You are often a covered entity and a business associate at once, across state lines, on infrastructure you do not own.
What usually goes wrong
- Video, chat, and recording storage all in ePHI scope
- Multi-state licensure and varying state privacy law
- Consumer app UX colliding with authentication requirements
- Cloud and CDN subprocessors needing BAAs
What SuperHIPAA does about it
- Dual-role scoping so you can answer both kinds of customer questionnaire
- Recording, retention, and transcript handling policy
- Full subprocessor and BAA chain mapping
- Trust centre page so prospects stop emailing your founders
Your obligations in one paragraph
As a both, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.
Where most telehealth actually stand
The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.
Getting started
- Free readiness assessment — scored report, no call required
- Gap assessment — if the score shows real exposure
- Implementation — we fix it with you, or hand your team the plan
- Platform — keeps it true after we leave
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.