The American College of Surgeons Health Policy Research Institute

American College of Surgeons Health Policy Research Institute
Advancing Health Policy Information
for Surgery in the United States

How to Verify Current HIPAA Rules for Telehealth

HIPAA telehealth · privacy and security

A platform is not “HIPAA compliant” in the abstract. Covered entities must evaluate how a remote technology creates, transmits, stores and exposes protected health information in the actual telehealth workflow.

Editorial status: federal privacy explainer; no vendor endorsement.Source retrieved August 27, 2026

Who the HIPAA rules cover

HHS Office for Civil Rights guidance applies HIPAA duties to covered health plans, covered healthcare providers and their business associates as relevant. It does not turn every consumer app, employer or private conversation into a HIPAA-covered activity.

For telehealth, covered entities must use reasonable privacy safeguards. When electronic protected health information is transmitted or maintained electronically, Security Rule risk analysis and risk management can apply to the technology and surrounding systems.

The communication channel changes the analysis

OCR’s audio-only guidance distinguishes a traditional landline from electronic technologies such as mobile networks, internet-based voice services, apps and systems that record or transcribe a session. Electronic channels can introduce storage, interception, authentication and access risks that must be assessed.

Vendor claim is not the whole workflow

Encryption or a marketing label does not answer whether a business associate agreement is required, who can access recordings, how identities are verified or how devices and accounts are secured.

A current privacy check

  • Identify whether the organization and vendor are covered or contracted entities.
  • Map where protected information is transmitted, stored or recorded.
  • Confirm access controls, authentication, retention and incident procedures.
  • Separate HIPAA analysis from insurance coverage and prescribing authority.

What patients and organizations can verify next

Patients can ask how privacy is protected and whether a session is recorded. Organizations should use current OCR guidance and their own documented risk analysis. This article does not certify a product or provide a compliance determination.

Scroll to Top