Skip to main content
Telehealth

Telehealth: Stop Ignoring Audio-Only and Start Complying with HIPAA

You think video is the only way to do telehealth? That's wrong. Audio-only is now a permanent Medicare option. Here's how to build a compliant, practical program.

Who This Is For

If you're a small practice or a health IT vendor trying to make sense of telehealth, this is for you. You've heard the hype about video visits and remote monitoring, but you're ignoring the simplest tool you already have: the telephone. And you're probably also ignoring the HIPAA rules that apply to every call, text, or email you send. Let's fix that.

The Contrarian Take: Audio-Only Is Not a Fallback

Common advice says telehealth means video, video, video. But the federal government just made audio-only a permanent part of Medicare telehealth. In the CY 2025 Physician Fee Schedule final rule, CMS finalized a permanent revision to the definition of an 'interactive telecommunications system' to include two-way, real-time audio-only communication technology for any Medicare telehealth service furnished to a beneficiary in their home, when the distant-site practitioner is technically capable of audio-video and the patient is not capable of or does not consent to video (Federal Register, CY 2025 Physician Fee Schedule). That's not a temporary pandemic waiver. That's a permanent change. If you're not offering audio-only, you're turning away patients who need you.

Step 1: Know What Telehealth Really Is

Telehealth is a subset of health information technology, which uses hardware and software to store, share, retrieve, and analyze health information among patients, providers, and payers (ONC / HHS, Health IT). It's not just video visits. It's any remote interaction that uses electronic communications to exchange health information. That includes phone calls, patient portals, and even secure messaging. So when you think about telehealth, think about every channel you use to communicate with patients, not just the ones with a camera.

Step 2: Treat Every Call Like a HIPAA Compliance Test

Here's where most people get sloppy. They assume that because they're a doctor or a small clinic, HIPAA doesn't apply to them. Wrong. Under HIPAA, a 'covered entity' is a health plan, a health care clearinghouse, or a health care provider that transmits health information in electronic form in connection with a covered transaction (eCFR 45 CFR Part 160). That's you. And your business associates – your telehealth platform vendor, your answering service, even your cloud storage provider – are also subject to HIPAA rules if they handle protected health information (PHI) on your behalf (45 CFR 160.103). So the first step is to get a business associate agreement with anyone who touches your patient data. No exception.

Step 3: Apply the Minimum Necessary Standard

When you're on a phone call with a patient, you don't need to discuss their full medical history. The HIPAA Privacy Rule's 'minimum necessary' standard requires that, when using or disclosing PHI, a covered entity or business associate must make reasonable efforts to limit the information to the minimum necessary to accomplish the intended purpose (45 CFR 164.502(b)). That means on an audio-only call, you should only ask for and share the information you need for that visit. If you're billing for a telehealth visit, you don't need to read the patient's entire chart aloud. Keep it minimal.

Step 4: Lock Down Your Security

The HIPAA Security Rule requires three categories of safeguards: administrative, physical, and technical (ONC / HHS, Health IT). The technical safeguards (45 CFR 164.312) include access control – i.e., who can log into your systems and what they can see. You need to have unique user IDs, automatic logoff, and encryption if you're transmitting ePHI. Don't think you're too small to be a target. The penalty for a HIPAA violation can be up to $2,190,294 per violation for willful neglect not corrected within 30 days (Federal Register, 2026 HIPAA CMP Adjustment). That's not a typo. That's a seven-figure fine.

Step 5: Choose Your Tech – But Don't Overthink It

If you're building a telehealth program, you have a choice between legacy standards like HL7 Version 2 and modern APIs like FHIR. HL7 v2 remains the standard for high-throughput legacy workflows, while FHIR is favored for developer-facing, mobile, and cloud-native applications (HL7 International). For a small practice, you probably don't need to build your own platform. But if you're a vendor, you need to make a choice. Let's compare:

Criterion HL7 v2 FHIR
Adoption Used by over 95% of US healthcare organizations (HL7 International) Modern, growing; R5 defines 157 resources (HL7 FHIR, Resource Index)
Best for Legacy systems, high-volume messaging Mobile apps, cloud-native, patient access
Complexity Mature, but complex and inflexible RESTful, easier for developers

If you're starting fresh, I'd lean toward FHIR, especially if you want to comply with US Core and the information blocking rules. But don't rip out a working HL7 v2 system just to be trendy.

Step 6: Don't Forget the Information Blocking Rule

Telehealth isn't just about getting patients to you. It's about sharing data with them and other providers. The 21st Century Cures Act made sharing electronic health information the expected norm, and information blocking is a practice that interferes with access, exchange, or use of EHI (ONC / HHS, Information Blocking). If you're a provider, you're an 'actor' under the rule. That means you can't refuse to give a patient their records just because you're using a telehealth platform that doesn't integrate well. You need to make sure your telehealth vendor doesn't create a barrier to data sharing.

Step 7: Audit Your Telehealth Program Regularly

Finally, don't set it and forget it. The HIPAA Security Rule requires ongoing risk analysis and management (45 CFR 164.308). That means you should regularly review who has access to your systems, what data is being transmitted, and whether your business associates are compliant. The NIST SP 800-66 guide can help you understand the Security Rule, but it doesn't replace it (NIST SP 800-66).

Quick tip: Before your first audio-only visit, test your call recording feature. If you record calls, that recording is PHI and must be stored securely.

What I'd Actually Do

Here's my blunt recommendation: Start offering audio-only visits tomorrow. Don't wait for a video platform. Use a HIPAA-compliant phone service or a secure telehealth app that supports audio-only. Get a business associate agreement with your vendor. Apply the minimum necessary standard to every call. And make sure your security is up to snuff – because one breach could cost you millions. The era of telehealth is here, and audio-only is a permanent part of it. Embrace it, or get left behind.

Sources

  • ONC / HHS (Health IT) - https://www.healthit.gov/topic/health-it-basics
  • eCFR 45 CFR Part 160 (HIPAA Definitions) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
  • eCFR 45 CFR Part 164 Subpart E (Privacy Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E
  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688
  • HL7 International - https://www.hl7.org/fhir/
  • HL7 FHIR (Resource Index) - https://www.hl7.org/fhir/resourcelist.html
  • ONC / HHS (Information Blocking) - https://www.healthit.gov/topic/information-blocking

Share this article:

Comments (0)

No comments yet. Be the first to comment!