Count the video visits your practice ran last week. Now count how many of those platforms, transcription tools, waiting-room widgets, and appointment-reminder services you have a signed Business Associate Agreement for. If those two numbers don't reconcile, you have a hipaa telehealth compliance gap that predates any breach and will be the first thing an OCR investigator finds.

This is a working guide for practice owners, privacy officers, and compliance leads who already run telehealth and need to know what the obligations are, who inside the practice owns each one, and what the documented evidence looks like when someone asks. No clinical guidance, no theory — just the paperwork and controls that have to exist.

The Enforcement Discretion Expired in 2023. Nothing Replaced It.

During the public health emergency, OCR said it would not impose penalties against providers who used non-public-facing communication apps in good faith for telehealth. That notification of enforcement discretion expired on August 9, 2023, and the 90-day transition period ran out on November 11, 2023.

Since that date, every telehealth encounter has been governed by the full Privacy, Security, and Breach Notification Rules — the same standards that apply to an in-person visit and a paper chart. There is no telehealth carve-out, no reduced standard for video, and no grace period still running in December 2025.

What changed operationally is smaller than most practices assume and larger than they prepared for. The clinical workflow stayed the same. The documentation burden did not.

What HIPAA Telehealth Compliance Actually Requires

If you need the short answer for a board memo or a staff meeting, here it is. A covered health care provider running telehealth must:

  1. Execute a Business Associate Agreement with every vendor that creates, receives, maintains, or transmits PHI on your behalf — video platform, scheduling tool, transcription service, cloud storage, interpreter service.
  2. Include the telehealth stack in your Security Rule risk analysis under 45 CFR 164.308(a)(1)(ii)(A), by name, with identified threats and vulnerabilities.
  3. Apply reasonable and appropriate safeguards — encryption in transit and at rest, unique user IDs, automatic logoff, audit logging, access controls tied to job role.
  4. Verify patient identity before disclosing PHI over a remote channel, and document the verification method in policy.
  5. Train the workforce on remote-visit-specific risks: household bystanders, screen sharing, recording, personal devices.
  6. Follow the Breach Notification Rule — 60 days to notify affected individuals from discovery, with the HHS report timing driven by whether the incident affects 500 or more people.

Everything below expands one of those six. HHS maintains a plain-language summary of the underlying obligations on its Telehealth and HIPAA page, which is worth printing for your policy binder.

Your Video Platform Is a Business Associate. Get the Paper.

The most common failure I see in telehealth files is a signed terms-of-service and no BAA. A clinician picked a platform, clicked through the consumer sign-up, and started seeing patients. Two years later nobody can produce an agreement.

The conduit exception is narrower than your vendor claims

Vendors sometimes argue they are mere conduits, like the phone company or the postal service. OCR has read that exception narrowly: it covers entities that transmit information and have only transient access to it. A platform that stores session recordings, retains chat transcripts, holds appointment metadata, or maintains a patient-facing account is not a conduit. It is a business associate, and you need the agreement.

The same applies to your ambient documentation tool, your e-signature intake vendor, your SMS reminder service, and any AI scribe that processes visit audio. If the vendor touches the encounter, it goes on the list.

What a telehealth BAA needs to say

A compliant agreement under 45 CFR 164.504(e) must establish permitted uses and disclosures, require safeguards, obligate the business associate to report security incidents and breaches to you, extend the terms to subcontractors, address return or destruction of PHI at termination, and give you the right to terminate for material breach.

For telehealth specifically, negotiate three additions: a defined breach notification window shorter than 60 days (10 business days is a reasonable ask), a clear statement of whether session recordings are retained and for how long, and a prohibition on using your patients' data to train models unless you expressly authorize it in writing.

If you are chasing signatures across a dozen vendors and don't want to route each one through outside counsel, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which matters when you need eleven agreements this month and none next quarter.

Track the agreements somewhere an auditor can read

Your BAA register should list: vendor legal name, service description, PHI categories touched, execution date, renewal or review date, breach notification window, and the internal owner. A spreadsheet is fine. A pile of PDFs in someone's email is not.

Audio-Only Visits: Where the Security Rule Stops and the Privacy Rule Doesn't

OCR issued guidance in June 2022 on remote communication technologies for audio-only telehealth, and it still governs. The distinction it draws is technical and practically useful.

A traditional landline call is not electronic media under the Security Rule, so the Security Rule's technical safeguards do not attach to that transmission. The Privacy Rule always attaches. Minimum necessary, verification of identity, and the duty to avoid incidental disclosures apply to every phone call your staff makes.

The moment the call moves to VoIP, a smartphone app, a softphone in your practice management system, or anything that transmits over the internet, the Security Rule applies in full — and the vendor providing that service is a business associate. Most practices that think they are running "just phone visits" are actually running VoIP. Check with whoever administers your phone system before you assume otherwise.

The Risk Analysis That Has to Name the Telehealth Stack

OCR's enforcement pattern over the last two years has been unusually consistent: a large share of resolved investigations turn on the absence of an accurate, thorough, enterprise-wide risk analysis. The agency launched a dedicated risk analysis enforcement initiative in late 2024, and the resulting settlements have included small practices, not just health systems.

A risk analysis that predates your telehealth program is not a risk analysis of your telehealth program. Update it. The document should identify every system where ePHI lives or moves, including:

  • The video platform and its recording storage location
  • Clinician endpoints — laptops, tablets, personal phones running the app
  • Home network connections and any VPN in use
  • Transcription, scribe, or note-generation tools
  • Patient-facing scheduling and intake forms
  • Interpreter and third-party participant workflows

For each, document the reasonably anticipated threats, current controls, likelihood and impact, and the remediation decision. NIST's SP 800-66 Revision 2 is the reference OCR points to for methodology, and it includes worked examples you can adapt without hiring anyone.

