Industry

HIPAA compliance for telehealth

You are often a covered entity and a business associate at once, across state lines, on infrastructure you do not own.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

You are often a covered entity and a business associate at once, across state lines, on infrastructure you do not own.

What usually goes wrong

  • Video, chat, and recording storage all in ePHI scope
  • Multi-state licensure and varying state privacy law
  • Consumer app UX colliding with authentication requirements
  • Cloud and CDN subprocessors needing BAAs

What SuperHIPAA does about it

  • Dual-role scoping so you can answer both kinds of customer questionnaire
  • Recording, retention, and transcript handling policy
  • Full subprocessor and BAA chain mapping
  • Trust centre page so prospects stop emailing your founders

Your obligations in one paragraph

As a both, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.

Where most telehealth actually stand

The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.

Getting started

  1. Free readiness assessment — scored report, no call required
  2. Gap assessment — if the score shows real exposure
  3. Implementation — we fix it with you, or hand your team the plan
  4. Platform — keeps it true after we leave

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Are telehealth covered entities or business associates?

Typically **Both**. It matters because it changes which obligations are yours directly and which flow through a BAA. The readiness assessment determines your scope in the first three questions.

How long does it take to get compliant?

For an organisation starting from near zero, 8–12 weeks to a defensible position: risk analysis complete, required safeguards implemented, policies live, workforce trained. Anyone promising two weeks is selling you a certificate.

What does it cost?

Platform starts at a published monthly price — see pricing. Services are fixed-fee. There is no 'contact us for a quote' wall on this site.

Do you replace our IT provider?

No. We tell your IT provider exactly what to configure and then verify they did it.

Can we use Zoom or FaceTime for visits?

Consumer video without a BAA is out. Several mainstream platforms offer healthcare tiers with a BAA — what matters is the executed BAA and the security configuration, not the brand name on the app.

Is the COVID-era enforcement discretion still in effect?

No — that flexibility ended in 2023. You now need a BAA-covered platform and documented safeguards like any other ePHI system, and running on the old assumption is a live gap.

Can we record telehealth sessions?

Recordings are ePHI: encrypted storage, access controls, a retention policy, and patient awareness are all required. The simplest defensible answer is often not to record at all — and to document that decision.

Do you handle multi-state licensure questions too?

No — licensure is a legal question for counsel, and we say so rather than dabble. We cover the privacy and security side, and the risk register gives licensure findings a place to live alongside everything else.

Are analytics pixels on our booking pages a HIPAA problem?

Potentially a serious one. OCR's tracking-technology guidance treats identifiers sent to ad and analytics vendors from authenticated pages — and some unauthenticated ones — as PHI disclosures, and telehealth booking flows are exactly the surface at issue. Audit every tag on pages touching appointments or symptoms, and remove or gate anything without a BAA.

Our clinicians see patients from home. What does that require?

The home becomes part of your environment: managed or policy-covered devices with encryption and screen lock, a private space out of household earshot, and no session content on personal accounts. A remote-work policy plus device controls covers it — assuming the home office is out of scope is the mistake.

Does asynchronous care — chat, messaging, photo submissions — carry the same obligations as video?

Yes, and arguably more, because messages and images persist where a video call ends. Every store-and-forward channel needs a BAA-covered platform, retention rules, and access controls, and patient photo submissions are ePHI from the moment they upload. Map each channel in the risk analysis, not just the video visit.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo