Skip to main content
Telehealth

Telehealth Security: What Practitioners Actually Need to Know

Telehealth isn't just video visits. We debunk myths about HIPAA, audio-only care, and data sharing, and give you the real-world essentials for secure virtual practice.

Imagine you're a clinician about to start your first telehealth shift. You've got your laptop, a headset, and a list of patients. But then the practice manager says, "Make sure it's HIPAA compliant." You pause—what does that even mean for a video call? You're not alone. Many of us in health informatics have been there, and the confusion is understandable. Telehealth regulations and standards are a patchwork, and the stakes are high: a breach can cost you more than your reputation. So let's cut through the noise and answer the questions we actually get from colleagues.

Is Telehealth Even HIPAA-Compliant?

Yes, but only if you use the right tools and follow the rules. HIPAA applies to any electronic protected health information (ePHI), which includes video, audio, and text exchanged during telehealth. The Privacy Rule covers PHI in any medium, while the Security Rule specifically protects ePHI (ONC / HHS (HIPAA Basics)). That means your telehealth platform must have safeguards like encryption and access controls, and you need a business associate agreement (BAA) with the vendor. A BAA is a contract where the vendor agrees to handle your patients' data responsibly—without it, you're likely violating HIPAA.

Can I Use FaceTime or Zoom for Telehealth?

Only if you have a BAA with the vendor and the product is configured to meet HIPAA requirements. Consumer-grade video apps are not designed for healthcare. Even if a platform claims to be HIPAA-compliant, you must enable the security features—like encryption and access controls—and have that BAA in place. Otherwise, you're risking a breach. For most practices, a dedicated telehealth platform that offers BAAs and is designed for clinical use is the safer bet.

What About Audio-Only Calls? Are They Allowed?

Yes, and this is a common misconception. Many assume telehealth requires video, but Medicare has permanently allowed audio-only for certain services. Specifically, the CY 2025 Physician Fee Schedule finalized a revision to the definition of an 'interactive telecommunications system' to include two-way, real-time audio-only communication for telehealth services furnished to a beneficiary in their home, when the distant-site practitioner is technically capable of audio-video and the patient cannot or does not consent to video (Federal Register (CY 2025 Physician Fee Schedule)). So audio-only is a legitimate option, but you must document why video wasn't used.

How Do I Keep Patient Data Secure During a Telehealth Visit?

The HIPAA Security Rule outlines three categories of safeguards: administrative, physical, and technical (ONC / HHS (Health IT)). For telehealth, technical safeguards are key: unique user IDs, automatic logoff, and encryption are required or addressable (eCFR 45 CFR Part 164 Subpart C (Security Rule)). That means your platform should encrypt data in transit and at rest, and you should use strong passwords and multi-factor authentication. Also, be careful where you take calls—don't use a public Wi-Fi without a VPN, and ensure your physical environment is private.

Can I Text My Patients? What About Email?

Yes, but with the same precautions. Texting and email can be HIPAA-compliant if you use secure messaging platforms with encryption and BAAs. Standard SMS and unencrypted email are risky because they can be intercepted. The minimum necessary standard applies: you should only share the information needed for the purpose (eCFR 45 CFR Part 164 Subpart E (Privacy Rule)). So, for reminders, a simple text is fine, but for clinical details, use a secure portal.

What Happens If There's a Breach?

You have to notify patients, and there are penalties. Under the Breach Notification Rule, you must notify each individual whose unsecured PHI was breached without unreasonable delay, and no later than 60 days after discovery (eCFR 45 CFR Part 164 Subpart D (Breach Notification)). Financially, HIPAA penalties can be steep: the calendar-year cap for HIPAA penalties was raised to $2,190,294 for 2026, and the maximum per violation is $73,011 for most tiers (Federal Register (2026 HIPAA CMP Adjustment)). So a single breach can be costly, not to mention the damage to your reputation.

Is Telehealth Data Interoperable? Can I Share Records Easily?

It's improving. Historically, telehealth platforms were siloed, but now we have standards like FHIR that make data sharing easier. FHIR uses RESTful APIs and resources like Patient and Observation (HL7 International). The U.S. Core Data for Interoperability (USCDI) defines what data elements must be shared, and USCDI v3 expanded to 94 data elements in 19 classes (ONC Standards Bulletin 2022-2 (USCDI v3)). For telehealth, that means your visit notes and vitals can be pushed to the patient's EHR if your systems support FHIR. But not all platforms do, so check with your vendor.

What Is the Biggest Mistake Practices Make?

Assuming that because a tool is popular, it's compliant. For example, using a consumer video app without a BAA is a common and dangerous error. Another mistake is neglecting to train staff on security policies. The Security Rule requires administrative safeguards, including workforce training (eCFR 45 CFR Part 164 Subpart C (Security Rule)). You can have the best technology, but if your staff doesn't know how to use it securely, you're at risk.

Telehealth ToolHIPAA-Compliant?Key Requirements
Dedicated telehealth platform (e.g., Doxy.me, Zoom for Healthcare)Yes, if configuredBAA, encryption, access controls
Consumer video apps (FaceTime, Skype)No, unless BAABAA from vendor, encryption enabled
Audio-only phone callsYes, under conditionsPatient consent, documentation
Secure messaging apps (e.g., Spok, TigerConnect)Yes, if BAABAA, encryption, audit logs
  • Always sign a BAA with your telehealth vendor.
  • Use strong authentication and encryption.
  • Document patient consent for audio-only visits.

Quick tip: Before your first telehealth session, run a test call with a colleague to ensure video and audio work, and that your background isn't exposing patient info on a whiteboard.

Sources

  • ONC / HHS (HIPAA Basics) - https://www.healthit.gov/topic/privacy-security-and-hipaa/hipaa-basics
  • eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  • eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688

Remember: The most important thing is to treat telehealth with the same rigor as in-person care—secure the data, document properly, and stay informed.

Share this article:

Comments (0)

No comments yet. Be the first to comment!