Telehealth kept its pandemic scale but lost its pandemic permissions. The enforcement discretion that let providers see patients over any video app died with the public health emergency, and since November 2023 the ordinary machinery, BAA-covered platforms, risk-analyzed workflows, secured endpoints, applies to every visit. The quieter exposure sits in front of the video call: the scheduling pages, symptom checkers, and portal logins whose trackers have generated more breach reports and litigation than the sessions themselves. A telehealth program is compliant when its whole path is, from the first page view to the closing click.
| Discretion ended | PHE end May 11, 2023; transition closed Nov 6, 2023 |
|---|---|
| Platform floor | BAA + encryption, authentication, audit capability |
| No such thing | ”HIPAA-certified” software |
| Remote perimeter | Endpoints, networks, rooms, recordings |
| Sharpest risk | Trackers on health-related web pages |
Building the compliant stack
Re-paper the pandemic stack. Every telehealth tool gets a BAA and a configuration review; discretionary-era tolerance is gone.
Extend the risk analysis to the living room. Remote endpoints, home networks, and recording flows belong in the security risk assessment, the unassessed vector is the enforcement pattern.
Strip ad tech from health pages. OCR’s tracking position plus FTC actions make third-party pixels on scheduling and portal pages the top remediation item; the breach playbook covers what happens if they already fired.
Run the state matrix. Telehealth consent, recording consent, and licensure bind per patient location; OCR enforcement trends cover the federal side.
Your telehealth front door is a webpage: find out what it sends to third parties with a free scan.