Some healthcare events may involve Protected Health Information (PHI), making unauthorized access or data leaks a potential risk to sensitive patient information.
Therefore, you need to be aware of common HIPAA risks associated with virtual events and how to avoid them, so you can be sure that appropriate security measures are in place to protect patient privacy.
What is HIPAA?
The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement HIPAA’s requirements. HIPAA, or the Health Insurance Portability and Accountability Act of 1996, establishes national standards for protecting certain individually identifiable health information and regulates how covered entities and business associates use and disclose that information.
What is Protected Health Information (PHI)?
Protected Health Information (PHI) under HIPAA is tied to information held or transmitted by covered entities and business associates, subject to the applicable HIPAA definitions and exclusions. The U.S. Department of Health and Human Services (HHS) describes business associates as entities that create, receive, maintain, or transmit PHI (on behalf of covered entities or business associates.)
PHI includes a wide range of information, such as:
- Patient full name
- Date of birth
- Medical record number
- Address, phone number and email id
- Lab and test reports like blood tests, X-rays, Sonography, CT Scans, MRI and more
- Diagnosis, medical condition and treatment procedure
- Information about patient medical prescription and medications
7 Common HIPAA Risks That Can Occur In Virtual Events and How to Prevent Them
1 – Unauthorized People Joining the Session
An unauthorized person may gain access to PHI disclosed during the session—creating a potential privacy or security incident.
For example, they could
- Hear a discussion about a patient.
- View PHI shared on the screen.
- Access sensitive information shared in the chat.
How to Prevent it
- Require participants to sign in using their individual accounts before joining the session
- Use waiting room and verify the participants’ identities before admitting them
- Immediately remove an unknown or unauthorized person from the event
2 – Using a Virtual Event Platform Without Appropriate HIPAA Safeguards
A virtual event platform that does not provide appropriate safeguards for HIPAA-regulated use can put patient information at risk.
Suppose a hospital hosts an event where doctors share patient information, test reports, and treatment options. And if the platform is not capable of handling PHI, the patient information could be exposed through live sessions, chats, transcripts, or stored event data.
How to Prevent it
- Check whether the online event platform provider will sign a Business Associate Agreement (BAA), where applicable.
- Choose an event platform that supports HIPAA-regulated use and appropriate safeguards
- Review the platform’s security, access-control, encryption, audit, recording, and data-retention features
3 – Exposure of Protected Health Information (PHI) Due to Screen Sharing
The presenter may accidentally display a patient portal and EHR screen that contains PHI (Protected Health Information), a patient’s file, a clinical test record or disease treatment history. Everyone present at the event can see it.
How to Prevent it
- Ask the presenter to close any EHR or patient-record windows containing PHI before sharing their screen
- Ask presenter to share specific window instead of entire desktop
4 – Recording the Whole Event
If you record the entire event, any PHI discussed, shown, or shared during the session—such as the patient’s medical condition, test results, treatment details, and more—will become part of the recording.
For example, If the doctor is discussing a patient’s specific medical condition during the live session, the team may choose not to record that portion of the session.
Recording PHI is not automatically prohibited, but recordings containing PHI must be appropriately safeguarded and handled in accordance with applicable HIPAA requirements.
How to Prevent it
- Do not record the part of the session where patient case is discussed
- Stop recording before discussing sensitive patient information
5 – Participant Discussion in Chat That Discloses PHI
During a virtual event, a patient might share their own old Protected Health Information (PHI)—such as medical record number or medical test results—in the chat.
How to Prevent it
- Warn all patients not to share any confidential information in the chat
- Disable participant-to-participant chat
6 – Weak Event Password
If your event password is weak, unauthorized people can enter your event and access the session, and view PHI and other sensitive information. An unauthorized person may hear your conversation, view information shared on screen, access chat discussions, or attempt to record the session.
How to Prevent it
- Use strong and unique event password
- Enable multi-factor authentication (MFA)
- Use waiting room
- Don’t publish meeting credentials on social media
7 – Creating Automated Transcripts and Event Summaries
Today’s virtual event platforms feature built-in AI capabilities that automatically convert conversations into transcripts, summaries, captions, searchable text, and AI-generated notes.
This means that the patient’s Protected Health Information (PHI) may be stored in locations other than the original event such as virtual event platforms, cloud storage, or AI solutions.
How to Prevent it
- Disable automatic transcription and event summaries
- Make sure the event platform provider will sign a Business Associate Agreement (BAA), where applicable
Final Thoughts
Virtual healthcare programs can give rise to HIPAA-related risks, as such programs often involve the sharing and discussion of patients’ private health-related and sensitive information. If appropriate security measures are not used, patient information may be exposed during virtual healthcare events.
Unsecured event platforms, unauthorized people and weak event passwords can make sensitive information vulnerable. By using a virtual event platform with appropriate HIPAA safeguards, creating strong event passwords, and removing unauthorized people from the session, you can protect patients’ sensitive health information and reduce the risk of HIPAA violations.
FAQs:
Yes, especially when they capture protected health information (PHI). Recordings should be protected with appropriate access controls and made available to only authorized individuals based on the purpose and applicable policies.
As a healthcare organization, you need to consider the following security features in a virtual event platform.
- Data encryption
- Strong user authentication
- Access Control
- Secure Recording
- Audit logs
- HIPAA-related safeguards
- Signing a Business Associate Agreement (BAA)
In accordance with healthcare program policies and applicable privacy rules, patients may take screenshots or photos. However, they should not capture other patients’ Protected Health Information (PHI) or confidential information without authorization or permission.
Organizations can support HIPAA compliance for virtual events by implementing appropriate safeguards to protect protected health information (PHI) such as data encryption, strong access control, participant authentication, secure storage for event recording and more. They should also evaluate how the platform handles PHI and whether a Business Associate Agreement (BAA) is required.
Healthcare organizations can host various types of virtual events such as telehealth consultations, patient education sessions on understanding conditions, treatments, medications, & preventive care, clinical case discussion, staff training sessions on providing good patient care, and panel discussion that involve physicians, specialists, and other healthcare experts.
