Article Reviewed by a licensed insurance professional: Sam Meenasian (CA dept of insurance license #0F75955).
Estimated reading time: 5 minutes
For many employers, remote and hybrid work are now ongoing operating models, not short-term exceptions. NCCI describes remote work as a major and durable shift in the U.S. work environment, and federal guidance continues to address telework as a standing model for wage-hour compliance, accommodations, safety, and security.
That means employers should stop treating remote work as an informal arrangement. If your policy has not been materially updated since the early pandemic years, it may no longer match current risk. A current remote work policy should address who may work remotely, where they may work, how time is recorded, what technology is allowed, how injuries and incidents are reported, and how insurance and reimbursement issues are handled.
Apply existing policies to remote employees
Remote employees should remain subject to the same confidentiality, acceptable-use, anti-harassment, records retention, code of conduct, and customer information rules that apply in the office. Your policy should say that clearly and require a written acknowledgment. FTC guidance specifically says security policies should cover employees who telecommute or access sensitive data from home or another offsite location.
Define eligibility and approved work locations
Not every job should be remote eligible. Define eligibility based on job duties, supervision needs, service standards, security requirements, and performance history. The policy should also require approval before an employee works from a new state or another unapproved location, because state labor rules can vary significantly, including minimum wage, overtime, and reimbursement requirements.
Set clear availability and timekeeping rules
Expectations about availability, meetings, response times, and core working hours should be documented. For nonexempt employees, the policy should require accurate daily timekeeping and prior approval for overtime, but it must also state that all time actually worked must be reported and paid. DOL guidance makes clear that remote employees must be paid for work the employer knows or should know is being performed, including work not requested but suffered or permitted. DOL also states that short breaks of 20 minutes or less are compensable, while unpaid meal periods generally require the employee to be fully relieved of duty.
Address data security, AI use, and personal devices
Data security is one of the largest remote work risks. Company-managed devices are the safest default. If you allow personal devices, require written approval, MFA, encryption, screen-locks, current patches, approved apps, secure home Wi-Fi, and immediate reporting of lost or compromised devices. FTC recommends secure remote access controls, MFA, WPA2 or WPA3 home network protection, and vendor contract security provisions. NIST warns that BYOD creates unique security and privacy challenges. NIST also says organizations should manage the unique risks posed by generative AI, so your policy should prohibit entering confidential, customer, employee, regulated, or privileged information into unapproved AI tools.
Spell out equipment and expense reimbursement
List exactly what equipment the company provides, who maintains it, what the employee must return at separation, and which costs are reimbursable. Under federal law, employer-benefit expenses generally cannot reduce required minimum wage or overtime pay. Some states impose broader reimbursement obligations. California and Illinois are two clear examples. That means remote work stipends, internet costs, phone use, and other expenses should be reviewed by state and by job type instead of handled with a one-size-fits-all rule.
Handle safety and injury reporting carefully
Employers should not overstate their responsibility for employees’ home offices. OSHA says it will not inspect employees’ home offices, does not expect employers to inspect them, and will not hold employers liable for employees’ home offices. At the same time, employers can remain responsible for hazards caused by materials, equipment, or work processes they provide or require, and some home injuries can still be work-related when the employee is performing paid work and the injury is directly related to that work. A good policy should require a designated workspace, a safety self-certification, prompt reporting of any injury, and clear procedures for incident investigation.
Include an accommodation process
A remote work policy should make clear that disability-related requests are handled separately through the interactive accommodation process. EEOC states that the ADA does not require every employer to offer telework as a general program. But telework can be a reasonable accommodation in some cases, even when the employer does not broadly allow remote work, if the employee can perform essential functions remotely and the arrangement does not create undue hardship.
Train employees and post notices correctly
A written policy is not enough by itself. Train employees on timekeeping, after-hours work, safe remote access, AI rules, incident reporting, and equipment handling. If your workforce is fully remote, some federal labor notices can be posted electronically, but DOL says that approach works only when employees exclusively work remotely, customarily receive information electronically, and can readily access the postings at all times.
Review insurance before a claim happens
Remote work changes the insurance conversation. At a minimum, employers should review workers’ compensation, cyber liability, off-premises business property, and any applicable professional liability exposures with their broker. NAIC notes that business-related property losses or liability exposures are typically excluded from a traditional homeowners policy and may require business coverage, and it specifically advises telecommuters to confirm workers’ compensation crossover to the home office. The FTC recommends cyber insurance that addresses first-party and third-party losses, vendor breaches, business interruption, forensic support, defense, and regulatory response.
Remote work is not inherently unmanageable. But informal rules, outdated handbooks, and vague insurance assumptions create avoidable claims and coverage gaps. If your current policy still reads like a temporary pandemic exception, it is time to update it with input from HR, IT, payroll, legal, and your insurance advisor.











