Skip to main content
Article Last Updated 04/16/2026

Article Reviewed by a licensed insurance professional: Sam Meenasian (CA dept of insurance license #0F75955).

Estimated reading time: 5 minutes

For many employers, remote and hybrid work are now ongoing operating models, not short-term exceptions. NCCI describes remote work as a major and durable shift in the U.S. work environment, and federal guidance continues to address telework as a standing model for wage-hour compliance, accommodations, safety, and security.

That means employers should stop treating remote work as an informal arrangement. If your policy has not been materially updated since the early pandemic years, it may no longer match current risk. A current remote work policy should address who may work remotely, where they may work, how time is recorded, what technology is allowed, how injuries and incidents are reported, and how insurance and reimbursement issues are handled.

Apply existing policies to remote employees

Remote employees should remain subject to the same confidentiality, acceptable-use, anti-harassment, records retention, code of conduct, and customer information rules that apply in the office. Your policy should say that clearly and require a written acknowledgment. FTC guidance specifically says security policies should cover employees who telecommute or access sensitive data from home or another offsite location.

Define eligibility and approved work locations

Not every job should be remote eligible. Define eligibility based on job duties, supervision needs, service standards, security requirements, and performance history. The policy should also require approval before an employee works from a new state or another unapproved location, because state labor rules can vary significantly, including minimum wage, overtime, and reimbursement requirements.

Set clear availability and timekeeping rules

Expectations about availability, meetings, response times, and core working hours should be documented. For nonexempt employees, the policy should require accurate daily timekeeping and prior approval for overtime, but it must also state that all time actually worked must be reported and paid. DOL guidance makes clear that remote employees must be paid for work the employer knows or should know is being performed, including work not requested but suffered or permitted. DOL also states that short breaks of 20 minutes or less are compensable, while unpaid meal periods generally require the employee to be fully relieved of duty.

Address data security, AI use, and personal devices

Data security is one of the largest remote work risks. Company-managed devices are the safest default. If you allow personal devices, require written approval, MFA, encryption, screen-locks, current patches, approved apps, secure home Wi-Fi, and immediate reporting of lost or compromised devices. FTC recommends secure remote access controls, MFA, WPA2 or WPA3 home network protection, and vendor contract security provisions. NIST warns that BYOD creates unique security and privacy challenges. NIST also says organizations should manage the unique risks posed by generative AI, so your policy should prohibit entering confidential, customer, employee, regulated, or privileged information into unapproved AI tools.

Spell out equipment and expense reimbursement

List exactly what equipment the company provides, who maintains it, what the employee must return at separation, and which costs are reimbursable. Under federal law, employer-benefit expenses generally cannot reduce required minimum wage or overtime pay. Some states impose broader reimbursement obligations. California and Illinois are two clear examples. That means remote work stipends, internet costs, phone use, and other expenses should be reviewed by state and by job type instead of handled with a one-size-fits-all rule.

Handle safety and injury reporting carefully

Employers should not overstate their responsibility for employees’ home offices. OSHA says it will not inspect employees’ home offices, does not expect employers to inspect them, and will not hold employers liable for employees’ home offices. At the same time, employers can remain responsible for hazards caused by materials, equipment, or work processes they provide or require, and some home injuries can still be work-related when the employee is performing paid work and the injury is directly related to that work. A good policy should require a designated workspace, a safety self-certification, prompt reporting of any injury, and clear procedures for incident investigation.

Include an accommodation process

A remote work policy should make clear that disability-related requests are handled separately through the interactive accommodation process. EEOC states that the ADA does not require every employer to offer telework as a general program. But telework can be a reasonable accommodation in some cases, even when the employer does not broadly allow remote work, if the employee can perform essential functions remotely and the arrangement does not create undue hardship.

Train employees and post notices correctly

A written policy is not enough by itself. Train employees on timekeeping, after-hours work, safe remote access, AI rules, incident reporting, and equipment handling. If your workforce is fully remote, some federal labor notices can be posted electronically, but DOL says that approach works only when employees exclusively work remotely, customarily receive information electronically, and can readily access the postings at all times.

Review insurance before a claim happens

Remote work changes the insurance conversation. At a minimum, employers should review workers’ compensation, cyber liability, off-premises business property, and any applicable professional liability exposures with their broker. NAIC notes that business-related property losses or liability exposures are typically excluded from a traditional homeowners policy and may require business coverage, and it specifically advises telecommuters to confirm workers’ compensation crossover to the home office. The FTC recommends cyber insurance that addresses first-party and third-party losses, vendor breaches, business interruption, forensic support, defense, and regulatory response.

Remote work is not inherently unmanageable. But informal rules, outdated handbooks, and vague insurance assumptions create avoidable claims and coverage gaps. If your current policy still reads like a temporary pandemic exception, it is time to update it with input from HR, IT, payroll, legal, and your insurance advisor.

Sam Meenasian

Sam Meenasian is the Operations Director of USA Business Insurance and an expert in commercial lines insurance products. With over 20 years of experience and knowledge in the commercial insurance industry, Meenasian contributes his level of expertise as a leader and an agent to educate and secure online business insurance for thousands of clients within the Insurance family. CA dept of insurance license #0F75955