Security Risk Analysis

Telehealth HIPAA Violation: Non-Compliant Platform

Using consumer video platforms for patient care and the end of COVID-era enforcement discretion

Quick Answer

Healthcare providers that use non-HIPAA-compliant video conferencing platforms without business associate agreements for telehealth visits face HIPAA enforcement action. COVID-era enforcement discretion has ended, and OCR is actively pursuing providers who continue using platforms like Zoom without proper safeguards.

Case Overview: Telehealth Platform Violations

During the COVID-19 pandemic, OCR exercised enforcement discretion and did not pursue providers who used video conferencing platforms like Zoom, FaceTime, or Google Meet for patient care, recognizing the emergency need for rapid telehealth expansion. However, in 2021, OCR announced that this temporary enforcement discretion would expire, and providers must transition to HIPAA-compliant platforms.

Beginning in 2022 and continuing to present, OCR has pursued enforcement actions against providers who continued using non-compliant platforms for patient care after the enforcement discretion period ended. Violations include:

Key Timeline

Dozens
Enforcement Cases
$50K-$200K+
Penalty Range
2022-Present
Active Enforcement Period
Increasing
Case Frequency

What Went Wrong

Failure to Obtain Business Associate Agreements

Inadequate Evaluation of Platform Security

Lack of Staff Training

Inadequate Notice to Patients

Inadequate Breach Notification

OCR Enforcement and Findings

Covered Entity Responsibility

OCR has clarified that covered entities are responsible for ensuring telehealth platforms used for patient care comply with HIPAA. This responsibility includes:

HIPAA Violations Identified

Business Associate Rule Violations (45 CFR Part 164)

Administrative Safeguards Violations

Technical Safeguards Violations

OCR Guidance on Compliant Platforms

OCR has provided guidance that HIPAA-compliant telehealth platforms should:

Settlement Patterns and Trends

Increasing Penalties

OCR penalties for telehealth violations have ranged from $50,000 to $200,000+ depending on:

Common Corrective Actions

Settlements typically require:

Enforcement Trend

OCR has made clear that:

Lessons Learned

Temporary Discretion Is Temporary

OCR's temporary enforcement discretion during COVID-19 was explicitly temporary and time-limited. Providers should have understood that compliant platforms would eventually be required. Continuing to use non-compliant platforms after the discretion period ended represents a knowing violation.

Covered Entities Must Evaluate Vendors

Healthcare providers cannot simply use consumer platforms because they are convenient or free. Every vendor and platform must be evaluated for HIPAA compliance before being used for patient care. This is a covered entity's responsibility, not the platform vendor's responsibility.

Business Associate Agreements Are Required

No vendor can be used for patient care without a signed business associate agreement specifying HIPAA obligations. Even if a vendor claims HIPAA compliance, the agreement must be in place. Agreements should address specific security requirements and audit rights.

HIPAA-Compliant Platforms Are Available

Multiple vendors now offer HIPAA-compliant telehealth platforms specifically designed for healthcare. These platforms have appropriate security safeguards and are prepared to execute business associate agreements. Cost should not be a barrier to compliance—there are compliant options at various price points.

Staff Training Is Essential

Even with a compliant platform, staff must be trained on proper use, including password protection, use of waiting rooms, ending sessions properly, and not recording without consent. Telehealth security is as important as office-based patient care security.

Enforcement Is Active and Escalating

OCR has made telehealth platform compliance a priority area. Providers who have not transitioned to compliant platforms face increasing risk of enforcement action. Self-disclosure and rapid remediation can reduce penalties, but enforcement is expected to continue.

Telehealth HIPAA Compliance Checklist

Platform Selection and Evaluation

Evaluate all telehealth platforms for HIPAA compliance before use
Verify platform has end-to-end encryption for video and audio
Confirm platform provides audit logging and activity monitoring
Assess vendor security practices and certifications (SOC 2, ISO 27001)
Ensure platform can securely handle patient consent and documentation

Business Associate Agreements

Execute business associate agreement before using any vendor platform
Require vendor to maintain HIPAA-compliant safeguards
Include breach notification requirements and timelines
Establish rights to audit and monitor vendor compliance
Maintain copies of all business associate agreements

Workforce Training and Policy

Develop documented policy for telehealth platform use and security
Train all staff on proper use of telehealth platform
Educate staff on password protection and access controls
Establish procedures for use of waiting rooms and session controls
Provide training on proper ending of sessions and data handling

Patient Communication

Inform patients of telehealth platform used for care
Obtain informed consent for use of specific platform
Provide privacy notice explaining telehealth data handling
Explain session recording policies (if recording is used)
Document patient consent for telehealth use

Technical Implementation

Enforce strong passwords for telehealth sessions
Use waiting room functionality to control access
Disable features that may expose patient information
Implement proper session termination procedures
Maintain secure disposal of recordings or session data

Monitoring and Compliance

Conduct regular audits of telehealth platform use
Monitor vendor security practices and certifications
Maintain documentation of platform compliance assessment
Review vendor breach notification procedures annually
Update platform usage if vendor security changes negatively

Frequently Asked Questions

Can healthcare providers use Zoom if it's HIPAA-compliant? +

Yes, if Zoom or any platform has HIPAA-compliant features and the provider has a business associate agreement with Zoom. However, providers must ensure they are using the compliant version with appropriate security settings enabled. The free or standard version of Zoom is not HIPAA-compliant. Providers must specifically select and configure HIPAA-compliant options and execute the necessary business associate agreement.

What should healthcare providers do if they have been using non-compliant platforms? +

Providers should immediately: (1) transition to a HIPAA-compliant platform, (2) document the platform change, (3) obtain a business associate agreement with the new platform, (4) notify patients of the change, (5) conduct a risk assessment to determine if breaches occurred, (6) notify OCR if breaches occurred, and (7) provide additional staff training. Self-disclosure to OCR, though not required, can demonstrate good faith compliance efforts and may reduce penalties if enforcement action is initiated.

Are there HIPAA-compliant free or low-cost telehealth platforms? +

Several HIPAA-compliant telehealth platforms are available, with various pricing models. While many traditional consumer platforms (Zoom, Google Meet, FaceTime) require additional security configuration, purpose-built healthcare telehealth platforms are designed for HIPAA compliance. Many offer tiered pricing to accommodate different practice sizes. Providers should not assume that cost limitations justify using non-compliant platforms—compliant alternatives exist at reasonable cost.