
Quick Answer: HIPAA Telehealth Requirements for Small Clinics
A HIPAA-compliant telehealth setup for small clinics requires a signed Business Associate Agreement (BAA) with your video platform, end-to-end encryption using AES-256 and TLS 1.2 or higher, unique session links with waiting room controls, and audit logs retained for at least six years. The COVID-19 Public Health Emergency enforcement discretion period ended May 2023, and the Office for Civil Rights (OCR) now enforces all HIPAA Security Rule requirements for virtual care. Consumer platforms like personal Zoom accounts and FaceTime are not HIPAA-compliant without a signed BAA and proper configuration.
Telehealth Security for Small Clinics: What the HIPAA Rules Actually Require
Telehealth has moved from a pandemic-era workaround into a permanent part of healthcare delivery. More than 80 percent of healthcare organizations now offer some form of virtual care, and a majority of patients expect telehealth options from their providers. But every virtual visit creates security risks that don't exist in a traditional exam room: patient data traverses public networks, providers connect from home environments, and personal devices replace locked-down clinical workstations.
The end of the COVID-19 Public Health Emergency (PHE) in May 2023 permanently changed the compliance picture for telehealth security for small clinics. The enforcement discretion period that allowed providers to use consumer-grade platforms like FaceTime, personal Zoom accounts, and Skype without a BAA has expired. OCR has resumed full enforcement of the HIPAA Security Rule (45 CFR Part 164) for all virtual care activities. Small clinics that continued using non-compliant platforms after the PHE termination face penalties ranging from $100 to $50,000 per violation, depending on the level of culpability.
For small clinics with limited IT resources, building a secure telehealth program can feel like a heavy lift. The requirements are achievable: select a HIPAA-compliant platform with a signed BAA, implement technical safeguards on provider and patient endpoints, establish secure workflows for virtual visits, and train staff on telehealth-specific risks. This guide walks through the specific technical controls, platform selection criteria, and operational procedures needed to meet the HIPAA Security Rule under 45 CFR §164.308, §164.310, and §164.312, and to protect the patient trust your practice depends on.
The same HIPAA obligations apply to dental offices, chiropractic clinics, and any other covered entity that offers virtual appointments. Specialty does not change the compliance picture. For broader context on how the HIPAA Security Rule applies to virtual care and other digital health workflows, see our overview of HIPAA cybersecurity requirements for medical practices.
Telehealth Security By the Numbers
American Hospital Association, 2024
Verizon Data Breach Investigations Report 2025
OCR enforcement; up to $1.9M per category annually
Telehealth Security Risks That Threaten Patient Privacy
Each virtual visit creates multiple exposure points that don't exist in a traditional in-office encounter. Video streams can be intercepted if the connection lacks end-to-end encryption. Screen recordings, whether from malware or an accidental screen share, can capture protected health information (PHI) displayed during the visit. Unauthorized individuals in the patient's or provider's physical environment may overhear sensitive conversations without either party realizing it.
The device and network environment compounds these risks. Home WiFi networks are frequently shared with family members and consumer IoT devices, including smart speakers, streaming sticks, and home assistants, that can be compromised and used to eavesdrop on network traffic. Personal laptops often lack the full-disk encryption, access controls, and endpoint security software the HIPAA Security Rule requires. Without proper controls, PHI is exposed at every stage: during transmission, on the provider's device, on the patient's device, and in temporary files or browser cache that persist after the session ends.
The integration of telehealth with electronic health record (EHR) systems creates additional data flow risk. Patient information moves between the telehealth platform, the EHR, secure messaging systems, and potentially cloud storage. Each handoff is a potential exposure point. According to the 2025 Verizon Data Breach Investigations Report, 68 percent of healthcare breaches involve a human element such as credential misuse, and 13 percent specifically involve misconfigured cloud storage or data transfer vulnerabilities.
Unauthorized session access is a risk category unique to telehealth. Sessions using predictable meeting IDs or missing waiting room controls can be accessed by uninvited parties through what security researchers call "meeting hijacking" attacks. Without proper authentication, an attacker who obtains or guesses a meeting link can observe an entire patient encounter. Session recordings retained beyond their useful period, stored without encryption, or saved to personal cloud accounts create long-term PHI exposure risk that persists years after the visit.
Small clinics are primary targets in healthcare cybercrime, not incidental ones. Large health systems invest heavily in security operations, making smaller practices with fewer IT controls a more accessible entry point. Understanding how attacks against healthcare practices unfold and what defenses actually work is covered in our guide to healthcare data breach prevention.
