Telehealth HIPAA Violation: Non-Compliant Platform
Using consumer video platforms for patient care and the end of COVID-era enforcement discretion
Quick Answer
Healthcare providers that use non-HIPAA-compliant video conferencing platforms without business associate agreements for telehealth visits face HIPAA enforcement action. COVID-era enforcement discretion has ended, and OCR is actively pursuing providers who continue using platforms like Zoom without proper safeguards.
Case Overview: Telehealth Platform Violations
During the COVID-19 pandemic, OCR exercised enforcement discretion and did not pursue providers who used video conferencing platforms like Zoom, FaceTime, or Google Meet for patient care, recognizing the emergency need for rapid telehealth expansion. However, in 2021, OCR announced that this temporary enforcement discretion would expire, and providers must transition to HIPAA-compliant platforms.
Beginning in 2022 and continuing to present, OCR has pursued enforcement actions against providers who continued using non-compliant platforms for patient care after the enforcement discretion period ended. Violations include:
- Using Zoom or similar consumer platforms for telehealth without BAA
- Failure to obtain business associate agreements from platform providers
- Using platforms that do not implement appropriate security safeguards
- Continuing use of non-compliant platforms after knowing of HIPAA requirements
- Inadequate training of staff on telehealth security requirements
Key Timeline
- March 2020: OCR announced temporary enforcement discretion for telehealth
- March 2021: OCR announced enforcement discretion would expire end of 2021
- January 2022: Enforcement discretion ended; full HIPAA compliance required
- 2022-Present: OCR pursuing enforcement actions against non-compliant providers
What Went Wrong
Failure to Obtain Business Associate Agreements
- Providers using Zoom, FaceTime, or Google Meet for patient consultations
- No business associate agreements between provider and platform vendor
- Assumption that platform provider was responsible for HIPAA compliance
- Lack of understanding that provider is responsible for platform selection
- Continued use after being notified of HIPAA requirements
Inadequate Evaluation of Platform Security
- No assessment of whether platform met HIPAA security requirements
- Reliance on free or low-cost consumer video platforms
- Awareness of security weaknesses (inadequate encryption, data storage practices)
- Use of platforms without end-to-end encryption for patient care
- No evaluation of vendor security practices or certifications
Lack of Staff Training
- Providers did not train staff on telehealth security requirements
- Staff used platforms unsecured (public meetings, no passwords)
- Failure to implement access controls or use waiting rooms
- Patient information shared or visible in video settings
Inadequate Notice to Patients
- Patients were not informed of platform used for telehealth
- Patients did not consent to use of specific platform
- No notice that non-HIPAA-compliant platform would be used
- Providers continued using non-compliant platforms despite knowing requirements
Inadequate Breach Notification
- When telehealth sessions were breached or exposed, notification was delayed
- Providers assumed no breach occurred without encryption violation
- Incomplete investigation of telehealth session exposure
OCR Enforcement and Findings
Covered Entity Responsibility
OCR has clarified that covered entities are responsible for ensuring telehealth platforms used for patient care comply with HIPAA. This responsibility includes:
- Evaluating vendor compliance with HIPAA requirements
- Obtaining business associate agreements from all vendors
- Verifying that vendors implement appropriate safeguards
- Ensuring adequate training of staff on telehealth security
- Monitoring vendor compliance with HIPAA obligations
HIPAA Violations Identified
Business Associate Rule Violations (45 CFR Part 164)
- § 164.502(e) - Failure to obtain business associate agreement before using vendor
- Using vendor not under business associate agreement
- Inadequate business associate agreements not addressing HIPAA requirements
Administrative Safeguards Violations
- § 164.308(a)(1) - Inadequate vendor evaluation and risk assessment
- § 164.308(a)(3) - Insufficient training on telehealth platform security
- § 164.314(a)(2) - Failure to ensure vendor maintains HIPAA safeguards
Technical Safeguards Violations
- § 164.312(a) - Use of platform without appropriate access controls
- § 164.312(c) - Lack of integrity controls in platform
- § 164.312(e) - Inadequate encryption or communications security
OCR Guidance on Compliant Platforms
OCR has provided guidance that HIPAA-compliant telehealth platforms should:
- Implement end-to-end encryption for video and audio communications
- Use industry-standard authentication mechanisms
