At 8:40 on a Tuesday, a patient joins a video visit from her kitchen table. Before your clinician says a word, her data has already passed through a scheduling platform, a web-based intake form, an e-signature tool, a video vendor, and — if you use ambient documentation — a transcription service. That is five business associates deep, and the encounter has not started.

This post is about that chain. Using a telehealth visit for si joint dysfunction as the working example, it walks through intake, consent, recording, vendor agreements, and records requests from the administrator's chair. It is not clinical guidance. The only clinical fact that matters here is a workflow fact: these visits routinely generate a referral to physical therapy, sometimes imaging, and often a note that travels to a primary care physician. Records move between organizations, and every movement is a privacy decision someone in your office is making — deliberately or not.

What a Telehealth Visit for SI Joint Dysfunction Actually Touches

Sit down with your practice manager and list every system that holds a fragment of one telehealth encounter. Most small practices are surprised by the length.

  • Scheduling and reminders. Appointment type, phone number, sometimes the reason for visit in a free-text field.
  • Digital intake. Pain history, prior treatments, medication list, insurance card images, driver's license photo.
  • E-signature. Telehealth consent, financial policy, Notice of Privacy Practices acknowledgment.
  • Video platform. Session metadata, participant identity, chat logs, any recording.
  • Documentation tooling. Ambient scribe audio, draft notes, model outputs.
  • Outbound referral. Fax service, direct messaging, or a portal upload to a PT clinic or imaging center.
  • Billing. Clearinghouse, statement vendor, payment processor.

Seven systems. Seven potential breach vectors. Seven contracts that either exist or do not. The clinical complexity of si joint dysfunction is irrelevant to your risk profile; the vendor count is the whole story.

Build the inventory as a document, not a memory

Assign one person — usually the privacy officer or office manager — to maintain a single spreadsheet with vendor name, data elements touched, BAA status, BAA date, contract renewal date, and the internal owner. Review it quarterly. When OCR asks how you knew who had your PHI, this spreadsheet is the answer. When a vendor announces an incident, this spreadsheet tells you in ninety seconds whether you are affected.

The Three Consents Your Front Desk Keeps Confusing

Staff routinely collapse three distinct documents into one "telehealth form." They are not the same, they are governed by different authorities, and they fail differently.

This is a state law and payer requirement, not a HIPAA requirement. Most states require the patient to be told that the visit is being conducted remotely, that they may decline and be seen in person, and — in some states — that the encounter may be recorded. Some payers require documentation that consent was obtained and when. Your telehealth consent should be dated, tied to the encounter, and retrievable without opening the video vendor's console.

2. Notice of Privacy Practices acknowledgment

HIPAA requires you to make a good-faith effort to obtain written acknowledgment that the patient received your NPP. In a virtual-first workflow, that means the NPP must be available before the visit — linked in the intake email and posted on your website — not handed over in a lobby the patient never enters. If your NPP still describes only in-person operations and paper records, it is stale.

3. Authorization for disclosure

A HIPAA authorization under 45 CFR 164.508 is a different animal entirely. It is required for uses and disclosures that fall outside treatment, payment, and health care operations — marketing, most research, disclosures to an employer, disclosures to a personal injury attorney. Your front desk should know that "the patient's lawyer called about the injury claim" triggers an authorization, and that a signed telehealth consent does nothing for that request.

Do You Need a HIPAA Authorization to Send Telehealth Notes to a Physical Therapist?

No. HIPAA permits a covered entity to disclose protected health information to another provider for that provider's treatment of the patient without a signed authorization (45 CFR 164.506). The minimum necessary standard does not apply to treatment disclosures. In practice, that means the note from a si joint dysfunction telehealth visit can go to the receiving PT clinic under your normal referral process.

Three caveats your staff should carry:

  1. State law may be stricter, particularly where the record contains behavioral health, substance use (42 CFR Part 2), or HIV-related information.
  2. The transmission method still has to be secure. Permission to disclose is not permission to email an unencrypted PDF to a Gmail address.
  3. Verification is mandatory. Confirm the requesting party is who they claim to be before anything leaves your system. Callback verification to a number you look up independently, not the number on the fax cover sheet.

Recording, Screen Share, and the Camera-On Problem

Musculoskeletal telehealth visits are visually driven. A clinician may ask the patient to stand, walk, or change camera angle. That means the video frame is now capturing the patient's home — family members walking through, a roommate on the couch, prescription bottles on the counter, mail on the table.

Decide your recording policy before your clinicians decide it for you. Most practices are better served by a default of no recording, with recording as a deliberate, documented exception. If you do record:

  • Confirm the video vendor stores recordings under a BAA and tell you the storage region and retention period.
  • Set an automatic deletion schedule and verify it actually runs. Ask for a screenshot of the retention setting for your compliance file.
  • Document consent to record separately from consent to the visit, and check whether your state is a two-party consent jurisdiction.
  • Treat the recording as part of the designated record set if it is used to make decisions about the patient. That has access-request consequences, covered below.

Also train clinicians on their own frame. Whiteboards with the day's schedule, a second monitor showing another patient's chart, and open exam room doors are all disclosures. HHS maintains a plain-language overview of HIPAA requirements for telehealth that is worth circulating to clinical staff verbatim. Remember that the pandemic-era enforcement discretion for telehealth technologies ended in August 2023 — consumer video apps without a BAA are no longer covered by any grace period.

Your Vendor List Is the Real Compliance Artifact

Run this test on your own practice. Pick the newest tool your team adopted in the last twelve months — a scheduling widget, an AI scribe trial, a form builder, a texting service. Now find the executed Business Associate Agreement. Can you produce it in under five minutes, with a countersignature and a date?

In most practices the answer is no for at least one vendor, and the gap is almost always a tool that entered through a clinician or a front-desk workaround rather than through procurement. Telehealth accelerates this because the friction to sign up for a new tool is a credit card and four minutes.

Fix it structurally. Write a one-line rule into your policy manual: no tool that touches patient information goes live without a signed BAA on file and an entry in the vendor inventory. Then make signing easy enough that nobody routes around it. If you are chasing paperwork for a form builder, a transcription tool, and a fax service at the same time, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than emailing a vendor's sales rep and waiting nine days for their legal template.

What to check inside the BAA, not just that one exists

  • Breach notification timeline. Anything longer than 10 days from discovery compresses your own 60-day clock uncomfortably.
  • Subcontractor flow-down. Your video vendor's cloud host and transcription partner are your exposure too.
  • Return or destruction of PHI at termination, with a defined format for the export.
  • Cooperation with patient access requests, so you can meet your 30-day obligation when the data lives on their servers.

Intake Forms, Trackers, and the Front Door of Your Website

The intake page is the least-governed surface in most practices. Marketing built it. Nobody in compliance has looked at the page source since launch.

Open your telehealth landing page and your appointment request form in a browser and inspect what scripts load. Analytics pixels, ad retargeting tags, chat widgets, and session-replay tools all sit between the patient and your intake queue. When a page is dedicated to a specific condition — a landing page for back and si joint dysfunction consults, for example — the URL itself can be revealing, and session-replay tools can capture keystrokes in form fields before submission.

OCR's guidance on online tracking technologies has been through litigation, and portions of it were vacated by a federal court in 2024. The narrower legal question does not change the operational one: if a third-party script on your site collects identifiable health information without a BAA and without authorization, you have a problem under HIPAA, under the FTC Act, or under state privacy law — often more than one. Inventory the scripts, remove what you cannot justify, and document the review with a date and a name.

When the Patient Asks for the Video

Six weeks after the visit, the patient emails: "Please send me everything from my telehealth appointment, including the recording." Your clock started the day the request arrived.

Under the HIPAA right of access, you have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. You must provide the record in the form and format requested if readily producible. Fees are limited to a reasonable, cost-based amount — labor for copying, supplies, and postage. Search and retrieval time is not billable. HHS's right of access guidance is the authoritative reference, and OCR has brought a long line of enforcement actions against practices that ignored or slow-walked these requests.

Two operational decisions to make in advance:

  1. Define your designated record set in writing. Which telehealth artifacts are in it? The clinical note, yes. The raw scribe audio? The chat transcript? The recording? Decide, document, and apply consistently — not case by case under pressure.
  2. Know how to export from every vendor. If the recording lives with your video platform, test the export path once, before a real request lands, and note the steps in your procedure.

A Two-Week Cleanup Plan You Can Assign Tomorrow

Days 1–3 — Inventory. Office manager lists every system touching a telehealth encounter, with the data elements each one holds. No judgment, just the list.

Days 4–6 — BAA reconciliation. Privacy officer matches each vendor to an executed agreement. Anything missing goes on a remediation list with a named owner and a due date.

Days 7–8 — Consent audit. Pull ten completed telehealth charts at random. Confirm each has a dated telehealth consent, an NPP acknowledgment, and a verification note for any outbound disclosure. Record the pass rate.

Days 9–10 — Website review. Marketing and privacy sit together, inspect scripts on intake and condition pages, and remove or contract for anything that collects identifiable information.

Days 11–12 — Recording and retention. Confirm the default setting in your video platform, the retention period, and who has administrative access. Revoke access for anyone who left.

Days 13–14 — Document it. Write the two-page memo describing what you found and what you changed, sign it, date it, and file it with your risk analysis. Undocumented remediation is indistinguishable from no remediation when an investigator arrives.

None of this requires a new platform or a certification — and no vendor, including us, can issue a government-recognized HIPAA credential, because none exists. What it requires is a named owner, a written record, and a schedule.

Close the Vendor Gaps First

The intake and consent work above is worth nothing if a business associate is holding your PHI without an agreement. Start there: pull the vendor list, find the gaps, and produce the missing Business Associate Agreements this week rather than next quarter. If your broader documentation set — risk analysis, policies, workforce training records — is equally thin, automated HIPAA compliance documentation will get you to a defensible baseline faster than rebuilding templates by hand. Either way, the next telehealth visit for si joint dysfunction should run on a workflow you can describe on paper.