Skip to main content
Telehealth

Telehealth Isn't Dying: It's Getting Real, and Here's What That Means

Telehealth is maturing beyond the pandemic hype. I argue the real challenge is making it work within HIPAA and interoperability standards—here's a practical field guide for the wary clinician.

Everyone loves to say telehealth is dead—that the pandemic-era boom was a bubble and now we're back to the sterile exam room. That's wrong. Telehealth isn't dying; it's getting real. The wild-west days of video visits with no standards are over. What's emerging is a disciplined, data-heavy telehealth practice that demands you understand health IT, HIPAA, and interoperability. And if you're a clinician or a clinic manager, you ignore that at your peril.

Let's get concrete. Imagine you're a family physician in a small practice. You've been doing telehealth since 2020, but you've never thought much about the plumbing. You just log into your portal and talk to patients. Then, in 2026, you get a notice: your practice is being audited for HIPAA compliance, and your telehealth platform—the one you picked because it was cheap—fails the Security Rule's technical safeguards. You're facing a fine. What now?

The Misconception: Telehealth Is Just Video

If you think telehealth is just turning on a camera, you're missing the point. The real work is in the data. Telehealth is a health IT application, and under the hood, it's governed by the same rules as your EHR. The HIPAA Security Rule—which you're bound by as a covered entity—requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) (ONC / HHS (Health IT)). That means your telehealth platform must have access controls, encryption, and audit logs. The Access Control standard even includes addressable specifications like automatic logoff and unique user identification (eCFR 45 CFR Part 164 Subpart C (Security Rule)). So when you're shopping for a telehealth tool, you're not just buying a video link—you're buying a security system.

Here's the kicker: the stakes are higher than you think. The HIPAA civil monetary penalty cap for Tier 4 violations—willful neglect not corrected within 30 days—is now $2,190,294 (Federal Register (2026 HIPAA CMP Adjustment)). That's not a typo. One breach, one missed encryption, and you could be looking at millions. So the first order of business is to treat telehealth as a security project, not a convenience.

The Reality Check: Interoperability Is the Glue

But security is only half the story. The other half is making sure your telehealth data actually flows somewhere useful. If you're doing a video visit and then faxing the notes to the patient's primary care doc, you're not doing telehealth—you're doing a phone call with extra steps. Real telehealth requires interoperability.

That's where standards come in. The industry is moving toward FHIR (Fast Healthcare Interoperability Resources), which uses RESTful APIs to exchange discrete data like Patient, Encounter, and Observation (HL7 International). FHIR R4, published in 2018, was the first normative release, and it's the basis for the US Core Implementation Guide, which defines the minimum data elements for patient access (US Core Implementation Guide). And as of 2026, USCDI v3—which has 94 data elements across 19 classes—becomes the baseline for certified health IT (ONC / HHS (HTI-1 Final Rule)).

So when you're evaluating a telehealth platform, ask: does it support FHIR? Can it exchange data with your EHR using standards like HL7 v2 or FHIR? If not, you're building a silo, and silos are the enemy of good care. The CMS Interoperability and Patient Access rule already requires many payers to offer Patient Access APIs using FHIR R4 (Federal Register (CMS Interoperability and Patient Access Final Rule)). Your telehealth platform should be part of that ecosystem, not an island.

The Practical Playbook: What to Do Now

Let's walk through the steps you'd take in that audit scenario.

  • Conduct a risk assessment. NIST SP 800-66 Rev. 2 is your guide; it's the updated cybersecurity resource for implementing the HIPAA Security Rule (NIST SP 800-66 Rev. 2 (HIPAA Security Resource Guide)). Use it to identify gaps.
  • Check your business associate agreements. Your telehealth vendor is a business associate, and you're responsible for ensuring they protect PHI (eCFR 45 CFR Part 160 (HIPAA Definitions)). If they don't, you're on the hook.
  • Implement technical safeguards. Encrypt data in transit and at rest, enforce strong authentication, and enable automatic logoff. These aren't optional; they're the core of the Security Rule (eCFR 45 CFR Part 164 Subpart C (Security Rule)).

Quick tip: Don't forget audio-only visits. In 2025, CMS finalized a rule allowing audio-only telehealth when the patient can't or won't do video, but only if the practitioner is technically capable of video (Federal Register (CY 2025 Physician Fee Schedule)). So you need to document why you used audio-only—that's a compliance landmine.

The Bottom Line: Telehealth Is a System, Not a Feature

Telehealth is maturing from a novelty into a standard care modality, and that means it's subject to the same rules and expectations as any other health IT. If you treat it as a video call, you'll fail. If you treat it as a secure, interoperable extension of your EHR, you'll thrive. The 96% of hospitals and 78% of physicians using certified health IT (ONC / HHS (HTI-1 Final Rule)) are not going back to paper. Neither should you.

My recommendation: don't wait for an audit. Start now by reviewing your telehealth platform against the HIPAA Security Rule and the USCDI standards. The cost of ignoring it is not just a fine—it's patient trust. And in the end, that's the only currency that matters.

Sources

  • ONC / HHS (Health IT) - https://www.healthit.gov/topic/health-it-basics
  • eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
  • ONC / HHS (HTI-1 Final Rule) - https://healthit.gov/regulations/hti-rules/hti-1-final-rule/
  • NIST SP 800-66 Rev. 2 (HIPAA Security Resource Guide) - https://csrc.nist.gov/pubs/sp/800/66/r2/final
  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382

Share this article:

Comments (0)

No comments yet. Be the first to comment!