Featured | Sep 3, 2026

HIPAA Compliant Telehealth: The Complete Guide + Free Checklist & Risk Assessment

This guide covers what HIPAA compliance actually requires for telehealth organizations today: platform and vendor rules, patient verification, workforce training, technical safeguards, and breach notification. It includes a free interactive compliance risk check and a downloadable 12-point checklist so compliance teams can benchmark their own program against current requirements, not proposed future ones

HIPAA Compliant Telehealth: The Complete Guide + Free Checklist & Risk Assessment

HIPAA Compliant Telehealth 2026: Requirements, Risk Assessment, and Checklist

Telehealth is now a routine part of outpatient, behavioral health, and specialty care delivery. With that permanence comes full regulatory accountability. This guide covers what HIPAA compliance for telehealth requires today, how to assess your program's risk posture, and a practical checklist to benchmark against current obligations.

Key Takeaways

  • Since August 9, 2023, there is no telehealth enforcement discretion in effect. Full HIPAA Privacy, Security, and Breach Notification Rules apply to most virtual care, including video conferencing and most audio telehealth.
  • Consumer apps like standard Zoom, FaceTime, and WhatsApp are generally not HIPAA compliant telehealth platforms because they will not sign Business Associate Agreements or provide required safeguards.
  • A documented risk analysis, technical safeguards (encryption, access controls, audit logs), identity verification, and patient consent processes are core pillars of compliant telehealth.
  • Non-compliance with HIPAA can lead to significant penalties, OCR investigations, corrective action plans, and reputational damage.
  • Use the compliance checklist below and an interactive compliance risk check tool to benchmark your telehealth program against current requirements.

Check Your Compliance Risk Right Now

Before working through the full guide below, get a directional read on where your own program stands. This interactive tool covers the same six areas OCR reviews when it looks at a telehealth program, in about three minutes.

The HIPAA Telehealth Compliance Checklist

Use this checklist to benchmark your program against current requirements. Download it as a reference your team can work through together, or use it alongside the risk check above.

  • BAA in place with every vendor that creates, receives, maintains, or transmits PHI for telehealth services
  • Encryption in transit and at rest configured and validated for the telehealth platform, recordings, and stored messages
  • Documented identity verification procedure for new telehealth patients and higher-risk use cases
  • Documented telehealth consent process covering privacy risks, public locations, and third-party presence
  • Initial HIPAA and telehealth-specific training completed for all workforce members, with annual refreshers scheduled
  • Unique credentials for all telehealth users, multi-factor authentication where reasonable, automatic session timeouts, and virtual waiting rooms enabled
  • Audit logs for telehealth sessions enabled, retained appropriately, and reviewed on a defined schedule
  • HIPAA security risk analysis covering telehealth completed or updated within the last 12 months, with risk management actions underway
  • Written breach notification procedures referencing HIPAA's 60-day timeline, clear escalation paths, and at least one tabletop exercise completed
  • Cross-state practice and licensure tracking in place, including state-specific telehealth regulations and any stricter privacy or breach laws
  • Telehealth platforms implement administrative, physical, and technical safeguards

    Download the checklist below
     

    Your subscription could not be saved. Please try again.
    Thank you. Please check your email.

What HIPAA Compliance Means for Telehealth

Key Definitions

The Health Insurance Portability and Accountability Act (HIPAA) protects individually identifiable health information across every care setting, including telehealth. There is no separate telehealth exception to HIPAA rules; they apply fully to virtual care.

HIPAA compliance for telehealth means applying the same standards that govern in-person encounters, adapted to remote communication technologies, because HIPAA requires compliance with the Privacy Rule and Security Rule obligations that apply to protected health information. Protected health information (PHI) in electronic form (ePHI) includes data created during video calls, audio sessions, chat messaging, remote monitoring, and asynchronous communication used by healthcare providers.

Covered Entities and Business Associates

Covered entities under HIPAA include covered health care providers who transmit protected health information electronically in standard transactions, health plans, and healthcare clearinghouses. A business associate is any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Using telehealth technology alone does not make a provider a covered entity; the determining factor is whether the provider conducts standard electronic transactions such as claims or eligibility checks.

Safeguards Overview

Organizations need administrative, physical, and technical safeguards for HIPAA compliance. Telehealth sessions generate, store, and transmit patient data through multiple systems: telehealth platforms, electronic health records, cloud storage, and payment processors. Each component broadens the compliance surface. Even non-covered providers (some cash-pay mental health practices, for instance) should follow HIPAA-level safeguards as a best practice to protect patient privacy and meet professional standards and support HIPAA compliance for virtual care.

