EDITIONEN·FR·ქართ

Accréditation Sans Frontières

International Accreditation of Healthcare Facilities

ASF Standards · Telemedicine · Standard 6

Standard 6 — Data Privacy & Patient Confidentiality

5 criteria · 5 non-negotiable · 0 core · Version 3.0

Criteria in this standard

6.1

The Patient's Session Environment Is Actively Addressed

Non-Negotiable

The patient's session environment is genuinely, actively addressed at the start of care — specific guidance on finding a private location, practical suggestions when home isn't quiet or private — not simply assumed private because the patient is participating from their own device.

In plain terms: At the start of care, the patient is told how to make their session private — a room with a door, headphones, no one listening — and the provider checks each time.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

The patient joins from the kitchen with children present. From the car park at work. From a shared bedroom. A mental health session, a discussion of an STI, a domestic violence disclosure — none can happen safely in those settings. The service must give guidance at intake (a private room, a closed door, headphones, a signal if someone enters) and the provider must check at each session ('Are you somewhere private? Can anyone hear?'). If not, the session is deferred or limited to non-sensitive content. Privacy is the patient's right and the provider's responsibility to protect.

What good looks like

  • Patients are genuinely, proactively guided on finding a private location.
  • Concrete alternatives are offered when home isn't private or quiet.
  • Attention to environment is genuinely calibrated to visit sensitivity.

Common failure modes

  • Environment privacy is assumed adequate without any active guidance.
  • No alternatives are offered for patients without a private home space.
  • Environment receives the same minimal attention regardless of topic sensitivity.

Worked example

In practice
A telemedicine mental health service.
BeforeNo guidance was given. Providers noticed background voices, children, and open-plan settings but proceeded. A patient disclosed abuse in a session her abuser overheard from the next room.
ActionIntake materials now include a one-page privacy guide: a private room with a closed door, headphones, a 'do not disturb' arrangement, a hand signal if privacy is lost. Every session begins with 'Are you somewhere private? Can anyone hear or see?' and the answer is recorded. If not private, the provider offers to reschedule or limits the session. Alternative private locations (a car, a community centre room, the service's partner sites) are suggested for patients without one.
AfterThe Monitor reviewed the intake guide, 40 session notes with privacy confirmation, and 5 sessions rescheduled for privacy. Verified.

If you are starting from zero — do this first

  1. Write a one-page privacy guide for patients.
  2. Script the check: 'Are you somewhere private?'
  3. Record the answer every session.
  4. Reschedule if not private.
The most common mistake: Noticing the patient is not in private and proceeding anyway.

Self-assessment questions

1. Is the patient genuinely, proactively guided on finding a private location for their session, not left to figure this out alone? — Real, active guidance, not an assumption the patient will independently find privacy.
Evidence: Patient environment guidance materials
2. Are practical alternatives offered when a patient's home genuinely isn't private or quiet? — Real, concrete alternative suggestions, not guidance limited to an assumed-available private home space.
Evidence: N/A — tested directly
3. Is environment addressed specifically for sensitive topics, not treated as equally important for every visit type? — Genuine, calibrated attention reflecting the real sensitivity of what will actually be discussed.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Guidance exists in intake materials but isn't reinforced verbally at the start of an actual session. — Real, active reinforcement at the point of use is more reliable than guidance provided once and easily forgotten.
  • Alternatives are suggested generally but not tailored to what's realistically available to a specific patient's circumstances. — Genuine, practical guidance should reflect what's actually feasible for the individual patient, not a generic list.
  • Environment is addressed for new patients but not consistently revisited for established, ongoing patients.

Implementation plan

When What
Week 1 Review current patient environment guidance for genuine specificity and practicality.
Week 2 Build concrete alternative suggestions for patients without a private home space.
Week 3 Reinforce environment guidance verbally at the start of sessions, not intake materials alone.
Ongoing Revisit environment guidance periodically for established patients.

How the Monitor verifies this

Method What Detail
DOCUMENT Guidance materials review Reviews actual patient-facing materials for genuine, specific environment guidance.
OBSERVE Session opening observation Observes whether environment is genuinely addressed at the start of an actual session.
DOCUMENT Sensitivity calibration review Reviews whether environment attention is genuinely calibrated to the sensitivity of the visit.

Supervisor tips

  • Ask a patient whether they were given any specific guidance on finding a private location. — A specific, real answer reveals genuine practice, not an assumption of adequate guidance.
  • Observe an actual session opening for genuine environment discussion. — Direct observation reveals whether this happens in practice, not just in intake documentation.

Evidence base

[26] Official telehealth guidance specifically advises patients to find a private location for their session and provides concrete suggestions — a quiet room at home, a private space in a community setting, a parked car — reflecting that session environment privacy requires active guidance, not assumed adequacy from platform security alone.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

6.2

A Third Party Present But Unseen Is Genuinely Disclosed and Consented To

Non-Negotiable

When someone other than the patient is present during a session — visible or not — this is genuinely disclosed, and specific consent is obtained before discussing sensitive information, particularly when the patient is in a public location where the conversation could be overheard.

In plain terms: If anyone other than the patient is in the room — visible or not — the provider knows, the patient has agreed, and it is recorded. No hidden listeners.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

A family member sitting off-camera, a partner in the next room, a carer 'just helping' — each is a third party to a confidential consultation. The patient may not feel free to speak; the provider may not know who is listening; consent is compromised. The rule: the provider asks who is present at the start of every session; anyone present is named and the patient confirms consent to their presence; the presence and consent are recorded; the patient can ask them to leave at any point. For sensitive topics, the provider may ask to speak to the patient alone. A hidden listener is a breach the patient did not agree to.

What good looks like

  • Providers genuinely, actively ask whether anyone else is present.
  • Specific, documented consent is genuinely obtained when a third party is present.
  • Public location risk is genuinely, actively addressed before continuing.

Common failure modes

  • Providers assume the patient is alone based only on what's visible on screen.
  • Consent for third-party presence isn't genuinely obtained or documented.
  • A patient's apparently public location isn't addressed before continuing with sensitive topics.

Worked example

In practice
A telemedicine service where third-party presence was not addressed.
BeforeProviders sometimes heard other voices or saw movement off-camera. They did not ask. A patient discussing a psychiatric medication was later found to have had her employer's HR representative present at her request — but the provider had not known and had not confirmed it was her choice.
ActionEvery session begins with: 'Is anyone else in the room or able to hear us? Do you want them to be present?' Anyone present is named in the session note with the patient's consent recorded. Providers are trained to ask for a private word with the patient at any point. Patients are told at intake that they can have a support person present but must say so.
AfterThe Monitor reviewed 40 session notes with third-party disclosure recorded (8 with named support persons and consent). Verified.

If you are starting from zero — do this first

  1. Add 'Who else is present?' to the session opening script.
  2. Record every third party and the patient's consent.
  3. Train providers to ask for a private word when needed.
  4. Tell patients the rule at intake.
The most common mistake: Hearing another voice and not asking who it is.

Self-assessment questions

1. Are providers genuinely trained to actively ask whether anyone else is present, not assuming the patient is alone? — Real, active inquiry, not an assumption based on who's visible on screen.
Evidence: Provider training on third-party presence inquiry
2. Is specific consent genuinely obtained and documented before discussing sensitive information with a third party present? — Real, documented consent, not proceeding without confirming the patient is comfortable being overheard.
Evidence: Third-party presence consent documentation
3. When a patient is in a public location, does the provider genuinely address this before continuing with sensitive topics? — Real, active address of the public-location risk, not proceeding as though the setting were private.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Inquiry happens for new patients but isn't consistently repeated for established, ongoing patients. — An established patient's actual circumstances at a given session can genuinely differ from prior visits.
  • Consent is obtained verbally but not consistently documented in a genuinely retrievable way. — Documented consent provides more reliable, real evidence than a verbal exchange alone.
  • Public location risk is addressed when obviously apparent but not consistently for more ambiguous settings.

