OCR Releases HIPAA Guidance for mHealth App Use | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

OCR Releases HIPAA Guidance for mHealth App Use

February 19, 2016
by Rajiv Leventhal
| Reprints

The Department of Health and Human Services’ (HHS) Office of Civil Rights (OCR) has released further guidelines to help healthcare professionals fully understand Health Insurance Portability and Accountability Act (HIPAA) laws.

Last month, OCR released well-received guidelines to help ensure that individuals understand and can exercise their right to access their health information. Although HIPAA laws have always provided individuals with the right to access their health data, consumers haven’t gotten much guidance from the feds on how to exercise that right—until recently.

Now, OCR has released new guidance related to mobile health (mHealth) apps. It specifically focuses on two questions:

1. How does HIPAA apply to health information that a patient creates, manages or organizes through the use of a health app?

2. When might an app developer need to comply with the HIPAA Rules?

The answers to these questions are fact and circumstance specific, OCR stresses. The guidelines provide six scenarios based on a specific set of facts. Change in a scenario may of course change the analysis and, as a result, change the determination of whether the app developer is required to comply with HIPAA. 

OCR goes on to say that even if you are not a covered entity, you may be a business associate if you are creating or offering the app on behalf of a covered entity (or one of the covered entity’s contractors), and in that case you are required to comply with certain provisions of the HIPAA Rules. In general, a business associate is a person [or entity] who creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity or another business associate. So, most vendors or contractors (including subcontractors) that provide services to or perform functions for covered entities that involve access to PHI are business associates, OCR says.

To read more about key HIPAA questions related to health app use, and to see the scenarios outlined by OCR, click here for the guidance.

Topics

News

Community Data Sharing: Eight Recommendations From San Diego

A learning guide focuses on San Diego’s experience in building a community health information exchange and the realities of embarking on a broad community collaboration to achieve better data sharing.

HealthlinkNY’s Galanis to Step Down as CEO

Christina Galanis, who has served as president and CEO of HealthlinkNY for the past 13 years, will leave her position at the end of the year.

Email-Related Cyber Attacks a Top Concern for Providers

U.S. healthcare providers overwhelmingly rank email as the top source of a potential data breach, according to new research from email and data security company Mimecast and conducted by HIMSS Analytics.

Former Health IT Head in San Diego County Charged with Defrauding Provider out of $800K

The ex-health IT director at North County Health Services, a San Diego County-based healthcare service provider, has been charged with spearheading fraudulent operations that cost the organization $800,000.

Allscripts Touts 1 Billion API Shares in 2017

Officials from Chicago-based health IT vendor Allscripts have attested that the company has reached a new milestone— one billion application programming interface (API) data exchange transactions in 2017.

Dignity Health, CHI Merging to Form New Catholic Health System

Catholic Health Initiatives (CHI), based in Englewood, Colorado, and San Francisco-based Dignity Health officially announced they are merging and have signed a definitive agreement to combine ministries and create a new, nonprofit Catholic health system.