Count the vendors on your remote-care list. One calls itself a telehealth platform, one calls itself a telemedicine solution, one sells "virtual care infrastructure," and the signed agreement in your file cabinet says "video visit software." Four names, four contracts, and no one at your practice can say with confidence which of them touches protected health information and which of them signed a Business Associate Agreement.

That is the practical stakes of telehealth vs telemedicine. The distinction is not academic vocabulary — it decides which vendors land on your BAA list, which services your billing staff can document defensibly, and what your privacy officer has to produce when a patient asks for "everything from my virtual visits." This guide walks through the operational mechanics, then makes the privacy, records-handling, and vendor implications explicit.

Telehealth vs Telemedicine: The Short Answer for Administrators

Telemedicine refers to clinical services delivered remotely by a licensed clinician to a patient — the remote equivalent of an encounter that would otherwise happen in your exam room. Telehealth is the broader umbrella: it includes telemedicine, plus non-clinical and non-encounter activities such as provider-to-provider consultation, remote patient monitoring data collection, patient education, administrative check-ins, and continuing education.

Put operationally: every telemedicine service is telehealth. Not every telehealth service is telemedicine. HRSA's federal resource hub at telehealth.hhs.gov uses telehealth as the governing term for exactly this reason — it has to cover activities that never produce a billable clinical encounter.

For your purposes, the split matters in three places: what you bill, what you document, and which vendors handle PHI. The third one is where practices get hurt.

Where the Word Choice Actually Bites: Your Vendor Inventory

Practices tend to build their BAA list around the encounter. Video visit platform? Obviously a business associate. Scheduling system that feeds it? Usually caught. Everything else in the telehealth-but-not-telemedicine category gets missed.

Here's what typically falls through:

  • Remote patient monitoring vendors. Blood pressure cuffs, glucose meters, and weight scales streaming readings into a dashboard. No clinician is on the call. PHI is still moving.
  • Secure messaging and patient portal add-ons purchased separately from the EHR, often by a clinician with a credit card.
  • Interpretation and translation services joining virtual encounters as a third party.
  • Store-and-forward image transfer tools — dermatology photos, retinal images, wound care documentation.
  • Appointment reminder and intake-form vendors that collect symptom data before the visit.
  • Transcription, ambient documentation, and AI scribe tools that record the encounter audio.

Every one of those is telehealth. None of them is telemedicine in the narrow sense. All of them create, receive, maintain, or transmit PHI on your behalf, which is the actual test under 45 CFR 160.103 — not whether a doctor was on camera.

Three questions that settle any remote-care vendor

  1. Does the vendor touch identifiable patient data at any point? Including in transit, including if it claims the data is encrypted end-to-end and it "can't see" it. Conduit exception is narrow — it covers transmission-only services like ISPs and the postal service, not platforms that store data.
  2. Does the vendor retain anything? Recordings, chat logs, connection metadata, uploaded documents, waiting-room screenshots. Ask for the retention schedule in writing.
  3. Who are the subcontractors? Cloud hosting, transcription, analytics, customer support tooling. Your BAA has to flow down.

Assign this inventory to one person. In most practices under 30 staff, that is the practice administrator. Above that, it belongs to the privacy officer with a quarterly review calendar.

HIPAA Never Defines Either Term — Which Is the Whole Problem

Search the Privacy Rule and the Security Rule for "telehealth" or "telemedicine." You will not find operative definitions that change your obligations. HIPAA regulates PHI and the entities that handle it. The delivery modality is irrelevant to whether the rules apply.

That neutrality cuts both ways. It means you cannot argue a service is outside HIPAA because it isn't "real" telemedicine. It also means the enforcement discretion many practices leaned on during the public health emergency is gone — OCR ended the telehealth-specific discretion in 2023, and there is no remaining allowance for consumer video apps that won't sign a BAA. HHS's telehealth guidance for HIPAA-covered providers is the current baseline.

So the compliance question is never "is this telehealth or telemedicine?" It is "does this arrangement move PHI to a third party, and do I have a signed agreement covering it?"

If your answer to that second half is "probably, somewhere," you have a documentation problem. HHS publishes sample business associate agreement provisions, but sample provisions are not a signature-ready contract, and most administrators do not want to spend a week assembling one per vendor. If you need to close gaps quickly, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription, which matters when you're papering six vendors at once rather than buying a platform.

Billing Documentation: Modifiers, Place of Service, and Who Owns the Grid

The billing side is where telehealth vs telemedicine turns into a documentation discipline rather than a vocabulary exercise. Payers do not use the terms consistently, and their policies do not match each other.

The code sets distinguish remote encounters in a few ways your billing staff needs to track. Place-of-service codes separate encounters where the patient is in their home from encounters where the patient is at another originating site. Modifiers signal whether a service was furnished via interactive audio-and-video or audio-only. Additional code families cover asynchronous store-and-forward, brief virtual check-ins, e-visits through the portal, and remote monitoring device supply and management.

None of that tells you what to bill for a given patient. That determination belongs to the treating clinician and your certified coders, applied against the payer's published policy in effect on the date of service.

How your practice should document code selection

Build a payer policy grid and treat it as a controlled document. At minimum it should record, per payer:

  • Which remote modalities the payer recognizes (audio-video, audio-only, asynchronous, monitoring)
  • Required modifiers and place-of-service conventions
  • Originating-site and geographic restrictions, if any
  • Consent documentation the payer requires in the note
  • Effective dates and the URL of the policy you relied on
  • Date last verified and the initials of the person who verified it

That last line is the one auditors care about. "We checked in Q4 and here is who checked" is a defensible answer. "That's how we've always done it" is not.

Medicare's remote-service policies have been running on short-term statutory extensions attached to funding legislation, which means expiration dates have moved more than once and sometimes land only weeks out. Do not print a fee schedule and forget it. Check the effective dates against CMS's Medicare telehealth information before each quarter's billing meeting, and put a named owner on that task.

Recordings, Chat Logs, and the 30-Day Access Clock

A patient emails your office: "Send me everything from my virtual visits last year." You have 30 days to respond, with one possible 30-day extension and written notice explaining the delay. HHS's right of access guidance has been an enforcement priority for years, and OCR has resolved a long series of access-related cases.

Now answer the harder question: what is "everything"? Your designated record set includes the records you use to make decisions about that patient. For remote care, that plausibly reaches:

  • The clinical note documenting the encounter
  • Secure messages exchanged through the portal that informed care decisions
  • Images and documents the patient uploaded
  • Remote monitoring readings your clinicians reviewed
  • Session recordings, if your practice retains them and clinicians rely on them

The operational risk is that half of that data lives in a vendor system your EHR does not index. If your monitoring vendor holds twelve months of readings and your portal vendor holds message threads, your records clerk cannot fulfill the request from one screen.

Fix this before the request arrives. Write down, per remote-care vendor, where the data lives, how to export it, how long export takes, and who at the vendor to contact. Put that vendor's export SLA into the contract at renewal. A 30-day clock does not pause because your vendor's support queue is backed up.

Decide the recording policy, then enforce it

Recording remote encounters creates a durable, high-sensitivity artifact. Some practices record for documentation quality; many decide the retention burden isn't worth it. Either choice is defensible. Having some clinicians record and others not, with no written policy, is not.

If you record: document the retention period, the access controls, the deletion procedure, and whether recordings are part of the designated record set. If you don't record: turn the feature off at the platform administrative level, not by asking staff nicely.

State law drives most remote-care consent requirements, and they vary. Several states require documented patient consent to receive services remotely before the encounter begins, and some require it in writing. Your billing payer policies may separately require consent language in the note.

Give your front desk a script and a checkbox, not a paragraph to improvise. A workable script covers: the encounter is happening remotely, the technology being used, the patient's right to request an in-person visit instead, any expected cost-sharing difference, and a note that connection failures may end the visit early.

Then confirm the consent lands somewhere retrievable. A verbal consent noted in a scheduling comment field that gets overwritten at the next appointment is not documentation.

A 30-Day Cleanup Plan You Can Assign This Week

  1. Days 1–5: Pull every recurring software charge from the last twelve months of practice credit card and AP records. Any vendor touching patient data goes on the list, regardless of what it calls itself.
  2. Days 6–10: Match each vendor to a signed BAA. Note the signature date, the subcontractor flow-down language, and the breach notification window. Flag anything unsigned, expired, or signed by someone no longer employed.
  3. Days 11–18: Close the gaps. Send BAAs to unsigned vendors with a response deadline. If a vendor refuses, escalate to a replacement decision — that is a leadership call, not a staff call.
  4. Days 19–24: Build the records-export map. One row per vendor: data type, export method, export owner, turnaround time.
  5. Days 25–30: Update the payer policy grid and confirm the coding documentation workflow with your billing lead. Verify remote-service effective dates.

Document that you did this. Your risk analysis obligation under the Security Rule is ongoing, and a remote-care vendor sweep is exactly the kind of evidence that demonstrates the analysis is real rather than a binder from three years ago. If you'd rather not rebuild the whole document set by hand, tools that automate HIPAA risk analysis reports and policy generation can produce the artifacts and let your team spend its hours on the vendor conversations that actually require judgment.

Stop Debating the Word, Start Auditing the Data Flow

The telehealth vs telemedicine question resolves cleanly once you stop treating it as a definition and start treating it as a scope question. Telemedicine is the clinical encounter. Telehealth is everything remote, clinical and otherwise. HIPAA follows the PHI in both cases, and your BAA list has to be as broad as your data flows — not as narrow as your video visit calendar.

Start with the vendor inventory. If it surfaces agreements you can't find or vendors you never papered, build the Business Associate Agreements you're missing and get them signed before the next records request or vendor questionnaire forces the issue.