TeleMed Today
Compliance

Telehealth Security and HIPAA: What Providers Need to Know in 2026

What does HIPAA require for telehealth? Learn about BAAs, encryption, video platforms, AI scribes, texting, patient privacy, risk assessments, and telehealth security in 2026.

By TeleMed Today Editorial Team·Published ·Updated ·15 min read

A telehealth visit looks simple.

A patient clicks a link. A clinician joins. They talk. The visit ends.

Behind that call, though, there may be an electronic health record, scheduling platform, cloud provider, billing company, text messaging system, patient portal, remote monitoring device, and increasingly an AI tool helping write the clinical note.

Every additional system creates another place where patient information can move. That is the real issue with telehealth security.

HIPAA did not suddenly appear when healthcare moved onto video. The same basic responsibility remains: protected health information has to be handled appropriately whether the patient is sitting across from you in an exam room or talking to you through a phone from hundreds of miles away.

The technology changed. The responsibility did not.

Key takeaway

HIPAA compliance in telehealth is not about choosing one "HIPAA-compliant" video platform. Providers need to understand the entire path patient information takes — from scheduling and video visits to EHRs, messaging, cloud vendors, billing systems, AI tools, and remote monitoring devices.

Table of contents

Does HIPAA Apply to Telehealth?

Yes. HIPAA can apply to telehealth when a covered entity or business associate creates, receives, maintains, or transmits protected health information through virtual care. Providers still need to consider privacy, security, and breach-notification obligations. The fact that care takes place through video, phone, or another digital system does not create a blanket HIPAA exemption.

What HIPAA Actually Means for Telehealth

HIPAA is not a special set of rules for video calls.

For organizations subject to HIPAA, the rules generally follow the protected health information. If electronic protected health information — usually called ePHI — is created, received, maintained, or transmitted through virtual care, the HIPAA Security Rule may apply.

That includes much more than the video itself. Think about everything surrounding a modern virtual visit:

  • Appointment scheduling
  • Patient registration
  • Video conferencing
  • Electronic health records
  • Patient portals
  • Electronic prescribing
  • Text messages
  • Email
  • Billing
  • Cloud storage
  • Remote patient monitoring
  • AI transcription
  • AI documentation tools

This is why buying a platform marketed for healthcare does not suddenly make a telehealth program compliant. The video call is only one piece.

For a broader look at the infrastructure behind virtual care, see our guide to telehealth technology. If any of the vocabulary in this article is unfamiliar, the telehealth glossary defines the terms in plain English.

The Three HIPAA Rules Providers Should Understand

You do not need to become a healthcare attorney to understand the basic structure. Three parts of HIPAA matter heavily in virtual care.

The Privacy Rule

The HIPAA Privacy Rule governs how protected health information may be used and disclosed.

Virtual care does not remove a patient's privacy rights. A provider still has to think about who can see information, why that person has access, and whether the disclosure or access is appropriate.

The practical version is simple: the fact that information is digital does not make it less private.

The Security Rule

The HIPAA Security Rule focuses specifically on electronic protected health information.

HHS describes safeguards in three broad categories:

Administrative safeguards. Policies, procedures, workforce training, risk analysis, security management, and related organizational controls.

Physical safeguards. Protecting computers, workstations, phones, offices, devices, and other physical access points.

Technical safeguards. Controls such as authentication, access management, audit controls, integrity protections, and transmission security.

This distinction matters because cybersecurity is not simply an IT department problem. A strong encryption system does not help much if an employee leaves an unlocked laptop in a public place.

Healthcare organizations should review the current HHS Security Rule guidance when evaluating their own programs.

The Breach Notification Rule

Organizations also need procedures for what happens when protected health information may have been improperly accessed, acquired, used, or disclosed. HHS publishes the requirements in the Breach Notification Rule.

This is one reason technical safeguards matter.

The goal is not to pretend every possible incident can be prevented. That is unrealistic.

The goal is to reduce risk, recognize problems quickly, limit damage, understand what information may have been affected, and have a real process for responding.

The Pandemic Exception Is Over

This deserves its own section because some healthcare organizations built habits during COVID that never disappeared.

During the COVID-19 public health emergency, federal regulators exercised temporary enforcement discretion involving certain telehealth technologies used in good faith. Those temporary policies should not be treated as the permanent operating standard for telehealth in 2026. HHS has since published current guidance on specific questions, including audio-only telehealth.

If a telehealth workflow was assembled quickly in 2020 or 2021 and nobody has seriously reviewed it since, review it.

A lot has changed. Technology changed. Vendor contracts changed. Security expectations changed. And the temporary emergency environment ended.

Business Associate Agreements: The BAA Question

One of the first questions a healthcare organization should ask when reviewing a vendor is:

Does this company handle protected health information on our behalf?

If the answer is yes, another important question may be: does this relationship require a Business Associate Agreement?

A Business Associate Agreement — usually shortened to BAA — establishes responsibilities in certain relationships where a vendor or other organization qualifies as a business associate under HIPAA.

This can involve more vendors than people initially expect. Depending on the arrangement, that may include:

  • Telehealth platforms
  • EHR vendors
  • Cloud providers
  • Patient messaging systems
  • Transcription services
  • AI scribes
  • Billing companies
  • IT vendors
  • Answering services
  • File-storage services

Do not assume a vendor is covered simply because its homepage says "HIPAA compliant."

Ask about the BAA. Then determine which products and services the agreement actually covers.

That second part matters. A technology company may offer multiple products while its BAA only applies to a portion of them.

Healthcare organizations should also remember that not every vendor touching data automatically qualifies as a business associate. The nature of the relationship matters. HHS provides guidance on covered entities and business associates, along with sample Business Associate Agreement provisions.

There Is No Magic "HIPAA Certified" Software

This is one of the most persistent misconceptions in digital healthcare.

There is no magic software purchase that makes an organization HIPAA compliant. A platform can offer features that support compliance. That is different.

A healthcare organization can purchase excellent technology and still use it badly. For example:

The organization buys a secure platform. Then everybody shares the same login. Problem.

Or multi-factor authentication is available but nobody enables it. Problem.

Or recordings automatically save into an employee's personal cloud account. Problem.

Or the video platform is well secured but patient information is routinely being sent through an unapproved email system. Problem.

Security is a chain. Mistakes and attackers tend to find the weakest link.

10 Questions to Ask Before Choosing a Telehealth Vendor

Before choosing a telehealth vendor, ask these questions:

Vendor security checklist

  1. Will you sign a Business Associate Agreement when required?
  2. Which specific products and services are covered by that agreement?
  3. Where is patient information stored?
  4. Is data encrypted while being transmitted?
  5. Is stored patient information encrypted?
  6. Does the platform support multi-factor authentication?
  7. What audit logs are available?
  8. How long is patient information retained?
  9. Which subcontractors may handle patient information?
  10. What happens to our data when the relationship ends?

Do not accept "enterprise-grade security" as the entire answer. Get specifics.

What to Look for in a Telehealth Platform

Do not start with the marketing page. Start with the workflow.

Business Associate Agreement

Determine whether the vendor qualifies as a business associate and whether an appropriate BAA is required. If it is, make sure the agreement covers the actual product being used.

Encryption

Understand how sensitive information is protected while being transmitted and while stored.

Do not stop at the word "encrypted." Understand where the information goes.

Individual Accounts

Employees should have individual credentials where appropriate. Shared passwords make accountability much harder.

Multi-Factor Authentication

If a system containing sensitive patient information is accessible through the internet, multi-factor authentication is an important control and should generally be considered where supported.

Role-Based Access

Your receptionist probably does not need the same access as your medical director.

Give people the access they need to do their jobs. Not more.

Audit Logs

An organization should be able to understand who accessed sensitive systems and when. This becomes especially important when investigating a suspected security incident.

Session Controls

For video visits, consider features such as:

  • Waiting rooms
  • Participant admission
  • Meeting locks
  • Unique visit links
  • Recording controls
  • Screen-sharing controls

Data Retention

Know what information the vendor stores. Know where it goes. Know how long it stays there. Know whether you can delete it.

Those four questions eliminate a surprising amount of confusion.

The Risk Assessment Is Where This Becomes Real

A security risk analysis should not be a document somebody completed three years ago and forgot about.

Walk through the actual organization. Ask:

Where does patient information enter? Where does it go? Who can access it? Which vendors touch it? Which devices contain it? Which systems connect to the EHR?

What happens when an employee leaves? What happens when a laptop disappears? What happens when someone clicks a phishing link? What happens when a telehealth vendor has a security incident? What happens when a new AI tool is introduced?

Those are useful questions. The boring things matter too. In healthcare, that is often where the problems live.

Organizations building a virtual care program from scratch can see where the risk analysis fits in the larger sequence in our guide to how to start a telemedicine program.

Telehealth Security Problems Are Usually Ordinary

People hear the word cybersecurity and picture somebody in a dark room hacking into a hospital.

That does happen. But healthcare organizations also lose information through extremely ordinary mistakes.

Someone emails the wrong patient. Someone clicks a fake Microsoft login page. An employee loses a laptop. A former employee still has access. A clinician texts patient information from a personal phone. Someone records a visit and forgets where the recording is being stored. A telehealth link gets forwarded. An employee downloads a spreadsheet containing patient information and leaves it sitting on a desktop.

Security failures do not need to be sophisticated. That is why basic operational discipline matters.

Texting Patients

Patients text. Providers text. Pretending otherwise does not create a security policy.

Organizations need clear rules around:

  • Which platforms employees may use
  • What kinds of information can be sent
  • When communication should move into a secure portal
  • How patient communication preferences are handled
  • Whether messages become part of the medical record

Appointment reminders are different from sending detailed clinical information.

A message saying "Your appointment is tomorrow at 2 PM" creates a different privacy risk from "Your psychiatric medication evaluation for bipolar disorder is tomorrow at 2 PM."

Do not put sensitive information into communications when it does not need to be there.

For providers operating across multiple jurisdictions, also review our guide to telehealth laws and our overview of telemedicine laws by state.

Email and Telehealth

Email creates many of the same questions.

Organizations should know:

  • Which email system employees use
  • Whether appropriate security controls are enabled
  • Whether PHI is permitted through that system
  • How messages are retained
  • Whether accounts use MFA
  • Whether automatic forwarding is allowed
  • How patient communication preferences are documented

The answer should not change depending on which employee you ask. That is what policy is for.

AI Scribes Changed the Conversation

This is becoming one of the most important telehealth security questions.

AI documentation tools can listen to a clinical conversation and generate a draft note. That can save clinicians time.

It can also mean that another technology company is processing one of the most sensitive things a healthcare organization possesses: the actual patient conversation.

Before deploying an AI scribe, ask:

  • Does the vendor sign a BAA when required?
  • Does it retain the audio?
  • Does it retain the transcript?
  • How long is data retained?
  • Where is the data stored?
  • Can the organization delete it?
  • Is patient information used to train models?
  • Are subcontractors involved?
  • What happens when the contract ends?
  • Who reviews the generated clinical note before it becomes part of the record?

Do not accept "AI-powered healthcare compliance" as an answer. Get actual answers.

And remember that an AI-generated clinical note still needs appropriate clinical review.

Remote Patient Monitoring Adds More Doors

Remote patient monitoring expands telehealth beyond the video appointment.

A blood-pressure cuff, scale, glucose monitor, pulse oximeter, cardiac device, or other connected technology may transmit patient information without the patient actively doing anything.

That means providers should understand the entire path.

Device → application → cloud → vendor → provider → EHR

Every arrow deserves attention. Ask:

Where is the information stored? Who can access it? How is the user authenticated? Does the device connect through a personal phone? Which vendor controls the cloud environment? How does the data get into the EHR?

If nobody inside the organization can explain where the information goes, that is worth fixing.

See our full guide to remote patient monitoring for more on how these programs work.

Working From Home

Remote healthcare created another clinical environment: the clinician's house.

A home office still needs to be treated like a place where healthcare is happening. Consider:

  • Who can hear the conversation
  • Whether headphones should be used
  • Where screens are positioned
  • Whether computers are shared
  • Whether devices automatically lock
  • Whether smart speakers are nearby
  • Whether paperwork is visible
  • Whether recordings are permitted
  • Whether family members can walk into the room

Privacy does not stop because the clinician left the medical office.

Mental Health and Telepsychiatry Raise the Stakes

Privacy matters in every healthcare setting. It can feel especially important during mental health and behavioral health care.

A patient discussing depression, trauma, medications, substance use, family conflict, or suicidal thoughts may be sharing information they do not want roommates, employers, family members, or other people overhearing.

Providers offering telepsychiatry should think about both technical privacy and the patient's physical environment. A secure platform does not make the appointment private if the patient is sitting in a crowded workplace break room.

Patients Have a Role Too

Patients should not have to become cybersecurity experts before seeing a doctor. But a few habits help.

When possible:

  • Take the visit somewhere private
  • Use headphones if other people are nearby
  • Keep your phone or computer updated
  • Protect your device with a password or biometric lock
  • Be cautious with unexpected appointment links
  • Avoid sharing login credentials
  • Ask before assuming a session is being recorded

If somebody claiming to be your healthcare provider unexpectedly asks for a password, payment information, or sensitive personal information, verify the request directly with the healthcare organization.

HHS publishes telehealth privacy and security guidance for patients. Patients preparing for their first visit may also find our telehealth video visit tips helpful.

Telehealth Security Checklist for Healthcare Organizations

Healthcare organizations should periodically be able to answer these questions.

Organization checklist

  • Do we know every system that creates, receives, maintains, or transmits ePHI?
  • Have we completed an appropriate security risk analysis?
  • Have required BAAs been executed?
  • Do employees have individual accounts?
  • Is multi-factor authentication enabled where appropriate?
  • Are laptops, phones, and other devices appropriately secured?
  • Do we know who has access to patient information?
  • Are former employees promptly removed from systems?
  • Can we review relevant audit logs?
  • Do we know where video recordings are stored?
  • Do we know where AI transcripts are stored?
  • Have new AI tools been included in our security review?
  • Are employees trained to recognize phishing attempts?
  • Do we have clear policies for texting?
  • Do we have clear policies for email?
  • Do we have an incident-response process?
  • Do employees know who to contact when something goes wrong?

If several answers are "I don't know," that is useful information. It tells you where to start.

What Patients Should Ask

Patients do not need to interrogate their doctor about encryption protocols. Three questions cover a lot of ground.

Is this a secure telehealth system?

Is this visit being recorded or transcribed?

Who has access to the information from this visit?

If an AI documentation tool is listening to the conversation, patients should feel comfortable asking what it does.

Telehealth Security and Reimbursement Are Connected Operationally

Security and reimbursement are different subjects, but operationally they often touch the same systems.

The scheduling platform may collect insurance information. The EHR documents the encounter. The billing company may receive clinical or demographic information. Claims systems may transmit protected data.

As telehealth programs grow, providers should map privacy and security controls across the entire revenue cycle rather than viewing the video visit in isolation. For more on payment rules, see our guide to telehealth reimbursement.

HIPAA Is the Starting Point

Healthcare organizations sometimes approach HIPAA as the finish line. That is the wrong way to think about security.

Compliance establishes requirements. Security is the ongoing work of protecting the organization and the people whose information it holds.

Telehealth makes healthcare easier to reach. That is a good thing. But convenience also creates more connections, more vendors, more devices, and more places where information can travel.

The best telehealth programs make the experience simple for the patient while doing the complicated work behind the scenes. That is what good security looks like.

Editorial note: TeleMed Today independently covers telemedicine, virtual care, digital health policy, and healthcare technology. This article is educational and is not legal, cybersecurity, medical, or compliance advice. Healthcare organizations should evaluate their specific obligations with qualified legal, privacy, compliance, and information-security professionals. Last reviewed: August 2026.

Frequently asked questions

Is telehealth covered by HIPAA?
HIPAA can apply to telehealth when covered entities and business associates create, receive, maintain, or transmit protected health information through virtual care. Virtual treatment does not create a blanket exemption from HIPAA.
Does a telehealth company need a BAA?
A BAA may be required when a vendor qualifies as a business associate because it handles protected health information on behalf of a covered entity. Providers should evaluate the specific relationship instead of relying solely on the vendor's marketing.
Is Zoom HIPAA compliant?
Do not evaluate a platform solely by brand name. Different products, plans, configurations, contracts, and uses may have different implications. A healthcare organization should verify the specific service being used, applicable BAA coverage, and its own configuration.
Is FaceTime HIPAA compliant for telehealth?
Healthcare organizations should evaluate communication technologies under current HIPAA requirements and their own compliance policies rather than relying on temporary pandemic-era enforcement discretion.
Does HIPAA require telehealth encryption?
The HIPAA Security Rule requires appropriate safeguards for electronic protected health information. Encryption can be an important technical safeguard, but encryption alone does not determine whether an organization's overall telehealth operation is compliant.
Are AI medical scribes HIPAA compliant?
There is no universal answer based simply on the term "AI scribe." Healthcare organizations should evaluate the vendor relationship, BAA requirements, data flows, retention policies, subcontractors, security controls, and how patient information may be used.
Can doctors text patients?
HIPAA does not simply prohibit all patient texting. Healthcare organizations should establish policies for approved communication systems, security controls, patient preferences, and the sensitivity of the information being transmitted.
Is telehealth safer than an in-person visit from a privacy standpoint?
Neither format is automatically more private. Telehealth creates different risks involving devices, internet connections, vendors, recording, home environments, and digital data. In-person care has its own privacy and security risks.

Sources & further reading

About this article. This is general educational information, not medical, legal, or billing advice. Telehealth regulations change frequently — verify current rules with CMS, your state licensing board, and your payers before acting.