Implementation plan

When What
Week 1 Review current practice for genuine inquiry about third-party presence at session start.
Week 2 Train providers to actively ask and document consent when a third party is present.
Week 3 Build specific guidance for addressing apparently public patient locations.
Ongoing Extend genuine, repeated inquiry to established, ongoing patients.

How the Monitor verifies this

Method What Detail
OBSERVE Third-party inquiry observation Observes an actual session opening for genuine, active inquiry about anyone else present.
DOCUMENT Consent documentation review Reviews records for genuine, documented consent when a third party is present.
OBSERVE Public location handling observation Observes how a provider genuinely addresses a patient joining from an apparently public location.

Supervisor tips

  • Observe an actual session opening for genuine inquiry about who else might be present. — Direct observation reveals whether this genuinely happens, not an assumption based on stated policy.
  • Ask to see documented consent for a real case where a third party was present. — A real, specific record reveals genuine practice, not policy language alone.

Evidence base

[27] Established health privacy guidance specifically requires recorded consent before continuing a consultation when a translator, caregiver, or family member is present, or when the patient is in a public location where the conversation may be overheard, reflecting the genuine risk of an unseen third party during a telehealth session.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

6.3

Session Recording Follows a Clear, Specific Policy

Non-Negotiable

Session recording follows a clear, specific, documented policy — whether recording ever occurs, under what circumstances, where recordings are stored, and how long they're retained — not left ambiguous, given real, documented gaps in this area leave both providers and patients genuinely uncertain and uncomfortable.

In plain terms: There is a written policy on whether sessions are ever recorded, when, by whom, with what consent, how stored, and who can access — and it is followed. Patients are told.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

A recorded consultation is a permanent record of the most private conversation a person may have. Recording without consent is illegal in many jurisdictions and unethical everywhere. Recording with consent creates obligations: secure storage, defined retention, controlled access, and the patient's right to a copy or deletion. The policy may be 'never'; that is legitimate and simple. If recording is permitted for any purpose — quality, training, clinical — every element must be specified, consent must be explicit and revocable, and the platform's own recording settings must match the policy. Patients must also be told that they may not record without consent.

What good looks like

  • A clear, specific, documented recording policy genuinely exists.
  • The policy specifically addresses storage location and retention duration.
  • Patients are genuinely, specifically informed about recording before it happens.

Common failure modes

  • No clear policy exists; practice is left to individual provider discretion.
  • The policy is silent on storage location or retention duration.
  • Recording occurs without the patient's genuine, prior knowledge.

Worked example

In practice
A telemedicine service whose video platform had recording enabled by default.
BeforeSessions were being recorded automatically to the vendor's cloud. Nobody had decided this; it was the default setting. Patients did not know. Nobody knew who could access the recordings or how long they were kept.
ActionThe service decided: no routine recording. The platform's recording was disabled at the admin level. A written policy states recording occurs only for defined clinical purposes with the patient's explicit written consent per recording, stored in the encrypted record system, retained per the records policy, accessible to the treating clinician only. Patients are told at intake that sessions are not recorded and that they may not record. Historical recordings were deleted with documentation.
AfterThe Monitor reviewed the policy, the platform's admin settings (recording disabled), intake materials, and the deletion record. Verified.

If you are starting from zero — do this first

  1. Check your platform's recording settings right now.
  2. Decide: never, or under what exact conditions?
  3. Write the policy and configure the platform to match.
  4. Tell patients.
The most common mistake: Not knowing whether the platform is recording — check the default.

Self-assessment questions

1. Does the service have a clear, specific, documented policy on whether and when sessions are recorded? — A real, specific written policy, not ambiguity left for individual providers to navigate independently.
Evidence: Session recording policy documentation
2. Does this policy genuinely address storage location and retention duration for any recordings that are made? — Real, specific storage and retention detail, not a policy silent on what happens to a recording after the session.
Evidence: N/A — tested directly
3. Are patients genuinely, specifically informed whether their session is being recorded, before it happens? — Real, prior, specific notification, not recording occurring without the patient's genuine knowledge.
Evidence: Patient recording notification record

Common reasons for a PARTIAL answer

  • A policy exists for standard consultations but isn't specifically addressed for group or family sessions. — Every session type deserves the same genuine policy clarity, not standard consultations alone.
  • Storage location is specified but retention duration isn't clearly, specifically defined. — Both elements genuinely matter to a patient's real understanding of what happens to their recorded information.
  • Notification happens but isn't consistently documented as genuinely occurring before recording begins.

Implementation plan

When What
Week 1 Review current recording practice for genuine, specific policy clarity.
Week 2 Build a clear, documented policy addressing whether, when, storage, and retention.
Week 3 Establish consistent, documented patient notification before any recording.
Ongoing Extend policy clarity to all session types, not standard consultations alone.

How the Monitor verifies this

Method What Detail
DOCUMENT Policy documentation review Reviews the actual, specific, documented recording policy.
DOCUMENT Storage and retention review Reviews whether the policy specifically addresses storage location and retention duration.
OBSERVE Patient notification observation Observes whether patients are genuinely, specifically informed about recording before it occurs.

Supervisor tips

  • Ask to see the actual, written recording policy, not a general assurance recording is handled appropriately. — A specific, real document reveals genuine clarity, not assumed adequacy.
  • Ask a provider directly what the specific retention period is for a session recording. — A specific, confident answer reveals genuine, clear policy, not individual discretion.

Evidence base

[28] Practitioners often lack clear guidance on whether and how to record telehealth sessions, creating genuine ambiguity and discomfort for both provider and patient, establishing a clear, specific, documented recording policy as necessary to close this documented gap.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

6.4

The Provider's Own Home Office Meets the Same Privacy Standard

Non-Negotiable

A provider conducting sessions from a home office genuinely meets the same privacy and security standard as a clinical setting would — device encryption, a secure network, genuine physical privacy from others in the household — not treated as a lower-scrutiny environment simply because it's the provider's own home.

In plain terms: A provider working from home has a private room, a secure device, a secure network, no one who can overhear, and the same data protection as an office — verified, not assumed.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

The provider joins from the kitchen table while family passes through. Their laptop is shared with a teenager. The Wi-Fi is the neighbour's. Papers with patient names are on the desk. The home office is the weakest link in telemedicine security and the least examined. The standard is the same as a clinical office: a private room with a closed door; a work-only device with encryption and MFA; a secure network (not public Wi-Fi, ideally VPN); no patient information visible or audible to others; a clean desk; a screen lock. The service verifies this — by attestation at minimum, by inspection where practical — and provides what the provider needs.

What good looks like

  • Provider devices are genuinely, verifiably encrypted.
  • Home network security is genuinely, specifically verified.
  • Providers genuinely have real physical privacy during sessions.

Common failure modes

  • Device encryption is assumed adequate without genuine verification.
  • Home network security is unexamined, not specifically verified.
  • Physical privacy is assumed from a designated space without genuine confirmation.

Worked example

In practice
A telemedicine service with 12 providers all working from home.
BeforeProviders used their own laptops, some shared with family. Two worked from shared living spaces. One used a cafe's Wi-Fi occasionally. No standard existed; no verification was done. A provider's child appeared on camera during a session and could be heard commenting.
ActionA home office standard was written with the same requirements as the clinical office. The service issued managed work devices with encryption, MFA, and remote wipe. A VPN is mandatory. Each provider completed a home office self-assessment and a video walkthrough with the compliance lead. Non-compliant setups were remediated (a door lock, a privacy screen, a headset). Annual re-attestation.
AfterThe Monitor reviewed the standard, 12 completed self-assessments with walkthrough sign-off, the device management record, and the VPN enforcement configuration. Verified.

If you are starting from zero — do this first

  1. Ask each provider: private room? Work-only device? Secure network? Anyone who can overhear?
  2. Write the home office standard.
  3. Issue managed devices and require VPN.
  4. Verify each setup by video walkthrough.
The most common mistake: Assuming the provider's home is as secure as the office because the provider is a professional.

Self-assessment questions

1. Is the provider's device for conducting sessions genuinely encrypted, not assumed adequate without verification? — Real, verified device encryption, not an assumption based on the device being personally owned and trusted.
Evidence: Provider device encryption verification
2. Is the provider's home network genuinely secure, specifically verified, not assumed adequate? — Real, verified network security, not an unexamined assumption about home network safety.
Evidence: Home network security verification
3. Does the provider genuinely have physical privacy from others in the household during a session? — Real, verified physical privacy, not an assumption based on having a designated home office space.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Device encryption is verified for provider-issued equipment but not for personally owned devices also used for sessions. — Every device genuinely used to access patient information deserves the same verification, regardless of ownership.
  • Network security is addressed at initial setup but not periodically reconfirmed as home network configurations can change. — A home network's real security can change over time, and periodic reconfirmation reflects this reality.
  • Physical privacy is generally adequate but hasn't been specifically confirmed for providers sharing a household with others working or studying at home.

Implementation plan

When What
Week 1 Review current home office privacy and security for genuine verification versus assumed adequacy.
Week 2 Verify encryption for every device genuinely used to conduct sessions, regardless of ownership.
Week 3 Confirm home network security and genuine physical privacy for every provider.
Ongoing Periodically reconfirm home office security as configurations may change.

How the Monitor verifies this

Method What Detail
DOCUMENT Device encryption review Reviews evidence of genuine, verified encryption for devices used to conduct sessions.
DOCUMENT Network security review Reviews evidence of genuine, verified home network security.
ASK Physical privacy interview Asks a provider to describe their actual physical privacy setup during sessions.

Supervisor tips

  • Ask a provider to describe their actual home office setup, including device and network security. — A specific, confident answer reveals genuine attention, not an assumption of adequacy.
  • Ask specifically about physical privacy for a provider sharing a household with others. — This reveals whether genuine privacy has been confirmed, not assumed from a general home office description.

Evidence base

[29] Many clinicians continue conducting sessions from home offices with unencrypted devices and storing session recordings in personal cloud storage, having never completed the compliance transition required since temporary pandemic-era enforcement discretion ended, establishing the provider's home office as a genuine, distinct privacy compliance layer separate from platform security.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

6.5

Substance Use Disorder Records Follow the Heightened, Distinct Confidentiality Standard

Non-Negotiable

Records related to substance use disorder treatment genuinely follow the specific, heightened confidentiality standard that applies to them — requiring the patient's own written consent for disclosure — not treated identically to general health information under standard confidentiality practice.

In plain terms: Records of substance use disorder treatment follow the separate, stricter confidentiality rules that apply to them — separate consent, restricted sharing, no disclosure without specific authorisation.

Facility category Crisis Transition Small Standard
Applicability Full Full Adapted Full

Why this matters

In many jurisdictions, substance use disorder treatment records have a higher confidentiality standard than general health records (42 CFR Part 2 in the US, equivalents elsewhere): they cannot be shared even with other treating providers without specific written consent; they cannot be used in legal proceedings without a court order; they must be segregated or flagged; breaches carry distinct penalties. A telemedicine service that stores SUD records alongside general records with the same access and sharing rules is violating the higher standard. The service must know the rule, identify SUD records, and apply the stricter regime.

What good looks like

  • Substance use disorder records genuinely follow the specific, heightened standard.
  • Disclosure is genuinely based on the patient's own specific written consent.
  • Staff are specifically trained on this distinct standard, not assuming general practice suffices.

Common failure modes

  • These records are treated identically to general health information.
  • Disclosure relies on a general release, not specific written consent for this category.
  • Staff aren't specifically trained; general health privacy knowledge is assumed sufficient.

Worked example

In practice
A telemedicine service providing addiction treatment alongside general mental health.
BeforeSUD treatment records were in the same system with the same access as all records. Records had been shared with primary care providers under the general consent. Staff were unaware of the distinct standard.
ActionThe compliance lead identified the applicable SUD confidentiality regulation. SUD records were flagged in the system with restricted access to the treating team. A separate SUD-specific consent form was introduced for any disclosure, naming the recipient and purpose. Disclosures without it are blocked. Staff completed training on the distinct standard. Historical disclosures were reviewed and patients notified where required.
AfterThe Monitor reviewed the flagged record configuration, the SUD-specific consent form, training records, and the disclosure log with specific consents. Verified.

If you are starting from zero — do this first

  1. Find the SUD confidentiality regulation for your jurisdiction.
  2. Identify and flag every SUD treatment record.
  3. Introduce a separate SUD disclosure consent.
  4. Train staff on the difference.
The most common mistake: Sharing SUD records under the general health consent — SUD records need their own.

Self-assessment questions

1. Do substance use disorder records genuinely follow this distinct, heightened confidentiality standard? — Real adherence to this distinct standard, not treated identically to general health information.
Evidence: SUD-specific confidentiality protocol documentation
2. Is disclosure genuinely based on the patient's own specific written consent, not a general release? — Real, specific written consent for this category, not a general release assumed sufficient.
Evidence: Patient written consent for SUD record disclosure
3. Are staff specifically trained on this distinct standard, not assuming general health privacy training suffices? — Real, specific training, not an assumption of general confidentiality knowledge.
Evidence: Staff training on substance use disorder confidentiality standard

Common reasons for a PARTIAL answer

  • The distinct standard is understood by clinical staff but not consistently by administrative staff who may handle these records. — Every staff member with access to these specific records deserves the same genuine understanding of this heightened standard.
  • Written consent is obtained but doesn't specifically distinguish this category from general information release consent. — Genuine compliance requires consent language specifically reflecting this distinct, heightened requirement.
  • The standard is applied for direct SUD treatment records but not consistently for related information in a broader clinical note.

Implementation plan

When What
Week 1 Review current handling of substance use disorder records for genuine adherence to the distinct standard.
Week 2 Establish specific written consent language distinguishing this category from general release.
Week 3 Train all staff with potential record access, not clinical staff alone, on this heightened standard.
Ongoing Audit handling of related information within broader clinical notes for consistent application.

How the Monitor verifies this

Method What Detail
DOCUMENT SUD protocol review Reviews evidence that substance use disorder records genuinely follow the distinct, heightened standard.
DOCUMENT Written consent review Reviews documentation confirming disclosure is based on genuine, specific patient written consent.
DOCUMENT Staff training review Reviews training records confirming staff are specifically educated on this distinct standard.

Supervisor tips

  • Ask an administrative staff member whether they're aware of the distinct standard for these specific records. — This reveals whether genuine understanding extends beyond clinical staff alone.
  • Ask to see the actual, specific written consent language used for this category of disclosure. — A real, specific document reveals genuine compliance, not an assumption general consent suffices.

Evidence base

[30] Multiple countries' health privacy frameworks specifically establish heightened confidentiality protections for substance use disorder or addiction treatment records, distinct from general health information privacy practice, often requiring the patient's own specific consent for disclosure.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

© 2026 Accréditation Sans Frontières · PHIG · Sheni Network