At 7:40 a.m. a patient emails your front desk a photo of a lab report because the intake link "wouldn't take the attachment." The report shows a protein panel — total protein, albumin, and the s globulin fraction — plus the patient's full name, date of birth, and the ordering physician's office. Your scheduler forwards it to the nurse's personal Gmail so the telehealth visit at 9:15 isn't wasted. That single sequence involves an unencrypted inbound email, an intake vendor that failed silently, and a transmission of PHI to an account you cannot audit, suspend, or search. Nobody made a clinical decision. You still created three problems you now own.

This article is about the administrative machinery around that kind of encounter — intake, consent, vendor agreements, records movement, and documentation. It is not clinical guidance and contains none.

What an s globulin telehealth visit actually looks like from the administrator's chair

Globulin values show up on routine serum protein panels, which means they arrive at your practice from outside labs, hospital systems, and prior treating physicians far more often than they originate in your own building. When a value prompts a follow-up conversation, that conversation frequently involves a specialist — hematology, immunology, rheumatology — and sometimes an infusion or specialty pharmacy provider. Records move between organizations. That is the only clinical fact you need for the rest of this piece.

Operationally, a single telehealth consult built around an s globulin result touches more entities than a standard office visit:

  • The patient's own device and network
  • Your scheduling and intake form vendor
  • Your video platform
  • Your EHR and its document-import pathway
  • One or more outside labs or a health information exchange
  • A referral recipient, often at a different covered entity
  • Occasionally a translation service, transcription tool, or AI scribe

Seven or eight relationships. Each one needs a written agreement, a defined data scope, and a person on your staff who can name it during an audit. Most practices can name three.

The intake form is where most s globulin privacy problems start

Pre-visit intake for a specialty-adjacent consult tends to sprawl. Somebody adds a free-text box labeled "paste your lab results here." Somebody else adds an upload field for PDFs. Then a well-meaning clinician asks for family history, current medications, and prior treatment history so the visit runs efficiently. Within a year your intake form is collecting more sensitive information than your EHR problem list, and it lives in a vendor system that nobody has reassessed since go-live.

Run a field-level minimum necessary review

Print your intake form. Beside each field, write the specific operational reason the data must be collected before the visit rather than during it. Fields that survive stay. Fields that exist because "it's nice to have" get deleted. This exercise typically removes 15 to 30 percent of a mature intake form, and every removed field is data you no longer have to secure, retain, produce on request, or report if breached.

Pay particular attention to free-text boxes. A patient asked to describe why they were referred will write a paragraph containing diagnoses, family member names, and employer details. You cannot apply granular access controls to a paragraph. Structured fields with fixed options are easier to segment and easier to redact when a records request arrives asking for something narrower.

Fix the attachment path before you fix anything else

If your upload widget fails on large files or certain image formats, patients will default to email or text. Test uploads on a phone, on cellular data, with a 12-megabyte photo, at least quarterly. Then give your front desk a scripted response for inbound unencrypted email that contains PHI: acknowledge receipt, do not forward, import through the sanctioned pathway, log the incident, and send the patient the secure link with a one-sentence explanation.

Patients are allowed to email you in the clear if they choose to. Your staff forwarding that message to a personal account is a different matter entirely, and it is the part that shows up in a risk analysis as an unmanaged transmission channel.

Telehealth vendors supply a consent checkbox. It typically covers the technology and the possibility of connection failure. It does not cover the things administrators get asked about later.

Your consent packet for a remote consult should separately address:

  1. Modality and fallback. What happens if video drops — telephone continuation, reschedule, or in-person conversion — and how the encounter is documented in each case.
  2. Location disclosure. Licensure and emergency response both depend on knowing where the patient physically is. Capture it as a discrete field, not a verbal aside.
  3. Third parties in the room. A family member off-camera on the patient's side, a scribe or student on yours. Both get named in the note.
  4. Recording. See below.
  5. Outbound records movement. Explicit acknowledgment that results, including the panel containing the s globulin value, may be transmitted to a referral recipient and returned to the ordering physician.
  6. Communication preferences. Which channels the patient authorizes for follow-up, and a note that SMS and unencrypted email carry risk.

HIPAA does not prohibit recording a telehealth encounter. State wiretapping and two-party consent statutes may, and they follow the patient's location as well as yours. If your platform offers recording, decide deliberately whether to enable it, document the decision, and if you enable it, get affirmative consent captured in the record — not just a checkbox buried in a technology disclosure. If you disable it, verify quarterly that a vendor update has not silently re-enabled it as a default.

The same logic applies to AI scribes and transcription add-ons. A transcript is a recording. It is also PHI, stored somewhere, under someone's retention schedule.

Do you need a BAA with a telehealth platform for s globulin visits?

Yes. If a vendor creates, receives, maintains, or transmits PHI on your behalf, a Business Associate Agreement is required before PHI flows — and that includes video platforms, intake form vendors, scheduling tools, transcription services, and cloud storage, even when the vendor claims it never "looks at" the data. The HIPAA enforcement discretion that permitted non-compliant telehealth technology during the COVID-19 public health emergency ended August 9, 2023. There is no remaining grace period. HHS maintains specific guidance on HIPAA and telehealth that spells out the current expectations.

Two exceptions people misapply: a conduit like an internet service provider that only transmits data without access is not a business associate, and a clinician at another covered entity you refer to is not your business associate — that is a treatment disclosure. Everything else on your telehealth stack needs paper.

If your vendor list has grown faster than your agreement file, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, which matters when you are backfilling agreements for six vendors in an afternoon rather than budgeting for another subscription.

The 30-day clock that starts when the patient asks for the visit record

After an s globulin consult, patients frequently want the whole packet: your note, the outside lab report you imported, and the referral letter. Under the HIPAA right of access you have 30 calendar days from the request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS publishes detailed right-of-access guidance, and access failures have been a persistent enforcement theme for years.

The wrinkle with imported outside records is that staff hesitate. A front desk trained to "only release what we generated" will withhold the lab report that came from the reference lab. Wrong instinct. If the record is in your designated record set and you used it to make decisions about that patient, it is generally accessible to the patient — regardless of who originally produced it.

Write the release decision tree down

One page, taped inside the release coordinator's desk drawer:

  • Patient requesting their own record → right of access, 30 days, cost-based fee
  • Patient directing the record to a third party → written, signed, specific direction required
  • Another treating provider requesting for treatment → permitted disclosure, log it
  • Attorney, employer, insurer outside payment or operations → valid authorization required
  • Anything involving reproductive health care → check the current attestation requirements before releasing
  • Unsure → escalate to Privacy Officer same day, do not send

Assign the work: four roles, no ambiguity

Privacy Officer. Owns the intake field inventory, the consent packet text, the release decision tree, and the incident log. Reviews the vendor list quarterly.

Security Officer. Owns access controls, audit log review, encryption verification on every channel, and the risk analysis. If these two roles are one person in your practice, say so in writing and document the time allocation.

Front desk lead. Owns the inbound-PHI script, upload testing, and location capture. Reports failed uploads weekly, not annually.

Release coordinator. Owns the 30-day clock with a tickler at day 10 and day 20, plus the disclosure log.

A workable 10-business-day sequence

Days 1–2: list every system that touched PHI in a telehealth encounter last month. Pull it from your invoices, not from memory. Days 3–4: match each system to an executed BAA and flag the gaps. Days 5–6: field-level minimum necessary review of the intake form; delete what fails. Day 7: rewrite the consent packet against the six items above. Day 8: test uploads on three devices. Days 9–10: train the front desk on the inbound-PHI script and document attendance.

What an auditor wants to see afterward

Your risk analysis should name the telehealth pathway explicitly — intake vendor, video platform, transcription tool, referral transmission method — with the safeguards applied to each. NIST's SP 800-66r2 guide to implementing the HIPAA Security Rule is the most practical free framework for structuring that analysis, and it maps cleanly to the Cybersecurity Framework if your larger referral partners ask for that mapping.

Keep the boring artifacts: executed BAAs with dates, the consent packet version history, training sign-in sheets, quarterly upload test results, audit log review notes with the reviewer's name. When something does go wrong, breach notification runs on a 60-day outer limit from discovery, with incidents affecting 500 or more individuals reported to HHS without unreasonable delay and smaller incidents submitted annually within 60 days of the calendar year's end. Documentation is what turns a bad afternoon into a manageable one.

Also check whether any patient-facing app you offer alongside the visit sits outside HIPAA and inside the FTC's jurisdiction. The FTC's health privacy business guidance is worth thirty minutes of your marketing lead's time before they add another tracking pixel to a page that mentions lab panels.

Start with the two gaps you can close this week

Pull the vendor list. Match it to signed agreements. Where a telehealth or intake vendor is handling PHI without one, build the BAA and get it signed before the next scheduled consult. If the exercise reveals that your risk analysis and policy set are also out of date, automated risk analysis and policy generation will get the document set current faster than a from-scratch rebuild. Neither step requires a clinical decision, and both are things you can finish before the end of the month.