PHE Enforcement Discretion Has Ended
The COVID-19 Public Health Emergency ended May 11, 2023. OCR enforcement discretion for non-compliant telehealth platforms expired simultaneously. Providers using consumer-grade video tools without a Business Associate Agreement after that date are operating outside HIPAA compliance. If your clinic still uses a personal Zoom account, FaceTime, or any platform without a signed BAA, verify and correct your platform configuration before your next patient session.
Choosing a HIPAA-Compliant Telehealth Platform
The single most important requirement for any telehealth platform is a signed Business Associate Agreement. Under 45 CFR §164.502(e), covered entities may not disclose PHI to business associates unless a BAA is in place that establishes the associate's permitted uses and disclosures of PHI and requires appropriate safeguards. Using any platform for patient visits without a signed BAA violates HIPAA regardless of the platform's technical security features. Verbal assurances and website claims of HIPAA compliance are not sufficient. OCR requires a written, executed agreement.
Beyond the BAA, evaluate platforms on encryption standards. End-to-end encryption ensures video and audio streams are encrypted from the provider's device to the patient's device, and cannot be accessed by the platform provider or any intermediary. Platforms should use AES-256 encryption for data at rest and Transport Layer Security (TLS) 1.2 or higher for data in transit, consistent with NIST SP 800-52 Rev. 2 guidance on secure communication protocols.
Access control features are non-negotiable. The platform must generate unique meeting links for each session, not static room IDs that can be reused or leaked. Waiting room functionality prevents patients from entering the session until the provider explicitly admits them. Session locking allows the provider to seal the session once all expected participants have joined. These three features together address the most common telehealth access control failures cited in OCR enforcement cases.
Audit logging is required under 45 CFR §164.312(b). Logs must capture session start and end times, participant identities, IP addresses, authentication events, and any access to recorded sessions. These logs must be retained for at least six years under 45 CFR §164.316(b)(2)(i) and reviewed regularly, at minimum monthly, for anomalies or unauthorized access attempts.
Platform vendors commonly offering signed BAAs and HIPAA-compliant configurations include Doxy.me, Zoom for Healthcare, Microsoft Teams for Healthcare, Cisco Webex Health, VSee, and SimplePractice Telehealth. The consumer versions of these platforms, including personal Zoom accounts and Microsoft Teams Personal edition, do not include BAAs and are not HIPAA-compliant. Verify your specific subscription tier and configuration directly with the vendor, and obtain a signed BAA before conducting any patient visit.
If your practice records telehealth sessions for clinical documentation, confirm that recording storage is covered by your BAA and that the platform supports compliant retention and destruction policies consistent with your state's medical records requirements. Our HIPAA compliance checklist for small practices covers the full documentation review your practice needs.
Securing the Provider Environment
Platform selection is only half the equation. The security of the provider's physical and technical environment during telehealth sessions directly determines whether PHI remains protected, and whether your practice meets the HIPAA Security Rule's physical safeguard requirements at 45 CFR §164.310.
Providers should conduct telehealth visits from private, enclosed spaces with a door that can be closed and locked during sessions. Open offices, shared workspaces, hallways, or public locations like coffee shops do not meet the physical safeguard standard. Position the monitor so it is not visible through windows or open doorways. Install privacy screens on monitors in spaces that are sometimes visible to others during or outside of session hours.
Network security is equally important. Use a wired Ethernet connection whenever possible. It is more stable and substantially harder to intercept than WiFi. When WiFi is unavoidable, protect all traffic with a Virtual Private Network (VPN) configured to your clinic's network standards. See our guide to choosing the right VPN for healthcare settings for implementation specifics. Ensure the WiFi network used for telehealth uses WPA3 encryption with a strong, unique password, and is isolated from guest networks and consumer IoT devices sharing the same physical space.
Device security requires the same rigor applied to in-office workstations. Use dedicated devices for telehealth whenever possible rather than personal laptops also used for family activities, shopping, or social media. When personal devices are unavoidable, deploy Mobile Device Management (MDM) software that enforces encryption, screen locks, remote wipe capability, and application controls. Apply operating system and application patches promptly. The 2025 Verizon DBIR found that 15 percent of healthcare breaches involved exploitation of known vulnerabilities for which patches were available but not applied.
Role-Based Access Control (RBAC) is a layer that many small clinics overlook. Not every staff member needs access to the telehealth platform's administrative panel, session recordings, or audit logs. This principle of least privilege is codified in the NIST Cybersecurity Framework and directly supports HIPAA's minimum necessary standard under 45 CFR §164.514(d). For a detailed look at endpoint security options appropriate for small clinical settings, see our analysis of Endpoint Detection and Response (EDR), Managed Detection and Response (MDR), and Extended Detection and Response (XDR) solutions for medical practices.
