HIPAA Policies You Need in Place Before Offering Telehealth Visits
HIPAA Compliance for Telehealth
Before you launch virtual care, confirm that every telehealth workflow protects Protected Health Information under the HIPAA Privacy Rule and HIPAA Security Rule. Telehealth does not change your status as a covered entity or business associate; it simply introduces new ways ePHI can be created, transmitted, and stored.
Create or update policies that address telehealth-specific issues, including how you verify patient identity and location, prevent unauthorized recording, manage screenshots and chat transcripts, and apply the minimum necessary standard to audio, video, images, and logs. Define who may be present off‑camera and how that presence is documented.
Execute a Business Associate Agreement with each vendor that touches PHI—your telehealth platform, e‑fax, cloud storage, transcription, and analytics providers. The BAA must describe permitted uses and disclosures, safeguards, breach reporting duties, and return or destruction of PHI at termination. Confirm Telehealth Technology Vendor Compliance through due diligence and documented security attestations.
Train your workforce on these telehealth policies, sanction violations, and keep a current inventory of systems used for virtual care. Appoint a privacy officer and a security officer responsible for oversight, complaints, and periodic policy review.
Technology Requirements
Platform and security controls
- Use a platform that supports strong encryption in transit, role‑based access, unique user IDs, multifactor authentication, and audit logs.
- Disable default recording unless medically necessary and authorized; if recorded, store PHI securely with retention and access controls.
- Protect data exchanged in chat, file transfer, images, and remote monitoring feeds with the same safeguards as the video stream.
Workforce devices and networks
- Require device encryption, automatic screen locks, timely patching, and endpoint protection on all clinician devices used for telehealth.
- Use secure Wi‑Fi, avoid public networks, and require VPN or equivalent protections for remote staff handling ePHI.
- Prevent local downloads of PHI when feasible; route documentation directly into your EHR or secure repository.
Vendor due diligence and resilience
- Document Telehealth Technology Vendor Compliance through security questionnaires, certifications, penetration tests, and BAAs.
- Maintain a downtime and contingency plan for outages, with alternate communication channels and data backup/restore procedures.
Informed Consent
Adopt a clear informed consent process tailored to virtual care. Tell patients what telehealth is, its benefits and limits, and how their information will be protected and used under the HIPAA Privacy Rule. Use plain language and offer interpreter services when needed.
- Explain technology risks (for example, connectivity failures) and reasonable privacy risks inherent to remote communication.
- State alternatives to telehealth, how to revoke consent, and what to do in emergencies (telehealth is not for life‑threatening conditions).
- Document consent in the record; when obtained verbally, note date, time, and the staff member who obtained it.
Patient Education
Provide simple, step‑by‑step instructions that help patients protect their own privacy and make visits successful. Reinforce how their Protected Health Information will be handled and how they can reach support.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
- Send pre‑visit checklists covering device setup, app downloads, testing audio/video, and a secure way to share photos or documents.
- Encourage a private location, headphones, locked screens, and closing unrelated apps or smart speakers during the visit.
- Explain how after‑visit summaries, prescriptions, and messages will be delivered securely.
Secure Environment
Establish standards for where and how telehealth is conducted to minimize incidental disclosures. Apply them in clinics, homes, and any remote site where staff work.
- Use private rooms, position cameras away from whiteboards or charts, and prevent bystanders from overhearing or viewing PHI.
- Adopt clean‑desk and screen‑privacy practices; log out of systems when idle and lock rooms when unattended.
- Prohibit always‑listening devices in clinical spaces and restrict personal device use unless enrolled in your security program.
Data Breach Notification
Define Breach Notification Procedures that comply with HIPAA and your state laws. Your policy should address how to identify, investigate, and report a suspected incident involving telehealth systems, devices, or vendors.
Incident response steps
- Contain and secure: isolate affected accounts or devices and preserve logs for forensics.
- Assess: perform a documented risk assessment considering the nature of PHI involved, who received it, whether it was actually viewed, and mitigation performed.
- Notify: if a breach is confirmed, notify affected individuals without unreasonable delay and no later than 60 days from discovery, and notify HHS (and the media when 500+ residents of a state are affected) as required.
- Remediate: close control gaps, retrain staff, and update policies to prevent recurrence.
Risk Analysis
Conduct and document a Security Rule–aligned Risk Assessment in Telehealth before go‑live and after major changes. Map how ePHI flows through scheduling, virtual waiting rooms, the video platform, chat, remote monitoring, and the EHR.
How to run a telehealth risk assessment
- Inventory assets (platforms, devices, integrations) and PHI types captured during encounters.
- Identify threats and vulnerabilities (misconfiguration, weak authentication, improper recording, data residue in caches or logs).
- Evaluate likelihood and impact, then select administrative, physical, and technical controls to reduce risk to a reasonable and appropriate level.
- Create a risk register with owners, remediation actions, timelines, and acceptance criteria; review at least annually.
Common telehealth‑specific risks
- Meeting links forwarded or guessed; require authenticated entry and waiting rooms.
- Unapproved apps or browser extensions capturing audio/video; lock down endpoints.
- Residual PHI in screenshots, transcripts, or temporary files; set retention and secure deletion rules.
Conclusion
Putting the right HIPAA policies in place for telehealth means aligning governance, technology, and day‑to‑day behavior. When you combine clear procedures, vendor controls, informed consent, patient education, secure environments, robust breach handling, and a living risk analysis, you create virtual care that is both compliant and trusted.
FAQs
What HIPAA policies are mandatory before starting telehealth visits?
You need written policies covering Privacy Rule uses and disclosures, Security Rule safeguards, identity and location verification, no‑recording or controlled‑recording rules, access management, audit logging, contingency planning, workforce training and sanctions, vendor oversight with BAAs, Breach Notification Procedures, and documentation/retention standards tailored to virtual care.
How do Business Associate Agreements affect telehealth services?
A Business Associate Agreement binds each vendor that creates, receives, maintains, or transmits PHI on your behalf. It requires safeguards, limits on PHI use, prompt breach reporting, subcontractor flow‑downs, and secure return or destruction of PHI. Without a BAA, using that telehealth vendor for PHI is not compliant.
What are the informed consent requirements for telehealth?
Obtain and document consent that explains what telehealth is, benefits and limitations, privacy and security considerations, alternatives, how to withdraw, and what to do in emergencies. Use plain language, verify identity and patient location, and store the consent in the medical record.
How should providers handle data breaches during telehealth encounters?
Follow your incident response plan: contain the issue, investigate, and perform a risk assessment. If a breach is confirmed, notify affected individuals without unreasonable delay (no later than 60 days), notify HHS and media as applicable, remediate control gaps, retrain staff, and update policies to prevent recurrence.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.