Did You Know That 96% of Hospitals Now Offer Telehealth? Here's the Catch.
By 2021, 96 percent of U.S. non-federal acute care hospitals had adopted certified health IT (ONC / HHS (Report to Congress)). That's the good news. The catch? Your telehealth program might be leaking PHI through a channel you didn't even know existed: audio-only calls. And I'm not talking about the video call that drops to audio. I'm talking about a deliberate, policy-driven decision to allow audio-only visits for patients at home.
You're probably thinking, “Audio-only? That's not telehealth. That's a phone call.” Wrong. As of the CY 2025 Physician Fee Schedule, CMS permanently revised the definition of an “interactive telecommunications system” to include two-way, real-time audio-only communication for Medicare telehealth services furnished to a beneficiary in their home—when the provider is technically capable of audio-video and the patient can't or doesn't consent to video (Federal Register (CY 2025 Physician Fee Schedule)). That means audio-only is now a legitimate telehealth modality, and it's subject to the same HIPAA rules as video. But here's the problem: many health systems have built their telehealth programs around video-only, and they've forgotten to secure the audio-only back door.
I'm going to walk you through the real questions I hear from IT directors and privacy officers, and I'll debunk the biggest myth about telehealth and HIPAA along the way.
Is an Audio-Only Telehealth Visit Actually Covered by HIPAA?
Yes, and if you think otherwise, you're in for a rude awakening. HIPAA's Privacy Rule protects individually identifiable health information in any form or medium, including electronic media (eCFR 45 CFR Part 160 (HIPAA Definitions)). An audio-only call that involves a provider discussing a patient's condition is PHI, plain and simple. The Security Rule applies because that PHI is transmitted electronically. So, that 20-minute phone call to a patient's cell phone? It's ePHI.
But here's the nuance: the Security Rule is scalable. You don't need the same level of encryption for a phone call as you do for a patient portal. The key is to conduct a risk analysis and implement reasonable safeguards. NIST SP 800-66 Rev. 1, the official implementation guide, emphasizes that it's about addressing your specific risks, not a one-size-fits-all checklist (NIST SP 800-66 (HIPAA Security Guide)). So, don't panic—but do plan.
Do I Need to Get Patient Consent for Audio-Only Telehealth?
No, not specifically for HIPAA. Consent for treatment is a separate matter, but HIPAA's Privacy Rule allows treatment-related communications without a specific authorization. The bigger issue is notice: you still need to provide your Notice of Privacy Practices, just as you would for any other encounter. And under the Privacy Rule's minimum necessary standard, you should only use or disclose the minimum PHI needed for the purpose (eCFR 45 CFR Part 164 Subpart E (Privacy Rule)). In practice, that means don't ask the patient to spell out their full Social Security number over the phone if you don't need it for the visit. Keep it to what's necessary.
What About Encryption? Is a Regular Phone Call Secure Enough?
This is where the myth-busting comes in. Many people think that a standard phone call is “no big deal” because it's not the internet. But HIPAA doesn't mandate specific technologies; it requires that you implement technical safeguards to protect ePHI. The Security Rule's technical safeguards include access control, audit controls, integrity, and transmission security (eCFR 45 CFR Part 164 Subpart C (Security Rule)). For audio-only, transmission security means you should use encryption where feasible—like a secure VoIP app with end-to-end encryption—rather than the plain old telephone system (POTS).
But here's the kicker: if you're using a business associate, like a telehealth platform, you need a BAA. And that BAA must be in place before any PHI is shared. A business associate is anyone who creates, receives, maintains, or transmits PHI on your behalf (eCFR 45 CFR Part 160 (HIPAA Definitions)). If your audio-only platform doesn't have a BAA, you're in violation, even if the call is encrypted. I've seen health systems assume that because they're using a major telecom provider, they're covered. Not necessarily. Check your vendor contracts.
What Are the Real Penalties if I Screw This Up?
Let's talk numbers, because that's what gets leadership's attention. The maximum penalty for a willful neglect violation that isn't corrected is now $2,190,294 per violation category (Federal Register (2026 HIPAA CMP Adjustment)). That's not a typo. And the per-violation cap for Tiers 1-3 is $73,011. For a small clinic, one mistake could bankrupt you. But the bigger risk is the cumulative impact of multiple violations. The Breach Notification Rule requires you to notify patients within 60 days of discovering a breach of unsecured PHI (eCFR 45 CFR Part 164 Subpart D (Breach Notification)). That's a lot of notification letters, not to mention the reputational damage.
So, Should I Just Ban Audio-Only Telehealth Altogether?
No, that's the wrong answer. Banning audio-only would be a disservice to your patients. Many patients, especially in rural areas or with limited broadband, rely on audio-only. The whole point of CMS's rule is to expand access. Instead, you need a policy that addresses the risks. Start with a risk assessment: which staff are using audio-only, what platforms are they using, and are those platforms secure? Then, implement training so that staff know to verify patient identity before discussing PHI, and to use encrypted platforms when possible. If you don't have an encrypted platform, you can still use a standard phone line, but you must document the risk and implement mitigations, like calling from a private office and not a speakerphone.
What About Business Associate Agreements for Audio-Only Platforms?
This is a big one. If you're using a telehealth platform that supports audio-only, you absolutely need a BAA. And don't assume that a platform that's HIPAA-compliant for video is automatically compliant for audio. Read the fine print. Some platforms have different security features for audio-only modes. I recommend you audit every vendor that touches your PHI, even for phone calls. That includes your VoIP provider if you're using one.
How Do I Train Staff to Handle Audio-Only Visits?
Training is your safety net. Staff need to know the basics: don't leave PHI on voicemail, verify the patient's identity before discussing anything, and be aware of their surroundings. A nurse calling from a busy nurses' station on speakerphone is a violation waiting to happen. The Security Rule's administrative safeguards require that you train your workforce on security policies (eCFR 45 CFR Part 164 Subpart C (Security Rule)). Make it practical: role-play a scenario where a patient calls and asks for test results. What should the staff member say? They should verify the patient's identity, then discuss the results, but they should also check that the patient is in a private place. It's common sense, but you'd be surprised how often it's overlooked.
Bottom Line
Audio-only telehealth is here to stay, and it's a legitimate way to provide care. But it's also a HIPAA liability if you treat it as an afterthought. The single best move you can make is to conduct a risk assessment specific to audio-only visits, update your policies and BAAs, and train your staff on the do's and don'ts. That's not just a compliance exercise—it's good medicine. Because when you protect your patients' PHI, you protect their trust.
Sources
- ONC / HHS (Report to Congress) - https://healthit.gov/news/onc-outlines-health-it-interoperability-progress-report-congress/
- eCFR 45 CFR Part 160 (HIPAA Definitions) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
- eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
- eCFR 45 CFR Part 164 Subpart E (Privacy Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E
- Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!