A newer version of the platform is available. Please refresh the page.
Roy Huggins, LPC NCC
https://personcenteredtech.com
Table Of Contents
1. How Do You Document Emails and Text Messages Received From Clients?
A “record” is much more than just the document that sits in our filing cabinets. A record is any recorded information regarding a client’s care including emails, texts, and phone messages as well as documentation of sessions and information exchanged with other providers. All communications with a client are legally part of their health record, and thus we need to be mindful of how we manage them.
Documenting emails
Most people can read their email on a computer, meaning emails can be printed and placed in a paper record, or copied and pasted into an electronic record.
Email sits on the servers of the companies that provide your email service. Following a thorough risk analysis, some clinicians may decide that leaving emails on the server is sufficient to maintain them, as opposed to copying the emails into a record-keeping system.
This analysis should, at the very least, include an analysis of how reliably your service maintains backups of its data and how easy it is for you to find emails that are part of a given client’s record.
Many technical experts advise that emails should be copied directly into whatever system you use to maintain client records. That helps to make sure you have them all in one place. But this is not an absolute necessity if you are able to earnestly and competently assess whether or not it works to keep emails on your service provider’s servers.
Note well that any email service you subscribe to must, at the very least, provide you with a Business Associate Agreement (BAA). You also need to keep up good practices to maintain the security of your email accounts.
Documenting Text Messages
Text messages can be printed to be included in the client’s records. If your printer and your smartphone are connected via trustworthy WiFi, you can print through the wireless printer and you’re golden.
If your electronic record system is online, you can likely connect to that system on your smartphone. From there, it should be a simple matter to copy and paste text messages from the texting app to the record system.
Emailing text messages to yourself so that you can print the email is problematic. Sending information in an ordinary email (or SMS text) means sending it over the open Internet without any measures in place to protect it from prying eyes. So if you use this method, then you put that text message through confidentiality jeopardy. What’s more, the client has no awareness that you’re doing this, and never expected their message to be re-transmitted over the open Internet.
There are services out there — and they are always “cloud” services — that will help you extract text messages from your smartphone. Usually the point of the service is to make sure the information is backed up, but they can also be used to make it easier to print text messages or move them to another place. When you use a cloud service, the first and most basic thing you look for is that Business Associate Agreement. No matter how simple or inconsequential the service seems to be, using it still means entrusting confidential information to a third party. HIPAA always requires a BAA in that case.
Are voicemail messages, emails, and texts part of the clinical records?
Among the many digital complexities therapists face these days is the question of whether Emails and phone text messages are part of the clinical records. This issue is similar to the pre-digital question of whether phone messages should be included in the treatment records. Like phone messages, emails and text messages that have clinical or other significance should be considered as part of the clinical records. Like phone messages and phone calls, texting and emails that simply discuss scheduling issues or other issues with little or no clinical significance do not need to be included in the clinical records. In addition to clinical importance, archiving email, voicemail, or texts may also become important in cases, such as where therapists are inundated with messages from clients, harassed, stalked, or threatened by clients, or during crisis and other high-pressure situations.
2. Using Secure Email and Texting With Clients
Sacred space of therapy is founded on the safety of the environment, and we have long accepted that both privacy of the physical space and the promise of confidentiality in the professional relationship are foundational to that safety — both felt and actual. Emailing and texting clients is not inherently unethical but to ensure a safe and confidential space online, requires technical security. When an email crosses the Internet to get to its next destination, it passes through many different machines on the way. If that email’s content isn’t obscured by encryption, then it can be read by all of those machines through which it passes. You can’t be secure it is only read by your client.
Encryption is the cyber-equivalent of sound-resistant walls, closed doors and noise machines in the hallway.
In terms of stretching ethical confidentiality standards, unencrypted communication could be likened to walk-and-talk therapy or therapy in coffee shops. In other words, they’re ethically feasible with earnest and healthy due diligence and when the client gets sufficient benefit to justify accepting the risks involved (or the risks are low enough at the start to be acceptable.)
A vital difference, however, is that walk and talk therapy and ecotherapy inherently offer health gains that can justify stretching confidentiality. For each client, we need to determine if we can say the same of nonsecure communications. If we cannot, then it will take very special circumstances to justify putting that stress on the client’s confidentiality.
If you wish to maintain the sanctity of the therapy space, whether in an office or online, you need to employ secure communications tools for that.
