Q. My understanding is that HIPAA doesn’t mandate use of a specific security standard. Are we required to keep documentation explaining why we chose a particular security standard? I’ve also been told that we are required to encrypt data according to National Institute of Standards and Technology standards. Is this spelled out in the regulations?
Q. We acquired a home health agency and now employ home health nurses, physical therapists, speech therapists, etc. Can we permit workforce members to use their personal cell phones to communicate with patients? Is there a HIPAA-compliant means of doing so for calls, email, and text messages?