It's 7:40 a.m. and your telehealth queue holds fourteen visits. Four of them are respiratory follow-ups where the patient will hold a device up to the camera. If your practice schedules asthma and nebulizer visits remotely, that camera feed is the least complicated part of the encounter. The complicated part is everything wrapped around it: the intake form the patient filled out on your website at 11 p.m., the consent record nobody can locate, the durable medical equipment supplier that will email you a fulfillment confirmation, and the six vendors that touched protected health information before the clinician said hello.

This post is for the administrator who owns that workflow. No clinical guidance here — just the records, consent, and vendor plumbing.

Why an Asthma and Nebulizer Visit Generates More Records Than You Think

A routine sinus complaint over video produces one note and one claim. A respiratory follow-up rarely stays that contained. These encounters commonly involve equipment supplied by an outside company, prescriptions routed to a pharmacy, and periodic specialist involvement. Every one of those handoffs is a disclosure your practice has to be able to account for.

Map it on paper once. For a typical remote asthma and nebulizer follow-up at a primary care practice, the PHI touchpoints usually include:

  • The scheduling or patient-portal vendor that captured the appointment reason
  • The digital intake form platform, including any symptom questionnaire
  • The video platform, plus whatever recording or transcription feature is enabled
  • The EHR and its dictation or ambient documentation add-on
  • The e-prescribing route and, where equipment is involved, a DME supplier
  • The billing clearinghouse and, downstream, the payer
  • Any school, employer, or camp form your front desk completes afterward

That's seven organizations touching one visit. Your accounting-of-disclosures obligation and your breach-notification exposure both scale with that list, not with visit length.

The school and work form nobody assigned an owner

Respiratory conditions generate authorization-based disclosures at a higher rate than most chronic conditions, because schools, daycares, camps, and employers routinely request documentation about medication administration and equipment use. These are not treatment disclosures. They require a valid HIPAA authorization signed by the patient or personal representative, and they need to be logged.

Assign a named owner. In most small practices this lands on the front desk by default and gets handled inconsistently — one staffer collects a signed authorization, another faxes the form because "the school already knows." Write the rule down, put the authorization form in the intake packet for pediatric respiratory patients, and audit a sample every quarter.

The Intake Form Is a Privacy Event Before the Clinician Logs In

Most practices treat digital intake as a convenience feature. Your Security Rule risk analysis has to treat it as a system that creates, receives, maintains, and transmits ePHI.

Three questions to answer about your intake vendor this week:

  1. Is there an executed BAA on file, and does it name the actual legal entity you contracted with? Parent companies rename subsidiaries. A BAA signed with a company that no longer exists under that name is a documentation gap you will have to explain.
  2. Where does the form data live between submission and EHR import? If it sits in a vendor-hosted queue for 30 days, that's a repository you own responsibility for.
  3. What analytics or advertising code runs on the page where a patient types a respiratory symptom?

That third question is the one that has caused practices the most trouble. OCR's guidance on online tracking technologies addresses tracking code on webpages and in patient portals. A federal court vacated the portion of that guidance covering unauthenticated public pages, but the underlying analysis for authenticated portals and patient-specific pages still stands — and separately, the FTC has pursued health data sharing under its own authority and the Health Breach Notification Rule. If an ad pixel fires on the page where a patient discloses that a visit is for asthma and nebulizer refill management, you have a problem that is easier to prevent than to remediate.

A short, boring fix

Have someone open your intake page in a browser with developer tools and list every third-party domain the page contacts. Bring that list to your IT vendor and require a written justification for each one. Practices that do this typically find two or three trackers nobody in the building authorized, usually installed by a marketing contractor years ago.

Do You Need a BAA With Your Telehealth Platform?

Yes, in nearly every case. A video platform that transmits and stores PHI on behalf of your practice is a business associate and requires a signed Business Associate Agreement before the first patient visit. The pandemic-era enforcement discretion that allowed non-public-facing consumer video apps without a BAA expired in 2023; there is no ongoing exception. HHS maintains a telehealth and HIPAA resource page for covered entities.

The narrow exception is a true conduit — an entity that transmits data without accessing or storing it, like a telecommunications carrier. Modern video platforms with recorded sessions, chat logs, waiting rooms, and cloud storage do not qualify. Neither do transcription services, scheduling tools, form builders, or the DME supplier's ordering portal if it processes PHI for you.

If you are staring at a vendor list with more gaps than agreements, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It's a one-time purchase, no subscription — which matters when you need four agreements this month and none next quarter.

