CMS has issued
HIPAA Security Guidance (
link to guidance document pdf) for HIPAA covered entities on the risks and possible mitigation strategies for remote use of and access to Protected Health Information (EPHI). The guidance sets forth CMS' minimal compliance expectations for covered entities seeking to safeguard EPHI that is accessed, stored or transported offsite.
This guidance should be useful for those health care facilities and providers to assess current policies and procedures used to maintain the confidentiality of health information.