Can You Record Telehealth Sessions? HIPAA Rules
Understand HIPAA recording requirements, consent rules, encryption standards, and state wiretapping laws for compliant telehealth documentation
Understanding Telehealth Recording Laws
HIPAA Does Not Prohibit Recording
HIPAA itself does not prohibit recording telehealth sessions. However, HIPAA imposes important requirements:
- Recordings containing PHI must be treated as protected health information
- All HIPAA Security Rule protections apply (encryption, access controls, audit logs)
- Patient authorization is required (though technically part of privacy, not recording-specific)
- Breach notification rules apply if recordings are compromised
State Recording Laws Override HIPAA
State wiretapping and eavesdropping laws often impose stricter requirements than HIPAA:
- One-party consent states: Only the provider needs to consent to recording
- All-party consent states: Every participant must consent
- Recording consent: Separate from general treatment consent
- Criminal penalties: Unauthorized recording may be criminal, not just civil
Many providers mistakenly believe they can record sessions "for their own notes." State law doesn't care about intent—unauthorized recording is illegal regardless of purpose. Even recording for clinical documentation requires patient consent in all-party consent states.
State-by-State Recording Requirements
All-Party Consent States (Most Restrictive)
In these states, all participants must consent to recording. Recording without consent is illegal:
- California, Connecticut, Florida, Illinois, Maryland, Michigan, Missouri, Montana, Nevada, New Hampshire, Ohio, Pennsylvania, South Carolina, Tennessee, Washington
- Some states have additional penalties (criminal fines up to $10,000+)
- Recording without consent may result in civil lawsuits in addition to criminal charges
One-Party Consent States (More Permissive)
In these states, the provider can record without patient consent:
- Most states fall into this category
- However, HIPAA still requires patient authorization for use/disclosure
- Patient must know recording occurs (include in Notice of Privacy Practices)
- Still requires secure storage and access controls
Hybrid Approach for Multi-State Practices
If you treat patients in multiple states, best practice is to follow all-party consent rules for everyone:
- Obtain explicit consent from all participants before recording
- This approach complies with strictest state requirements
- Protects your practice across all jurisdictions
- Simplifies policy consistency
Recording Consent Requirements
Critical: Separate Recording Consent
Recording consent must be distinct from general telehealth consent:
- Patient may consent to telehealth but refuse recording
- Include specific, separate checkbox for recording consent
- Explain recording purpose clearly
- Document what happens to recordings after encounter
Recording Consent Must Include
- Purpose: Explain why you're recording (clinical notes, quality assurance, education, etc.)
- Access: Who will have access to recordings (just clinician, quality assurance team, supervisors, students)
- Retention: How long recordings will be kept
- Disposal: How recordings will be destroyed
- Re-use: Whether recordings may be used for teaching, training, or research
- Right to refuse: Explicit statement patient can decline recording
- State-specific language: In all-party states, acknowledge state recording law requirements
Sample: "I consent to this telehealth session being recorded by [Provider/Organization]. I understand the recording will be stored [describe location/encryption] and will be accessible to [list who]. The recording will be retained for [specify time period] and then securely destroyed. I understand I can revoke this consent by written notice, and that refusing to be recorded will not affect my care."
Secure Storage and Technical Requirements
Encryption Requirements
Recordings containing PHI must be encrypted per Security Rule standards:
- In transit: Encrypted transmission (TLS 1.2 or higher)
- At rest: AES-256 encryption or equivalent
- Key management: Secure storage of encryption keys separate from data
- Standards: NIST-approved encryption algorithms minimum
Access Controls
- Limit access to authorized personnel only
- Implement role-based access controls
- Require strong authentication (multi-factor recommended)
- Log all access to recordings (audit trail)
- Automatically timeout inactive sessions
Storage Location
- Store in HIPAA-compliant data centers
- Preferably in United States
- Document data location in privacy policies
- Ensure vendor has signed Business Associate Agreement
- Verify vendor's security certifications
Retention and Destruction
- Document retention period in consent form
- Automate deletion or destruction after retention period
- Verify complete destruction (not just deletion)
- Maintain audit logs of destruction
- Consider compliance with state medical record retention laws
Patient Rights and Obligations
Patient Right to Know About Recording
- Patients must know if recording occurs
- This applies even in one-party consent states
- Include recording policy in Notice of Privacy Practices
- Clearly disclose recording before session starts
Patient Right to Review Recordings
Under HIPAA, patients have right to access their health records, including recordings:
- Patients can request copies of recordings
- You must provide within 30 days (extending to 60 in some cases)
- Can charge reasonable copying fees
- Verify patient identity before providing access
Patient Right to Refuse Recording
- Patients can decline to be recorded
- Must provide care without recording if requested
- Refusal cannot affect treatment or payment
- Document refusal in medical record
Patient Right to Request Deletion
- In some states, patients can request deletion of recordings
- California and some other states recognize "right to deletion"
- May need to comply even if normal retention period not expired
- Verify state law requirements
Ensure Your Recording Practices Comply with HIPAA and State Laws
Get expert guidance on implementing secure, compliant recording procedures. Our security assessment includes review of your recording policies and technical safeguards.
Start Your Assessment