Adhesive Capsulitis Telehealth Intake: A Privacy Guide
Count the systems that touch one telehealth shoulder visit at your practice. Scheduling widget on the website. Online intake form vendor. Photo or video upload tool. The video platform itself. Ambient or manual transcription. The EHR. The e-fax or direct message that sends records to the orthopedic group. That is seven vendors for a single adhesive capsulitis follow-up, and at least five of them hold protected health information at rest.
This post is for the person who signs those contracts and answers the records request thirty days later. It is not clinical guidance and contains none. It is a workflow map: where consent lives, which vendors need a Business Associate Agreement, how the referral disclosure works, and what happens when the patient asks for the recording.
Why an Adhesive Capsulitis Encounter Generates Cross-Organization Records Traffic
You do not need to know anything about the shoulder to administer this workflow. You need to know one uncontroversial operational fact: this is a condition that commonly involves a primary care visit, a specialist referral, imaging, and a course of physical therapy — often at three or four different tax IDs.
That structure is the whole administrative story. Records leave your organization. Records arrive from organizations you did not vet. Consent forms signed in your portal do not travel with the patient. Your release-of-information queue fills with requests from PT clinics that have their own intake stack and their own idea of what "send everything" means.
A telehealth-first workflow adds a layer. The intake now happens on the patient's phone, sometimes days before the visit, through a vendor your practice manager selected because it integrated cleanly with the calendar. That vendor is a business associate. Whether it is under agreement is a separate question, and it is the one that shows up in an OCR data request.
The Pre-Visit Intake Form Is Part of the Designated Record Set
Administrators routinely treat the online intake form as a scheduling artifact — something that feeds the chart and then stops mattering. It does not stop mattering. If the clinician used it to make decisions about the patient, it belongs to the designated record set, and the patient can request it.
Photo and Video Uploads Need a Named Owner
Telehealth intake for musculoskeletal complaints frequently asks the patient to upload a short video or a few photos before the visit so the clinician can review them without burning call time. Those files are PHI the moment they land.
Three questions your privacy officer should be able to answer in under a minute:
- Where do the files physically rest — the form vendor's storage bucket, the video platform, or the EHR?
- What is the retention period in that vendor's system, and does it match your record retention policy?
- If the patient revokes and asks for deletion of the upload, who executes that in the vendor console, and how is it logged?
In most practices I have reviewed, the honest answer to the first question is "all three," and nobody has ever deleted anything from the form vendor. That is a defensible position only if your BAA and your retention schedule say so on purpose.
Free-Text Fields Are Where Sensitive Data Hides
An intake form for an adhesive capsulitis visit typically includes an open box: "anything else you want the clinician to know." Patients use that box for substance use history, mental health treatment, immigration status, and domestic violence disclosures. Your form vendor's search index, backup exports, and support-team access controls now apply to that content.
Ask the vendor directly whether their support staff can read submission contents in the clear, and whether that access is logged. Get the answer in writing before renewal.
Do You Need a BAA With Your Telehealth Video Vendor?
Yes, in nearly every case. If a vendor creates, receives, maintains, or transmits PHI on your behalf, it is a business associate and requires a signed Business Associate Agreement before it touches patient data. A telehealth platform transmitting a live encounter, storing a recording, or generating a transcript meets that test.
The narrow exception is the conduit exception, and it is far narrower than vendors claim. It covers entities that merely transport data without accessing it beyond what is random or infrequent — think the postal service or a plain internet service provider. A platform that stores video, retains chat logs, or produces transcripts is not a conduit. Encryption alone does not convert a vendor into a conduit either.
Note also that the enforcement discretion OCR extended to non-public-facing telehealth technologies during the COVID-19 public health emergency ended in 2023, with a short transition period after. There is no standing exception for telehealth platforms anymore. HHS publishes sample business associate agreement provisions if you want to see the baseline required terms.
If your vendor list has grown faster than your contract file — and after two years of telehealth expansion, it probably has — you can produce a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase rather than a subscription. That is usually faster than waiting three weeks for a vendor to send back their own template with the indemnification stripped out.
Mapping the Vendors in One Telehealth Encounter
Build this map once for a representative visit type and reuse it. Here is the version for a telehealth adhesive capsulitis consultation, with the compliance question attached to each stop.
- Website scheduling widget. Is it collecting appointment reason on an unauthenticated page? Are third-party analytics or ad pixels loading on that page?
- Intake form vendor. BAA on file, dated before first PHI transmission. Retention schedule documented.
- File upload / media storage. Often a subprocessor of the form vendor. Named in the BAA's subcontractor flow-down clause?
- Video platform. BAA on file. Recording default set intentionally, not left at the vendor's factory setting.
- Transcription or documentation assistant. BAA on file. Written confirmation of whether encounter data is used to train models, and whether you opted out.
- EHR. Under contract already, but confirm the telehealth integration path and whether it creates a second copy outside the EHR.
- Referral transmission — direct messaging, e-fax, or portal upload. Verify the receiving endpoint before the first send, not after.
Assign each row an owner by name. "IT" is not an owner. A person who will answer an email is an owner.
Consent: Three Different Documents That People Keep Merging
Front-desk staff and portal builders tend to collapse these into one checkbox. They are legally distinct, and merging them creates a record you cannot defend.
Notice of Privacy Practices Acknowledgment
Required for direct treatment relationships. In a telehealth-first workflow, the NPP has to be available electronically and the good-faith effort to obtain acknowledgment has to be documented electronically. If a patient never sets foot in your building, a paper signature line in your workflow is a defect, not a formality.
State Telehealth Informed Consent
This is state law, not HIPAA, and requirements vary considerably. Some states require documented consent to the telehealth modality before every encounter; others require it once per care episode. If your practice is licensed across state lines, your intake form logic needs to branch by the patient's physical location at the time of the visit — which means you also need to capture that location.
Consent to Record
Recording an encounter is a separate decision from conducting it. Some states require all-party consent for recording. Your platform's default recording setting is a compliance decision that a vendor made for you. Change it deliberately and document who changed it.
Minimum Necessary Does Not Apply to the Referral — But Something Else Does
When you send records to the orthopedic group or the PT clinic for treatment purposes, the minimum necessary standard does not apply. Treatment disclosures to another provider are carved out. Administrators frequently get this backward and either over-redact clinical context or panic about a routine send.
What does apply: verification of the recipient's identity and authority. The most common real-world failure in a specialist referral workflow is not over-disclosure of content — it is disclosure to the wrong destination. A stale fax number for a PT clinic that moved. A direct address typed from memory. A patient portal upload to a duplicate chart.
Build a two-step verification into your ROI workflow for any new external recipient: confirm the endpoint by phone or a verified directory, then log the confirmation with the staff member's initials and date. Reverify annually. The HHS breach portal is populated with misdirected-disclosure incidents that a thirty-second phone call would have prevented.
The 30-Day Clock When the Patient Wants the Video
Under the HIPAA right of access, you generally have 30 days to provide a copy of records in the designated record set, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS maintains detailed right of access guidance that your ROI staff should have bookmarked.
The telehealth wrinkle: patients now ask for things your ROI clerk has never produced. A recorded encounter. A pre-visit video upload. A chat transcript. An AI-generated draft note.
Your rule of thumb should be functional, not format-based. If the item is maintained by or for your practice and used to make decisions about that individual, it is in the designated record set regardless of whether it is a PDF, an MP4, or a row in a vendor's database. "The video lives at our vendor and we cannot export it" is not an exemption — it is a contract defect you should fix at renewal by requiring an export capability in the BAA or the service agreement.
Write the export procedure down now, before the request arrives. Which staff role opens the vendor console, what format the file is delivered in, how it is transmitted to the patient securely, and where the fulfillment is logged.
Tracking Technologies on the Page Where Patients Book
Your marketing team may have built a landing page for shoulder and joint services because it converts. If that page loads third-party analytics, advertising pixels, or session-replay scripts, and a visitor's information is combined with anything indicating a relationship to your practice, you have a disclosure question — and depending on the vendor, a BAA question.
The legal landscape here shifted after litigation in 2024 narrowed part of OCR's original position on unauthenticated pages, but the underlying exposure did not vanish. The FTC has pursued health-data sharing cases under its own authority, entirely independent of HIPAA. HHS keeps its current position posted in its guidance on online tracking technologies.
The practical move: run your own site through a browser's network inspector, list every third-party domain that fires on the scheduling and service-line pages, and hand that list to whoever owns the website. Ask which ones are contractually covered. Repeat quarterly, because marketing tags reappear.
A 30-Day Cleanup Sequence You Can Actually Run
Week 1 — Inventory. Privacy officer walks one telehealth encounter end to end and writes down every system it touches. Not from memory; from the actual booking.
Week 2 — Contracts. Match each system to a signed BAA. Note the execution date, the subcontractor flow-down clause, the breach notification window, and the data-return-or-destruction provision. Every gap gets a name and a due date.
Week 3 — Settings. Recording defaults, retention periods, staff access levels, and support-access logging at each vendor. Screenshot the current state and file it as evidence of review.
Week 4 — Procedures. Update your ROI procedure to cover video, transcripts, and uploads. Update your NPP acknowledgment flow for remote patients. Brief the front desk on the two-step recipient verification for referrals. Fold the findings into your risk analysis rather than filing them separately — if that process is manual today, automated risk analysis and policy generation will save your privacy officer a week.
None of this is exotic. It is the same discipline you already apply to paper, extended to a workflow that grew sideways while everyone was busy. The adhesive capsulitis visit is just a convenient stress test: it crosses organizations, generates media files, and ends in a referral, so it exercises almost every control you have.
Start With the Contract Gap
Pull your vendor list this week and find the systems holding PHI without a signed agreement. Then close them one at a time. You can generate a signature-ready BAA in about ten minutes and export it as PDF or DOCX — a one-time purchase, no subscription — which is generally faster than negotiating a vendor's template line by line. Fix the paperwork first; the settings and procedures are easier once the contracts are real.