HIPAA and Telehealth After the COVID-19 Public Health Emergency

Telemedicine usage rose from 7% to 47% during COVID-19, driven by CMS expansions and private health plans broadening Medicare and Medicaid services coverage, including Medicare coverage for virtual visits. The percentage of telehealth users has since settled at around 15%.

During the COVID-19 public health emergency, HHS relaxed HIPAA enforcement through the HHS Office for Civil Rights (OCR), issuing enforcement discretion notices that permitted good-faith use of non-public-facing consumer tools for telehealth remote communications. These relaxed guidelines allowed providers to use platforms like FaceTime or standard Zoom temporarily. After the emergency, organizations had to adopt compliant tools and updated policies to ensure compliance.

Key dates: the public health emergency ended May 11, 2023. A 90-day transition period for HIPAA compliance began on May 12, 2023, and temporary HIPAA guidelines for telehealth ended in August 2023. Healthcare providers had a 90-day transition to HIPAA compliance post-COVID.

As of August 10, 2023, covered entities must use HIPAA compliant telehealth platforms and fully comply with HIPAA Privacy, Security, and Breach Notification Rules. Enforcement activity has refocused from pandemic leniency to traditional investigations, with risk analysis failures and basic security gaps remaining among the most commonly cited deficiencies. Returning to noncompliant tools can also lead to HIPAA violations.

Note: verify the exact enforcement discretion end date against HHS's official notice before publishing; secondary sources consistently cite August 9–10, 2023, but this should be confirmed against the primary HHS.gov notice given how specific and checkable the date is.

Platform and Vendor Compliance for Telehealth

Selecting HIPAA compliant telemedicine platforms and managing your vendor ecosystem is foundational to telehealth HIPAA compliance. Providers must use secure video applications and avoid public social video tools for telehealth.

What makes a platform a HIPAA compliant telehealth platform: willingness to sign a Business Associate Agreement (BAA), support for encryption, access controls, audit logging, and secure configurations to address common security risks in telehealth. Enterprise versions of tools (Zoom for Healthcare, for example) offer these features. Consumer versions of the same tools generally do not provide BAAs or sufficient security measures and are therefore not HIPAA compliant.

A Business Associate Agreement is required with telehealth vendors. This applies to every vendor that creates, receives, maintains, or transmits PHI, including telehealth software, cloud hosting, transcription services, and analytics tools. HIPAA compliant telehealth platforms must secure data transmission and encrypt patient data during transmission, helping them meet HIPAA Privacy and Security Rules.

Healthcare providers must secure the entire telehealth application ecosystem, not just the video stream. Common telehealth stack components include:

  • Video platform
  • EHR integration
  • Cloud storage
  • Payment processor
  • Remote patient monitoring devices

Each PHI-touching vendor must have a signed BAA. When evaluating vendor security posture, ask about encryption standards (TLS in transit, encryption at rest), data storage locations, subcontractor BAAs, incident response procedures, and audit log availability.

Signing a BAA alone does not make a tool compliant. Covered entities must configure features correctly and implement appropriate administrative policies. Maintain an up-to-date inventory of all telehealth-related vendors and review BAAs and security attestations regularly.

Privacy in telehealth depends not only on technology but also on reliable identity verification and informed patient consent workflows. Healthcare providers must verify patient identities during telehealth consultations. Patient identity verification is a key compliance challenge, and telehealth providers face challenges with user authentication and secure communications.

Practical verification methods include demographic checks, photo ID comparison, security questions, or patient portal authentication. Verification is especially important for first telehealth visits, referrals, and high-risk specialties like psychiatry or substance use treatment.

Some states and payers explicitly require telehealth-specific consent documentation. Telehealth consent should address:

  • Technology limitations and potential privacy risks
  • Contingency plans for technical failure
  • Whether others are present (family, interpreters, students)
  • How follow-up or in-person care will be arranged

Document consent and verification in the record or within the telehealth platform and retain records in line with HIPAA and state-law requirements.

Workforce Training Requirements for HIPAA-Compliant Telehealth

Many OCR settlements cite inadequate training. Training staff on securing patient information is necessary for compliance with HIPAA regulations, and practices for telehealth must include conducting training regarding privacy rules.

The HIPAA Privacy Rule and Security Rule require role-appropriate training for all workforce members who interact with PHI: clinicians, schedulers, IT staff, and contractors. Initial onboarding should cover the organization's chosen HIPAA compliant telehealth platform, including secure login procedures, screen-sharing rules, and messaging protocols.

