Skip to main content

Business Compliance for Virtual Care

Running a virtual care practice requires navigating complex healthcare regulations. CareLaunch is designed to help healthcare entrepreneurs maintain compliance without becoming regulatory experts. This guide covers the key compliance requirements and how CareLaunch helps you meet them.

HIPAA Compliance

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information. As a healthcare provider, you're required to:

  • Protect patient health information (PHI)
  • Implement administrative, physical, and technical safeguards
  • Provide patients with rights over their health information
  • Report breaches of unsecured PHI

How CareLaunch Supports HIPAA Compliance

Technical Safeguards:

  • 256-bit AES encryption for data at rest and in transit
  • Secure, HIPAA-compliant video conferencing
  • Encrypted messaging and file storage
  • Automatic session timeouts
  • Secure authentication with optional two-factor authentication

Administrative Safeguards:

  • Role-based access controls
  • Comprehensive audit logging
  • User activity monitoring
  • Automatic backup and disaster recovery

Business Associate Agreement (BAA):

  • CareLaunch provides a signed BAA with all plans
  • The BAA is included at no additional cost
  • Review and sign during account setup

Your HIPAA Responsibilities

While CareLaunch provides compliant infrastructure, you're responsible for:

  1. Workforce Training: Train all staff on HIPAA requirements
  2. Policies and Procedures: Develop and maintain HIPAA policies
  3. Risk Assessments: Conduct regular security risk assessments
  4. Incident Response: Have a plan for responding to potential breaches
  5. Patient Rights: Honor patient requests for access, amendments, and restrictions

HIPAA Best Practices

Access Management:

  • Grant minimum necessary access to each team member
  • Review user access regularly and remove inactive users
  • Use strong, unique passwords
  • Enable two-factor authentication for all users

Communication:

  • Use CareLaunch's secure messaging for all patient communications
  • Never send PHI via regular email or text
  • Verify patient identity before sharing information
  • Document all patient communications

Device Security:

  • Use encrypted devices for accessing CareLaunch
  • Enable screen locks and automatic timeouts
  • Avoid accessing patient data on public networks
  • Keep software and operating systems updated

Telehealth Regulations

State Licensure Requirements

Telehealth regulations vary by state. Key considerations:

Provider Licensure:

  • You must be licensed in the state where the patient is located
  • Some states have telehealth-specific licenses or registrations
  • Interstate compacts (like IMLC for physicians) may simplify multi-state practice

Informed Consent:

  • Most states require specific telehealth consent
  • CareLaunch provides customizable telehealth consent forms
  • Document consent before providing telehealth services

Prescribing Regulations:

  • Rules for prescribing via telehealth vary by state
  • Some states require in-person visits for certain prescriptions
  • Controlled substance prescribing has additional requirements

Staying Current with Regulations

Telehealth regulations evolve frequently. Stay informed by:

  • Subscribing to state medical board updates
  • Joining professional associations
  • Following telehealth policy organizations
  • Consulting with healthcare attorneys when needed

CareLaunch Telehealth Compliance Features

  • State-Specific Consent Forms: Customizable templates for each state
  • Location Verification: Confirm patient location at time of service
  • Documentation: Comprehensive visit documentation
  • Audit Trail: Complete record of all telehealth encounters

Payment and Billing Compliance

PCI DSS Compliance

When accepting credit card payments, PCI DSS (Payment Card Industry Data Security Standard) applies:

CareLaunch Handles:

  • Secure payment processing through certified processors
  • Encrypted transmission of payment data
  • No storage of full credit card numbers
  • Regular security assessments

Your Responsibilities:

  • Never write down or store credit card numbers
  • Use CareLaunch's payment system for all transactions
  • Report any suspected payment fraud immediately

Healthcare Billing Regulations

Transparent Pricing:

  • Clearly display service prices to patients
  • Document services provided
  • Maintain accurate financial records

Anti-Kickback and Stark Laws:

  • Don't pay for patient referrals
  • Ensure financial relationships comply with regulations
  • Document any business arrangements

Data Privacy Beyond HIPAA

State Privacy Laws

Some states have additional privacy requirements:

California (CCPA/CPRA):

  • Additional consumer privacy rights
  • Disclosure requirements for data collection
  • Right to opt out of data sales

Other States:

  • Virginia, Colorado, Connecticut, and Utah have comprehensive privacy laws
  • More states are enacting similar legislation
  • CareLaunch helps you comply with state-specific requirements

International Considerations

If serving patients outside the US:

GDPR (European Union):

  • Strict consent requirements
  • Data subject rights
  • Data transfer restrictions

Canadian Regulations:

  • PIPEDA and provincial health privacy laws
  • Specific requirements for health information

Compliance Documentation

Required Policies

Develop and maintain these policies:

  1. Privacy Policy: How you collect, use, and protect patient information
  2. Notice of Privacy Practices: HIPAA-required patient notice
  3. Telehealth Policy: Your telehealth procedures and patient expectations
  4. Consent Forms: Informed consent for treatment and telehealth
  5. Financial Policy: Payment terms, cancellation policies, fees

Record Retention

Maintain records according to requirements:

  • Medical Records: Typically 7-10 years (varies by state)
  • Billing Records: At least 7 years
  • HIPAA Documentation: 6 years from creation or last effective date
  • Business Records: Follow state and federal requirements

CareLaunch automatically retains data according to configurable retention policies.

Compliance Monitoring

Audit Logs

CareLaunch maintains comprehensive audit logs:

  • User login and logout events
  • Patient record access
  • Changes to patient data
  • System configuration changes
  • Message and communication logs

Access audit logs at Settings > Security > Audit Logs.

Regular Reviews

Conduct regular compliance reviews:

Monthly:

  • Review user access and remove unnecessary permissions
  • Check for unusual activity in audit logs
  • Verify backup completion

Quarterly:

  • Review and update policies as needed
  • Conduct mini risk assessments
  • Train new staff on compliance

Annually:

  • Comprehensive HIPAA risk assessment
  • Policy review and updates
  • Staff training refresher
  • Review BAAs with all vendors

Incident Response

Preparing for Incidents

Have a plan before incidents occur:

  1. Identify Response Team: Who handles incidents?
  2. Document Procedures: Step-by-step response process
  3. Contact Lists: Legal, IT, and regulatory contacts
  4. Communication Templates: Pre-drafted notifications

Responding to Potential Breaches

If you suspect a breach:

  1. Contain: Immediately stop the breach if possible
  2. Assess: Determine what data was affected
  3. Document: Record all details and actions taken
  4. Notify: Contact CareLaunch support and your legal counsel
  5. Report: File required notifications (HHS, state, patients)

CareLaunch Incident Support

In case of a security incident:

  • 24/7 security incident hotline
  • Forensic investigation support
  • Breach notification assistance
  • Remediation guidance

Resources

Compliance Tools in CareLaunch

  • Consent Management: Track and manage patient consents
  • Audit Logs: Comprehensive activity logging
  • Access Controls: Role-based permissions
  • Secure Communications: HIPAA-compliant messaging and video
  • Document Management: Secure storage and retention

External Resources

Getting Help

For compliance questions:

  • CareLaunch Support: [email protected]
  • Legal Counsel: Consult a healthcare attorney for specific situations
  • Professional Associations: Many offer compliance resources and guidance

Remember: CareLaunch provides compliant infrastructure, but ultimate compliance responsibility rests with your practice. When in doubt, consult qualified legal and compliance professionals.