Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Telehealth Clinicians

The HIPAA compliance and security operating system for telehealth practices. Remote care spreads the clinical environment across platforms, home offices, personal devices, recordings, and multiple states — and a signed platform BAA covers none of it. Patient Protect runs the risk analysis across that whole footprint, sets remote-work policy, trains the workforce, and keeps the evidence.

Telehealth does not change the covered-entity test. A clinician or practice that electronically conducts an adopted transaction — or has one conducted on its behalf — is covered just as an in-person practice would be. Once covered, the duties below apply to the full remote-care environment.

HIPAA compliance is not optional for a covered telehealth practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a telehealth practice’s Security Risk Analysis must cover

Telehealth distributes the clinical environment across platforms, homes, devices, networks, recordings, messaging, and multiple states. Every one of those locations and systems becomes part of the practice's security and privacy responsibility.

  • The telehealth platform, its configuration, administrative access, integrations, waiting-room controls, chat, metadata, and recording features
  • Every clinician device, home-office environment, local network, headset, camera, screen, and physical privacy condition
  • EHR, intake, scheduling, patient portal, e-prescribing, laboratory, billing, and payment systems
  • Session recordings, transcripts, chat logs, uploaded documents, asynchronous messages, and cloud storage
  • Email, text, support, after-hours communication, and patient identity-verification workflows
  • Remote workforce onboarding, access changes, device loss, account compromise, and termination
  • Vendors and subcontractors that maintain or transmit ePHI for the practice

What the telehealth compliance program must also address

  • A BAA with every platform or service vendor functioning as a Business Associate
  • Written privacy and security standards for clinician home offices and remote work
  • Identity verification, recording consent, emergency-location, and session-privacy procedures
  • State licensure, telehealth-consent, prescribing, and breach-notification requirements in every operating jurisdiction
  • EPCS requirements when controlled substances are prescribed electronically
  • Training on remote privacy, device security, social engineering, recordings, and cross-state workflows

Using a healthcare-branded video platform is one control. It is not the telehealth practice's entire compliance program.

What HIPAA actually looks like for telehealth clinicians.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Telehealth practices operate under HIPAA as covered entities through standard electronic transactions, with specific overlays from the DEA's telemedicine final rule (effective 2026 post-PHE), state-by-state telehealth licensure compacts (IMLC for medical, PSYPACT for psychology, ASLP-IC for SLP/audiology, others), and state-specific telehealth practice rules. The post-PHE landscape restored most pre-pandemic prescribing limits with specific telehealth-permitted exceptions. State medical boards govern licensure and practice standards; state pharmacy boards govern e-prescribing requirements; state insurance commissioners govern parity-of-coverage rules for telehealth services.

OCR enforcement patterns

OCR's telehealth enforcement record has expanded as the post-PHE landscape took shape. Recurring patterns include disclosure errors when a telehealth platform is shared across multiple covered entities, recording without consent, audio-only services used outside permitted scenarios, and missing in-person evaluation for controlled-substance prescribing where DEA rules require it. The FTC's BetterHelp settlement and GoodRx settlement (both 2023) under the Health Breach Notification Rule signaled regulatory attention on telehealth and consumer-health data sharing that complements HIPAA enforcement.

Standards beyond HIPAA

DEA EPCS for any controlled-substance prescribing. The DEA telemedicine final rule and its specific exceptions (one-day supply, etc.). State telehealth licensure compacts. Audio-only restrictions in many state telehealth frameworks. State-specific consent requirements for telehealth visits. CMS reimbursement rules for telehealth services post-PHE. State controlled-substance e-prescribing requirements that may exceed federal DEA minimums.

Common compliance gaps

Common in telehealth compliance reviews: licensure-state mismatch where the patient's state of residence differs from the prescriber's licensure state, audio-only services used outside permitted DEA or state framework, recording-of-visits without clear consent infrastructure, missing in-person evaluation for controlled-substance prescribing, multi-state breach notification matrix not pre-built, telehealth platform BAA assumed but not verified, and inadequate identity verification at the start of clinical encounters.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State law governs patient record retention, and telehealth-specific rules vary widely. DEA EPCS retention requirements are separate and longer for controlled-substance prescribing audit trails (typically two to five years depending on rule). State medical boards may require longer retention for telehealth visits than for in-person visits in some jurisdictions. Multi-state telehealth operations face the highest retention floor of any operating jurisdiction's law.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to telehealth clinicians based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where telehealth clinicians are most exposed.

Your telehealth platform vendor may not cover you

Zoom, Doxy.me, SimplePractice, Spruce — a signed BAA is mandatory, but most clinicians never verify encryption settings, recording storage locations, or session metadata handling. The COVID-era enforcement discretion has ended, so those configuration decisions now sit squarely inside the practice's own Security Rule obligations.

Home offices and personal devices are uncontrolled environments

Clinicians conducting sessions from home laptops, tablets, and personal phones introduce risks no brick-and-mortar practice faces. Shared family devices, unencrypted Wi-Fi, screen visibility to household members — each is a potential breach vector OCR evaluates during audits.

Session recordings and chat logs create long-lived ePHI

Recorded telehealth sessions, chat transcripts, and asynchronous messages are ePHI that must be encrypted at rest, access-controlled, and retained per your retention policy. Many clinicians store recordings in consumer cloud storage with no BAA and no access audit trail.

Multi-state practice multiplies regulatory exposure

Telehealth clinicians often serve patients across state lines. Each state may layer additional privacy requirements on top of federal HIPAA. A single compliance gap doesn't just affect one jurisdiction — it can trigger enforcement actions in every state where you treat patients.