Ongoing refresher training (annually or when major changes occur) should address telehealth-specific risks: working from home, using mobile devices, handling calls when a patient is in a public place, and managing family presence during sessions. Platform-specific security features like multi-factor authentication, virtual waiting rooms, and locked meetings should be part of training content.

Organizations should document who was trained, when, and on what topics, and maintain these records for at least six years.

Technical Safeguards for HIPAA-Compliant Telehealth

Safeguards Overview

The HIPAA Security Rule requires technical safeguards for electronic PHI (ePHI). These safeguards protect confidentiality, integrity, and availability across telehealth workflows.

Common Technical Safeguards

Required and addressable technical safeguards relevant to telehealth include:

  • Access controls must implement unique user logins and multi-factor authentication in telehealth
  • Automatic logoff after inactivity
  • Strong encryption during video and audio calls to secure data transmission
  • End-to-end encryption for data in transit and at rest
  • Integrity controls for stored records
  • Regular audit logging to monitor access to patient information

Audit Logging and Monitoring

Monitoring of who accesses patient data is a critical component of HIPAA compliance. Covered entities must maintain audit trails for telehealth communications, and logs should be reviewed on a defined schedule, not just enabled.

Data must be minimized in telehealth; only necessary information should be collected and retained. Telehealth sessions must adhere to privacy laws to prevent unauthorized data access. Healthcare providers must conduct virtual visits from secure locations to protect sensitive data.

For audio-only telehealth: traditional landline calls fall outside the Security Rule's scope, but VoIP, mobile, and internet-based audio are treated as electronic communications and must follow full Security Rule safeguards.

Device-level protections include disk encryption, up-to-date patches, mobile device management, and screen privacy. A secure telehealth architecture ties platform controls, network firewalls, VPNs, and endpoint protections together into a layered defense.

HIPAA Risk Assessment for Telehealth: A Closer Look

Risk Assessment Steps

A documented risk analysis is an explicit Security Rule requirement and the single most frequently cited deficiency in OCR enforcement actions. Healthcare providers must conduct risk analyses for telehealth. Periodic risk assessments are essential for identifying vulnerabilities in telehealth technologies.

A HIPAA risk assessment for telehealth should identify where ePHI is created, received, maintained, and transmitted across telehealth platforms, EHRs, devices, and cloud services. Threats to evaluate include unauthorized access, misdirected messages, interception of network traffic, lost or stolen devices, weak authentication, and platform misconfiguration.

For each threat-vulnerability pair, estimate likelihood and potential impact, then select reasonable safeguards tailored to your organization's size and complexity. HHS does not prescribe a single methodology; organizations may use NIST-aligned frameworks, the HHS Security Risk Assessment tool, or other structured approaches.

Updating Risk Management

Risk analysis is not a one-time project. Update it when adding new telehealth features, onboarding vendors, scaling remote work, or after significant incidents. Risk management must follow: documented remediation plans, timelines, and assigned responsibility for closing identified gaps.

The interactive compliance risk check above gives you a fast, directional read across these same areas. It is a self-assessment starting point, not a substitute for the full, documented risk analysis the Security Rule requires.

Breach Notification Requirements for Telehealth Incidents

The HIPAA Breach Notification Rule applies equally to telehealth incidents. HIPAA compliance requires handling breaches of protected health information properly. Incidents involving PHI breaches require a documented response plan that is tested periodically.

Telehealth-specific breaches may include sending visit summaries to the wrong patient, misconfigured meeting links allowing unauthorized attendees, or compromised telehealth user accounts. Any unauthorized disclosure of unsecured PHI is presumed to be a data breach unless a risk assessment determines low probability of compromise.

Individual notification requirements: affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. When a breach affects 500 or more residents of a state or jurisdiction, the covered entity must also notify the Department of Health and Human Services and prominent media outlets. Smaller breaches must be logged and reported to HHS annually.

Telehealth providers should maintain incident response plans that explicitly cover virtual care workflows and vendors, with clear roles and decision trees. Test breach response procedures using telehealth-specific scenarios.

Cross-State and Regulatory Considerations for Telehealth

HIPAA sets a national baseline for PHI privacy and security, but telehealth regulations vary significantly across states. State privacy and breach notification rules can be stricter: shorter notification timelines, broader definitions of personal information, or special rules for mental health and substance use records under frameworks like 42 CFR Part 2.

Multi-state licensure and credentialing present challenges. Inaccurate licensure data can lead to unauthorized access in telehealth. Other healthcare providers operating across state lines must comply with each state's telehealth, prescribing, and consent rules. Organizations should track where both providers and patients are located at the time of each encounter, as location determines which state laws apply.

Compliance teams should use structured tools or services to monitor changes in state telehealth regulations, licensure compacts, and payer policies that interact with HIPAA obligations. Organizations offering telemedicine services should also monitor payer and agency guidance that affects eligibility and delivery rules. The Health Resources and Services Administration provides telehealth guidance, tools, and other health resources that can help inform compliance monitoring.

Where HIPAA Security Rule Requirements for Telehealth Are Heading

OCR issued a Notice of Proposed Rulemaking (NPRM) in December 2024 to modernize the HIPAA Security Rule. Proposed changes include mandatory multi-factor authentication, explicit encryption requirements for ePHI at rest and in transit, annual penetration testing, faster incident reporting timelines, and elimination of the "required vs. addressable" distinction.

This proposed rule is not yet binding law. The projected finalization date has been pushed to mid-2027. Until a final rule takes effect, enforcement continues under the existing Security Rule. However, regulators increasingly expect risk-based controls beyond the bare minimum.

Organizations should treat likely future requirements as best practices now: stronger identity proofing, MFA for remote access, continuous monitoring, and formal vendor risk management. Building flexibility into telehealth programs now reduces disruption later.

Assessing Your Telehealth Program: Next Steps

Achieving HIPAA compliant telehealth requires coordinated work across technology, policies, training, vendor management, and risk analysis. Providers must demonstrate that their systems protect all forms of PHI during telehealth interactions.

Review your current telehealth program against the compliance checklist above and note specific gaps in BAAs, encryption, training, or documentation. An interactive compliance risk check tool can help organizations quickly identify highest-priority telehealth risks and organize remediation steps. Such a tool surfaces risk indicators and gives directional guidance but does not replace a full, documented HIPAA security risk analysis.

Take incremental but consistent steps: validate platform compliance, refresh BAAs, update administrative policies, schedule training, and plan a comprehensive telehealth-focused risk assessment within your next review cycle.

 

Cross-State Licensure Tracking and Risk Management

Cross-state licensure tracking is one of the most complex and critical compliance challenges in telehealth. Missing a license renewal or failing to track changes in licensure status can lead to significant legal and operational risks, including unauthorized practice allegations and HIPAA violations. Managing clinicians across multiple states demands precise, automated oversight to ensure every license is current and compliant.

This is where CE App excels. Trusted by leading telehealth organizations such as TimelyCare, Maven Clinic, Within Health, Equip Health, and Galileo, CE App provides automated, clinician-specific, state-by-state licensure tracking that scales with your organization. As your telehealth footprint expands, CE App ensures no license lapses go unnoticed, reducing risk and easing administrative burdens.

By integrating CE App's telehealth lincesure tracking solution into your compliance program, you gain confidence that your cross-state licensure management is accurate, up-to-date, and fully aligned with regulatory requirements. This proactive approach transforms a major compliance headache into a streamlined, reliable process—empowering your team to focus on delivering quality care without compromising legal standing.

Frequently Asked Questions

Need help? Start here for fast solutions.

HIPAA applies to covered entities that transmit health information in certain electronic transactions (claims, eligibility checks), regardless of whether they provide telehealth services. Some fully self-pay practices that never conduct standard electronic transactions may not be HIPAA covered entities. However, state laws and professional ethics still require strong privacy protections, and aligning with HIPAA-level safeguards is recommended to meet patient expectations.

HIPAA does not ban recording telehealth sessions, but any recording containing PHI becomes ePHI and must be protected with full Security Rule safeguards. Record only when there is a clear clinical, operational, or legal reason. Document how recordings are made, stored, accessed, and deleted. Obtain explicit patient consent for recording even where not legally mandated, and include recordings in your retention schedule and risk analysis.

Personal devices are not automatically prohibited, but they must meet the same security standards as organizational devices: encryption, access control, patching, and remote-wipe capability. Organizations should maintain clear bring-your-own-device policies defining acceptable use and required security controls. Many organizations limit telehealth access to managed devices because they are easier to secure and audit.

Providers should inform patients about privacy risks of public or shared locations and recommend private spaces and headphones. Document when a patient declines privacy recommendations and obtain verbal acknowledgment before proceeding with sensitive discussions. Consider deferring highly sensitive topics or rescheduling when privacy cannot reasonably be ensured, especially in behavioral health or substance use treatment.

Learn more about the CE App

See how your organization can use CE App to increase revenue and improve continuing education compliance.

Ready for simplified continuing education?