Miami, FL

302-205-0504
All articles

Is my telehealth platform HIPAA compliant?

Short answer: there is no government approved list of telehealth platforms, and no approval program at all. What matters is whether the vendor will sign a business associate agreement covering the product you actually use, and what you do with it afterwards.

I am Scott Derby, I am an attorney. There is a page on the government’s own website that has been misleading psychologists and mental health therapists for three years, and it is why so many practices think their telehealth setup is compliant when nobody has ever told them it is.

Search for HIPAA and telehealth and you will find a page on HHS.gov that names ten video vendors. It looks official, because it is official. It is not what people think it is.

Read the disclaimer the Office for Civil Rights attached to that list. In its own words, it had not reviewed the agreements offered by those vendors, and the list does not constitute an endorsement, certification, or recommendation. Those were vendors that represented themselves as compliant. Nobody checked.

And the policy behind that page is gone. It was pandemic enforcement discretion. The notification expired with the public health emergency at 11:59 at night on 11 May 2023, and the ninety day transition period after it ran out on 9 August 2023. Since 10 August 2023, the ordinary rules have applied in full. The page is still up, with no expiration notice on it anywhere.

While we are there, one thing that page never permitted, even at the height of the pandemic: public facing platforms. Facebook Live, Twitch and TikTok were excluded the entire time.

So what do the rules actually require? If a video vendor creates, receives, maintains, or transmits protected health information on your behalf, it is generally a business associate, and you need a compliant business associate agreement with it. Check that the agreement covers the specific product and service tier you actually use, not the vendor in general.

Then the rest of the work is yours. Include the technology in your risk analysis. Configure it properly. Use it properly. A signed agreement is necessary. It is not the whole answer.

Now the part people miss entirely. The platform is only part of it. Your room matters too.

Encryption protects a session while it crosses a network. It does not stop somebody in the next room from hearing you, and it does not by itself protect what is stored on your device. Think about your door, your headphones, who else is in the house, and who can see your screen.

Your client’s side is not something you control, but you can raise it. Ask, gently, at the start: are you somewhere you can speak freely?

This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.