OLERE Telehealth and Technology 2 — Questions and Answers
Question 1: An Oklahoma LPC providing telehealth services must verify the client's location at the start of each session primarily to:
- Bill insurance correctly for the telehealth service
- Ensure the LPC is licensed in the state where the client is physically located during the session (Correct answer)
- Comply with DEA requirements for telehealth
- Schedule sessions across time zones accurately
Correct answer: Ensure the LPC is licensed in the state where the client is physically located during the session
A counselor providing telehealth must be licensed in the state where the client is physically present during the session. Verifying client location at each session ensures the counselor is practicing within their licensed jurisdiction.
Counseling jurisdiction is determined by the client's physical location at the time of service, not by where the client lives or where the counselor practices. An Oklahoma LPC can see Oklahoma residents via telehealth, but if a client travels to another state during an established course of treatment, the counselor must either be licensed in that state or address the session legally. Verifying client location at the start of each session is both a legal necessity and an ethical obligation.
Question 2: Which of the following represents a HIPAA-compliant approach for an Oklahoma counselor conducting telehealth sessions?
- Using any video chat application as long as the session content is therapeutic
- Using a HIPAA Business Associate Agreement-covered telehealth platform (Correct answer)
- Using a consumer video platform such as standard FaceTime or Zoom personal account
- Conducting phone-only sessions because audio is more secure than video
Correct answer: Using a HIPAA Business Associate Agreement-covered telehealth platform
HIPAA-compliant telehealth requires using platforms that provide a Business Associate Agreement and have appropriate security features including encryption and access controls. Consumer-grade applications without BAAs do not meet HIPAA requirements.
HIPAA's Security Rule requires that when electronic protected health information is transmitted, it must be done through secure, HIPAA-compliant platforms. For telehealth, this means using platforms that provide a signed Business Associate Agreement, end-to-end encryption, and appropriate security features. Consumer applications without BAAs are not HIPAA-compliant for clinical use. The counselor bears responsibility for verifying HIPAA compliance of any technology used.
Question 3: An Oklahoma LPC is seeing a client via telehealth when the client suddenly discloses active suicidal ideation with intent and a means. The counselor should:
- Continue the telehealth session and address the crisis with standard therapeutic techniques
- Obtain the client's physical location and local emergency contacts and activate local emergency services if needed (Correct answer)
- Terminate the telehealth session and ask the client to go to the nearest ER
- Contact the client's emergency contact without disconnecting the telehealth session
Correct answer: Obtain the client's physical location and local emergency contacts and activate local emergency services if needed
Telehealth crisis management requires having the client's physical address and local emergency contact information available before any session. When a telehealth client discloses imminent suicidal risk, the counselor must be able to activate local emergency services using that information.
Crisis management in telehealth requires specific advance planning. Before beginning telehealth services, counselors should obtain the client's current physical address, a local emergency contact, and the nearest emergency services information. When an imminent crisis occurs during a telehealth session, the counselor must maintain the connection as much as possible while assessing risk, confirm the client's current location, and contact local emergency services with the client's location if warranted.
Question 4: An Oklahoma LPC wants to use a mobile app to communicate with clients between sessions. The primary consideration before implementing this is:
- Whether clients prefer texting to phone calls
- Whether the app is HIPAA-compliant and whether its use is clinically appropriate for each client (Correct answer)
- Whether the app is free for clients to download
- Whether the app has a five-star rating in the app store
Correct answer: Whether the app is HIPAA-compliant and whether its use is clinically appropriate for each client
Between-session communication technology must be HIPAA-compliant to protect client information, and its clinical appropriateness must be evaluated for each client, as not all clients benefit from increased accessibility.
Using mobile apps for client communication requires two parallel considerations. First, HIPAA compliance: any app used for client communication must provide a BAA, encryption, and appropriate security features. Standard SMS text messaging is not HIPAA-compliant. Second, clinical appropriateness: not all clients benefit from between-session contact via app, as for some clients with dependency presentations, increased accessibility could reinforce problematic patterns. The counselor must evaluate each client's needs and document the rationale.
Question 5: An Oklahoma LPC wants to store client records using a cloud-based platform. Under HIPAA, the cloud provider is considered a:
- Covered entity with independent HIPAA obligations
- Business Associate requiring a Business Associate Agreement with the counselor (Correct answer)
- Third party with no HIPAA obligations
- Government contractor subject to separate federal privacy rules
Correct answer: Business Associate requiring a Business Associate Agreement with the counselor
A cloud storage provider that handles protected health information on behalf of a covered entity is a Business Associate under HIPAA, requiring a signed Business Associate Agreement before storing any client information.
Under HIPAA, a Business Associate is an entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity such as a counseling practice. Cloud storage providers that store client records are Business Associates, regardless of whether they can access the data content. The covered entity must execute a signed Business Associate Agreement with the cloud provider. Using a cloud provider without a BAA is a HIPAA violation.
Question 6: An Oklahoma LPC discovers that a client has been sharing screenshots of their telehealth sessions on social media. The counselor's best response is to:
- Terminate services immediately due to the confidentiality breach
- Address the behavior therapeutically and establish clear technology guidelines for future sessions (Correct answer)
- File a complaint with the social media platform
- Ignore the situation because the client cannot violate the counselor's confidentiality
Correct answer: Address the behavior therapeutically and establish clear technology guidelines for future sessions
While clients cannot technically violate the counselor's confidentiality, sharing session content creates privacy concerns and potential harm. The counselor should address it therapeutically and establish clear technology guidelines.
Clients do not have the same confidentiality obligations as counselors and can legally share information about their own treatment. However, sharing session screenshots raises serious concerns including potentially compromising the client's own privacy and undermining the therapeutic process. The counselor should address this therapeutically, explore the client's motivations, and establish clear technology guidelines for future sessions.
An Oklahoma LPC providing telehealth services must verify the client's location at the start of each session primarily to: