Long COVID Telehealth Privacy: Your Rights and How to Protect Your Health Data
HIPAA Compliance in Telehealth
When your telehealth visit is delivered by a HIPAA-covered provider (or its business associate), the HIPAA Privacy Rule and Security Rule apply to your Patient Health Information Safeguards. That protection extends to electronic PHI shared over Remote Communication Technology, including audio-only care when implemented consistent with HIPAA requirements. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/index.html?utm_source=openai))
Covered entities must implement Telehealth Security Measures—risk analysis, access controls, authentication, audit controls, and transmission security—to keep ePHI confidential and available only to authorized people. If a vendor (for video, messaging, storage, or analytics) will create, receive, maintain, or transmit ePHI, your provider must have a Business Associate Agreement (BAA) with that vendor. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/index.html?utm_source=openai))
HIPAA also limits uses and disclosures, requires the “minimum necessary” standard, and enforces breach notification obligations. If a consumer app is used outside your provider’s HIPAA environment, HIPAA may not apply—but your data can still be protected by other laws discussed below.
State Data Privacy Laws
Beyond HIPAA, State Health Data Protections increasingly cover health-related data collected by apps, websites, and telehealth tools. Washington’s My Health My Data Act restricts the collection, sharing, and sale of “consumer health data,” with compliance starting March 31, 2024 (June 30, 2024 for small businesses). ([app.leg.wa.gov](https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.030&utm_source=openai))
Nevada’s SB 370 similarly governs “consumer health data” held by companies that may fall outside HIPAA, effective March 31, 2024. ([leg.state.nv.us](https://www.leg.state.nv.us/Session/82nd2023/Bills/SB/SB370_EN.pdf?utm_source=openai))
California’s CCPA/CPRA grants residents rights to access, delete, and limit the use of sensitive personal information—which expressly includes health information—when processed by covered businesses. ([cppa.ca.gov](https://cppa.ca.gov/faq?utm_source=openai))
Note: If a telehealth service or related app is not a HIPAA entity, federal consumer protection law may still apply. In 2024, the FTC updated the Health Breach Notification Rule to clarify coverage of many health apps and similar technologies. ([ftc.gov](https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-finalizes-changes-health-breach-notification-rule?utm_source=openai))
Telehealth Privacy Rights
You retain core HIPAA rights in telehealth: to receive a Notice of Privacy Practices, to request confidential communications, to ask for access and amendments to your records, and to obtain an accounting of certain disclosures. Providers generally must act on access requests within 30 days (with one 30-day extension if necessary). ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.524))
You also benefit from civil rights protections telehealth must honor. HHS’s 2024 Section 1557 final rule specifically addresses nondiscrimination in the delivery of health programs and activities through telehealth, including effective communication and digital accessibility. ([regulations.justia.com](https://regulations.justia.com/regulations/fedreg/2024/05/06/2024-08711.html?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Telehealth Technology Compliance
Secure platforms should provide end-to-end transport encryption, unique user IDs, role-based access, multi-factor authentication, robust logging, and timeout/lockout controls. These align with HIPAA’s technical safeguards for telehealth encounters and remote monitoring. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.312?utm_source=openai))
Ask your provider whether the telehealth vendor signs a BAA, where data are stored, whether sessions are recorded, and how long any recordings or chat transcripts are retained. These Patient Health Information Safeguards help ensure appropriate use and deletion policies across the full lifecycle of your data. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/business-associates/index.html?utm_source=openai))
Long COVID as a Disability
Long COVID can qualify as a disability under the ADA, Section 504, and Section 1557 when symptoms substantially limit one or more major life activities (for example, breathing, concentrating, or endurance). That status can trigger reasonable modifications and accessible telehealth, as part of broader Disability Rights in Healthcare. ([hhs.gov](https://www.hhs.gov/civil-rights/for-providers/civil-rights-covid19/guidance-long-covid-disability/index.html?utm_s%0D%0Aource=gwtodayemail&utm_source=openai))
If you need accommodations during virtual care—such as extra time, captioning or interpreters, alternative formats, or flexibility with pacing—tell your provider in advance. These requests sit within Civil Rights Protections Telehealth and cannot be denied for discriminatory reasons. ([regulations.justia.com](https://regulations.justia.com/regulations/fedreg/2024/05/06/2024-08711.html?utm_source=openai))
Telehealth Privacy Tips
- Before your visit, confirm that your provider’s platform is HIPAA-compliant and that it uses a vendor under a BAA; ask whether sessions are recorded and how data are stored.
- Join from a private, secure network; avoid public Wi‑Fi. Update your device, enable full-disk encryption, and use strong passcodes or biometrics.
- Close other apps, disable screen notifications and smart speakers, and use headphones to prevent unintended disclosures.
- Share only what’s necessary; if asked to use a third‑party app, request its privacy policy and opt out of tracking or targeted ads when possible.
- Use the patient portal for messages and documents instead of unencrypted email or SMS whenever possible.
- After the visit, review visit notes and request corrections if something is inaccurate; exercise your right of access to obtain copies for your records.
Enforcement Discretion During COVID-19
During the COVID‑19 Public Health Emergency, OCR exercised enforcement discretion allowing “good‑faith” telehealth on non‑public‑facing tools. That discretion expired May 11, 2023. OCR then allowed a 90‑day transition period (May 12–August 9, 2023) to restore full HIPAA compliance for telehealth. After 11:59 p.m. on August 9, 2023, normal HIPAA enforcement resumed. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/telehealth/index.html?utm_source=openai))
FAQs
What are my privacy rights during a telehealth visit for Long COVID?
You have HIPAA rights to access, request corrections, and receive confidential communications, plus civil rights protections requiring nondiscriminatory, accessible telehealth. If you need accommodations (for example, captioning or extra time), your provider must consider reasonable modifications. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.524))
How does HIPAA protect my telehealth health information?
HIPAA’s Privacy and Security Rules require Patient Health Information Safeguards—policies, technical controls, and BAAs with vendors—so ePHI sent over Remote Communication Technology stays private and secure, including for audio-only telehealth when HIPAA conditions are met. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/index.html?utm_source=openai))
Can Long COVID qualify as a disability under telehealth laws?
Yes. Federal guidance explains that Long COVID can be a disability if it substantially limits a major life activity, which activates protections under the ADA, Section 504, and Section 1557. Those protections apply to virtual care settings, too. ([hhs.gov](https://www.hhs.gov/civil-rights/for-providers/civil-rights-covid19/guidance-long-covid-disability/index.html?utm_s%0D%0Aource=gwtodayemail&utm_source=openai))
What precautions can I take to protect my privacy during telehealth sessions?
Use a private connection and headphones, keep your device updated, limit app permissions, and ask your provider to use a HIPAA‑compliant platform with a signed BAA. Prefer secure portals for messaging, and review your records after the visit to spot and correct inaccuracies. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/business-associates/index.html?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.