Photo Credit: Getty Images
Remote staffing done right: ensuring efficiency, security and HIPAA compliance with remote workers
By Peter Cass, OD
July 10, 2026
My company, Practice Performance Partners, has been consulted by hundreds of practices in the past year who are concerned about the recent HIPAA breaches and what that may mean for their HIPAA compliance related to their remote workers.
This issue is driven by a common staffing challenge: finding and retaining qualified staff while maintaining excellent customer service. To accomplish this, many practices are adopting remote staffing models for things like scheduling, insurance verification, billing support, patient communications, documentation assistance and other administrative functions.
While the remote workforce trend is no longer new, the level of responsibility being delegated to off-site staff and the amount of protected health information (PHI) they encounter during their work is changing. That reality creates an important question for healthcare providers:
Can remote workers be HIPAA compliant?
The answer is yes—but only when healthcare organizations approach remote staffing with the same level of diligence they apply to any other member of their workforce. And this often leads to the next question:
DOES THE USE OF REMOTE WORKERS REQUIRE SPECIAL PATIENT AUTHORIZATION?
Absolutely not. Despite social media posts and even stated requirements from some EHR vendors, there are no laws or regulations requiring a doctor to obtain patient authorization to use remote workers. Despite bias from some individuals, remote workers are remote, whether they work in the same city or overseas. A few states have regulations restricting the use of overseas workers’ access to information processing for Medicaid patients. These restrictions cannot be overridden by patient authorization, but the solution is simple: do not use overseas workers in the processing of Medicaid claims.
REMOTE WORKERS ARE HERE TO STAY
For many practices, remote workers provide access to a larger talent pool, greater scheduling flexibility and relief from ongoing staffing shortages. Remote assistants, remote billers, schedulers and scribes can often take on repetitive administrative tasks that consume valuable time in the practice.
Companies specializing in healthcare staffing have emerged to help practices identify, train, and onboard qualified remote personnel. Some organizations, such as Teem, focus specifically on healthcare-related administrative support and provide structured hiring, training, and performance management processes. These services can simplify recruitment challenges for practices that are struggling to fill certain positions.
However, no matter how remote workers are sourced, one principle remains unchanged:
A remote employee who has access to PHI creates the same HIPAA obligations as an employee located inside the practice.
The location changes. The responsibility does not.
HIPAA DOESN’T CARE WHERE THE EMPLOYEE IS LOCATED
One of the most common misconceptions regarding remote staffing is that HIPAA requirements become more flexible when work occurs outside the practice.
HIPAA’s Privacy Rule and Security Rule apply regardless of where an individual is working from.
If a remote worker can access patient information, healthcare organizations must ensure appropriate administrative, physical and technical safeguards are in place.
SECURITY MUST COME BEFORE CONVENIENCE
Many practice owners begin their remote staffing journey by focusing on cost savings or operational efficiency. While those benefits may exist, security should be the first consideration.
Before granting any level of system access, practices should evaluate:
- How PHI will be accessed
- Where data will be stored
- Whether devices are encrypted
- How users are authenticated
- What happens if equipment is lost or stolen
- Whether access can be audited and monitored
Unfortunately, many security incidents occur not because systems are compromised by sophisticated attackers, but because basic controls were overlooked.
THE IMPORTANCE OF WORKFORCE TRAINING
Technology alone cannot create HIPAA compliance. Remote workers must receive appropriate training regarding:
- HIPAA privacy requirements
- Security awareness
- Password management
- Phishing and social engineering threats
- Appropriate use of patient information
- Incident reporting procedures
Practices should avoid assuming a worker’s previous healthcare experience automatically means they understand the practices specific situation and expectations.
The most successful remote workforce programs establish clear procedures, provide documented training and regularly reinforce compliance responsibilities.
BUSINESS ASSOCIATE AGREEMENTS MATTER
One area that deserves special attention is the contractual relationship between the healthcare provider and any third-party staffing organization.
If a vendor has access to PHI, or facilitates access to PHI, the organization should carefully evaluate whether a Business Associate Agreement (BAA) is required, but this step is often overlooked.
Before entering any remote staffing arrangement, practices should review contracts carefully and ensure legal responsibilities are clearly defined. An agreement that creates confusion regarding HIPAA obligations can become a significant liability later.
As with any compliance-related decision, consultation with qualified legal counsel is advisable when uncertainty exists.
BUILDING A SECURE REMOTE WORKFORCE
Organizations that have successfully integrated remote workers into healthcare operations generally follow several common practices:
- Establish written policies: Remote work expectations should be documented and consistently enforced. Policies should address device usage, data handling, security requirements and reporting obligations.
- Use secure technology: Organizations should consider:
- Multi-factor authentication (MFA)
- Encrypted communications
- Secure VPN connections when appropriate
- Endpoint protection software
- Role-based access controls
- Limit access: Employees should only have access to the information necessary to perform their job responsibilities.
- Monitor activity: Audit logs and access monitoring provide important visibility into how systems and patient information are being used.
- Conduct ongoing risk assessments: The threat landscape continues to evolve. Practices should periodically review remote work arrangements and identify emerging vulnerabilities.
THE GOAL ISN’T TO AVOID REMOTE WORKERS
Some practices hear discussions about HIPAA risk and conclude that avoiding remote workers is the safest option. But that is the wrong takeaway.
Remote staffing can be highly effective when implemented correctly. Many practices have improved efficiency, reduced administrative burden and enhanced patient service through thoughtfully designed remote workforce programs.
The objective is not to eliminate remote work but to eliminate preventable risk.
REMOTE WORK REQUIRES THE SAME CARE AS IN-OFFICE STAFF
Remote workers are becoming an increasingly important part of modern healthcare operations. Whether a practice uses remote billers, schedulers, scribes, insurance verification specialists or virtual assistants, success depends on maintaining the same security and compliance standards that would be expected inside the office.
Organizations should evaluate staffing partners carefully, verify security controls, ensure proper contractual protections are in place and provide ongoing HIPAA training for everyone who touches patient information.
When those fundamentals are followed, remote workers can become a valuable extension of the healthcare team and improve operational efficiency while still protecting what matters most, patient trust.
Read more on general management here.
![]() |
Peter J. Cass, OD, is a partner in Practice Performance Partners, a faculty member for the University of Houston College of Optometry, an associate at MyEyeDr. Beaumont and a past president of the Texas Optometric Association. To contact him: Peter@PracticePerformancePartners.com |