- Implement logging and audit capabilities
- Maintain PHI security and confidentiality
- Have documentation of security practices available to covered entities
- Agree to Business Associate Rule obligations
Settlement Patterns and Trends
Increasing Penalties
OCR penalties for telehealth violations have ranged from $50,000 to $200,000+ depending on:
- Number of patient encounters using non-compliant platform
- Duration of platform use after enforcement discretion ended
- Whether patients experienced breach or exposure
- Provider's awareness of HIPAA requirements
- Prior compliance history
Common Corrective Actions
Settlements typically require:
- Immediate transition to HIPAA-compliant telehealth platform
- Comprehensive evaluation of all vendors and systems for HIPAA compliance
- Execution of business associate agreements with all vendors
- Enhanced workforce training on telehealth security
- Documented policy for telehealth platform security and selection
- Annual review and monitoring of vendor compliance
- Patient notification if breaches occurred
Enforcement Trend
OCR has made clear that:
- COVID-era discretion has ended permanently
- All telehealth platforms must comply with HIPAA
- Providers cannot use consumer video platforms for patient care
- Failure to transition to compliant platforms after 2022 demonstrates knowing violation
- Enforcement actions will continue and increase
Lessons Learned
Temporary Discretion Is Temporary
OCR's temporary enforcement discretion during COVID-19 was explicitly temporary and time-limited. Providers should have understood that compliant platforms would eventually be required. Continuing to use non-compliant platforms after the discretion period ended represents a knowing violation.
Covered Entities Must Evaluate Vendors
Healthcare providers cannot simply use consumer platforms because they are convenient or free. Every vendor and platform must be evaluated for HIPAA compliance before being used for patient care. This is a covered entity's responsibility, not the platform vendor's responsibility.
Business Associate Agreements Are Required
No vendor can be used for patient care without a signed business associate agreement specifying HIPAA obligations. Even if a vendor claims HIPAA compliance, the agreement must be in place. Agreements should address specific security requirements and audit rights.
HIPAA-Compliant Platforms Are Available
Multiple vendors now offer HIPAA-compliant telehealth platforms specifically designed for healthcare. These platforms have appropriate security safeguards and are prepared to execute business associate agreements. Cost should not be a barrier to compliance—there are compliant options at various price points.
Staff Training Is Essential
Even with a compliant platform, staff must be trained on proper use, including password protection, use of waiting rooms, ending sessions properly, and not recording without consent. Telehealth security is as important as office-based patient care security.
Enforcement Is Active and Escalating
OCR has made telehealth platform compliance a priority area. Providers who have not transitioned to compliant platforms face increasing risk of enforcement action. Self-disclosure and rapid remediation can reduce penalties, but enforcement is expected to continue.
Telehealth HIPAA Compliance Checklist
Platform Selection and Evaluation
Business Associate Agreements
Workforce Training and Policy
Patient Communication
Technical Implementation
Monitoring and Compliance
Frequently Asked Questions
Yes, if Zoom or any platform has HIPAA-compliant features and the provider has a business associate agreement with Zoom. However, providers must ensure they are using the compliant version with appropriate security settings enabled. The free or standard version of Zoom is not HIPAA-compliant. Providers must specifically select and configure HIPAA-compliant options and execute the necessary business associate agreement.
Providers should immediately: (1) transition to a HIPAA-compliant platform, (2) document the platform change, (3) obtain a business associate agreement with the new platform, (4) notify patients of the change, (5) conduct a risk assessment to determine if breaches occurred, (6) notify OCR if breaches occurred, and (7) provide additional staff training. Self-disclosure to OCR, though not required, can demonstrate good faith compliance efforts and may reduce penalties if enforcement action is initiated.
Several HIPAA-compliant telehealth platforms are available, with various pricing models. While many traditional consumer platforms (Zoom, Google Meet, FaceTime) require additional security configuration, purpose-built healthcare telehealth platforms are designed for HIPAA compliance. Many offer tiered pricing to accommodate different practice sizes. Providers should not assume that cost limitations justify using non-compliant platforms—compliant alternatives exist at reasonable cost.