HIPAA Audit Checklist for Telehealth Platforms: Identify BAA Coverage Gaps

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Checklist for Telehealth Platforms: Identify BAA Coverage Gaps

Kevin Henry

HIPAA

September 23, 2026

8 minutes read
Share this article
HIPAA Audit Checklist for Telehealth Platforms: Identify BAA Coverage Gaps

This audit checklist helps you evaluate how your telehealth platform protects Protected Health Information and pinpoints Business Associate Agreement coverage gaps before they lead to risk. Use it to verify safeguards, prove Audit Trail Compliance, and strengthen Breach Notification Requirements across your ecosystem.

Business Associate Agreement Verification

Confirm that every entity creating, receiving, maintaining, or transmitting PHI on your behalf has an executed Business Associate Agreement. Map data flows first so you can see which services touch PHI during scheduling, intake, video visits, messaging, storage, analytics, and support.

What to verify in each BAA

  • Scope: clear description of services and PHI types covered, including video, chat, recordings, transcripts, backups, and logs.
  • Safeguards: administrative, physical, and technical controls aligned to the Security Rule, including End-to-End Encryption commitments where applicable.
  • Use and disclosure: permitted purposes, minimum necessary, and explicit prohibitions (e.g., analytics or training outside stated purposes).
  • Subcontractors: flow-down obligations requiring subcontractor BAAs and Telehealth Vendor Management expectations.
  • Access, return, and destruction: timely return or secure disposal of PHI at termination; data location and retention limits.
  • Incident reporting: timelines, cooperation duties, forensic support, and Breach Notification Requirements.
  • Audit and monitoring: your right to assess controls, receive evidence, and address deficiencies.

Evidence to collect

  • Executed BAAs with version/date, signatories, and service descriptions.
  • Vendor subprocessor lists and notifications workflow.
  • Data flow diagrams and a coverage matrix mapping PHI to vendors/BAAs.

Common BAA coverage gaps

  • No BAA for embedded SDKs (video, messaging, transcription) or for crash reporting/analytics touching PHI.
  • BAA excludes mobile push notifications, call recordings, or support screen shares where PHI may appear.
  • Missing subcontractor obligations or outdated appendices after new features launched.
  • Vague encryption language that doesn’t commit to in-transit, at-rest, and key management specifics.
  • Termination terms lack data return/destruction detail or omit backup/archive disposition.

Encryption Implementation Review

Validate that encryption protects PHI everywhere it moves or rests. Confirm that what the product team labels “secure” aligns with End-to-End Encryption design claims and that keys are governed, rotated, and auditable.

Controls to test

  • In transit: TLS for APIs and signaling; certificate pinning in mobile apps; perfect forward secrecy; secure cipher suites.
  • At rest: strong encryption for databases, object stores, message queues, and media storage; managed keys with HSM/KMS and rotation.
  • End-to-End Encryption: session-level keys generated on clients for video/chat; server cannot decrypt media; verify participant identity and device trust.
  • Client-side risks: local caches, screenshots, notifications, offline storage, link previews; ensure PHI is not exposed.
  • Key management: separation of duties, access logging, escrow and recovery procedures, and incident response around key compromise.

Typical encryption gaps

  • Video streams only protected hop-by-hop, not end-to-end, despite marketing claims.
  • Attachments stored unencrypted in CDN caches or message thumbnails.
  • Push notification payloads reveal PHI in clear text.

Access Controls Assessment

Ensure only authorized people can reach PHI, with privileges tightly scoped to their duties. Role-Based Access Controls and multi-factor authentication are essential for clinicians, support staff, and administrators.

Key checks

  • Identity and authentication: MFA for workforce; SSO with SCIM provisioning; automated offboarding and access reviews.
  • RBAC design: distinct roles for clinicians, schedulers, billing, and support; break-glass procedures with justification and monitoring.
  • Least privilege: field-level and record-level controls; session timeouts; device posture or network rules for sensitive functions.
  • Patient identity: verified sign-up, recovery safeguards, and controls for proxies/guardians.

Frequent gaps

  • Shared admin accounts or weak MFA coverage for privileged roles.
  • Overbroad support permissions enabling unrestricted PHI views during troubleshooting.
  • No periodic entitlement reviews or stale access after role changes.

Audit Logs Examination

Comprehensive, immutable logging underpins Audit Trail Compliance and helps you detect misuse quickly. You should be able to answer who accessed which PHI, when, from where, and why.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Required events

  • User authentication attempts, MFA challenges, and SSO assertions.
  • PHI reads, edits, exports, downloads, and message/attachment views.
  • Privilege changes, role grants, and configuration updates.
  • API calls by service accounts and integrations.

Retention and integrity

  • Time-synchronized, write-once storage with tamper detection.
  • Retention aligned to policy and legal requirements; secure archives.
  • Alerting for anomalous patterns: bulk exports, after-hours spikes, or high-risk IPs.

Common logging gaps

  • Event logs omit read-only PHI views or attachment previews.
  • No linkage between patient identifiers and access events, complicating investigations.
  • Lack of searchability or dashboards for rapid incident triage.

Vendor BAA Coverage Analysis

Go beyond single contracts and evaluate ecosystem-wide coverage. Effective Telehealth Vendor Management ensures every upstream and downstream party meets your standards.

Steps to complete

  • Inventory vendors by function: video, chat, storage, transcription, AI scribing, e-signature, SMS/email gateways, analytics, support, and hosting.
  • Map PHI flows to each vendor and confirm a Business Associate Agreement exists and matches actual data use.
  • Review subcontractor disclosures, security reports, and incident histories; require remediation plans for gaps.
  • Establish onboarding/offboarding controls: security due diligence, BAA execution, change management, and annual reassessments.

Ecosystem gaps to watch

  • Consumer-grade tools (file sharing, notes, calendars) used with PHI without BAAs.
  • Analytics or APM tools capturing PHI in URLs, headers, or error logs.
  • Transcription or translation services processing recordings outside agreed regions or controls.

Secure Messaging Compliance

Messaging must protect PHI without relying on standard SMS or email. Verify that the platform’s chat, attachments, and notifications meet security and privacy expectations end to end.

Controls and practices

  • Use secure in-app messaging with End-to-End Encryption for message bodies and attachments; disable risky link previews.
  • Positive identity binding for patients and clinicians; prevent message forwarding and enable remote wipe.
  • Retention policy aligned to clinical and legal needs; export controls with explicit authorization.
  • Gateway configuration so SMS/email notifications never include PHI; ensure BAAs with any gateways in use.

Typical messaging gaps

  • PHI in notification previews or email summaries.
  • Unrestricted downloads to unmanaged devices without DLP safeguards.
  • No audit events for message reads or attachment opens.

Breach Notification Procedures

Document and rehearse a response plan so teams act quickly and consistently. Your procedure should guide detection, containment, risk evaluation, notification, and recovery while meeting Breach Notification Requirements.

Core components

  • Intake and triage: clear criteria for a suspected incident, 24/7 escalation paths, and decision ownership.
  • Investigation: preserve evidence, reconstruct the Audit Trail, and determine what PHI was affected and by whom.
  • Risk assessment: evaluate the nature and extent of PHI, unauthorized person, whether PHI was actually acquired/viewed, and mitigation.
  • Notifications: documented templates, approval workflow, recipient lists (individuals, partners, regulators), and delivery channels.
  • Coordination: how Business Associates notify Covered Entities and collaborate on facts and timelines.
  • Post-incident: remediation actions, lessons learned, policy updates, and stakeholder reporting.

Operational readiness checks

  • On-call matrix, contact lists, and legal/comms partners verified and tested.
  • Tabletop exercises covering telehealth-specific scenarios (lost device with cached chats, misrouted recording, vendor breach).
  • Evidence kits: log access, system diagrams, and contractual obligations at hand.

Summary and next steps

To close BAA coverage gaps, map PHI flows, verify BAAs line-by-line, harden encryption, enforce Role-Based Access Controls, prove Audit Trail Compliance, govern vendors continuously, secure messaging end to end, and drill your notification playbook. Maintain a living coverage matrix so product changes automatically trigger contract and control reviews.

FAQs

What constitutes a BAA coverage gap in telehealth platforms?

A coverage gap exists when a person or technology that creates, receives, maintains, or transmits PHI lacks an executed, accurate Business Associate Agreement or when the BAA’s scope does not match real-world data flows. Examples include embedded video or transcription SDKs without BAAs, vague encryption clauses, missing subcontractor flow-downs, or terms that ignore backups, logs, or notifications where PHI may appear.

How can audit logs help detect unauthorized PHI access?

High-fidelity audit logs create a verifiable trail of authentication events, PHI reads/exports, admin changes, and API calls. With retention and immutability controls, you can baseline normal behavior and alert on anomalies such as bulk exports, off-hours spikes, or access from unexpected locations. This visibility speeds investigations and supports Audit Trail Compliance during regulatory reviews.

Why is encryption critical for telehealth HIPAA compliance?

Encryption reduces the risk that intercepted or lost data can be read, protecting PHI across networks, devices, and storage. In transit encryption prevents eavesdropping, at-rest encryption limits exposure from system compromise, and End-to-End Encryption ensures only intended participants can view session content. Together with disciplined key management, these controls materially lower breach likelihood and impact.

What are the key elements of breach notification protocols for telehealth?

Effective protocols define roles, escalation paths, investigation steps, and decision criteria; specify how to assess risk to individuals; and prescribe the timing, content, and channels for notifications to affected individuals and partners. They also describe how Business Associates coordinate with Covered Entities, how evidence is preserved, and how corrective actions and lessons learned are tracked for continuous improvement.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles