PREVENT Calculator Visits: Telehealth Intake Privacy
Your cardiology group just added twelve virtual risk-assessment slots a week. Each one runs the same way: the patient fills out a web form the night before, a medical assistant pulls recent lipid and kidney values from the lab interface, and the clinician runs a prevent calculator during the video visit to produce an estimated cardiovascular risk figure that gets pasted into the note. Four systems touched, three of them vendor-hosted, and nobody on your compliance side has looked at the data path end to end.
This post is about that path — the intake, consent, vendor, and records mechanics of a telehealth encounter organized around a risk calculator. It is not clinical guidance. Nothing here tells you or your clinicians how to interpret a number. It tells you where the protected health information goes, who has to sign what, and which of your existing forms is now out of date.
What a PREVENT calculator visit actually moves across systems
The administrative reason these visits deserve attention is simple: the inputs are scattered. A risk calculation of this type draws on demographics, blood pressure, cholesterol and glucose values, kidney function results, medication status, and — in some versions — a deprivation measure derived from the patient's ZIP code. Some of that lives in your chart. Some arrives from an outside lab. Some the patient types into a form.
That means a single 20-minute telehealth visit can involve:
- A patient-facing intake form, often hosted by a third party
- A video platform with a waiting room and possibly a chat log
- An inbound lab result feed or a faxed outside report that gets scanned
- The calculator interface itself — sometimes embedded in the chart, sometimes a browser tab
- The note, plus whatever patient-facing summary you send afterward
Each of those is a place where PHI sits, and each one either has a Business Associate Agreement behind it or does not. The visit type is new; your vendor inventory probably is not.
The ZIP code question comes up more than you expect
When a prevent calculator accepts a ZIP-code-based social deprivation input, front-desk and MA staff sometimes ask whether that field is "really" PHI. It is. Geographic data smaller than a state, combined with health information, is an identifier under the Privacy Rule's de-identification standard, and ZIP codes are explicitly listed there. Treat any log, spreadsheet, or export containing those values as a chart extract, not as demographics.
Does a prevent calculator visit need its own patient consent?
Short answer: no separate HIPAA authorization is required to run a risk calculation as part of treatment. Using PHI for treatment, payment, and health care operations does not require patient authorization under the Privacy Rule. Your Notice of Privacy Practices already covers it.
What you likely do need, depending on your state and payer mix:
- Telehealth consent — many states require documented consent to receive care by telecommunication, sometimes with specific disclosures about technology limitations and emergency procedures.
- Consent to text or email results — if you plan to send the risk summary by unencrypted email or SMS at the patient's request, document the request and that you explained the risk.
- Authorization for disclosure to a third party — if the patient wants the output sent to an employer wellness program, a life insurer, or a coaching app, that is not treatment. That needs a signed authorization with the required elements.
- Recording consent — if your platform records visits, state wiretap and two-party consent laws apply on top of HIPAA.
Bundle items one through three into a single intake acknowledgment rather than three separate signature events. Fewer forms, better completion rates, and one place to audit.
Your intake form is a vendor, not a form
This is where practices get caught. A clinician finds a slick online questionnaire, sends the link to patients, and starts collecting blood pressure readings and lab values through a general-purpose form builder that has never signed anything. The form works. The compliance posture does not.
Any service that creates, receives, maintains, or transmits PHI on your behalf is a business associate. A hosted intake form for a telehealth prevent calculator visit does all four. HHS maintains plain guidance on the required provisions of a business associate contract, and "we use their free tier" is not a defense.
Before the next visit is scheduled, answer three questions for every tool in the path:
- Does a signed BAA exist, and can you produce it in under five minutes?
- Does the vendor's own terms of service contradict the BAA — for example, by claiming rights to use submitted data for product improvement?
- Where is the data stored, and does the vendor use subcontractors who also touch it?
If the answer to the first question is no for even one tool, stop and paper it. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — which is usually faster than waiting three weeks for a vendor's legal team to send their template back.
Three intake paths, ranked by exposure
Lowest exposure: patient completes a questionnaire inside your patient portal. The data never leaves a system you already have an agreement for, and the responses land in the chart with an audit trail.
Moderate: a dedicated intake vendor with a signed BAA, configured so responses transfer into the chart and are then purged from the vendor after a defined retention window. Ask for the purge setting in writing; defaults are usually "keep forever."
Highest: a generic form builder, a shared clinic email inbox, or a staff member's spreadsheet. If your prevent calculator workflow currently depends on any of these, that is your first remediation item this quarter.
Charting the output so a records request doesn't become a dispute
Assume every risk figure you produce will eventually be requested — by the patient, by a specialist, by a disability reviewer, or by a plaintiff's attorney. That changes how you document it.
Set a standing rule that the note captures the inputs used, the tool and version, the date, and the resulting figure. Not because a policy demands it, but because a year later nobody can reconstruct a number from memory, and a chart that shows a result with no traceable basis is a records problem long before it is a clinical one.
Then decide, in writing, whether the calculator output is part of the designated record set. If the figure informs care and lives in the chart, it is. That means it travels with a right of access request, generally within 30 days, and it must go to the patient in the form and format they request if you can readily produce it. A PDF export of the note satisfies that. A screenshot someone took on a personal phone does not.
The referral hand-off
Risk-assessment visits frequently end with a referral or a request for outside records — that is the ordinary administrative consequence of care coordination, and it is where information moves between organizations. Disclosures for treatment purposes do not require authorization, but they do require your minimum-necessary habits to hold. Send the relevant note and results, not the entire chart. Log the disclosure if it falls outside treatment, payment, or operations.
Also confirm your fax and direct-message destinations before the volume ramps. Misdirected disclosures remain one of the most common small-practice incidents, and a new visit type is exactly when a stale fax number resurfaces.
Tracking code on the page where patients find your risk tools
If your marketing team built a landing page — "Find out your cardiovascular risk, schedule a virtual assessment" — check what analytics and advertising scripts run on it, and check the same for the intake form.
OCR's bulletin on the use of online tracking technologies remains the reference point here. Litigation has narrowed parts of that guidance, but the underlying exposure has not changed: if a third-party script captures an IP address alongside evidence that a specific person is seeking care for a specific condition, you have a disclosure to justify. Advertising platforms will not sign a BAA.
Practical steps, in order:
- Pull the list of scripts loading on the scheduling and intake pages. Your web developer can do this in ten minutes.
- Remove advertising and session-replay tools from any authenticated page or symptom-specific intake flow.
- Move conversion tracking to a server-side event that fires without patient identifiers, or accept coarser marketing data.
- Document the decision. An unexplained tracker is worse than a documented one.
Separately: if any patient-facing app in this workflow is not covered by HIPAA — a standalone wellness tool your practice merely recommends — the FTC's Health Breach Notification Rule may reach it. Know which regime applies to which tool before you point patients at anything.
A 30-day rollout, with names attached
Assign these. Unassigned checklists do not get done.
Days 1–5 — Privacy Officer. Diagram the data path for one completed prevent calculator visit, from the scheduling click to the closed note. List every system and every human who touched PHI. Expect to find two vendors you did not know about.
Days 6–12 — Privacy Officer plus whoever owns contracts. Match each system to a signed BAA. Paper the gaps. Verify retention and purge settings for the intake tool in writing.
Days 13–18 — Front-desk lead. Consolidate telehealth consent, communication-preference documentation, and the NPP acknowledgment into one intake step. Write the two-sentence script staff use when a patient asks why the form wants a ZIP code.
Days 19–24 — HIM or records lead. Confirm the calculator output is included in your designated record set definition and that a standard chart export captures it. Test one release-of-information request end to end.
Days 25–30 — IT plus marketing. Audit trackers on all pages in the funnel. Confirm the video platform's recording setting matches your policy, not the vendor's default.
Then feed the whole thing back into your risk analysis. A new encounter type with new vendors is a change in scope, and the Security Rule expects your analysis to reflect current reality — see the HHS Security Rule guidance materials for what "current" means in practice. If maintaining that documentation set by hand is the bottleneck, automated risk analysis and policy generation will get you to a defensible baseline faster than another shared spreadsheet.
The one thing to fix this week
Pick the tool in your prevent calculator workflow with the least paperwork behind it — usually the intake form — and close that gap first. Everything else on the list survives another month. An unpapered vendor holding lab values and ZIP codes does not.
If the missing piece is the agreement itself, build a signature-ready BAA in a single sitting and get it out for signature before your next batch of virtual assessment slots opens.