Conducting audits allows organizations to determine if they meet the necessary policies and procedures for compliance with required standards. Text messaging is a popular communication channel in healthcare, and conducting HIPAA compliance audits helps maintain patient privacy when using this medium.
The Final Omnibus Rule is a set of revisions to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. It expanded the definition of business associates to include entities that handle ePHI on behalf of covered entities. This means that if a healthcare organization uses a third-party text messaging platform to transmit ePHI, that platform would be considered a business associate and must comply with HIPAA regulations.
It also strengthened the required privacy and security protections for ePHI. This led to the expansion of breach notification requirements and more stringent penalties for violations committed in the protection of ePHI. The main aim of the revision was to provide patients with greater control over their health information, enhance privacy and security safeguards, and promote compliance across the healthcare industry.
Related: How do I know when my HIPAA privacy obligation for email encryption ends?
During a HIPAA compliance audit, the assessment of text messaging usage in a healthcare organization focuses on evaluating whether the organization's practices align with HIPAA requirements and ensure the privacy and security of protected health information (PHI). The specific focus and depth of the assessment may vary depending on the scope of the audit and the auditors' requirements.
During HIPAA compliance audits, auditors often focus on several common areas of concern or violations related to text messaging. These include:
Implementing corrective measures may include adopting secure text messaging platforms that offer end-to-end encryption and other necessary security features. Additionally, developing and enforcing clear policies and procedures specific to text messaging can provide guidance in navigating avoidable violations. All of this goes hand in hand with engaging trustworthy and efficient vendors in all methods of communication, from texting to HIPAA compliant email.
Related: HIPAA's Transaction and Code Sets Rule