A new patient books a 50-minute virtual consult with your rheumatology group. Before the appointment, your intake link collects a 14-page questionnaire, a symptom timeline going back nine years, records releases for four prior providers, and — because the clinician asked — two short videos of the patient demonstrating joint range of motion at home. That single appointment for a suspected hypermobility ehlers evaluation touched five vendors before anyone said hello on camera.

This post is for the person who signs those vendor contracts and answers the complaint if something goes sideways. It is not clinical guidance. It is an operational walkthrough of intake, consent, records movement, and business associate coverage for a visit type that generates unusually heavy documentation traffic.

Why Hypermobility Ehlers Visits Stress Your Intake Pipeline

The administrative reality is simple: hypermobile Ehlers-Danlos evaluations are typically multi-specialty and record-heavy. A patient arriving at your practice has often already seen primary care, orthopedics, cardiology, GI, and physical therapy. That means inbound record requests, outbound referrals, and a chart that accumulates documents from organizations you have no contract with.

Add telehealth and you get a second problem. Remote assessment often relies on patient-submitted media and detailed self-reported history. Both arrive through channels that were never designed as clinical intake — email attachments, patient portal messages, texted video links, cloud storage folders shared by the patient.

Neither of those facts is a clinical matter. They are workflow facts, and they determine where your PHI actually lives.

Do You Need a BAA for a Telehealth Platform? A Direct Answer

Yes, if the platform creates, receives, maintains, or transmits protected health information on your behalf. The OCR Notification of Enforcement Discretion that allowed non-public-facing consumer video apps during the COVID-19 public health emergency expired on August 9, 2023, with a 90-day transition period that closed on November 6, 2023. Since then, telehealth technology has been governed by the ordinary rules: a covered entity must have a signed business associate agreement in place with any vendor handling PHI, and the vendor must meet Security Rule obligations.

The narrow exception is the conduit exception, which covers entities that merely transmit data without accessing it — a telecommunications carrier, for example. Most video platforms, form builders, transcription services, and cloud storage providers do not qualify, because they store or process the content. HHS maintains current guidance on HIPAA and telehealth that is worth reading annually, not once.

If your vendor inventory has gaps — and after three years of post-PHE cleanup, most do — a six-step wizard that produces a signature-ready Business Associate Agreement will close them faster than routing every one through outside counsel. It exports to PDF and DOCX, and it is a one-time purchase rather than another subscription line item.

Pull up your own pre-visit workflow and trace every hop. For a typical hypermobility ehlers telehealth intake, here is what you will usually find.

1. The form builder

Long intake questionnaires rarely live in the EHR. They live in a third-party form tool that someone in your office selected because it was easy. Ask three questions: Is there a signed BAA? Where is the data stored and for how long? Does the form page load analytics, chat widgets, or advertising pixels?

That last question matters. OCR and the FTC have both addressed tracking technologies on pages that collect health information. The FTC's Health Breach Notification Rule reaches health apps and connected services outside HIPAA entirely, so "we're not a covered entity for that piece" is not the shield people assume it is.

2. The e-signature service

Consent forms, financial policies, and release authorizations get signed electronically. The signature vendor holds executed documents containing the patient's name, diagnosis context, and provider relationships. That is PHI. It needs a BAA and a retention setting that matches your policy, not the vendor's default.

3. The media upload path

This is the one that bites practices. If a clinician asks a patient to submit video of joint mobility, and your workflow does not specify a secure upload channel, the patient will email it. Now you have PHI in a mailbox with a different retention schedule, different access controls, and possibly a personal device sync.

Designate one upload path. Put it in the appointment confirmation. Train the front desk to redirect anything that arrives elsewhere, and document the redirect.

4. Transcription and ambient documentation

If any clinician in your group uses an ambient scribe or dictation service during telehealth encounters, that vendor processes the full audio of the visit. Confirm the BAA, confirm whether audio is retained after the note is generated, and confirm whether the vendor uses your data to train models. Get the training answer in writing in the contract, not in a sales email.

5. Interpretation and translation

On-demand interpreters are business associates when they are contracted through a service. A family member interpreting is not — but that arrangement requires its own documented patient agreement.

Your general Notice of Privacy Practices is not a telehealth consent, and a telehealth consent is not a recording consent. Keep them separate and keep them specific.