Provider Device Security Checklist
- Use a dedicated clinical device for telehealth, separate from personal-use laptops or family computers
- Enable full-disk encryption on all provider devices: BitLocker for Windows, FileVault for macOS
- Deploy MDM software with remote wipe capability on all devices used for virtual visits
- Apply all operating system and software patches within 72 hours of release
- Use a wired Ethernet connection; if WiFi is required, route all traffic through a clinic-configured VPN
- Enable automatic screen lock after 5 minutes of inactivity with a strong password or biometric unlock
- Restrict platform administrative access with role-based permissions; only designated staff manage settings
- Install and maintain endpoint security software with real-time threat detection on all telehealth devices
- Conduct every virtual care session from a private, enclosed space with the door closed
- Clear browser cache, temporary files, and clipboard memory after each session
Patient-Side Security Requirements
You cannot control a patient's home network or device, but you can establish minimum security expectations and give patients the tools to meet them. Clear, actionable guidance provided before the first visit reduces both security risk and last-minute technical problems that delay care.
Instruct patients to join telehealth visits from private locations where they will not be overheard. Public WiFi networks in coffee shops, libraries, airports, and hotel lobbies are frequently unencrypted and subject to passive eavesdropping. If a patient must connect from outside the home, recommend using a personal mobile hotspot rather than shared public WiFi. Patients with smartphones on a cellular data plan have a safer option readily available.
Provide written pre-visit instructions covering four topics: how to verify they are connecting to your practice's legitimate platform rather than a phishing site mimicking your practice; how to test audio and video before the session starts; what to do if they encounter technical difficulties; and how to securely end and fully close the session afterward. Include explicit guidance not to share the meeting link with others and to ensure no one else is present in the room unless the patient has explicitly authorized that person's participation in the clinical encounter.
Telehealth-themed phishing attacks, where patients receive fraudulent meeting invitations designed to harvest credentials or install malware, have become more frequent. Our resource on recognizing phishing attacks covers the patterns most commonly used against healthcare targets. Staff should be familiar with these patterns as well, since attackers also impersonate platform vendors and practice administrators to harvest staff credentials.
Verify patient identity at the start of each session using at least two identifiers, typically full name and date of birth. This satisfies the authentication requirement at 45 CFR §164.312(d) and prevents unauthorized individuals from impersonating patients to obtain medical information. Visual confirmation via video can serve as an additional factor, but should not be the only verification method used.
Recognize that digital literacy and technology access vary significantly across patient populations. Offer technical support by phone before the first visit to help patients download the platform app, test their connection, and troubleshoot issues. Maintain alternative appointment formats, including phone-only or in-person options, for patients who cannot meet minimum security requirements or who are uncomfortable with video visits. Document the patient's consent to telehealth and acknowledgment of security considerations in the medical record, consistent with your state's telehealth consent requirements.
Securing a Telehealth Session: Start to Finish
Generate a Unique Session Link
Create a new, unique meeting link for each patient encounter. Never reuse session IDs. Configure the waiting room to be active by default before the session is scheduled.
Verify Your Physical Space
Close and lock the door. Position your monitor away from windows. Attach a privacy screen if the space is sometimes visible to others. Silence personal devices not in use during the session.
Authenticate the Patient Before Starting
Ask for full name and date of birth before discussing any clinical information. Confirm no unauthorized third parties are present on the patient's end.
Lock the Session After All Participants Join
Once the patient is admitted from the waiting room, lock the session immediately. This prevents uninvited parties from joining mid-encounter even if the link is forwarded.
Manage Screen Sharing Carefully
Close all other applications and browser tabs before sharing your screen. Use the platform's built-in annotation tools instead of opening additional files. End screen sharing as soon as clinical discussion resumes.
Document the Encounter in Your EHR
Record the date and time, patient location (city and state), platform used, participants present, any technical issues, and the full clinical content. Many state medical boards require these specific elements.
End the Session and Clear Temporary Data
Formally end the session rather than just closing the window. Clear browser cache, temporary files, and clipboard memory. Verify any recording is stored in your BAA-covered, encrypted system.
Securing Your Telehealth Workflow End to End
Operational security for telehealth security for small clinics extends well beyond platform selection and device configuration. The workflows surrounding scheduling, session management, documentation, and data retention create their own set of HIPAA exposure points that must be addressed systematically.
Schedule telehealth appointments through your practice management system, not via personal email, text message, or consumer scheduling apps that lack BAAs. Configure automated reminders to exclude the meeting link until 15 to 30 minutes before the appointment. This reduces the window during which an intercepted or forwarded link could be used by an unauthorized party to join the session.
If sessions are recorded for clinical documentation, store recordings in encrypted, access-controlled storage covered by your BAA. Establish a documented retention and destruction policy for telehealth session data consistent with your state's medical records retention requirements, typically six to ten years for adult patients and longer for pediatric records. A recording saved to a personal Google Drive or iCloud account is PHI stored outside any BAA, regardless of how careful the provider was during the session itself.
Document every telehealth encounter in the patient's EHR, including the date and time, patient location, technology platform used, participants present, any technical issues encountered, and the clinical content of the visit. Many state medical boards require specific documentation elements for telehealth visits, including patient consent, provider location, and the technology platform used. Failure to document these elements creates compliance gaps that can complicate licensing board reviews and OCR investigations.
When screen sharing is necessary for patient education or reviewing test results, close all other applications and browser tabs before sharing to prevent accidental display of other patients' PHI. Use the platform's built-in annotation tools rather than opening additional files. End screen sharing immediately when clinical discussion resumes and verify that no shared content remains visible to the patient.
Staff Training and Security Awareness for Virtual Care
Technology controls alone cannot secure a telehealth program. The finding that more than two-thirds of healthcare breaches involve a human element, whether credential misuse, misconfiguration, or social engineering, makes clear that staff behavior is as important as software configuration. Every provider and staff member with access to the telehealth platform, scheduling system, or patient EHR needs role-specific training before participating in virtual care delivery.
Training for telehealth security for small clinics should cover four areas. First, platform security: how to generate and distribute meeting links, how to use the waiting room and session lock features, how to verify patient identity, and what to do when an unexpected participant appears in a session. This is specific operational knowledge required to run a HIPAA-compliant virtual visit, not general computer literacy.
Second, device and network hygiene: the difference between a clinic-managed device and a personal device, why home WiFi requires a VPN, and how to recognize signs that a device may be compromised. Many providers using personal laptops for telehealth have no awareness that their device's security posture falls short of what HIPAA requires.
Third, phishing and social engineering: telehealth session invitations are an increasingly common lure in healthcare-targeted phishing campaigns. Attackers impersonating platform vendors or practice administrators have successfully harvested credentials from clinical staff by sending fraudulent "platform upgrade" or "account verification" notifications. Staff need to recognize spoofed meeting links and suspicious requests for login credentials.
Fourth, incident response: staff need to know exactly what to do, and who to notify, if a session is accessed by an unauthorized party, a device is lost or stolen, or they suspect a security incident has occurred. Hesitation in the first hours after an incident can convert a containable event into a reportable breach. Document training completion for every staff member with a date and content record. HIPAA requires training under 45 CFR §164.308(a)(5), and OCR routinely requests training records during investigations. Annual refreshers are the minimum. Conduct additional training whenever you change platforms, add new workflow steps, or become aware of a new threat targeting telehealth systems.
Need a HIPAA Telehealth Security Assessment?
Our healthcare cybersecurity team evaluates telehealth platform configurations, BAA coverage, endpoint security, and HIPAA documentation for small clinics across medical and dental specialties.
Building a Sustainable Telehealth Security Program
Telehealth security is not a one-time configuration. It is an ongoing program that must evolve alongside emerging threats, regulatory updates, and changes to your clinical workflows. Small clinics that treat security as a setup task rather than a continuous discipline are the ones that appear in OCR enforcement case resolutions.
Healthcare cyberattacks have intensified significantly, with medical records commanding premium prices on criminal markets because they contain both clinical and financial data in a single record. Nation-state actors and ransomware groups have increased their focus on smaller healthcare targets, documented in CISA's healthcare cybersecurity advisories and in attacks against medical device manufacturers and clinic networks throughout 2025 and 2026. Understanding how ransomware threats targeting healthcare operate helps clinics prioritize defenses before an incident forces the issue. See our overview of ransomware threats in healthcare for context on the current threat environment.
Establish a formal review cycle. At minimum, conduct an annual review of your platform contract and BAA, security configurations, audit log summaries, incident reports, and staff training completion records. Update your telehealth risk assessment whenever you change platforms, add new clinical workflows, expand to new provider locations, or experience a security incident. The HIPAA Security Rule at 45 CFR §164.308(a)(1) requires that risk assessments be kept current. A single assessment conducted at program launch does not satisfy this requirement, and OCR has cited stale risk assessments as independent compliance failures in published enforcement cases.
