HIPAA Compliance by Vertical
HIPAA Compliance for Telehealth Platforms
HIPAA compliance for telehealth platforms — video PHI, asynchronous messaging, multi-state licensure, and the post-PHE enforcement environment.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- PHI in scope: Video and audio recordings of clinical encounters, Asynchronous chat and store-and-forward messaging, Connected device data (remote patient monitoring), Provider notes synchronized to the EHR.
- Start with these controls: End-to-end encryption for video and async messaging; BAA with the video platform vendor (Zoom for Healthcare, Doxy.me, etc.); BAA with every AI scribe / transcription vendor.
- The most common mistake: Using a consumer Zoom account instead of Zoom for Healthcare with a BAA
- A signed BAA is required with every vendor that touches PHI, and no tool is HIPAA compliant on its own.
PHI handled in this environment
- Video and audio recordings of clinical encounters
- Asynchronous chat and store-and-forward messaging
- Connected device data (remote patient monitoring)
- Provider notes synchronized to the EHR
- Patient-uploaded photos and documents
Common compliance pain points
- Recording and retention defaults: Most video platforms default to recording on. Without an explicit BAA-aligned retention policy, you accumulate PHI you do not need and cannot lawfully destroy without paperwork. Define retention up front, configure platform defaults to match, and document why.
- Multi-state and multi-payer routing: Different states have different data localization rules layered on top of HIPAA. California, Texas, and New York each have privacy statutes that may require additional safeguards beyond HIPAA. Telehealth that crosses state lines must reconcile the strictest applicable rule per session.
- Patient consent for non-encrypted channels: Patients who explicitly request unencrypted email/SMS communication can do so under HIPAA, but the consent must be documented. Telehealth platforms that allow it without that consent layer are creating systemic violations.
- Third-party scribes and transcription: AI scribes and transcription services touch the highest-value PHI in your stack — full clinical encounters. Each requires a current BAA, subcontractor disclosure, and documented retention/destruction.
Priority controls
- End-to-end encryption for video and async messaging
- BAA with the video platform vendor (Zoom for Healthcare, Doxy.me, etc.)
- BAA with every AI scribe / transcription vendor
- Documented retention policy with platform defaults aligned
- Patient consent capture for non-secure communication channels
- State-specific privacy controls layered on top of HIPAA
Common mistakes
- Using a consumer Zoom account instead of Zoom for Healthcare with a BAA
- Default video recording with no retention policy or destruction workflow
- AI scribe vendor in production without a current BAA
- No documented patient consent for SMS appointment reminders containing visit info
- Relying on the EHR vendor for breach notification without verifying their 60-day timeline matches yours
Enforcement context
After the COVID-19 Public Health Emergency ended in May 2023, OCR returned to active enforcement of HIPAA in telehealth contexts. Several settlements have specifically cited telehealth platforms or providers using non-BAA-covered consumer video services. The 2026 Security Rule update raises the floor further by mandating MFA, encryption, and continuous monitoring across all systems handling ePHI.
Frequently asked questions
What PHI do telehealth organizations handle?
Video and audio recordings of clinical encounters; Asynchronous chat and store-and-forward messaging; Connected device data (remote patient monitoring); Provider notes synchronized to the EHR; Patient-uploaded photos and documents. Any of these, combined with an identifier, is protected health information and brings the full Security Rule into scope.
What are the priority HIPAA controls for telehealth?
End-to-end encryption for video and async messaging; BAA with the video platform vendor (Zoom for Healthcare, Doxy.me, etc.); BAA with every AI scribe / transcription vendor; Documented retention policy with platform defaults aligned; Patient consent capture for non-secure communication channels; State-specific privacy controls layered on top of HIPAA.
What are the most common HIPAA mistakes in telehealth?
Using a consumer Zoom account instead of Zoom for Healthcare with a BAA; Default video recording with no retention policy or destruction workflow; AI scribe vendor in production without a current BAA; No documented patient consent for SMS appointment reminders containing visit info; Relying on the EHR vendor for breach notification without verifying their 60-day timeline matches yours.
What does HIPAA enforcement look like for telehealth?
After the COVID-19 Public Health Emergency ended in May 2023, OCR returned to active enforcement of HIPAA in telehealth contexts. Several settlements have specifically cited telehealth platforms or providers using non-BAA-covered consumer video services. The 2026 Security Rule update raises the floor further by mandating MFA, encryption, and continuous monitoring across all systems handling ePHI.