One note on the regulatory horizon: HHS published a proposed Security Rule update in January 2025 that would tighten and make mandatory a number of currently addressable specifications, including encryption and multi-factor authentication. It remains a proposed rule as of this writing. Practices that build toward it now will have less to do if and when it finalizes — and the controls are defensible regardless.

Your Clinician's Spare Bedroom Is Now a Treatment Space

Workstation use and workstation security are Security Rule standards, and they do not stop at your building's front door. Write a remote telehealth workspace policy and have every remote clinician attest to it annually.

The policy should cover: a door that closes, headphones for every session, screens angled away from doorways and windows, automatic screen lock at five minutes or less, no household members in the room during encounters, and no telehealth over open public Wi-Fi.

Personal devices

If clinicians use personal phones or laptops, you need either a mobile device management enrollment or a written BYOD policy with enforced encryption, remote wipe capability, and a prohibition on saving PHI locally. Pick one. "We trust our people" is not a safeguard and will not survive an investigation.

Recording

Decide, in writing, whether your practice records telehealth sessions. If yes, recordings are part of the designated record set and are subject to the right of access — which means a patient can request them, and your 30-day access clock runs on them. Many practices that never intended to record discover their platform defaults to on. Check the setting.

Scheduling Pages, Intake Forms, and Tracking Pixels

Telehealth programs usually arrive with a marketing push and a new landing page. That page is where analytics and advertising trackers get installed, often by a web contractor who has never heard of a BAA.

Any tracker on an authenticated page — the patient portal, the logged-in scheduling flow, the intake form that collects symptoms — is transmitting PHI to a third party. That third party is either a business associate with a signed agreement, or you have an impermissible disclosure. OCR's guidance on online tracking technologies, originally issued in December 2022 and revised in March 2024, was partially vacated by a federal court in June 2024 as applied to unauthenticated public webpages. The authenticated-page analysis was not disturbed. Treat your portal and booking flow as in scope.

Action item for your web owner this month: pull the full list of scripts running on every patient-facing page and reconcile it against your BAA register.

When a Telehealth Session Goes Wrong: The 60-Day Clock

A clinician screen-shares the wrong chart. A meeting link gets forwarded and an uninvited participant joins. A vendor emails you about unauthorized access to session recordings. Each is a potential breach and each starts the same sequence.

Day zero is discovery — the first day the incident is known, or reasonably should have been known, to any workforce member. From there:

  • Immediately: contain. Revoke the link, disable the account, pull the recording.
  • Within days: complete the four-factor risk assessment under 164.402 — nature and extent of PHI, who received it, whether it was actually acquired or viewed, and the extent of mitigation. Document each factor. A conclusion without the four factors is not a risk assessment.
  • Within 60 calendar days of discovery: notify affected individuals in writing.
  • 500 or more individuals: notify HHS and prominent media outlets within that same 60 days.
  • Fewer than 500: log it, and report to HHS within 60 days after the end of the calendar year.

Before you write your notification letter, read a few from your specialty and state on the OCR breach portal. It is a free education in what regulators consider adequate description.

A 30-Day Plan With Names Attached

Week 1 — Privacy Officer. Inventory every vendor touching a telehealth encounter. Compare against the BAA register. Produce a gap list.

Week 2 — Privacy Officer plus practice manager. Send agreements to every gap vendor. Set a two-week response deadline. Any vendor that refuses to sign goes on a replacement list with a date.

Week 3 — Security Officer or IT. Update the risk analysis with the telehealth stack. Pull platform configuration settings: recording defaults, retention, waiting room enforcement, meeting passcodes, session encryption.

Week 4 — Privacy Officer. Deliver a 20-minute telehealth-specific training module. Capture attendance with signatures and date. Update the remote workspace policy and collect attestations.

If your policy set itself is out of date — and for most practices that added telehealth mid-stream, it is — you can automate the risk analysis and the full policy document set rather than rebuilding templates by hand.

The Evidence File an Investigator Will Ask For

Assemble these six items in one folder and keep them current. This is what "we are compliant" looks like in practice:

  1. Current risk analysis, dated, naming telehealth systems
  2. Risk management plan showing what you decided to fix and when
  3. Signed BAAs for every telehealth vendor, with the register
  4. Written telehealth and remote workspace policies
  5. Training records with names, dates, and content covered
  6. Incident log — including incidents you determined were not breaches, with the four-factor analysis attached

One clarification worth making at your next staff meeting: Medicare telehealth payment flexibilities and HIPAA obligations are separate tracks. Congress has repeatedly extended reimbursement flexibilities in short increments, and those deadlines get a lot of attention. They have no bearing on your privacy and security duties, which are permanent. Watch HHS telehealth resources for the payment side and keep it out of your compliance calendar.

Start With the Vendor List

Solid hipaa telehealth compliance is mostly an inventory problem followed by a paperwork problem. Find every system that touches a remote encounter, get an agreement in place for each one, put them all in your risk analysis, and keep the evidence somewhere you can hand over in an afternoon.

If the missing agreements are what's blocking you, build and export a signature-ready BAA this week and start clearing the gap list. One vendor at a time is fine. Zero signed agreements in month twenty-four of a telehealth program is not.