Skip to main content
Telehealth

Is Telehealth HIPAA-Compliant? A Health Informatics Reality Check

Telehealth is booming, but is it HIPAA-safe? We debunk the audio-only myth, explain the Security Rule, and tell you what to do before your next virtual visit.

Is Telehealth HIPAA-Compliant? A Health Informatics Reality Check

You’ve probably typed this into Google at 2 a.m., worried because you just had a video visit with your doctor and your toddler was screaming in the background while you tried to talk about a sensitive issue. Or maybe you’re a clinician who’s been told to “just use Zoom” for telehealth, and you’re wondering if that’s actually okay. Let’s get one thing straight: I’m not a lawyer, and I’m not your compliance officer. But as a health informatics editor who has spent years knee-deep in the standards and rules that govern digital health, I can tell you this: the technology isn’t the problem — the confusion about the rules is.

Here’s my blunt take: most telehealth platforms are perfectly capable of being HIPAA-compliant, but compliance is a shared responsibility that requires deliberate action from both the provider and the patient. And the biggest myth I keep seeing — that audio-only phone calls are automatically non-compliant — is not just wrong, it’s dangerously oversimplified. In fact, as of 2025, Medicare explicitly allows audio-only telehealth in certain situations (Federal Register, CY 2025 Physician Fee Schedule). So before you panic, let’s walk through the questions I actually get asked, and I’ll give you the straight answers.

Is telehealth HIPAA-compliant?

Yes, but only if you use the right tools and follow the right procedures. HIPAA applies to covered entities (health plans, clearinghouses, and providers who transmit health information electronically) and their business associates. If you’re a provider using a telehealth platform, that platform is likely a business associate — and you need a signed Business Associate Agreement (BAA) with them. The HIPAA Security Rule specifically requires safeguards for electronic protected health information (ePHI), and those safeguards fall into three buckets: administrative, physical, and technical (ONC/HHS, Health IT). So, a platform that offers end-to-end encryption and access controls is a good start, but you also need policies, training, and physical security measures at your end.

Can I use FaceTime or Skype for telehealth?

Short answer: only if you’re willing to take on the risk, because consumer apps like FaceTime and Skype are not designed with HIPAA in mind, and they typically won’t sign a BAA. For example, FaceTime is end-to-end encrypted, but it’s not clear whether Apple will sign a BAA for it, and it doesn’t offer the administrative controls that a telehealth-specific platform does. Compare that to a platform like Doxy.me or Zoom for Healthcare, which are explicitly built for HIPAA compliance and will sign a BAA. My recommendation: don’t cut corners here. The cost of a non-compliant platform is not worth the risk of a breach — and trust me, the Office for Civil Rights can hit you with penalties that hurt.

What about audio-only phone calls — are they allowed?

This is the myth I want to bust wide open. Many people think that telehealth must include video, or it’s not “real” telehealth. That’s false. In the CY 2025 Physician Fee Schedule final rule, CMS permanently revised the definition of an “interactive telecommunications system” to include two-way, real-time audio-only communication technology for any Medicare telehealth service furnished to a beneficiary in their home, as long as the practitioner is technically capable of audio-video and the patient doesn’t consent to video (Federal Register, CY 2025 Physician Fee Schedule). So, yes, audio-only is allowed under Medicare in specific circumstances. But here’s the catch: you need to document why video wasn’t used, and you need to make sure your audio platform is secure. A regular phone line is fine, but a random VoIP service might not be. The takeaway: audio-only isn’t automatically non-compliant, but it’s not a free pass to ignore security.

What’s the difference between HIPAA Privacy and Security Rules?

They’re complementary, but they cover different things. The Privacy Rule protects all PHI — oral, paper, electronic — and limits its use and disclosure without authorization (ONC/HHS, HIPAA Basics). The Security Rule specifically protects ePHI and requires three types of safeguards: administrative (like policies and training), physical (like locks on server rooms), and technical (like encryption and access controls) (eCFR 45 CFR Part 164 Subpart C). For telehealth, the Security Rule is your main concern, but you also need to comply with the Privacy Rule’s “minimum necessary” standard — meaning you should only share the minimum amount of information needed for the visit (eCFR 45 CFR Part 164 Subpart E). So, when you’re setting up a telehealth program, you need both: privacy policies and security controls.

What happens if there’s a breach during a telehealth visit?

If unsecured PHI is breached, the HIPAA Breach Notification Rule requires you to notify the affected individuals without unreasonable delay, and in no case later than 60 days after discovery (eCFR 45 CFR Part 164 Subpart D). That’s not just a suggestion — that’s a hard deadline. And the penalties for non-compliance can be steep. As of January 28, 2026, the annual penalty cap per calendar year is $2,190,294, and the maximum per violation is $73,011 for most tiers, or $2,190,294 for willful neglect that isn’t corrected within 30 days (Federal Register, 2026 HIPAA CMP Adjustment). So, if a breach happens because you used a non-compliant platform, you’re looking at a potential six-figure fine — not to mention the reputational damage. My advice: spend the money on a compliant platform and a solid risk assessment now, because the cost of a breach is far higher.

How do I know if a telehealth platform is HIPAA-compliant?

You can’t just take a vendor’s word for it. You need to do your due diligence. First, ask for a BAA — if they won’t sign one, move on. Second, check whether they use encryption and access controls that align with the Security Rule’s technical safeguards (eCFR 45 CFR Part 164 Subpart C). Third, review their audit logs and breach notification procedures. And finally, consider using standards like FHIR if you’re integrating with an EHR — FHIR (Fast Healthcare Interoperability Resources) is HL7’s modern standard that uses RESTful APIs and discrete resources like Patient and Observation (HL7 International). A platform that supports FHIR is likely thinking about interoperability, which is a good sign. Here’s a quick comparison table I put together to help you evaluate your options:

Feature Consumer Apps (FaceTime, Skype) Telehealth-Specific Platforms
BAA available Usually no Yes, typically
Encryption End-to-end sometimes Yes, often with more controls
Access controls Limited Yes, with user roles and permissions
Audit logs Limited or none Yes, typically available
Integration with EHR No Often via FHIR or APIs

That table is a starting point, not a checklist. But it’s clear that telehealth-specific platforms are generally safer for HIPAA compliance.

What’s the single most important thing to remember about telehealth and HIPAA?

Here it is: You are responsible for your own compliance, not the platform. A platform can provide encryption and a BAA, but if you don’t train your staff, don’t enforce access controls, and don’t follow the minimum necessary standard, you’re still on the hook. HIPAA is about policies and practices as much as it is about technology. So, before you schedule your next telehealth visit — or start a telehealth service — take the time to do a risk assessment, sign a BAA, and document everything. Because in the world of health informatics, “it’s just a phone call” is no excuse for a breach.

Sources

  • ONC / HHS (Health IT) - https://www.healthit.gov/topic/health-it-basics
  • eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  • eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688
  • HL7 International - https://www.hl7.org/fhir/

Share this article:

Comments (0)

No comments yet. Be the first to comment!