A behavioral health group we reviewed last spring had eleven clinicians running telehealth sessions on three different platforms. Two were on the practice's paid enterprise account. Eight were on a departmental account with no signed BAA. One was using a personal consumer login from her kitchen because the enterprise seats had run out in March and nobody escalated it. That practice believed it had HIPAA compliant video conferencing. What it actually had was one compliant workflow and ten undocumented ones.

This article is for the person who has to fix that: the practice owner, privacy officer, or compliance lead who signs the vendor contract and answers the questions when a session recording turns up somewhere it shouldn't. It covers what makes a platform defensible, which settings you personally sign off on, and what evidence you need in the binder.

What Makes Video Conferencing HIPAA Compliant?

No video platform is HIPAA compliant on its own. Compliance is a property of your deployment, not the software. A telehealth video tool meets HIPAA requirements when all five of the following are true:

  • A signed Business Associate Agreement is in place between your covered entity and the platform vendor, executed before the first patient session.
  • Protected health information is encrypted in transit and at rest, using the vendor's HIPAA-eligible service tier rather than a free or consumer plan.
  • Access is controlled and unique per user — no shared clinician logins, no shared meeting links reused across patients.
  • Audit logging is enabled and retained, so you can reconstruct who joined which session and when.
  • The tool appears in your risk analysis with documented safeguards, and your workforce is trained on the specific configuration you approved.

Miss any one of these and you do not have HIPAA compliant video conferencing. You have a video call that happens to involve a patient.

The Enforcement Discretion Ended August 9, 2023 — Check Whether Your Workflow Noticed

During the public health emergency, OCR exercised enforcement discretion for telehealth conducted over non-public-facing remote communication technologies, including consumer platforms without a BAA. That flexibility expired after a 90-day transition period ending August 9, 2023.

Two and a half years later, the residue is still everywhere. Practices standardized on tools chosen in 2020 under emergency conditions and never revisited the account tier. Clinicians who onboarded during the flexibility window learned habits that were never retrained. HHS maintains current telehealth guidance for HIPAA-covered providers that no longer contains any of those allowances.

Your action item is narrow and specific: pull the list of every video tool used for patient encounters in the last 90 days, including one-offs. Not the approved list — the actual list. Ask the clinicians directly, then verify against your expense reports and single sign-on logs.

The BAA Is the First Gate, and It Is Where Most Practices Fail

The video vendor transmits and usually stores PHI on your behalf. That makes it a business associate. The conduit exception does not save you here — OCR's cloud computing guidance is explicit that a service provider maintaining electronic PHI is a business associate even if it never views the data.

Three failure patterns account for nearly every gap we find:

The BAA exists but covers the wrong entity

Your BAA is with the parent company; your clinicians are provisioned under a reseller or a regional subsidiary. Check that the legal entity named on the agreement matches the entity named on your invoice.

The BAA exists but the plan tier doesn't qualify

Most major platforms only extend BAA coverage to specific enterprise or healthcare SKUs. A clinician who upgrades her own seat with a credit card is almost certainly outside the covered tier. Reconcile seat counts quarterly against your license agreement.

The BAA was clicked through and nobody kept a copy

Vendor portals frequently offer a checkbox BAA buried in admin settings. If you accepted one, export the PDF, record the date and the name of the person who accepted, and file it. "It's in the portal somewhere" is not evidence.

You also need agreements flowing the other direction. If you provide the video platform to affiliated clinicians, host sessions for a referring group, or run interpretation services through a third party, you need executed BAAs with each. If drafting those from scratch is what's stalling you, a six-step BAA generator that exports signature-ready PDF and DOCX will get a defensible agreement in front of the vendor the same afternoon — one-time purchase, no subscription to manage.

Nine Settings Your Privacy Officer Signs Off On

A HIPAA-eligible license is the floor. The configuration is what gets audited. Document each of these decisions with a date and an approver:

  1. Waiting room or admit-by-host enabled. Prevents a patient walking into another patient's session. This is the single most common telehealth privacy incident we see reported internally.
  2. Unique meeting link per encounter. Personal meeting rooms reused across patients create predictable, shareable access.
  3. Cloud recording disabled by default. Turn it on per-encounter with documented clinical justification, or leave it off entirely.
  4. Chat and file transfer restricted. Session chat becomes PHI you now have to retain, produce, and dispose of. If you don't need it, close it.
  5. Transcription and AI note features off pending review. Any feature that processes audio through a subprocessor needs to be covered by your BAA and named in your risk analysis before use.
  6. Single sign-on with MFA required. No local passwords for clinician accounts.
  7. Session timeout and automatic logoff configured on the desktop and mobile clients.
  8. Audit log retention set to your maximum available window, with a monthly export to storage you control.
  9. Guest join from unmanaged devices restricted for workforce members — patients join as guests, clinicians never should.

