US Federal Law United States

Telehealth and HIPAA: Platforms, BAAs, and Post-PHE Rules

HIPAA requirements for telehealth after the COVID enforcement discretion ended: compliant platforms, BAAs, remote workforce safeguards, and website tracking risks.

Regulation

HIPAA Privacy and Security Rules applied to telehealth; OCR telehealth enforcement discretion (ended August 9, 2023, with a 90-day transition to November 6, 2023)

Max Penalty

Standard HIPAA civil penalty tiers apply to telehealth violations; non-compliant video platforms and tracker-laden portals create both OCR and FTC exposure

Enforcing Authority

HHS Office for Civil Rights (OCR); state medical boards and telehealth laws overlay

Official Source

www.hhs.gov

Executive Summary

  • The COVID-era enforcement discretion that tolerated consumer video apps for telehealth ended with the public health emergency on May 11, 2023; after the transition period closed November 6, 2023, full HIPAA compliance applies to every telehealth encounter.
  • A compliant telehealth stack requires a platform vendor that signs a BAA and supports Security Rule controls: encrypted transmission, access controls, and audit capability, consumer FaceTime/Skype-style tools without BAAs are out.
  • Remote care extends the compliance perimeter: clinician home networks, personal devices, household eavesdropping, and recorded sessions all enter the risk analysis.
  • OCR published telehealth-specific guidance for providers and patients, and its website-tracking positions hit telehealth hardest, appointment scheduling and symptom-checker pages feed exactly the data trackers collect.
  • State law overlays (consent to telehealth, recording consent, professional licensure) run alongside HIPAA and often bind first.

Telehealth kept its pandemic scale but lost its pandemic permissions. The enforcement discretion that let providers see patients over any video app died with the public health emergency, and since November 2023 the ordinary machinery, BAA-covered platforms, risk-analyzed workflows, secured endpoints, applies to every visit. The quieter exposure sits in front of the video call: the scheduling pages, symptom checkers, and portal logins whose trackers have generated more breach reports and litigation than the sessions themselves. A telehealth program is compliant when its whole path is, from the first page view to the closing click.

Discretion endedPHE end May 11, 2023; transition closed Nov 6, 2023
Platform floorBAA + encryption, authentication, audit capability
No such thing”HIPAA-certified” software
Remote perimeterEndpoints, networks, rooms, recordings
Sharpest riskTrackers on health-related web pages

Building the compliant stack

Re-paper the pandemic stack. Every telehealth tool gets a BAA and a configuration review; discretionary-era tolerance is gone.

Extend the risk analysis to the living room. Remote endpoints, home networks, and recording flows belong in the security risk assessment, the unassessed vector is the enforcement pattern.

Strip ad tech from health pages. OCR’s tracking position plus FTC actions make third-party pixels on scheduling and portal pages the top remediation item; the breach playbook covers what happens if they already fired.

Run the state matrix. Telehealth consent, recording consent, and licensure bind per patient location; OCR enforcement trends cover the federal side.

Your telehealth front door is a webpage: find out what it sends to third parties with a free scan.

Frequently Asked Questions

What changed when the enforcement discretion ended?

During the COVID public health emergency, OCR announced it would not penalize good-faith telehealth over non-public-facing consumer apps (FaceTime, Zoom without a BAA, Skype) even where HIPAA compliance was imperfect. That discretion ended with the PHE on May 11, 2023; OCR granted a 90-day transition through November 6, 2023, and since then the ordinary rules apply in full. Concretely: the platform must be under a BAA, the Security Rule risk analysis must cover the telehealth service, and the tolerated 'any video app in a pinch' posture is over. Providers still running pandemic-era stacks are carrying an unremediated known risk, the exact fact pattern current OCR enforcement targets.

What makes a telehealth platform HIPAA-compliant?

No platform is 'HIPAA-certified', no such certification exists. The question is whether the vendor will sign a BAA covering the service and whether the service supports your Security Rule obligations: encryption in transit (and at rest for recordings and chat), unique user authentication, access controls, session security, audit logging, and breach reporting commitments. Major healthcare-oriented offerings (Zoom for Healthcare, Microsoft Teams under Microsoft's BAA terms, Doxy.me, and EHR-integrated modules) meet these when configured correctly; free consumer tiers of the same brands often do not include BAA coverage. Configuration is on you: waiting-room controls, disabled unnecessary recording, scoped admin access, the BAA covers the vendor's side, not your settings.

How do we secure the remote-care environment itself?

Treat clinician endpoints and locations as part of the covered environment. Devices: managed or verified endpoints with encryption, screen lock, current patching, and no PHI stored locally without controls, personal devices need an enforceable BYOD policy. Networks: VPN or TLS-only access; no clinical sessions over open public Wi-Fi. Physical privacy: private rooms on both ends where feasible, headphones, and screen positioning, OCR's telehealth guidance treats overheard sessions as a real disclosure risk. Recordings: default off, and where used, stored as PHI with retention rules. Household members and smart speakers are the low-tech threats risk analyses skip; a documented remote-work safeguard policy plus training covers the gap.

Do website trackers really create telehealth HIPAA exposure?

Yes, this is the sharpest current risk. OCR's online-tracking guidance (issued 2022, revised 2024 after litigation trimmed parts of it) takes the position that IP addresses and identifiers collected on pages relating to an individual's health care can be PHI, and telehealth pages, appointment booking, provider search, symptom checkers, patient portal logins, are the paradigm cases. Analytics pixels sending that data to ad platforms without a BAA or authorization have driven hundreds of breach reports, class actions against health systems, and FTC actions (GoodRx, BetterHelp) where HIPAA did not reach. Practical floor: inventory every tracker, remove third-party ad tech from authenticated and health-related pages, and route necessary analytics through BAA-covered or first-party tooling.

What state-law issues stack on top of HIPAA for telehealth?

Three recurring layers. Consent: many states require documented patient consent to telehealth as a modality, separate from treatment consent. Recording: all-party consent states (California, Illinois, and others) make session recording without explicit consent a wiretap issue, HIPAA compliance does not cure it. Licensure and prescribing: the clinician generally must be licensed where the patient sits, with controlled-substance prescribing governed by Ryan Haight Act rules and evolving DEA telemedicine regulations. Add state health-data statutes, Washington's My Health My Data reaches telehealth data with a private right of action, and the compliance map is HIPAA plus a state matrix, checked per service line and per state served.

Regulatory Crosswalk

42 CFR Part 2FTC Health Breach Notification RuleState telehealth laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.