Your Notice of Privacy Practices is not telehealth consent. State law governs the second one, and requirements vary considerably — some states require documented verbal consent before each telehealth encounter, others accept a one-time written consent, and several impose specific disclosure language about modality limitations.

Build the consent record to capture, at minimum:

  • The date and time consent was obtained, and by whom
  • The modality used (video, audio-only, asynchronous)
  • Patient acknowledgment of the platform and any recording
  • The patient's physical location at the time of the visit
  • Identity verification method used

That location field is not bureaucratic decoration. Licensure and, in some states, privacy obligations follow the patient's location. If a patient joins an asthma and nebulizer follow-up from a relative's house two states away, your clinician needs to know before the encounter starts, and your record needs to reflect it.

The "who else is in the room" script

Respiratory visits skew toward pediatric and older adult patients, which means a third party is present more often than in other visit types. Your medical assistant should have a scripted line and a documentation field:

"Before we bring the provider in — is anyone else in the room with you? I'll note them in the chart."

For an adult patient, a family member's presence is a disclosure the patient is consenting to in the moment; note it. For a minor, note the accompanying adult's relationship. When an audit or a complaint arrives eighteen months later, this field is the difference between a documented decision and a guess.

Device and Supplier Data: The Handoff Most Practices Don't Log

When a remote visit results in equipment being ordered, the supplier becomes an outside organization holding your patient's information. Whether that supplier is a business associate or a separate covered entity depends on the arrangement. A DME company billing the payer directly for its own product is generally acting as its own covered entity, and treatment-related disclosures to it don't require a BAA. A vendor performing a function on your behalf — managing your refill queue, operating a portal you use to submit orders — is a business associate.

Get this classified in writing for each supplier relationship. Ambiguity here produces the worst kind of breach response: an incident occurs at the supplier, and nobody can say within 48 hours whether your practice has notification obligations.

Remote monitoring data adds a retention question

If your practice receives device-generated adherence or usage data through any connected platform, decide before you turn it on: does that data enter the designated record set? If a clinician reviews it and documents on it, treat it as part of the record and expect it to be included in a right-of-access request. Configure retention deliberately rather than accepting a vendor default that keeps everything forever in a jurisdiction you didn't choose.

A Worked Example of the Failure Mode

A four-provider practice moves respiratory follow-ups to video. Intake runs through a form tool the office manager signed up for with a corporate card — no BAA, month-to-month billing, never appeared on the vendor inventory. Fourteen months later the form vendor discloses a misconfigured storage bucket.

What the practice now has to do:

  1. Determine how many records were exposed, from a vendor with no contractual duty to help
  2. Conduct a four-factor risk assessment on data it never inventoried
  3. Notify affected individuals within 60 days of discovery
  4. Explain to OCR why an ePHI system was absent from the risk analysis
  5. Explain why no BAA existed

The last two items are the expensive ones. A missing BAA and an incomplete risk analysis are independent violations regardless of whether the breach itself was your fault. The NIST SP 800-66r2 implementation guide is the standard reference for building a risk analysis that survives scrutiny; if you'd rather not assemble that from scratch, tools that automate risk analysis reports and the supporting policy set will get you a defensible baseline faster than a spreadsheet will.

The Records Request That Arrives Six Months Later

A patient who had three remote asthma and nebulizer visits requests their complete record. Under the HIPAA right of access, you have 30 days, with one 30-day extension available if you notify the patient in writing.

Complete means complete. Ask now, not then:

  • Are intake form responses in the EHR, or still sitting in a vendor portal?
  • Are visit recordings retained, and are they part of the designated record set?
  • Are secure-message threads exportable?
  • Can you produce device or supplier data your clinician relied on?

Run a fire drill. Pick one closed telehealth encounter and assemble the full record as if a request had come in. Time it. If it takes your staff more than an hour, your workflow will not hold up under a real request, and right-of-access failures remain one of the most consistently enforced areas of the Privacy Rule.

A 30-Day Checklist for the Administrator Who Owns This

  • Week 1: Inventory every vendor touching a remote respiratory visit. Include anything paid for on a card rather than through procurement.
  • Week 2: Match each vendor to an executed BAA. Flag gaps and stale entity names.
  • Week 3: Audit twenty telehealth encounters for consent documentation, patient location, and third-party presence.
  • Week 4: Run the records-request fire drill and scan your intake page for third-party trackers.

None of this is glamorous, and none of it improves a single visit. It's what stands between your practice and a two-year corrective action plan.

If the vendor gap list is where you're stuck, start there — build the missing Business Associate Agreements and get them signed before the next batch of remote visits hits your schedule.