HIPAA Compliance in the Telehealth Era: What’s Changed and What Hasn’t

The Enforcement Discretion Is Over

During COVID, OCR issued a blanket enforcement discretion notice allowing providers to use non-HIPAA-compliant telehealth platforms without penalty. That discretion ended in May 2023.

Since then, OCR has signaled through formal guidance and enforcement actions that telehealth HIPAA compliance is a priority. Providers still using consumer-grade platforms like standard Zoom, FaceTime, or Google Hangouts for telehealth without a Business Associate Agreement are exposed to enforcement risk.

The pandemic created habits. Breaking those habits before OCR comes calling is the compliance challenge of 2026.

Business Associate Agreements for Telehealth Platforms

Every telehealth platform that transmits, stores, or processes protected health information is a business associate under HIPAA. That includes the video platform, the scheduling system, the secure messaging tool, and any cloud storage where visit recordings or documentation reside.

Each of these vendors must have a signed BAA with your organization. The BAA must address how PHI is encrypted in transit and at rest, the vendor’s breach notification obligations, what happens to PHI when the contract terminates, and the vendor’s obligations for cooperating with investigations.

A common gap: practices have a BAA with their primary telehealth platform but not with the transcription service, the AI clinical documentation tool, or the patient engagement app that sends appointment reminders. Each of these touches PHI and requires a BAA.

What Hasn’t Changed: The Security Rule Still Applies

The HIPAA Security Rule requirements predate telehealth and apply regardless of the delivery modality. What changes with telehealth is the attack surface.

Providers conducting visits from home offices face risks that don’t exist in a clinical setting. An unsecured home Wi-Fi network, a shared family computer, or a conversation overheard by household members all create potential violations.

The Security Rule requires that covered entities conduct a risk analysis that accounts for telehealth-specific risks, implement technical safeguards including encryption and access controls for all devices used for telehealth, establish physical safeguards for remote work environments, and train workforce members on telehealth-specific privacy and security practices.

These requirements aren’t new. But the expanded telehealth footprint means they apply to more devices, more locations, and more workforce members than before.

Patient Consent and Telehealth Recording

State laws govern whether telehealth visits can be recorded and what consent is required. This is separate from HIPAA and adds a layer of complexity for practices operating across state lines.

Some states require all-party consent for recording any conversation, including telehealth visits. Others allow single-party consent. Some states have specific telehealth consent requirements that go beyond general recording laws.

AI-powered clinical documentation tools that listen to the visit and generate notes are functionally recording the encounter. Even if the recording isn’t stored permanently, the act of processing the audio through an AI system may trigger recording consent requirements.

Before deploying any AI documentation or visit recording technology, verify the consent requirements in every state where you treat patients. And document that consent in a way that’s defensible if challenged.

Building a Telehealth Compliance Checklist

Every organization offering telehealth should maintain a compliance checklist that covers the following areas.

Platform compliance: BAAs in place with all vendors, encryption verified, access controls configured. Provider requirements: HIPAA training completed, secure workspace standards documented, multi-factor authentication enabled on all telehealth devices. Patient-facing requirements: informed consent obtained, state-specific recording consent addressed, notice of privacy practices updated for telehealth.

Operational controls: access logs reviewed monthly, incident response plan updated for telehealth-specific scenarios, and regular penetration testing of telehealth infrastructure.

The organizations that treat telehealth HIPAA compliance as a one-time project will eventually face an OCR investigation. The ones that build it into ongoing operations will be ready when that day comes.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Nexwell Health Partners provides management services, telehealth solutions, and compliance support for safety-net hospitals, FQHCs, and specialty practices. Contact us to schedule a consultation.

Sources

  1. HHS Notice on HIPAA Enforcement Discretion Expiration
  2. CMS Telehealth Policy Updates
  3. CMS Telehealth FAQ (Updated Feb 2026)