A Telehealth Startup's $1.5 Million Wake-Up Call
In 2023, a mental health telehealth company called Cerebral agreed to a $7.1 million settlement with the FTC after sharing patient data — including mental health conditions — with advertising platforms through tracking pixels embedded in their app. That same year, OCR was already ramping up investigations into telehealth platforms that had gotten comfortable during the COVID-era enforcement discretion period. The grace period was over.
If you're building, operating, or contracting with a telehealth app in 2026, the HIPAA compliance requirements for telehealth apps aren't optional guardrails. They're the difference between a functioning business and a front-page data breach story. And I've seen more app developers get this wrong than get it right.
This post walks through every requirement your telehealth platform must meet — from encryption standards to workforce training to business associate agreements. Whether you're a covered entity using a third-party app or a developer building one, this is the compliance blueprint you need.
Why Telehealth Apps Face Unique HIPAA Risks
Traditional healthcare settings have physical walls, locked filing cabinets, and on-premise servers. Telehealth apps have none of that. Every video session, chat message, uploaded photo, and e-prescription passes through cloud infrastructure that you may not even fully control.
That's what makes telehealth compliance harder, not easier. The attack surface is massive. Patient data — protected health information (PHI) — moves across mobile devices, APIs, cloud databases, and third-party integrations. Each handoff is a potential breach point.
I've consulted with telehealth startups that assumed HIPAA only applied to the video call itself. They forgot about the appointment reminders sent via unencrypted SMS. They overlooked the analytics SDK logging user behavior alongside patient identifiers. Those blind spots are exactly where OCR investigations begin.
The Core HIPAA Compliance Requirements for Telehealth Apps
1. Encryption of ePHI — In Transit and At Rest
The HIPAA Security Rule requires covered entities and business associates to implement technical safeguards that protect electronic PHI (ePHI). For telehealth apps, this means end-to-end encryption for video, audio, and messaging — and AES-256 encryption (or equivalent) for data stored in databases and backups.
HHS has been explicit: encryption is an "addressable" specification under the Security Rule, but if you choose not to encrypt, you must document why and implement an equivalent alternative. In practice, there is no reasonable alternative for a telehealth app. Encrypt everything. Full stop.
The HHS Security Rule guidance page lays out the technical safeguard requirements in detail.
2. Business Associate Agreements (BAAs) With Every Vendor
Your telehealth app doesn't exist in a vacuum. It sits on AWS, Azure, or Google Cloud. It uses Twilio for messaging, Stripe for payments, maybe a third-party EHR integration. Every one of those vendors that touches PHI is a business associate under HIPAA — and every one needs a signed BAA.
I've seen organizations assume that because a cloud provider is "HIPAA-eligible," they're automatically compliant. They're not. A BAA must be executed before any PHI flows through that service. Without it, you're in violation — even if no breach ever occurs.
OCR's settlement history makes this crystal clear. In 2018, OCR settled with Advanced Care Hospitalists for $500,000 in part because the practice failed to have a BAA in place with a medical billing vendor. The same logic applies to every technology vendor your telehealth app relies on.
3. Access Controls and Authentication
The Security Rule requires unique user identification, automatic logoff, and emergency access procedures. For a telehealth app, this translates to multi-factor authentication (MFA) for providers, role-based access controls for staff, and session timeouts that actually work.
Patients accessing their own data through a portal also need secure authentication — but be careful about making the process so cumbersome that people write passwords on sticky notes. The best telehealth apps I've audited use biometric login on mobile devices combined with token-based session management.
4. Audit Controls and Logging
Every access to ePHI in your telehealth app must be logged. Who accessed what record, when, and from which device. These audit logs aren't just for breach investigations — they're a proactive compliance requirement under 45 CFR § 164.312(b).
Store logs separately from your production database. Retain them for at least six years, which is the HIPAA document retention requirement. And actually review them. I've worked with organizations that had perfect logging in place and never once looked at the output. That's a policy on paper, not a practice in reality.
5. Risk Analysis — Not a One-Time Event
OCR has said it repeatedly: the most common finding in HIPAA enforcement actions is the failure to conduct a thorough, organization-wide risk analysis. For telehealth apps, this means evaluating every component — the app itself, the hosting infrastructure, third-party integrations, data flows, and user devices.
