 26 Mich. Tech. L. Rev. 229, 256 (2020).<\/p>\n<p><a href=\"#_ftnref36\" name=\"_ftn36\">[36]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref37\" name=\"_ftn37\">[37]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref38\" name=\"_ftn38\">[38]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<em>\u00a0 <\/em><\/p>\n<p><a href=\"#_ftnref39\" name=\"_ftn39\">[39]<\/a> <em>FAQs on Telehealth and HIPAA During the COVID-19 Nationwide Public Health Emergency<\/em>, U.S. Dep\u2019t of Health &amp; Hum. Servs., https:\/\/www.hhs.gov\/sites\/default\/files\/telehealth-faqs-508.pdf (last viewed Dec. 17, 2020).<\/p>\n<p><a href=\"#_ftnref40\" name=\"_ftn40\">[40]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref41\" name=\"_ftn41\">[41]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref42\" name=\"_ftn42\">[42]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref43\" name=\"_ftn43\">[43]<\/a> <em>See<\/em> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref44\" name=\"_ftn44\">[44]<\/a> Mohammad S. Jalali, Adam Landman, &amp; William Gordon, <em>Telemedicine, Privacy, and Information Security in the Age of COVID-19<\/em>, SSRN 1, 2 (July 8, 2020), https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3646320.<\/p>\n<p><a href=\"#_ftnref45\" name=\"_ftn45\">[45]<\/a> Deborah R. Farringer, <em>A Telehealth Explosion: Using Lessons from the Pandemic to Shape the Future of Telehealth Regulation<\/em>, SSRN 1, 28 (Aug. 5, 2020), https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3681070.<\/p>\n<p><a href=\"#_ftnref46\" name=\"_ftn46\">[46]<\/a> <em>See <\/em>Ajay Chawla, <em>Coronavirus \u2013 Covid 19 \u2018Zoom\u2019 Application Boon or Bane<\/em>, SSRN (May 20, 2020), https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3606716.<\/p>\n<p><a href=\"#_ftnref47\" name=\"_ftn47\">[47]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref48\" name=\"_ftn48\">[48]<\/a>\u00a0 <em>See<\/em> Michael Goodyear, <em>The Dark Side of Videoconferencing: The Privacy Tribulations of Zoom and the Fragmented State of U.S. Data Privacy Law<\/em>, 10 Hous. L. Rev. 76, 80-81 (2020).<\/p>\n<p><a href=\"#_ftnref49\" name=\"_ftn49\">[49]<\/a> Emily MacInnis, <em>Students, Professors Report Multiple Incidents of Zoombombing in One Day<\/em>, Daily Bruin (Oct. 11, 2020, 6:00 PM), https:\/\/dailybruin.com\/2020\/10\/06\/students-professors-report-multiple-incidents-of-zoombombing-in-one-day.<\/p>\n<p><a href=\"#_ftnref50\" name=\"_ftn50\">[50]<\/a> Chawla,<em> supra<\/em> note 46.<\/p>\n<p><a href=\"#_ftnref51\" name=\"_ftn51\">[51]<\/a> <em>Notification of Enforcement Discretion<\/em>, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref52\" name=\"_ftn52\">[52]<\/a> <em>See<\/em> Goldenfein, Green, &amp; Viljoen,<em> supra <\/em>note 3.<\/p>\n<p><a href=\"#_ftnref53\" name=\"_ftn53\">[53]<\/a> Mohammad S. Jalali, Adam Landman, &amp; William Gordon, <em>Telemedicine, Privacy, and Information Security in the Age of COVID-19<\/em>, SSRN (July 8, 2020), https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3646320.<\/p>\n<p><a href=\"#_ftnref54\" name=\"_ftn54\">[54]<\/a> <em>See <\/em>WebFX Team, <em>What are Data Brokers \u2014 and What is Your Data Worth?<\/em>, WebFX (Mar. 16, 2020), https:\/\/www.webfx.com\/blog\/internet\/what-are-data-brokers-and-what-is-your-data-worth-infographic\/ (Data brokers belong to a \u201cmulti-billion dollar industry made up of companies who collect consumer data and sell it to other companies, usually for marketing purposes.\u201d Because data brokers do not deal directly with consumers, many individuals are unaware these companies exist.).<\/p>\n<p><a href=\"#_ftnref55\" name=\"_ftn55\">[55]<\/a> Letter from James L. Madara, MD, CEO Executive Vice President, Am. Med. Ass\u2019n, to Lisa J. Pino, Dir., Off. Civ. Rts. (Oct. 25, 2021), https:\/\/searchlf.ama-assn.org\/letter\/documentDownload?uri=\/unstructured\/binary\/letter\/LETTERS\/2021-10-25-Letter-to-Pino-on-HIPAA-Flexibility.pdf.<\/p>\n<p><a href=\"#_ftnref56\" name=\"_ftn56\">[56]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref57\" name=\"_ftn57\">[57]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref58\" name=\"_ftn58\">[58]<\/a> Goldenfein, Green, &amp; Viljoen, <em>supra<\/em> note 3.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-10227\" src=\"https:\/\/jolt.richmond.edu\/files\/2022\/04\/Pic.jpg\" alt=\"\" width=\"850\" height=\"478\" \/><\/p>\n<p>Image source: https:\/\/labblog.uofmhealth.org\/rounds\/telehealth-visits-skyrocket-for-older-adults-but-concerns-and-barriers-remain<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Chris Jones &nbsp; I. Introduction COVID-19 sparked a \u201ctsunami of growth\u201d in the United States\u2019 telehealth industry.[1] The Office for Civil Rights (\u201cOCR\u201d) Notification of Enforcement Discretion for Telehealth Remote Communications During the COVID-19 Nationwide Public Health Emergency (\u201cNotification\u201d) allowed medical providers to utilize telehealth platforms that fell short of The Health Insurance Portability [&hellip;]<\/p>\n","protected":false},"author":5136,"featured_media":10227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-10218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.richmond.edu\/jolt\/files\/2022\/04\/Pic.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-2EO","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/5136"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=10218"}],"version-history":[{"count":3,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10218\/revisions"}],"predecessor-version":[{"id":10243,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10218\/revisions\/10243"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media\/10227"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=10218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=10218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=10218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}