Q: OCR has announced that it will waive enforcement discretion for HIPAA violations that occur at COVID-19 community-based testing sites. The agency did, however, indicate that reasonable safeguards should be implemented. What are your safeguard recommendations for a testing site that is constructed in a parking lot?
Q: Some of our physicians who ordinarily provide services in our provider-based department (PBD) are now providing services to patients in our relocated PBDs, including patients' home. Are we allowed to bill an originating site fee in these circumstances?
Q: A person handling PHI from a remote location admitted that he had clicked on what turned out to be a malicious link in his personal email while he was using a company laptop. The laptop contained access to patient data and PHI. This is the first time such an incident has taken place in my department. What should our response plan look like in this situation?