And you can't do it once and file it away. Your risk analysis must be updated whenever your app architecture changes, whenever you add a new vendor, and at minimum annually. The HHS risk assessment guidance provides a framework, but I'd recommend going beyond the basics if your app handles behavioral health or substance use data.
What Counts as a Telehealth App Under HIPAA?
This is a question I get constantly. The answer: if the app creates, receives, maintains, or transmits PHI on behalf of a covered entity, it falls under HIPAA. Period.
That includes video visit platforms, remote patient monitoring tools, asynchronous messaging apps used between providers and patients, digital intake forms, and even chatbot triage tools that collect symptoms alongside patient identifiers.
Consumer wellness apps that don't interact with a covered entity may fall outside HIPAA's scope — but the moment a hospital system or physician practice integrates that app into a clinical workflow, the app developer becomes a business associate and HIPAA applies.
The Breach Notification Rule Doesn't Have a "Small App" Exception
If your telehealth app experiences a breach of unsecured PHI affecting 500 or more individuals, you must notify HHS, affected patients, and in some cases the media — all within 60 days. Breaches under 500 still require individual notification and must be reported to HHS annually.
The 2022 OCR breach portal shows dozens of telehealth-related incidents, many stemming from misconfigured cloud storage, exposed APIs, or unauthorized tracking technologies. These weren't nation-state attacks. They were configuration errors that proper risk analysis would have caught.
You can review reported breaches on the HHS Breach Portal to see exactly how common these incidents have become.
Workforce Training: The Requirement Everyone Underestimates
Here's a pattern I see constantly: a telehealth company invests six figures in infrastructure security, then hands new employees a PDF and calls it HIPAA training. The Security Rule at 45 CFR § 164.308(a)(5) requires security awareness training for your entire workforce — not just clinicians. That includes developers, customer support agents, product managers, and contractors.
Training must be role-specific. A developer who has access to production databases faces different risks than a support agent who handles patient intake calls. Generic compliance videos don't cut it.
If your organization needs structured, role-appropriate training, our HIPAA Introduction Training for 2026 covers foundational requirements, while our Annual HIPAA Refresher keeps returning staff current on evolving enforcement trends and regulatory changes.
Training Documentation Matters as Much as the Training Itself
OCR doesn't just ask whether you trained your workforce. They ask for proof. Dates, attendee lists, topics covered, and completion records. If you can't produce documentation during an investigation, OCR treats it as if the training never happened.
I've audited telehealth companies that conducted excellent training but tracked nothing. When OCR came knocking after a breach, they had no evidence. That's an avoidable mistake.
The COVID Enforcement Discretion Period Is Long Gone
During the early months of the pandemic, OCR announced it would exercise enforcement discretion for telehealth providers using non-HIPAA-compliant platforms like FaceTime or Zoom (before Zoom offered BAAs). That discretion ended. HHS formally ended the COVID-19 public health emergency in May 2023.
Yet in 2026, I still encounter small practices using consumer-grade video tools without BAAs. If you're a covered entity — a physician practice, a hospital, a health plan — and you're offering telehealth through any platform, that platform must meet every HIPAA compliance requirement. No exceptions remain.
Dental offices offering virtual consultations face the same obligations. Our HIPAA Training for Dental Offices addresses telehealth scenarios specific to dental practices that have expanded into virtual care.
Your 2026 Telehealth HIPAA Checklist
- Signed BAAs with every vendor that touches PHI — cloud hosts, communication APIs, analytics tools, payment processors.
- End-to-end encryption for all video, audio, messaging, and stored ePHI.
- Multi-factor authentication for all provider and staff accounts.
- Comprehensive risk analysis updated at least annually and after any architectural change.
- Audit logging for all ePHI access, stored securely, retained for six years.
- Workforce training that is role-specific, documented, and refreshed annually.
- Breach notification procedures tested and ready to execute within 60 days.
- No tracking pixels or analytics SDKs that transmit PHI to advertising platforms.
The Bottom Line for Telehealth in 2026
The HIPAA compliance requirements for telehealth apps aren't a checkbox exercise. They're an ongoing operational commitment that touches every layer of your technology stack and every person in your workforce. OCR is actively investigating telehealth platforms, and the penalties reflect the seriousness of the risk.
Get your BAAs in order. Encrypt everything. Train everyone. Document it all. And when your app changes — because it will — update your risk analysis before the next sprint ships, not after the next breach lands.
Explore our full HIPAA training catalog to find courses that match your organization's telehealth compliance needs.