Do I Need a BAA With My Therapy Video Vendor? HIPAA Telehealth Compliance Guide

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Do I Need a BAA With My Therapy Video Vendor? HIPAA Telehealth Compliance Guide

Kevin Henry

HIPAA

July 29, 2026

8 minutes read
Share this article
Do I Need a BAA With My Therapy Video Vendor? HIPAA Telehealth Compliance Guide

Understanding Business Associate Agreements

If you are a HIPAA-covered entity providing teletherapy, you almost always need a Business Associate Agreement (BAA) with your video vendor. A business associate is any third party that creates, receives, maintains, or transmits Protected Health Information (PHI) on your behalf.

A BAA is a contract that binds the vendor to safeguard Protected Health Information (PHI), restrict use and disclosure, and support your compliance duties. Without an executed BAA, using a vendor for care delivery can expose you to HIPAA violations, even if the platform markets itself as “secure.”

What a compliant BAA should cover

  • Permitted and prohibited uses/disclosures of PHI, including de-identification and analytics language.
  • Administrative, physical, and technical safeguards aligned to the Security Rule and Telehealth encryption requirements.
  • Breach and security incident notification duties, including timelines and required details.
  • Flow-down of obligations to subcontractors and clear restrictions on offshore processing, if relevant.
  • Right to terminate, return, or destroy PHI upon contract end; provisions for data portability and retention.
  • Support for investigations, including access required during a HIPAA compliance audit.

When you do and do not need a BAA

You need a BAA if the vendor can access or store ePHI, including meeting metadata, chat logs, recordings, or support tickets containing PHI. The narrow “conduit” exception rarely applies to modern video services. When in doubt, obtain a signed BAA before using the platform for therapy.

Identifying HIPAA-Compliant Platforms

“HIPAA-compliant” is not a product label you can take on faith. A platform becomes suitable only when it will enter into a BAA and provides controls that let you meet the Security Rule. Marketing claims without a signed BAA are insufficient for telehealth.

Must-have capabilities to look for

  • Encryption in transit (e.g., modern TLS) and, where applicable, encryption at rest using strong ciphers.
  • Unique user authentication, role-based access, session timeouts, and multifactor authentication options.
  • Audit logs for user access, device info, admin actions, and PHI-relevant events.
  • Configurable meeting controls: waiting rooms, host admission, passcodes, and screen-share restrictions.
  • Data handling transparency: where data resides, what is stored, who can access it, and retention defaults.
  • Willingness to sign and honor a Business Associate Agreement that matches your practice needs.

Common platform categories

  • Dedicated telehealth platforms built for behavioral health that routinely sign BAAs.
  • Enterprise versions of general video tools that offer a BAA on healthcare or business plans.
  • EHR-embedded video modules covered under your EHR vendor’s existing BAA.

Free or consumer-grade tiers rarely include a BAA. Confirm the plan level, features, and contract terms in writing before seeing clients.

Evaluating Video Vendors

Treat selection as Vendor risk management, not just a feature comparison. Your goal is to reduce legal, security, and clinical risk while maintaining a smooth client experience.

Due diligence checklist

  • Security documentation: risk assessments, penetration testing summaries, and any independent attestations (e.g., SOC 2 Type II, HITRUST).
  • Privacy posture: how PHI is used, whether analytics or de-identification occur, and limits on marketing.
  • BAA terms: breach notification timelines, subcontractor governance, data return/destruction, and indemnification.
  • Access controls: SSO/MFA support, role-based permissions, and device/session management capabilities.
  • Logging and audit: exportable logs, admin alerts, and evidence you can use during a HIPAA compliance audit.
  • Operations: uptime SLAs, customer support, incident response maturity, and clear escalation paths.
  • Data lifecycle: retention controls for recordings, chat transcripts, and files; ability to disable storage by default.
  • Financial and contract terms: total cost of ownership, termination rights, and data portability safeguards.

BAA red flags

  • Language granting the vendor broad rights to use PHI for product development or advertising.
  • Delayed or vague breach notification obligations.
  • No commitment to flow-down BAA duties to subcontractors or to disclose them.
  • Unclear data deletion practices upon termination.

Implementing Telehealth Security Measures

Technology alone does not make you compliant. Pair your vendor’s controls with your own safeguards to protect client privacy and maintain continuity of care.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Configuration best practices

  • Require MFA for all staff with admin or scheduling privileges; disable shared accounts.
  • Use waiting rooms and host admission; lock sessions after the client joins.
  • Mandate unique meeting links and passcodes; avoid personal meeting IDs for clinical sessions.
  • Disable cloud recordings by default; if needed, store recordings only in BAA-covered, encrypted locations with strict retention.
  • Restrict screen sharing to the host; disable file transfer and chat retention unless clinically necessary.
  • Turn on audit logging and set alerts for anomalous logins and downloads.

Device and network hygiene

  • Maintain updated OS, browsers, and telehealth apps; enable full-disk encryption on clinician devices.
  • Use privacy filters, secure Wi‑Fi, and dedicated work profiles; prohibit family members from using work devices.
  • Adopt a documented patching cadence and endpoint protection; back up critical data regularly.

Operational safeguards

  • Complete a formal Security Risk Analysis and implement risk management plans.
  • Train staff on PHI handling, social engineering, and telehealth etiquette (e.g., verifying identity, scanning the room).
  • Maintain a contingency plan for outages, including telephone backup and emergency contact workflows.

Informed consent for telehealth is essential. Explain how the service works, the benefits and risks, and how PHI will be protected on the chosen platform.

Elements to include

  • Nature of teletherapy, potential technology failures, and privacy limitations outside your office setting.
  • How you secure sessions, whether any data is stored, and how long you retain it.
  • Client responsibilities: private location, secure devices, and not recording sessions without agreement.
  • Emergency procedures and client location requirements for crisis support and licensure boundaries.
  • Alternatives to telehealth, the right to withdraw consent, and how to file concerns.

Managing PHI in Teletherapy

Use the minimum necessary PHI during scheduling and sessions. Document care in your designated record system, and separate psychotherapy notes when appropriate.

Recordings, chat, and file sharing

  • Treat any recording or transcript as PHI; capture only when clinically necessary and with explicit consent.
  • Disable auto-transcription and chat retention unless you have a defined purpose and policy.
  • Store any artifacts solely in BAA-covered, encrypted repositories with clearly defined retention and disposal.

Access, amendments, and disclosures

  • Honor client rights to access and request amendments through secure channels.
  • Log and justify all disclosures; apply the minimum necessary standard to each.
  • Prepare breach response playbooks, including risk assessment, notification steps, and documentation templates.

Staying Current with HIPAA Enforcement

HIPAA is enforced by the Office for Civil Rights (OCR). Enforcement actions frequently cite missing BAAs, inadequate risk analyses, and weak access controls—issues common to telehealth if left unmanaged.

Practical maintenance cadence

  • Quarterly: review vendor settings, audit logs, access lists, and residual data (recordings, chat).
  • Semiannually: refresh staff training and run a tabletop exercise for a telehealth security incident.
  • Annually: complete a Security Risk Analysis, review all BAAs, and update policies based on new guidance.
  • Ongoing: monitor platform release notes and OCR guidance that affect Telehealth encryption requirements or privacy practices.

Conclusion

Yes—you generally need a signed Business Associate Agreement with your therapy video vendor. Choose a platform that will execute a BAA, supports robust security controls, and fits your workflow. Then reinforce it with sound configuration, informed consent, disciplined PHI handling, and periodic reviews aligned to OCR enforcement trends.

FAQs.

What is a BAA and why is it necessary for therapy video vendors?

A BAA is a contract requiring a vendor to safeguard PHI, limit its use, report incidents, and support your HIPAA obligations. Because video vendors transmit or may store PHI (e.g., metadata, chat, recordings, or support content), they are business associates; using them for care without a BAA risks noncompliance.

Which video platforms provide a valid BAA for telehealth?

Vendors that support healthcare use typically offer a BAA on paid healthcare or enterprise plans, including dedicated telehealth platforms, enterprise editions of general videoconferencing tools, and EHR-embedded video modules. Always verify the current plan requirements and obtain an executed BAA before delivering therapy.

Can I use free video platforms like Zoom or FaceTime for HIPAA-compliant therapy?

Usually no. Consumer or free tiers rarely include a BAA, and without a signed BAA you should not use the service for PHI. If a vendor offers a healthcare or enterprise plan with a BAA, upgrade first and confirm configuration and policies before seeing clients.

What additional steps must I take besides obtaining a BAA for telehealth compliance?

Complete a Security Risk Analysis, configure strong access and meeting controls, train staff, document informed consent, manage recordings and transcripts carefully, and monitor logs and vendor changes. Treat selection and oversight as ongoing Vendor risk management, and be prepared for a HIPAA compliance audit if one occurs.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles