HIPAA Training Checklist for Telehealth Coordinators: What to Do Before Recording a Virtual Visit
You play a central role in protecting patient privacy when a virtual visit will be recorded. Use this HIPAA training checklist to confirm your technology, workflows, and documentation meet requirements before you press Record.
The steps below align with HIPAA’s Privacy and Security Rules and emphasize practical controls you can verify in minutes. Integrate them into your pre-visit routine and audit them regularly.
Use HIPAA-Compliant Video Platforms
Pre-recording platform checks
- Verify a signed Business Associate Agreement exists with the vendor and is current; store a copy in your compliance repository.
- Confirm encryption in transit and at rest meets recognized Data Encryption Standards (for example, TLS for transport and AES-256 for storage).
- Enable End-to-End Encryption when feasible; if server-side recording is required, ensure secure transit, storage, and access controls compensate for E2EE being unavailable during capture.
- Require unique user accounts and multi-factor authentication for all staff who can schedule, host, or access recordings.
- Turn on waiting rooms/lobbies and disable auto-admit to prevent unauthorized entry.
- Restrict who can start/stop recordings and where files are saved (approved, encrypted repositories only—never local desktops).
- Activate Telehealth Session Logging and audit trails for joins, leaves, recording start/stop, and file access events.
Configuration hardening
- Default recording to Off; record only when clinically necessary and permitted by policy.
- Limit features that can expose PHI (file transfer, public chat retention, screen share by attendees) unless explicitly needed.
- Ensure role-based permissions reflect the minimum necessary standard.
Obtain and Document Informed Consent
Telehealth Informed Consent essentials
- Explain the purpose of recording, how it will be used, who can access it, retention timelines, and how patients can request restrictions.
- Describe risks, benefits, and alternatives to a recorded visit, and clarify that care is not contingent on consenting to recording when policy allows.
- State that the patient may pause or stop recording at any time and how to request deletion consistent with record-keeping laws.
How to capture consent
- Use e-sign forms or capture documented verbal consent; time-stamp, link to the encounter, and store in the EHR or designated consent repository.
- Perform Patient Identity Verification before consent (e.g., two identifiers and date of birth) and record the method used.
- For minors or adults with guardians, document the legal representative’s authority and relationship.
- Re-consent if the use, audience, or retention of recordings changes.
Complete Privacy and Security Training
Role-specific competencies
- Understand HIPAA’s minimum necessary standard, permitted uses/disclosures, and breach reporting timelines.
- Know how recordings count as ePHI, where they are stored, who may access them, and approved sharing workflows.
- Recognize phishing, social engineering, and unsafe storage practices that can expose recordings.
- Review Business Associate Agreement obligations that apply to your organization and vendors.
Before-you-record knowledge check
- Confirm you can locate the consent, verify platform encryption status, and trace where the recording will reside.
- Document training completion; schedule refreshers after major system or policy changes.
Ensure Device Security and Updates
Secure the host device
- Apply OS and application updates; enable automatic patching and reputable endpoint protection.
- Require full-disk encryption, strong passwords, and automatic screen lock with short timeouts.
- Use enterprise Wi‑Fi or a trusted network; avoid public Wi‑Fi. If remote, use a VPN approved by IT.
Privacy-in-practice checks
- Disable on-screen notifications and close unrelated apps to prevent accidental PHI exposure.
- Use a neutral background; ensure no paperwork or whiteboards with PHI is visible or audible.
- Set the recording path to an approved, encrypted location; if temporary local storage is unavoidable, transfer immediately and securely delete.
- Confirm alignment with organizational Data Encryption Standards for both storage and transfer.
Maintain Detailed Telehealth Documentation
What to record in the record
- Session metadata: date/time, platform, session ID, participants, locations, and whether recording occurred.
- Consent details: type (electronic or verbal), time-stamp, and summary of what was explained.
- Patient Identity Verification method and any interpreters or caregivers present.
- Clinical decisions, orders, and follow-ups consistent with standard documentation requirements.
Telehealth Session Logging and retention
- Maintain platform audit logs for access to recordings and administrative changes.
- Apply naming conventions, retention schedules, and legal hold procedures to recordings and logs.
- Restrict access using least-privilege roles; review permissions regularly.
Establish Emergency Protocols
Safety-first steps before recording
- Verify the patient’s physical location and a call-back number at the start of each visit.
- Keep local emergency service routing instructions available; confirm handoff procedures if a crisis emerges.
- Identify risks that may be heightened by recording (e.g., sensitive topics) and plan how to pause recording if needed.
When an incident occurs
- Follow the escalation pathway: pause recording, stabilize communication, contact emergency services as indicated, and notify internal teams.
- Document events, times, actions taken, and outcomes in the medical record and, if required, in incident reporting systems.
Conduct Regular Telehealth Risk Assessments
Operationalizing Telehealth Risk Management
- Inventory platforms, integrations (e.g., transcription), and data flows for recordings across their lifecycle.
- Identify threats and vulnerabilities, evaluate likelihood/impact, and prioritize mitigations with owners and deadlines.
- Test controls via tabletop exercises and mock breaches; refine based on findings.
- Review BAAs, encryption configurations, access roles, and retention rules at least annually or after major changes.
Conclusion
When you verify platform safeguards, obtain Telehealth Informed Consent, train staff, secure devices, document thoroughly, prepare for emergencies, and reassess risks routinely, you create a defensible process before recording any virtual visit. Use this checklist as your repeatable pathway to compliant, patient-centered care.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
FAQs.
What are the key HIPAA requirements for telehealth coordinators?
Use a HIPAA-compliant platform with a signed Business Associate Agreement, strong encryption, access controls, and audit logs. Apply the minimum necessary standard, verify patient identity, document Telehealth Informed Consent, secure devices and networks, maintain Telehealth Session Logging, and follow breach notification and retention policies.
How is informed consent documented in telehealth?
Capture Telehealth Informed Consent via e-sign or documented verbal consent, time-stamp it, and link it to the encounter. Note what was explained (purpose of recording, risks, access, retention), confirm Patient Identity Verification, include any guardian details, and store the consent with the record per policy.
What security measures protect virtual visits?
Enable End-to-End Encryption when possible, enforce MFA, and use encryption in transit and at rest aligned with Data Encryption Standards. Lock down recording permissions and storage locations, use waiting rooms, harden host devices and networks, and retain detailed Telehealth Session Logging and audit trails.
How often should staff complete HIPAA training?
Provide training at hire and at least annually, with additional refreshers after major technology, policy, or regulatory changes. Conduct targeted, role-specific modules for coordinators who handle recordings, and document completion for compliance audits.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.