Getting Clients Onboard
Sometimes it is difficult to convince clients to use secure communication tools, such as secure messaging (aka “encrypted email”) or secure texting apps. Research indicates that the therapist’s level of comfort with a piece of tech has a large impact on the client’s comfort and interest in using it. One should remember that this is a learning process that requires up-front focus and time investment, but becomes second nature as time goes on. That investment also turns into improved security for clients and the practice.
3. Apps You Can Use To Create Highly Private Spaces Online for Clients
There are different apps that can do what I’ve decided to call “high privacy.” That would be private communications where no one but you and your client could feasibly ever read the messages you exchange. Very importantly, “high privacy” as I have defined it here is not a requirement for HIPAA compliance. With a proper HIPAA Business Associate Agreement (BAA) in place, it’s legal to use texting and email services that are able to read your messages. That’s the purpose of the BAA — it’s the company’s assurances that they’ll keep your information private and secure. Here we’re talking about serving clients with even higher privacy desires than are typical or required by HIPAA.
A Review for Signal
Signal is an open-source texting app for pretty much all smartphones. “Open source” means it is free as in “free beer” but also free as in “free speech.” It is very easy to use for both clinicians and clients. Signal’s servers retain nothing about your texting exchanges, which makes Signal very resistant to all forms of privacy invasion (so long as you keep up your end of the security bargain, of course.) It is intended to be private enough to prevent anyone but the people involved in a conversation from being able to read any messages in that conversation. However, its highly private nature makes it harder to document the messages you exchange using it.
Caveat: After an update in 2016, Signal users can flip a switch that turns on “disappearing messages” in certain specific conversations. This means you’ll need to ask clients not to use it. For this reason, your risk analysis regarding Signal may need to take into account whether or not clients will cooperate with your request on this point.
4. Email and HIPAA Compliant Practice
Email, as a general medium, lacks those technological things we would want it to have for security. Those of us that are required to be HIPAA compliant need to be thoughtful about the ways we use it. Email is part of a modern culture of high-transparency communication. We clinicians sometimes find ourselves using it for sensitive conversations despite our usual vigilance around confidentiality.
Sensitive Conversations
Any email you send to or receive from clients contains both of your email addresses. Its content is going to be related to clinical work. It may be as simple as an appointment time, but it’s always about health care.
Email addresses can be used to identify people very easily, and email addresses are on the list of 18 identifiers that HIPAA defines as without-a-doubt personally identifying.
Personally identifying information combined with health information makes what HIPAA calls “protected health information.” Ethically, we would consider it “confidential information.”
This means that any email between clinician and client needs to be protected. “Protected” often means using encryption, but not always. “Protected” means that we apply a risk management lens to the confidentiality problems raised by email and come up with appropriate risk management strategies. What are the confidentiality problems raised by email?
Problem 1) Open Internet
Email is like a postcard passing through the wild hinterlands of the open Internet. Various nefarious elements may be able to see its contents as it goes by.
The most obvious and powerful risk management measure would, indeed, be to encrypt all emails. Encryption is a secret code, and everyone who wants to read the email needs to be in on the code. But just like an encrypted email would be useless to hackers who watch it fly by, it would also be useless to the client who receives it without some predetermined setup for unlocking the encryption.
An alternative to using encrypted email or secure messaging services is to just not send anything that a hacker would care to see. It may sound overly simple. And to be honest, it is. There is a lot that goes into the idea of collaborating with clients who want you to send them ordinary, unencrypted emails. While it is more than achievable and completely reasonable to do, you need to approach it with a good sense of how risk management works and with a good knowledge of the risks at play.
Problem 2) Email Sits In Places
Emails “sit” in places like a smartphone, a computer, an account on a server on the Internet, etc. If you’ve ever worked with clients who have nosy or abusive people in their lives, you may be familiar with the vulnerability of any of these things.
Even if you and the client are encrypting your messages, that won’t stop the nosy or abusive intruders. Why not? If the client can unlock the encryption for their own viewing, then they can certainly do so for the abuser. And abusers generally demand passwords from their targets.
Thus we see one of the many reasons why “encrypted” is not a synonym with “secure,” despite the advice we so frequently get in our professional circles.
5. Three Kinds of Email Security: How to Make an Informed and HIPAA-Aware Choice
Least Reliably Secure: Conventional Email
Classic conventional email can be read by anyone with access to the one of the many machines that the email passes through on its way across the Internet. Sometimes, however, modern email companies will make arrangements to use encryption when sending emails to each other. When they do this, they turn a conventional email into a “TLS-Secured Email,” described below. Even though conventional email sometimes gets spontaneously upgraded to TLS-Secured email, you can’t predict this upgrade and you usually can’t rely on it.
