Telehealth and HIPAA: Compliance Requirements for Virtual Healthcare Providers

Telehealth — the delivery of healthcare services through digital communications technology — expanded dramatically during the COVID-19 pandemic and has remained a permanent feature of the healthcare landscape. Patients appreciate the convenience of consulting their physicians without traveling to an office, and providers have embraced telehealth as a way to expand access and improve efficiency. But the shift to digital healthcare delivery has also created a more complex HIPAA compliance environment, because the technology used to deliver virtual care introduces new risks to the privacy and security of patient health information that traditional in-office care does not present in the same way.

Does HIPAA Apply to Telehealth?

Yes, unequivocally. HIPAA’s Privacy Rule and Security Rule apply to all protected health information, regardless of how the healthcare is delivered. A physician who treats patients via video call is subject to the same HIPAA obligations as a physician who sees patients in an office. A mental health counselor who conducts sessions over a secure messaging platform must protect patient information with the same standards as one who meets patients in person. The mode of delivery changes the specific technical safeguards required — protecting information transmitted over a network is different from protecting a physical paper chart — but it does not change the underlying legal obligation.

Entities providing telehealth services are typically covered entities under HIPAA — specifically, healthcare providers that transmit health information electronically in connection with covered transactions. This includes physicians, psychologists, counselors, nurse practitioners, physical therapists, and other licensed healthcare providers who deliver services via telehealth platforms. It also includes the organizations that support those providers, including group practices, telehealth companies, and remote patient monitoring services.

The Telehealth Platform: Business Associate or More?

When a healthcare provider uses a third-party telehealth platform to conduct virtual visits, that platform almost certainly qualifies as a business associate under HIPAA. The platform receives, maintains, and transmits protected health information as part of providing its services to the covered entity. Before using any telehealth platform, a covered entity must enter into a business associate agreement that satisfies HIPAA’s requirements.

Not all video conferencing platforms qualify as HIPAA-compliant telehealth platforms. During the COVID-19 public health emergency, the Department of Health and Human Services exercised enforcement discretion and allowed covered entities to use a broader range of communications technologies for telehealth without strict HIPAA compliance. That enforcement discretion has ended, and covered entities can no longer rely on it to justify using non-HIPAA-compliant platforms for telehealth services. A telehealth platform that is HIPAA-compliant will offer a business associate agreement, will use end-to-end encryption for communications, will implement appropriate access controls, and will maintain audit logs of system activity.

Security Safeguards for Telehealth

The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards to protect electronic protected health information. In the telehealth context, the most important technical safeguards relate to the security of the communications channel, the security of the devices used to deliver care, and the protection of any patient data stored by the telehealth platform or by the provider.

Transmission security is paramount. All electronic communications containing protected health information — video consultations, secure messages, clinical notes, prescription information — must be transmitted over encrypted channels. End-to-end encryption ensures that patient data cannot be intercepted and read by unauthorized parties during transmission. TLS encryption for data transmitted over the internet is a baseline requirement, and many telehealth platforms provide additional encryption layers.

Device security is also critical. Providers conducting telehealth visits on laptops, tablets, or mobile phones must ensure those devices are protected with access controls, including passwords or biometric authentication. Devices used for telehealth should be encrypted so that patient data cannot be accessed if the device is lost or stolen. Full-disk encryption is a standard technical safeguard for devices used to access ePHI. Remote wipe capability — the ability to remotely erase a device’s data if it is lost — is an important administrative safeguard for mobile devices.

Access controls must ensure that only authorized individuals can access patient information through the telehealth platform. Unique user identifiers, automatic logoff after periods of inactivity, and multi-factor authentication are important access control measures for telehealth systems. Multi-factor authentication is now widely considered a minimum standard for any system that stores or provides access to protected health information.

Patient Authentication and Verification

A compliance challenge specific to telehealth is verifying the identity of the patient before a virtual consultation. In an in-person visit, providers typically verify patient identity by reviewing a government-issued photo ID. In a telehealth setting, providers need a protocol for verifying that the person they are communicating with is actually the patient. The specific verification method will depend on the technology available and the sensitivity of the information being discussed, but providers should have a documented procedure for patient identity verification in telehealth encounters.

Patient authentication also intersects with the issue of informed consent for telehealth. Many states require healthcare providers to obtain explicit informed consent from patients before providing services through a telehealth platform, including informing patients about the privacy and security risks of telehealth technology. The specific requirements vary by state, and providers delivering services across state lines need to understand the consent requirements of each state in which their patients are located.

State Telehealth Privacy Laws

In addition to HIPAA, telehealth providers must comply with applicable state laws governing telehealth practice and patient privacy. Many states have enacted specific telehealth practice standards that regulate which services may be delivered via telehealth, what provider licensing requirements apply for cross-state telehealth, and what technology standards must be met. State medical practice acts and state mental health provider licensing laws frequently impose requirements that go beyond HIPAA, and providers who deliver telehealth services across state lines must understand the legal requirements of each state where they practice.

Several states have enacted mental health privacy laws that impose requirements on the protection of mental health records that are more stringent than HIPAA’s general standards. Providers delivering behavioral health services via telehealth should understand the specific mental health privacy laws of each state where their patients are located.

Remote Patient Monitoring

Remote patient monitoring — the collection of patient health data through wearable devices, sensors, or digital tools outside of traditional healthcare settings — is an increasingly important component of virtual care. Remote patient monitoring generates protected health information that is subject to all HIPAA requirements. The devices used for remote monitoring, the systems that collect and transmit the data, and any vendors involved in processing the data must all be part of a HIPAA-compliant program, with appropriate business associate agreements and security safeguards in place.

The data generated by remote patient monitoring devices also raises questions about consumer health data protection under state laws. Several states, including Washington, Nevada, Connecticut, and Colorado, have enacted health data privacy laws that apply to consumer health data collected outside of traditional HIPAA-covered relationships. Telehealth companies and healthcare technology providers should evaluate whether their remote monitoring programs trigger obligations under these state health data laws in addition to HIPAA.

Building a Telehealth HIPAA Compliance Program

A HIPAA compliance program for a telehealth provider should address all of the standard HIPAA requirements plus the specific risks of virtual care delivery. It should begin with a risk analysis that evaluates the specific technical and operational risks of the telehealth platform, the devices used, the network over which care is delivered, and the data storage and transmission practices of all involved systems. From the risk analysis, the organization should develop and implement a risk management plan, policies and procedures specific to telehealth, and training for all staff who use the telehealth platform.

Privacy and security policies should specifically address the use of approved telehealth platforms, the prohibition on using non-compliant communications tools for clinical care, requirements for device security, patient verification procedures, and the handling of technical incidents. The organization should test its incident response procedures regularly and update them as the technology environment evolves.

As telehealth continues to grow as a mode of healthcare delivery, HIPAA enforcement in this area is likely to intensify. The Office for Civil Rights has signaled its attention to telehealth compliance, and the combination of new technology risks and evolving patient expectations for digital privacy creates an environment where proactive compliance is both legally required and strategically sound.