HIPAA does not stop applying simply because a visit happens over video instead of in an exam room, but the practical compliance picture does shift in telehealth settings. Understanding what actually changes — and what stays the same — is useful for any practice building out remote care workflows.
The underlying rule stays constant
HIPAA's core requirements around protecting patient health information generally apply the same way in telehealth as they do in any other care setting. Patient information still needs to be safeguarded, access still needs to be limited to those with a legitimate need, and breach notification obligations still apply if protected health information is compromised. Telehealth does not create a separate, lighter version of HIPAA — it introduces new contexts in which the same underlying obligations need to be met.
Where the practical questions shift
What changes in telehealth is largely about the tools and environment involved. Questions that come up more often include whether a video platform offers appropriate safeguards and a business associate agreement, whether the connection between provider and patient is adequately secured, and how visit recordings, chat logs, or images shared during a session are stored and retained. These are the same categories of concern HIPAA has always addressed, just applied to a different set of technologies.
HIPAA does not create special telehealth exceptions — it applies the same obligations to a different set of tools, which is exactly where new questions tend to surface.
Platform selection matters
Many everyday video conferencing tools are not built with healthcare-grade safeguards by default, which is part of why platform choice is a common early decision point for telehealth compliance. Practices generally look for platforms willing to sign a business associate agreement and that offer appropriate encryption and access controls, rather than assuming any video tool is automatically appropriate for clinical use.
Documentation and consent considerations
Beyond the technology layer, telehealth visits often involve their own documentation and consent practices — confirming patient identity remotely, obtaining informed consent for a telehealth encounter where required, and documenting the visit in a way consistent with the practice's existing HIPAA policies. None of this replaces a practice's broader HIPAA compliance program; it generally extends that program to cover the specific realities of remote care.
Requirements vary by state and change over time — always confirm current requirements directly with the relevant state board or agency before making a compliance decision.