Skip to main content
Telehealth

Telehealth's Hidden HIPAA Trap: Why Your Video Visits Could Cost You $2.19M

Think telehealth is just a HIPAA checkbox? The real risk is in the details—audio-only visits, business associates, and breach notification deadlines. Here's how to avoid the $2.19M penalty.

The Myth: Telehealth Is Just a Video Call

You've heard it a hundred times: "Telehealth is just a video call—what's the big deal?" That's wrong, and it's the kind of thinking that gets healthcare providers fined and patients' data leaked. Telehealth isn't a technology; it's a clinical workflow that happens to use health IT. And like any workflow involving protected health information (PHI), it's governed by HIPAA rules that most people gloss over until it's too late. The myth is that HIPAA compliance is a one-time checkbox. The reality is that telehealth introduces unique vulnerabilities—from the device on the patient's kitchen table to the business associate who stores your recordings—that can turn a routine visit into a six-figure fine. This article is your blunt, practical guide to the telehealth HIPAA traps you're probably ignoring.

Is a Video Visit Even HIPAA-Covered?

Yes, and that's the first surprise. A video visit involves your patient's individually identifiable health information—their name, their symptoms, their diagnosis—which is PHI under 45 CFR 160.103. The HIPAA Privacy Rule covers PHI in any medium, not just paper or EHRs. (ONC / HHS (HIPAA Basics)) So when you're on that call, you're handling PHI, and the Security Rule's protections for ePHI kick in if you're storing or transmitting any of it electronically—which you are, during the call and when you record it. That means you need administrative, physical, and technical safeguards in place, not just a password on your laptop.

But I'm Using a Secure Platform—Aren't I Safe?

Secure platform or not, you're still responsible for what happens to the data. The HIPAA Security Rule has three safeguard categories: administrative, physical, and technical. (ONC / HHS (Health IT)) Your video platform might handle the technical side—encryption, access controls—but you're still on the hook for administrative safeguards like workforce training and risk analysis. And don't forget physical safeguards: who can walk into your office and see a screen with a patient's face? A breach isn't just a hacker; it's a lost laptop or an unlocked exam room. The platform is a tool, not a shield.

What About Audio-Only Visits? Do Those Count?

Here's a trap: until recently, Medicare only paid for audio-video telehealth. But in the CY 2025 Physician Fee Schedule final rule, CMS permanently allowed audio-only for certain services when the patient is in their home and can't or won't use video. (Federal Register (CY 2025 Physician Fee Schedule)) That's a policy change, not a HIPAA exemption. Audio-only visits still involve PHI—you're discussing symptoms and diagnoses—so they're fully subject to the Privacy and Security Rules. Many providers think "audio-only" means "HIPAA-lite." It doesn't. The same breach notification deadlines apply.

Who's Responsible If My Telehealth Vendor Leaks Data?

Your telehealth vendor is likely a business associate—defined as someone who creates, receives, maintains, or transmits PHI on your behalf. (eCFR 45 CFR Part 160 (HIPAA Definitions)) That means you need a business associate agreement (BAA), and you're still liable if they screw up. The HIPAA Breach Notification Rule says you must notify affected individuals no later than 60 calendar days after discovering a breach. (eCFR 45 CFR Part 164 Subpart D (Breach Notification)) So if your vendor has a breach, the clock starts when you learn about it—not when they tell you. You can't outsource responsibility; you can only outsource the work.

What Are the Real Penalties for Getting This Wrong?

Let's talk money, because that's what gets attention. The HIPAA civil monetary penalty cap for a calendar year is now $2,190,294, adjusted for inflation as of January 2026. (Federal Register (2026 HIPAA CMP Adjustment)) The maximum per violation is $73,011 for most tiers, but if you've got willful neglect and don't fix it within 30 days, you're looking at the full $2.19 million per year. (Federal Register (2026 HIPAA CMP Adjustment)) That's not a rounding error. A single telehealth breach, if you've ignored the Security Rule, could put you out of business.

So, What Should You Actually Do?

Stop treating telehealth as a side project. Here's a concrete example: Suppose you're a small practice using a popular telehealth app. You need to (1) sign a BAA, (2) do a risk analysis of that app—how does it store recordings? Who has access? (3) train your staff on the minimum necessary standard—don't share more PHI than needed, (4) have a breach response plan that can trigger the 60-day notification, and (5) check if your malpractice insurance covers telehealth. The table below breaks down the key areas:

Area What You Must Do Common Mistake
Business Associate Agreement Have a BAA with your video vendor Assuming "secure" means no BAA needed
Breach Notification Notify individuals within 60 days of discovery Waiting for the vendor to report first
Minimum Necessary Limit PHI to what's needed for the visit Sharing patient data with billing staff unnecessarily
Security Safeguards Implement administrative, physical, technical controls Only relying on the platform's encryption

The single most important thing to remember: Telehealth is not exempt from HIPAA. It's a clinical process that demands the same safeguards as any other PHI exchange. Get the BAA, train your staff, and have a breach plan—because the $2.19 million penalty is a real number, and it's counting on you to be careless.

Sources

  • ONC / HHS (HIPAA Basics) - https://www.healthit.gov/topic/privacy-security-and-hipaa/hipaa-basics
  • eCFR 45 CFR Part 160 (HIPAA Definitions) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
  • eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382

Share this article:

Comments (0)

No comments yet. Be the first to comment!