Second-Most Reliably Secure: TLS-Secured Email
We get TLS-secured email when the email providers involved in an exchange agree to use encryption. You usually don’t know when this has happened. TLS-secured email is simple to use, and it helps ensure that emails are encrypted all the way across an Internet transmission. It does not, however, secure emails from any prying eyes that may be present when an email sits in a client’s email provider’s data center or on the client’s computer/smartphone. It only protects transmission across the Internet. TLS-secured email isn’t feasible 100% of the time because it requires cooperation from the receiving email provider.
Most Reliably Secure: Escrow Email
Escrow email is the kind where you get an email that says, “Your clinician has sent you a secure message. Click here to read it.” You then click the provided link and it takes you to a webpage on the escrow email provider’s site. Then you do something to authenticate your identity, answer a security question, or something like that. After authenticating, you can read the secure message right there on the same webpage. Many hospitals and medical clinics now use escrow email regularly.
Escrow email can be frustrating to use, but it provides the best and most reliable security. Escrow emails never end up in clients’ inboxes or on their phones or computers because they don’t actually get sent over the Internet. Sometimes, for clients, that’s an annoyance. But when you need to ensure that your message or attachment stays away from interlopers in the client’s life, escrow email is one of your best bets.
6. Which Kind of Email Should You Use?
Reasons to Use Conventional Email
So if you do it properly and with intentionality, there are several ways that you can use conventional email services — and secure email services that are capable of conventional email, like Hushmail and LuxSci —and maintain HIPAA compliance.
Reasons to Use TLS-Secured Email
Reasons to Use Escrow Email
An email sent directly to the client can’t be taken back, which makes expiring messages impossible with conventional or TLS-secured email. Escrow services can do it. Note that the therapist’s escrow email service can (and usually does) still keep the message in the therapist’s “Sent” folder for permanent access. That way the therapist can access it indefinitely, but no one else can.
7. Therapy Business Line: HIPAA and “VoIP” Services
Google Voice Vs. Usual Phone Service?
Google Voice is an Internet phone service, which is called “Voice over IP,” or “VoIP” phone service. VoIP is an alternative to “classic” phone service. VoIP phone services are viewed by HIPAA authorities as electronic transmissions. That means that they fall under the HIPAA Security Rule without exception. As such, we are required by HIPAA to:
The requirement for a BAA is not a flexible point for HIPAA. If the company won’t do it, then it’s a HIPAA no-go. For example, as of June 2018 the following VoIP service providers won’t execute BAAs with customers, even if the customer is a HIPAA covered entity.
Providing VoIP service that meets the standards for HIPAA BAA is an expensive thing to do. Such services are not as cheap as the ones on the crossed-out list above. HIPAA-secure VoIP services, however, may still be less expensive than classic phone service.
8. Safe Harbor Conditions
When the HITECH Act was enacted in 2009, it introduced to HIPAA a concept called “breach notification.” In effect, that means that when a security “breach” happens — such as a laptop with health records on it being stolen or lost — the affected clients need to be notified as does the federal government.
There are great ways to secure tech devices so that even if they are stolen, no one can get in. This is important because of an exception to the breach notification rule if the lost computer or smartphone is well secured. It is called a “safe harbor.” This safe harbor affects only breach notification. This means that if you lose it or it gets stolen, you don’t have to report that breach to anyone.
How do I get the safe harbor conditions on my computer or phone?
The safe harbor is attained by making all the health information on the computer or smartphone totally unreadable — and that means encryption.We can’t just use any encryption, however. Legal safe harbor standards in general are an “A+” level of standard, meaning “full device/full-disk encryption.” This means that every little bit and byte on your computer or phone is encrypted and only your one special encryption password can unlock it all.
If you have a Mac whose operating system isn’t several years old, you can get full disk encryption simply by going to your security settings and activating FileVault2.
For Windows, there is also an encryption program called Bitlocker. You can’t buy BitLocker separately. It only comes with the Pro version of Windows. On an iPhone, you simply need to set a strong passcode. On Android phones, you need to turn on encryption in the security settings and set a strong passcode.
Of all the technological things you can do to protect your clients’ information, full-disk encryption is probably the easiest and least expensive way to simplify your security efforts. You do still need to behave in ways that support the encryption, though. For example, given that the encryption is unlocked while you’re using your devices, you need to lock it up again in order to qualify for the safe harbor.