A therapist in Florida conducts a video session with a patient using a consumer-grade messaging app. No encryption. No business associate agreement. No documentation of any risk analysis. Three months later, a disgruntled employee files a complaint with the Office for Civil Rights. The investigation doesn't just uncover one violation — it uncovers a pattern of neglect across the entire telehealth program.

I've seen this scenario play out more times than I can count since the post-pandemic surge in virtual care. Telemedicine and HIPAA compliance aren't optional partners — they're inseparable. And in 2026, with the enforcement discretion era firmly behind us, every provider offering virtual care needs to get this right or face serious consequences.

The Enforcement Discretion Era Is Over — Here's What That Means for You

During the COVID-19 public health emergency, HHS issued a Notification of Enforcement Discretion that allowed providers to use non-compliant platforms like FaceTime, Skype, and Zoom (consumer version) for telehealth without facing penalties. That discretion ended in August 2023.

Yet in my consulting work, I still walk into clinics and behavioral health practices that operate as if those relaxed rules are still in effect. They're not. Every telehealth encounter you conduct today must meet the full weight of the HIPAA Privacy, Security, and Breach Notification Rules.

If your organization hasn't updated its telehealth policies since 2022, you're almost certainly out of compliance.

What HIPAA Actually Requires for Telemedicine in 2026

Let's cut through the noise. Here's exactly what the HIPAA Security Rule demands when you transmit electronic protected health information (ePHI) through a telemedicine platform.

End-to-End Encryption Is Non-Negotiable

The Security Rule requires covered entities to implement technical safeguards that protect ePHI during transmission. For telemedicine, that means your platform must offer end-to-end encryption. Consumer video tools — the ones your staff might default to because they're convenient — rarely meet this standard.

You Need a Business Associate Agreement (BAA)

Any technology vendor that handles ePHI on your behalf is a business associate. That includes your telehealth platform provider, your cloud storage vendor, and even your appointment scheduling tool if it processes patient data. Without a signed BAA, you're violating HIPAA before the first video call even connects.

A Risk Analysis Must Cover Telehealth Specifically

Your HIPAA risk analysis can't be a generic document pulled from a template five years ago. It must specifically address the risks introduced by telemedicine — device security, network vulnerabilities, home office environments, patient-side privacy, and data storage. OCR has made risk analysis failures the single most cited deficiency in enforcement actions.

Access Controls and Audit Logs

Your platform must support unique user identification, automatic logoff, and audit logging. If you can't track who accessed a telehealth session and when, you have a Security Rule problem.

The $1.25 Million Mistake: When Telehealth Goes Wrong

In 2023, OCR settled with Lafourche Medical Group for $480,000 after a phishing attack compromised the ePHI of nearly 35,000 individuals. The root cause? No risk analysis had ever been conducted. Their electronic communications — including telehealth workflows — were completely unexamined for vulnerabilities.

That same year, OCR announced a string of enforcement actions targeting organizations that failed to implement basic Security Rule safeguards. Several involved electronic communications and remote access to patient data — the exact infrastructure that telemedicine depends on.

These aren't hypothetical risks. They're documented enforcement outcomes with real dollar amounts attached.

Can You Use Zoom, Teams, or Doxy.me for Telehealth?

This is the question I get asked most often. The answer depends entirely on which version of the platform you're using and whether you have a BAA in place.

Zoom for Healthcare — the HIPAA-compliant version — offers a BAA and meets encryption requirements. The standard consumer Zoom account does not. Microsoft Teams can be configured for HIPAA compliance under certain enterprise plans that include a BAA. Doxy.me markets itself as a HIPAA-compliant telemedicine solution and offers a BAA.

But here's what most organizations miss: signing a BAA doesn't make you compliant. You still need to configure the platform correctly, train your workforce, conduct your own risk analysis, and document everything. The BAA is one piece of a much larger puzzle.

I've audited organizations with excellent technology stacks that still had massive compliance gaps. The reason? Their staff had no idea how to use the tools securely.

Clinicians conducting sessions from coffee shops on public Wi-Fi. Medical assistants texting appointment links through personal phones. Front desk staff sharing login credentials because "it's easier." Every one of these behaviors is a potential HIPAA violation — and a potential breach.

Training Must Be Specific to Remote and Virtual Care

Generic HIPAA awareness training doesn't cut it for telemedicine. Your workforce needs targeted education on remote work security, ePHI handling in virtual environments, and the specific policies your organization has adopted for telehealth. Our HIPAA Training for Remote Healthcare Workers course was built for exactly this scenario — covering the real-world risks that remote and virtual care staff face every day.

If your team hasn't completed foundational training recently, the HIPAA Introduction Training 2026 course provides the baseline every covered entity employee needs before layering on telehealth-specific protocols.

The Patient Side of the Equation

Here's something that surprises a lot of providers: HIPAA doesn't regulate patients. If a patient chooses to join a telehealth session from a crowded waiting room at a tire shop, that's their prerogative. You can't force a patient to be in a private location.

But you can — and should — document that you informed the patient about privacy risks on their end. Many organizations now include a telehealth consent form that addresses this. It's not a HIPAA requirement per se, but it's a smart risk management practice and may be required under state telehealth laws.

State Laws Add Another Layer of Complexity

HIPAA sets the federal floor, but many states have enacted telehealth-specific privacy laws that go further. Some states require explicit patient consent for telehealth. Others have data residency requirements or specific rules about recording virtual sessions.

If you provide telemedicine across state lines — and many organizations do — you need to comply with the laws in the state where the patient is located, not just where your provider sits. This is a compliance minefield that catches multi-state practices off guard constantly.

A Practical Telemedicine HIPAA Compliance Checklist

I've distilled what I recommend to every organization offering virtual care into this actionable list:

  • Conduct a risk analysis that specifically addresses your telehealth technology, workflows, and data flows.
  • Use only platforms that offer a signed BAA and meet HIPAA encryption requirements.
  • Configure your platform properly — enable waiting rooms, disable recording by default, require authentication.
  • Train every staff member who participates in or supports telehealth encounters, with training specific to remote and virtual care environments.
  • Document your policies — including acceptable platforms, device requirements, and what to do if a breach occurs during a session.
  • Implement minimum necessary standards — only the ePHI needed for the encounter should be accessible during a session.
  • Review and update annually — your telehealth program will evolve, and your compliance documentation must keep pace.

Telemedicine and HIPAA Compliance Will Only Get More Scrutinized

OCR has signaled repeatedly that digital health is a priority enforcement area. The December 2022 bulletin on online tracking technologies demonstrated HHS's willingness to go after digital health tools that mishandle patient data. Telemedicine platforms sit squarely in that crosshair.

Virtual care isn't going away. Patients expect it. Payers reimburse for it. And your organization probably depends on it. But the convenience of telemedicine doesn't exempt you from the obligations that come with handling protected health information.

Get your risk analysis current. Get your BAAs signed. Get your workforce trained — and not with a slide deck from 2021. Explore the full catalog of HIPAA training courses to find what fits your team's needs right now.

Because when OCR comes calling, "we didn't know the enforcement discretion ended" won't be the defense you think it is.