Print the settings page. Screenshot it with a date visible. That artifact is worth more in an investigation than any policy paragraph.

Recordings Are PHI, and They Live in Your Designated Record Set

The moment you record a telehealth encounter, you have created a record with obligations attached. Assign a named owner and answer these in writing:

  • Where does it land? Vendor cloud, your own storage, or the chart. If it sits in vendor cloud, your BAA must cover storage, not just transmission.
  • How long do you keep it? Set a retention period consistent with your state's medical record rules and your existing chart policy. Then actually enforce deletion.
  • Is it part of the designated record set? If a recording is used to make treatment or payment decisions, a patient can request access to it under 45 CFR 164.524 — and your 30-day clock applies.
  • Who can retrieve it? Restrict recording download to the privacy officer and the treating clinician. Front desk staff do not need it.
  • How is it disposed of? Document the deletion method and keep the log.

Practices that cannot answer the retention question should not be recording. It is the cheapest risk reduction available in telehealth.

The Clinician's Room Is Part of Your Security Perimeter

Your platform can be flawless and still leak. Physical and administrative safeguards under the Security Rule extend to wherever the encounter happens.

Write a one-page telehealth environment standard and have every clinician attest to it annually. Ours covers: a door that closes, headset required so the patient's voice is not audible to household members, no telehealth from vehicles or public networks, screen positioned away from windows and doorways, screen-share limited to a single application rather than the full desktop, and no household members in the room during a session.

Add identity verification. Before discussing anything clinical, the clinician confirms the patient's full name and date of birth on camera, and documents that verification in the note. Wrong-patient telehealth sessions happen, and the note is your only proof they didn't.

The Evidence File: What an Auditor Actually Asks For

When a records request, a complaint, or a breach investigation lands, you produce documents, not explanations. Build the folder now:

  • Executed BAA with the video vendor, with the countersignature date.
  • License agreement or invoice showing the HIPAA-eligible plan tier and seat count.
  • Dated screenshots of the nine settings above.
  • The telehealth section of your current security risk analysis, naming the platform and the safeguards applied. NIST's SP 800-66 Revision 2 is the reference HHS points to for structuring that analysis.
  • Training records: date, attendee list, and the actual material used for telehealth-specific training.
  • Signed clinician attestations to the environment standard.
  • Your written policy on recording, retention, and disposal.
  • Twelve months of audit log exports.
  • An incident log — including the near-misses your staff self-reported.

If assembling that set from nothing feels like a quarter of work, it usually is. Tooling that generates the risk analysis and the supporting policy set shortens it considerably, but someone in your organization still has to make the configuration decisions and own them.

Worked example: a 12-provider group in three weeks

Week 1. Inventory every tool in use. Pull invoices, SSO logs, and interview clinicians. Expect to find two to three unapproved tools. Identify the one platform you will standardize on and confirm its BAA and tier.

Week 2. Execute or re-execute the BAA. Lock the nine settings and screenshot them. Write the environment standard. Deprovision every account outside the approved tenant and confirm deprovisioning in the admin console — not by email reply.

Week 3. Run a 30-minute training session on the approved workflow, including how to verify identity and what to do when a wrong participant joins. Collect attestations. Update the risk analysis. Set a calendar reminder for a quarterly seat-count reconciliation.

Where This Goes Wrong Next Quarter

Telehealth compliance decays quietly. The three drift patterns to guard against:

Feature creep. Your vendor ships an AI summarization feature and enables it by default. Subscribe your privacy officer to the vendor's release notes and review new features before they touch a patient session.

Seat sprawl. A new clinician starts, the enterprise seats are full, and someone improvises. Tie video provisioning to your HR onboarding checklist so it cannot be skipped.

Stale evidence. Screenshots from 2023 prove nothing about your current configuration. Re-capture annually, at minimum, and after any platform migration.

HHS has signaled continued attention to the Security Rule's technical safeguards through its January 2025 proposed rulemaking; whatever the final requirements look like, unique user identification, encryption, and audit controls will not get easier. Practices that already document their telehealth configuration will be adjusting a paragraph. Practices that don't will be starting over. You can also review reported incidents on the OCR breach portal to see how often vendor and configuration issues drive the numbers.

Your Next Step

Start with the gate that stops everything else: the agreement. Confirm you hold a signed, current BAA with every vendor touching a telehealth encounter — the video platform, the transcription service, the interpretation line, the scheduling tool that generates the join link. Where one is missing, generate a signature-ready Business Associate Agreement and send it out this week. Then work down the configuration list. The whole project is three weeks of unglamorous work, and it is the difference between explaining your telehealth program and defending it.