Medcurity HIPAA Resource Hub

Telehealth HIPAA Compliance Checklist

18 essential compliance items for virtual healthcare providers

Quick Answer

Telehealth adds unique HIPAA compliance requirements beyond traditional in-person care. Providers must ensure video platforms have Business Associate Agreements, obtain consent for session recording, verify patient location for interstate licensing, maintain secure virtual waiting rooms, document platform configurations, and manage encryption for all data transmission. This checklist covers the technical, administrative, and privacy requirements specific to virtual healthcare delivery.

Compliance Progress 0% Complete
Maintain Business Associate Agreements with all telehealth platforms, including video conferencing software
Administrative Medium Critical
Verify provider licensing in the state where patient is located; document patient state verification at each visit
Administrative Medium Critical
Establish written policies for emergency situations and patient privacy during telehealth consultations
Administrative Easy High
Document technical configurations and security settings of telehealth platform within system policies
Administrative Medium High
Provide HIPAA-specific training to staff on telehealth privacy and security requirements
Administrative Easy Critical
Ensure telehealth sessions occur in private physical spaces with no unauthorized observers or patient information visibility
Physical Easy Critical
Control access to devices/computers used for telehealth to prevent unauthorized use outside of scheduled sessions
Physical Medium High
Implement secure disposal procedures for telehealth devices that may contain PHI or healthcare data
Physical Medium High
Use end-to-end encryption for all telehealth video and audio transmissions to prevent eavesdropping
Technical Medium Critical
Disable screen sharing, file transfer, and recording features unless explicitly enabled with patient consent
Technical Easy High
Configure virtual waiting rooms to prevent patient information from being visible to other participants
Technical Easy High
Obtain explicit written consent before recording telehealth sessions, specifying storage duration and access permissions
Privacy Easy Critical
Verify patient identity through secure methods before initiating telehealth session and document verification method
Privacy Easy High
Obtain authorization before disclosing patient information to family members or caregivers present during telehealth visit
Privacy Easy High
Document and report any unauthorized access to telehealth platform or session recordings within breach notification procedures
Breach Notification Hard Critical
Maintain incident response procedures specific to telehealth technology failures and security breaches
Breach Notification Hard High

Secure Your Telehealth Operations

Virtual healthcare requires specialized security measures. Get a comprehensive assessment of your telehealth platform, policies, and data handling procedures to ensure full HIPAA compliance.

Assess Your Telehealth Security