Get Security Assessment

Telehealth Patient Consent: HIPAA & State Requirements

Navigate written vs. verbal consent, state variations, and documentation best practices for compliant telehealth services

Quick Answer
What consent do I need for telehealth services?
You need two separate consents: (1) Consent to receive telehealth services instead of in-person care, and (2) Consent for the use and disclosure of PHI in telehealth. HIPAA does not mandate written consent, so verbal consent documented in the medical record is acceptable, but many states require written consent. You must document the technology used, potential risks, emergency procedures, and the patient's rights to refuse or withdraw consent. Some states impose specific form requirements and cooling-off periods.

Understanding Telehealth Consent Requirements

Telehealth consent is distinct from traditional in-person care consent. It addresses both the delivery method (remote vs. in-person) and privacy concerns specific to virtual healthcare.

Why Telehealth Consent is Different

Telehealth introduces unique risks that patients must understand:

HIPAA Consent Requirements

HIPAA does not specifically require written consent for telehealth use, but it does require authorization for use and disclosure of PHI. This means:

Written vs. Verbal Consent

Aspect Written Consent Verbal Consent
Legal Clarity Provides clear documentation of patient agreement Relies on documentation in medical record
Evidence Signed document serves as evidence Requires detailed note in chart
State Requirements Required in most states Acceptable in fewer states
Patient Understanding Form can educate patient thoroughly Dependent on conversation quality
Enforcement Issues Easier to defend in disputes More challenging to prove
Administrative Burden Requires collection and storage of forms Documented in EHR only
Best Practice Recommendation

Use written consent for all telehealth services. Even though HIPAA permits verbal consent, written consent provides better legal protection, clearer patient education, and compliance with most state requirements. Include both service delivery consent and privacy authorization in one comprehensive form.

State-by-State Consent Variations

States with Specific Written Consent Requirements

Many states mandate written consent before providing telehealth services:

High-Regulation States
  • California: Requires written or electronic consent before telehealth visit. Must include risks and benefits specific to videoconferencing
  • Texas: Requires documented informed consent including technology used and alternative options
  • Florida: Requires written consent addressing security and privacy
  • New York: Requires written authorization addressing specific telehealth risks
  • Illinois: Requires informed consent with specific disclosures about technology
Mid-Level Regulation States
  • Pennsylvania, Ohio, Michigan: Recommend written consent but may accept documented verbal consent
  • North Carolina, Virginia: Require consent but provide flexibility on format
Lower-Regulation States
  • Colorado, Utah, Arizona: Minimal specific requirements; HIPAA standards generally sufficient
  • Many newer telehealth-friendly states defer to HIPAA standards

Key State-Specific Requirements

Essential Elements of Telehealth Consent

Required Information to Disclose

Your telehealth consent form must include:

Sample Consent Language

Sample Text: "I understand that this telehealth visit will be conducted using [platform name]. I am aware that telehealth has potential limitations compared to in-person care, including inability to perform complete physical examination. I understand my privacy is protected by HIPAA, but I acknowledge risks of electronic communication. I confirm I have a secure, private location for this visit and understand my responsibilities in maintaining confidentiality."

Documentation Requirements

What to Document in Medical Records

Consent Form Organization

Recommended Form Structure
  1. Title: "Informed Consent for Telehealth Services"
  2. Patient and provider identification
  3. Clear explanation of telehealth delivery method
  4. Specific risks and benefits
  5. Privacy and security disclosures
  6. Technical requirements and patient responsibilities
  7. Emergency procedures
  8. Checkbox: "I understand and consent to telehealth"
  9. Signature line with date
  10. Provider signature and credentialing information
  11. Effective date and validity period
Telehealth Consent Implementation Checklist
Develop state-specific telehealth consent form
Include all required disclosures for your state
Clearly explain technology platform and risks
Address patient privacy concerns and safeguards
Explain alternatives to telehealth delivery
Set clear emergency procedures
Obtain consent before first telehealth visit
Document consent method and details in EHR
Store signed consent forms securely
Review consent annually and update as needed

Special Consent Situations

Recording and Photography Consent

If you intend to record telehealth sessions, you need separate, explicit consent:

Students or Observers Present

If students or other observers will participate:

Third-Party Payers and Insurance

Standard HIPAA authorization covers insurance claims, but confirm consent addresses:

Ensure Your Telehealth Consents Meet All Requirements

Get expert guidance on developing compliant consent forms that meet HIPAA and state requirements. Our security assessment includes consent form review and recommendations.

Start Your Assessment

Frequently Asked Questions

Can a patient verbally consent to telehealth?
Yes, HIPAA permits verbal consent for telehealth if documented in the medical record. However, most states require written consent. Even where verbal consent is legally permitted, written consent is strongly recommended because it: (1) provides clear documentation, (2) ensures patient understanding through a detailed form, (3) demonstrates compliance in case of audit, and (4) is easier to defend in legal disputes. Best practice is to always obtain and retain written consent.
Do I need separate consent for different technologies?
Not necessarily. One comprehensive consent can cover your standard telehealth platforms (e.g., "secure HIPAA-compliant video conferencing platform"). However, if you plan to use significantly different technologies (e.g., transitioning from one platform to another with different security features), you should update the consent. You do need separate consent for recording, photography, or observer presence, as these are distinct disclosures.
How long is telehealth consent valid?
Consent validity depends on your consent form language. Many practices set consent to remain valid for 12 months or the duration of the patient relationship. You should review and update consent: (1) annually at minimum, (2) when changing telehealth platforms, (3) when security measures change significantly, (4) when state regulations change, and (5) if patient circumstances change (e.g., patient moves to different state). Some states allow ongoing consent if documented properly.
What if a patient refuses to consent to telehealth?
Patients have the right to refuse telehealth services. If a patient declines, you must: (1) respect their decision without penalty, (2) offer alternative in-person care if available, (3) document the refusal in the medical record, and (4) continue treating the patient through in-person visits if appropriate. Never coerce patients into telehealth. Ensure your consent form clearly states this right and that refusal will not affect their care relationship with you.