Stay current on OCR guidance and enforcement trends. OCR publishes case resolutions on the HHS Office for Civil Rights website, many of which involve telehealth-related violations including missing BAAs, insufficient access controls, and inadequate risk assessments. The Cybersecurity and Infrastructure Security Agency (CISA) and the HHS Health Sector Cybersecurity Coordination Center (HC3) both publish healthcare-specific threat briefings and vulnerability alerts. Subscribe to these services to receive timely notifications about exploits targeting telehealth platforms and clinical software.
Documentation is a compliance requirement, not an administrative formality. The HIPAA Security Rule at 45 CFR §164.316(b)(1) requires written documentation of your security program and its components. OCR routinely requests documentation packages during investigations: policies and procedures, risk assessments, BAAs, training records, audit log reviews, and incident reports. Failure to produce required documentation can result in penalties even when your technical security measures are adequate. Retain all documentation for at least six years from the date of creation or the date it was last in effect, whichever is later.
Telehealth security for small clinics requires the same technical controls as larger organizations but with more efficient implementation, because fewer people are available to manage them. A managed security partner with healthcare-specific experience can help small clinics maintain documentation standards, continuous monitoring, and incident response capability without dedicating full-time staff to compliance administration. To understand what a formal risk assessment covers for telehealth programs, see our overview of healthcare security risk assessments.
Bottom Line
Telehealth security for small clinics comes down to three things: a signed BAA with your platform, documented technical controls on both provider and patient endpoints, and ongoing training and risk assessment to keep pace with a changing threat environment. The PHE enforcement grace period is gone. Every virtual visit today is subject to full HIPAA Security Rule enforcement. Clinics that have not audited their telehealth platform configuration, BAA coverage, and staff training records since 2023 should do so now rather than waiting for an OCR inquiry to prompt the review.
Schedule Your HIPAA Telehealth Security Review
Our healthcare cybersecurity experts will evaluate your telehealth platform configuration, BAA coverage, endpoint security, and HIPAA documentation, then provide a prioritized action plan for your clinic.
Frequently Asked Questions
Yes. HIPAA applies to all locations where a provider conducts patient care and accesses PHI, including a home office. The HIPAA Security Rule's physical safeguard requirements at 45 CFR §164.310 apply to any location used to deliver virtual care. Providers working from home must ensure the space is private, devices are secured, and network connections are encrypted, typically via a VPN. The physical location of the session does not change the covered entity's compliance obligations.
No. Personal Zoom accounts do not include a Business Associate Agreement. Without a signed BAA, using Zoom or any other consumer platform for patient visits violates HIPAA under 45 CFR §164.502(e). Zoom offers a HIPAA-compliant Healthcare tier that includes a BAA, waiting room controls, audit logging, and appropriate encryption. The consumer product and the healthcare product are different service tiers with different compliance status. Verify your subscription level directly with Zoom before using the platform for patient care.
A Business Associate Agreement (BAA) is a written contract required by HIPAA between a covered entity (your clinic) and any vendor that creates, receives, maintains, or transmits PHI on your behalf. Under 45 CFR §164.502(e), a covered entity may not disclose PHI to a business associate unless a BAA is in place. A telehealth platform that hosts or transmits patient video sessions is a business associate. The BAA establishes the vendor's permitted uses of PHI, requires appropriate safeguards, and creates contractual accountability for breaches. A vendor's website privacy policy or terms of service do not substitute for a signed BAA.
HIPAA requires that security-related documentation be retained for at least six years under 45 CFR §164.316(b)(2)(i). For telehealth session recordings that function as clinical documentation, your state's medical records retention law governs the minimum period, which is typically six to ten years for adult patients and longer for records involving minors. Store all recordings in encrypted, access-controlled systems covered by your BAA. Recordings saved to personal cloud accounts like Google Drive or iCloud are PHI stored outside any BAA and outside HIPAA compliance, regardless of the platform used during the session.
Meeting hijacking occurs when an unauthorized party gains access to a telehealth session, either by guessing a predictable session ID, intercepting a meeting link, or receiving a forwarded invitation. The result is an uninvited observer or participant in a patient encounter. Prevent it by generating a unique meeting link for every session rather than using a static room ID, activating the waiting room so the provider controls who enters, and locking the session immediately after the patient joins. Configure your platform to require authentication for entry when the platform supports it.
The HIPAA Security Rule at 45 CFR §164.308(a)(1) requires that risk assessments be kept current, not conducted once and filed away. Update your telehealth risk assessment whenever you change platforms, add new clinical workflows, expand to new provider locations, experience a security incident, or become aware of a new threat targeting your platform or software. At minimum, conduct a formal review annually as part of your overall security program review. OCR has cited stale risk assessments as independent compliance failures in published enforcement cases, separate from any underlying technical violation.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.