Cover the modality, the limits of remote assessment as a matter of service delivery, what happens if the connection drops, how the patient reaches the practice afterward, and which state the clinician is licensed in. Several states impose their own telehealth consent requirements that exceed HIPAA. Check yours and check every state where your patients physically sit during visits.

If the visit is recorded, or if the patient submits video that becomes part of the record, say so explicitly. State that submitted media becomes part of the designated record set, describe retention, and describe who inside the practice can view it. Some states require all-party consent for recording; your consent form should not assume otherwise.

Because these evaluations frequently move between organizations, build the authorization workflow into intake rather than bolting it on later. Treatment, payment, and healthcare operations disclosures do not require authorization, but records requests to prior providers usually do require a signed release on the other organization's form. Collecting patient signatures on your release template at intake saves your staff two weeks of chasing.

Minors and proxy access

Many hypermobility ehlers evaluations involve adolescents. Your portal needs a documented rule for when a parent's proxy access changes at the age of majority — or earlier, under state minor-consent law for specific service categories. Set a calendar-driven review, because portals do not age patients out on their own.

The 30-Day Clock and the Records That Arrive From Everywhere

Under the Privacy Rule, you must act on a patient's request for access to their designated record set within 30 days, with one possible 30-day extension if you notify the patient in writing of the delay and the reason. HHS guidance on the individual right of access is unambiguous about scope: it includes records you received from other providers, not just records you created.

That is the operational trap in a record-heavy specialty. If your practice ingested 400 pages of outside imaging reports and prior consult notes, those pages are in the designated record set. Your release team needs a defined process for producing them, in the format the patient requested if you can readily produce it.

Separately, watch the information blocking rules. Delaying release of results or notes without a permitted exception creates a distinct exposure under ONC's framework — healthit.gov's information blocking resources lay out the exceptions in detail.

A Worked Intake Timeline With Role Assignments

  1. Day −10 (scheduler): Books the visit, confirms the patient's physical location on the day of service, and logs it. Sends the intake link and the designated media upload link in the same message.
  2. Day −9 (scheduler): Sends release authorizations for named prior providers. Sets a follow-up task for Day −5.
  3. Day −7 (records clerk): Transmits signed releases outbound. Logs each request with a due date.
  4. Day −3 (clinical support): Confirms intake questionnaire and any submitted media landed in the chart, not in a mailbox. Anything found in email gets moved and the mailbox copy deleted per policy, with the action noted.
  5. Day −1 (privacy officer, monthly spot check): Reviews one intake at random end-to-end, verifying every vendor touched has a current BAA on file.
  6. Day 0 (clinician): Confirms identity, confirms patient's location, confirms who else is in the room on both ends, and documents the telehealth consent acknowledgment.
  7. Day +2 (records clerk): Files inbound outside records into the chart with source and date received.
  8. Day +5 (billing): Verifies place-of-service and modality coding against documented location. CMS publishes current Medicare telehealth policy; your payer mix will have variations.

What to Audit This Quarter

  • Every vendor in the intake chain, matched against a signed, current BAA. Include subcontractor flow-down language.
  • Analytics and third-party scripts on any page that collects health information.
  • Retention settings on the form builder, e-signature service, and media storage — separately, because they will not match.
  • Access logs for submitted patient media. Who opened it, and did they need to?
  • State-by-state telehealth consent requirements for every state your patients occupy during visits.
  • Your breach response contacts and timeline, tested rather than assumed. The OCR breach portal is a useful reminder of how many incidents originate with a business associate rather than the practice itself.

One forward-looking note: OCR published a proposed Security Rule update for comment in January 2025 that would tighten expectations around asset inventories, encryption, and multi-factor authentication. Whatever its final form, a practice that already maintains an accurate vendor and asset inventory will have far less remediation work than one that does not.

Start With the Contracts You Cannot Produce

Pick one hypermobility ehlers telehealth encounter from last month and trace it vendor by vendor. Every vendor whose BAA you cannot pull up in two minutes is your first work item. Generate the missing agreements with a business associate agreement tool built for that specific job, get them signed, and file them where your next auditor will actually look. If the gap runs deeper than contracts — risk analysis, policies, the full document set — automating that documentation is the more efficient starting point.