Is telehealth subject to HIPAA?
Yes — if the practice is a covered entity. Telehealth does not change the covered-entity test, and once the practice is covered, the full Security Rule, Privacy Rule, and Breach Notification Rule apply to remote care exactly as they do in person. The COVID-era enforcement discretion has ended, so the transitional allowances that once covered consumer video tools no longer apply.
What telehealth platforms are HIPAA compliant?
A platform is HIPAA compliant only if it offers a signed BAA, end-to-end encryption, and proper access controls. Zoom (healthcare plan), Doxy.me, and several EHR-integrated platforms offer BAAs — but compliance also depends on how you configure and use them. Patient Protect's risk assessment evaluates your actual setup, not just the vendor's marketing claims.
Can I use my personal phone or laptop for telehealth?
You can, but only with proper safeguards — full-disk encryption, passcode lock, separate user profiles, and documented BYOD policies. OCR evaluates whether personal devices used for clinical care meet the same security standards as dedicated clinical systems. Patient Protect includes remote device policy templates and training modules for exactly this scenario.
What does HIPAA compliance cost for a telehealth practice?
Traditional compliance consultants charge $4,000–$10,000 per year for telehealth practices, often more for multi-state providers. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, platform BAA tracking, remote work policies, staff training, and continuous compliance monitoring.
Are audio-only telehealth visits HIPAA-compliant?
Audio-only telehealth (telephone-only) is permitted under HIPAA when the practice has appropriate safeguards — the call must occur on a HIPAA-compliant infrastructure, identity verification must occur before clinical content, and PHI must not be left on insecure voicemail systems. CMS extended audio-only Medicare reimbursement post-PHE for behavioral health and limited other categories; the HIPAA framework applies regardless of reimbursement category.
Does HIPAA require video for telehealth visits?
No. HIPAA is technology-agnostic — it requires safeguards proportionate to the risk, not specific media. Many state telehealth licensure frameworks require video for specific service types (controlled-substance prescribing, certain mental health services), but that's a state-law requirement layered on top of HIPAA, not a HIPAA requirement itself.
How do multi-state telehealth operations handle breach notification?
Each state where the breach affects residents has its own notification timeline, AG-notification threshold, and required disclosure content. A breach affecting residents of 30 states triggers 30 different notification clocks the moment it's detected. The practical implication: pre-load every operating-state's requirements into the breach response protocol so the response can ship parallel notifications rather than sequential ones.
Does a telehealth practice have to complete a HIPAA Security Risk Analysis?
Yes, and telehealth does not narrow the scope — it widens it. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For telehealth that means the platform and its configuration, administrative access, waiting-room controls, chat, metadata, and recording features; every clinician device, home network, and physical privacy condition; the EHR, intake, scheduling, portal, e-prescribing, and billing systems; session recordings, transcripts, and uploaded documents; and remote onboarding, device loss, account compromise, and termination. A signed platform BAA covers none of this — it is a contract, not an analysis.
Which of our telehealth vendors need Business Associate Agreements?
Any organization maintaining or transmitting ePHI for the practice: the telehealth platform itself, the EHR, scheduling and intake tools, patient messaging, e-prescribing service, transcription and recording storage, cloud storage and backup, billing service, and any subcontractor those vendors use. The platform is necessary but not sufficient — a signed platform BAA does not configure the platform, secure the clinician's device, control where recordings are stored, train the workforce, or complete the SRA. Payers, laboratories performing tests, and other treating clinicians involved in a patient's care are not business associates.
What are we responsible for in a clinician's home office?
All of it, from HIPAA's perspective. The home office is a location where the practice creates and maintains ePHI, so it belongs in the risk analysis and needs written standards the same way a clinic room would: a lockable or private space where sessions cannot be overheard, a screen not visible to household members, a secured home network rather than an open one, encrypted devices with automatic screen lock, a rule against shared family computers and accounts, headphone use, and a documented procedure for device loss. The uncomfortable part for most practices is that this requires telling clinicians how to arrange a room in their own home — which is exactly why it needs to be written policy rather than an assumption.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a telehealth practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.