Skip to main content
Telehealth

Telehealth Audio-Only: The HIPAA Fine Print You Can't Afford to Skip

Audio-only telehealth is now permanent for Medicare, but HIPAA compliance hinges on your technology and policies. Here's what practitioners must know.

You're a clinician or a health IT lead, and you've just heard that Medicare will now pay for audio-only telehealth visits. Your first question is probably: “Great, but what do I need to do to stay HIPAA compliant?” It's a fair question, and the answer isn't as simple as “just use any phone.” Let's cut through the noise.

Is audio-only telehealth really a thing now?

Yes, and it's about time. In the CY 2025 Physician Fee Schedule final rule, CMS permanently revised the definition of an “interactive telecommunications system” to include two-way, real-time audio-only communication for any Medicare telehealth service furnished to a beneficiary in their home—as long as the distant-site practitioner is technically capable of audio-video, but the patient is not capable of or does not consent to video (Federal Register CY 2025). That's a big deal for patients in rural areas or with limited broadband. But here's the catch: this change is about Medicare coverage, not HIPAA. You can have a covered telehealth service that still violates HIPAA if you're not careful.

Do I need video for HIPAA compliance if I'm doing audio-only?

No, and this is a common misconception. HIPAA's Security Rule applies to electronic protected health information (ePHI) in any form, including audio. The Security Rule requires you to implement administrative, physical, and technical safeguards to protect ePHI—whether it's transmitted over a video platform or a plain phone line (45 CFR 164.308, 164.310, 164.312). That means you need to ensure the audio connection is secure, encrypted where possible, and that you have policies and training in place. The fact that you're not using video doesn't exempt you from HIPAA. In fact, the Privacy Rule's minimum necessary standard still applies: you should limit the PHI you disclose to what's needed for the visit (45 CFR 164.502(b)).

What about using a regular phone line? Is that okay?

It can be, but you need to assess the risks. A standard landline might be acceptable if you have a private setting and you're not recording the call. But if you're using a cell phone or VoIP, you need to ensure the connection is encrypted. The HIPAA Security Rule requires you to protect ePHI from unauthorized access, and encryption is an addressable implementation specification—meaning you must either implement it or have an equivalent alternative. In practice, that means using a secure telehealth platform that offers end-to-end encryption, rather than just dialing a patient's cell phone from your personal smartphone. If you do use a regular phone, you must have a documented risk analysis and policies to mitigate the risks. The Office for Civil Rights has made it clear that you can't just “wing it.”

What are the real penalties for getting this wrong?

This is where it gets serious. For HIPAA violations, the civil monetary penalties are adjusted annually for inflation. As of January 28, 2026, the maximum penalty per violation is $73,011 for Tiers 1–3 (lack of knowledge, reasonable cause, and willful neglect corrected within 30 days), and for Tier 4—willful neglect not corrected within 30 days—the cap is $2,190,294 per violation (Federal Register 2026). And remember, that's per violation, not per incident. If you have a breach affecting multiple patients, the fines can add up quickly. The calendar-year cap is $2,190,294, but that's the maximum, not the typical. Still, the risk is real. And don't forget the Breach Notification Rule: if unsecured PHI is breached, you have to notify each affected individual no later than 60 calendar days after discovery (45 CFR 164.404). That's a lot of paperwork and reputational damage.

What's the one thing I should do right now?

Stop assuming that audio-only is “low risk” and start treating it like any other telehealth encounter. That means: use a HIPAA-compliant telehealth platform, even for audio-only calls, or have a documented risk assessment for using a standard phone. Train your staff on the specific policies for audio-only visits, including how to verify patient identity and ensure privacy. And finally, remember that the patient's consent matters—if they don't consent to video, you can still do audio, but you need to document that. The most important thing to remember is this: HIPAA doesn't care if you're using video or audio—it cares that you're protecting the patient's information. So, before you make that next call, ask yourself: is this connection secure? If you can't answer yes, don't make the call.

Quick tip: Always document the patient's consent for audio-only, and note why video wasn't used—that's your best defense if a complaint arises.

Sources

  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
  • eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  • eCFR 45 CFR Part 164 Subpart E (Privacy Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688
  • eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D

Share this article:

Comments (0)

No comments yet. Be the first to comment!