Episode 508: Reassurance About the Proposed HIPAA Security Rule Change-Induced Panic
Release Date: 03/07/2025
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Dr. Maelisa McCaffrey of QA Prep about common documentation issues that come up in group practice. We discuss: Maelisa’s background and business, QA Prep Why there aren’t black and white guidelines for documentation How to determine what to include in documentation The most common people who will read your notes Informed consent and documentation, especially for vulnerable populations Progress note templates and policies...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what you need to know about syncing your EHR calendar with HIPAA in mind. We cover: Managing confidentiality and availability of data Having redundancies for worst case scenarios Types of calendar syncs and their benefits and drawbacks How to sync your calendars in a HIPAA-appropriate way Listen here: For more, PCT Resources PCT's free Group Practice Service Selection Workbook & Worksheets -- support for selecting HIPAA-secure,...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we discuss using Google Vids in a group therapy practice context. We cover: Popular screen recording software, Loom, and why it’s not HIPAA compliance compatible Google Vids being covered by the Google Workspace BAA Use cases for screen recording software for group practices Key reminders and usage notes for Google Vids Listen here: For more, Resources Google Workspace Help Center: PCT Resources Free on-demand workshop: Free...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share steps to take to protect client information from being accessed at the US border. We discuss: Devices being searched by Customs and Border Patrol at the US border Why border agents can search devices without a warrant HIPAA being the minimum security standard, not the ceiling When HIPAA permits disclosure of PHI How clients can be impacted when PHI is accessed by law enforcement How to conduct a risk analysis of the potential impact of...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we debunk two common but dangerous myths about cross jurisdictional practice for therapists. We discuss: Common myths we hear about practicing telehealth across jurisdictions The risks of unpermitted practice The threshold of client risk (and the only instances where cross-jurisdictional practice is permitted for clients in crisis) What constitutes client abandonment and what doesn’t Requesting temporary practice permission from a different...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we dive into what group practice owners need to know about encrypted messaging apps. We discuss: Encrypted messaging apps in the news What end to end encryption means What to look for in an encrypted messaging service Why a Business Associate Agreement is necessary The difference in risk landscape for mental health therapists and government officials Safeguards, like device security measures, to take when using secure messaging apps Listen here: For...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re sharing recent developments related to teletherapy and Medicare, HIPAA’s proposed Security Rule changes, and cross-jurisdictional Compacts. We discuss: Expanded telehealth flexibilities and waivers for Medicare and where things currently stand Reactions to the proposed Security Rule updates Making updates even when they aren’t required to safeguard client info and your practice Timelines for applications opening for the Counseling Compact...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re dispelling myths about the upcoming in-person visit requirements for Medicare clients. We discuss: The uncertainty in our current regulatory landscape What the in-person visit requirements mean for Medicare clients (and what they don’t mean) Exceptions to the requirements for in-person visits Compliance and documentation for these requirements, in the event of a Medicare audit Steps to take as a therapy practice owner to be prepared for these...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re hoping to lower the level of distress around the proposed HIPAA Security Rule changes for therapy practice owners. We discuss: What the some of the proposed changes to the Security Rule are, including penetration testing The timeframe for these changes if they are implemented, and the likelihood they actually will be implemented The rationale behind the proposed changes, and why they’re necessary in our current threat landscape How following...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an update for you on the BOI registration requirements for business owners. We discuss: The recent court decision which reinstated the requirement, and when it goes into effect What our current guidance is on this requirement (and why) Where to file Upcoming regulatory changes that will be more consequential for group practice owners, including changes to Medicare Listen here: For more,
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we’re hoping to lower the level of distress around the proposed HIPAA Security Rule changes for therapy practice owners.
We discuss:
- What the some of the proposed changes to the Security Rule are, including penetration testing
- The timeframe for these changes if they are implemented, and the likelihood they actually will be implemented
- The rationale behind the proposed changes, and why they’re necessary in our current threat landscape
- How following the PCT Way can minimize the changes you need to make as HIPAA regulations evolve
- Centering client care and safeguarding client info as a motivating factor, rather than fear
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.
Resources
- JD Supra article summarizing proposed HIPAA Security Rule Changes and context: New Year, New HIPAA Security Rule: OCR Adds to Health Care Entities’ New Year’s Resolutions
- HHS Fact Sheet on proposed changes: HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information
- Full text of the Notice of Proposed Rulemaking (NPRM) in the Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information
- Comments on the NPRM (Note, you can also search the public comments by keyword; ability make comments closed on 3/7/25)
PCT Resources
- PCT's Comprehensive HIPAA Security Compliance Program (discounted) bundles:
- For Group Practices
- For Solo Practitioners
- PCT's HIPAA Risk Analysis & Risk Mitigation Planning service for mental health practices -- care for your practice using our supportive, shame-free risk analysis and mitigation planning service. You’ll have your Risk Analysis done within 2 hours, performed by a PCT consultant, using a tool built specifically for mental health group practice, and a mitigation checklist to help you reduce your risks.
- Group Practice Care Premium
- weekly (live & recorded) direct support & consultation service, Group Practice Office Hours -- including monthly session with therapist attorney Eric Ström, JD PhD LMHC
- + assignable staff HIPAA Security Awareness: Bring Your Own Device training + access to Device Security Center with step-by-step device-specific tutorials & registration forms for securing and documenting all personally owned & practice-provided devices (for *all* team members at no per-person cost)
- + assignable staff HIPAA Security Awareness: Remote Workspaces training for all team members + access to Remote Workspace Center with step-by-step tutorials & registration forms for securing and documenting Remote Workspaces (for *all* team members at no per-person cost) + more