Built for telehealth clinicians, not hospital systems.

Telehealth-specific risk assessment

SRA wizard covers video platform security, remote device policies, session recording storage, and cross-state practice — not a generic in-office questionnaire repurposed for virtual care.

Platform vendor BAA tracking

Track BAAs with Zoom, Doxy.me, SimplePractice, scheduling tools, payment processors, and every other vendor in your telehealth stack. Expiration alerts and e-sign built in.

Secure patient messaging

Replace personal texts, email, and consumer chat apps with BAA-gated messaging. Patient communication stays inside your compliance perimeter — no matter where you're practicing from.

Remote work policy templates

Pre-built policies for home office security, BYOD device management, and remote session protocols. Customize for your practice and document workforce acknowledgment automatically.

Multi-state licensure and breach notification matrix

Telehealth operations across 30+ states face a state-by-state matrix of licensure compacts, breach notification timelines, and AG-notification thresholds. The platform pre-loads each state's requirements; the alternative is reading 50 statutes after an incident with the timeline already running.

Post-PHE controlled substance prescribing compliance

The DEA's telemedicine final rule (effective 2026) restored most pre-PHE prescribing limits with specific telehealth-permitted exceptions. Patient Protect tracks prescriber-by-prescriber compliance with the registration, in-person evaluation, and audit-trail requirements that controlled-substance telehealth now requires.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25 personnel · No long-term contract

State-specific HIPAA rules for telehealth clinicians.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for telehealth clinicians.

Is telehealth subject to HIPAA?

Yes — if the practice is a covered entity. Telehealth does not change the covered-entity test, and once the practice is covered, the full Security Rule, Privacy Rule, and Breach Notification Rule apply to remote care exactly as they do in person. The COVID-era enforcement discretion has ended, so the transitional allowances that once covered consumer video tools no longer apply.

What telehealth platforms are HIPAA compliant?

A platform is HIPAA compliant only if it offers a signed BAA, end-to-end encryption, and proper access controls. Zoom (healthcare plan), Doxy.me, and several EHR-integrated platforms offer BAAs — but compliance also depends on how you configure and use them. Patient Protect's risk assessment evaluates your actual setup, not just the vendor's marketing claims.

Can I use my personal phone or laptop for telehealth?

You can, but only with proper safeguards — full-disk encryption, passcode lock, separate user profiles, and documented BYOD policies. OCR evaluates whether personal devices used for clinical care meet the same security standards as dedicated clinical systems. Patient Protect includes remote device policy templates and training modules for exactly this scenario.

What does HIPAA compliance cost for a telehealth practice?

Traditional compliance consultants charge $4,000–$10,000 per year for telehealth practices, often more for multi-state providers. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, platform BAA tracking, remote work policies, staff training, and continuous compliance monitoring.

Are audio-only telehealth visits HIPAA-compliant?

Audio-only telehealth (telephone-only) is permitted under HIPAA when the practice has appropriate safeguards — the call must occur on a HIPAA-compliant infrastructure, identity verification must occur before clinical content, and PHI must not be left on insecure voicemail systems. CMS extended audio-only Medicare reimbursement post-PHE for behavioral health and limited other categories; the HIPAA framework applies regardless of reimbursement category.

Does HIPAA require video for telehealth visits?

No. HIPAA is technology-agnostic — it requires safeguards proportionate to the risk, not specific media. Many state telehealth licensure frameworks require video for specific service types (controlled-substance prescribing, certain mental health services), but that's a state-law requirement layered on top of HIPAA, not a HIPAA requirement itself.

How do multi-state telehealth operations handle breach notification?

Each state where the breach affects residents has its own notification timeline, AG-notification threshold, and required disclosure content. A breach affecting residents of 30 states triggers 30 different notification clocks the moment it's detected. The practical implication: pre-load every operating-state's requirements into the breach response protocol so the response can ship parallel notifications rather than sequential ones.

Does a telehealth practice have to complete a HIPAA Security Risk Analysis?

Yes, and telehealth does not narrow the scope — it widens it. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For telehealth that means the platform and its configuration, administrative access, waiting-room controls, chat, metadata, and recording features; every clinician device, home network, and physical privacy condition; the EHR, intake, scheduling, portal, e-prescribing, and billing systems; session recordings, transcripts, and uploaded documents; and remote onboarding, device loss, account compromise, and termination. A signed platform BAA covers none of this — it is a contract, not an analysis.

Which of our telehealth vendors need Business Associate Agreements?

Any organization maintaining or transmitting ePHI for the practice: the telehealth platform itself, the EHR, scheduling and intake tools, patient messaging, e-prescribing service, transcription and recording storage, cloud storage and backup, billing service, and any subcontractor those vendors use. The platform is necessary but not sufficient — a signed platform BAA does not configure the platform, secure the clinician's device, control where recordings are stored, train the workforce, or complete the SRA. Payers, laboratories performing tests, and other treating clinicians involved in a patient's care are not business associates.

What are we responsible for in a clinician's home office?

All of it, from HIPAA's perspective. The home office is a location where the practice creates and maintains ePHI, so it belongs in the risk analysis and needs written standards the same way a clinic room would: a lockable or private space where sessions cannot be overheard, a screen not visible to household members, a secured home network rather than an open one, encrypted devices with automatic screen lock, a rule against shared family computers and accounts, headphone use, and a documented procedure for device loss. The uncomfortable part for most practices is that this requires telling clinicians how to arrange a room in their own home — which is exactly why it needs to be written policy rather than an assumption.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a telehealth practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your telehealth practice has compliance gaps beyond what your platform covers.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions