Remote coder in a shared apartment
PE-17 rules require privacy screen, headset for dictation, and no paper charts left on the kitchen table; manager attests quarterly.
PE-17 requires employing organization-defined security controls at alternate work sites, assessing such sites as needed, and providing a means for employees to communicate with information security personnel about security issues. Telehealth clinicians, remote coders, and hybrid admins process ePHI outside the facility — PE-17 extends physical and environmental expectations to those sites without pretending every home is a data center.
Define, communicate, and verify appropriate security controls for alternate work sites where ePHI is accessed, and give remote workforce a clear path to report security issues.
How this control shows up in healthcare and HIPAA-covered environments.
PE-17 rules require privacy screen, headset for dictation, and no paper charts left on the kitchen table; manager attests quarterly.
Policy prohibits public Wi-Fi without org VPN and visual privacy; access attempt from risky network triggers coaching.
Incident reported via the PE-17 security contact path; printing entitlement removed for that role.
Hybrid work is normal; assessors expect documented alternate-site safeguards — not only facility badge controls under PE-2/PE-3.
How this NIST control supports HIPAA Security Rule expectations.
Not usually — define risk-based assessments and mandatory self-attestations; inspect or interview higher-risk roles as needed.
AC-19 focuses on mobile device controls; PE-17 focuses on the alternate site environment and associated physical/procedural safeguards.
Yes — contingency relocation sites should meet PE-17/CP physical security expectations.
Related controls that commonly accompany PE-17.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.