Guide

Telehealth platforms: the BAA plus the settings that matter

Summary

No video product is 'HIPAA compliant' on its own — compliance is a combination of a signed business-associate agreement, the settings you enable, and how you use it. Since the COVID enforcement discretion ended, a consumer or free-tier app with no BAA no longer qualifies. Get the BAA, turn on encryption and a waiting room, use a business account, and record the platform in your risk analysis so you can prove the configuration.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Is my video platform HIPAA compliant?

Not by itself — 'HIPAA compliant' is not a property a video product carries out of the box. It is the combination of three things you control: a signed business-associate agreement with the vendor, the security settings you actually turn on, and the way you use the tool session to session. Since OCR's COVID-era enforcement discretion ended, a consumer app with none of that no longer passes 1.

That reframes the question you should be asking. Instead of 'is this platform compliant,' ask 'do I have a BAA for it, is it configured to safeguard PHI, and can I show both?' A well-known telehealth platform for private practice can be non-compliant in your hands if you never signed the BAA or left recording pointed at a consumer cloud. A lesser-known one can be compliant if you did the opposite. The product name is the least important variable.

The BAA is the threshold question

Before any setting matters, confirm the vendor will sign a business-associate agreement and that you have actually executed it. A video vendor that transmits or stores your patients' PHI is a business associate, and the BAA is the contract that binds it to safeguard that data and to notify you of a breach 2. No BAA means the platform is not a HIPAA-compliant option, regardless of how its marketing page reads.

Two traps catch solo practices here:

  • The free or personal tier usually has no BAA. Many platforms offer a BAA only on a paid healthcare plan. The consumer version of the same brand is a different product for compliance purposes.
  • A tool with no BAA is not lawless — it is governed elsewhere. A consumer app handling health data with no BAA can fall under the FTC's Health Breach Notification Rule instead 3. That does not make it a compliant clinical tool; it means a breach there still carries a federal notification duty, just under a different regulator.

Keep the executed BAA in your compliance file. If you cannot find it, you do not have it.

The settings that actually matter

A BAA sets the legal floor; the configuration is what actually protects PHI, and the Security Rule requires technical safeguards to match 4. Most exposure in telehealth comes not from the platform's encryption but from how the session is set up and joined. Walk the settings below once when you adopt a platform, and re-check them after any major update, because updates sometimes reset defaults.

  • Encryption on, end to end where offered. Confirm transport encryption is enabled, not merely available.
  • Waiting room and per-session links. A unique link per visit plus a waiting room prevents the wrong person joining or a reused link exposing a later patient.
  • Business account, not personal. Run visits from the healthcare account tied to your BAA, never a personal login.
  • Recording off, or pointed at compliant storage. Do not record to a consumer cloud. If you record, the storage is itself PHI and needs its own safeguards.
  • MFA and auto-lock. Multi-factor sign-in, and a screen that locks when you step away.
  • Disable data-sharing extras. Turn off analytics, AI transcription add-ons, or chat features that route content outside the BAA's scope.

These are administrative, physical, and technical safeguards scaled to a solo practice 5 — proportional to your size, but not optional. The same discipline extends past the platform: your office networks and your practice email are part of the same perimeter, and a hardened video call over an open network is only half-secured.

Audio-only and phone visits

Audio-only visits can be HIPAA-compliant, and OCR has published specific guidance on them 1. A standard telephone call over the traditional phone network is generally treated differently from an app that transmits voice over the internet, which is a business-associate arrangement like any other software. The practical rule: if the audio runs through software or a platform, the BAA-and-configuration analysis applies exactly as it does to video.

Two cautions for a solo practice leaning on audio-only. First, confirm your payers actually cover audio-only for the service before you rely on it clinically and financially; coverage and the privacy analysis are separate questions. Second, apply the same identity and setting discipline — verify who is on the line, avoid speakerphone in shared space, and do not leave PHI on voicemail beyond the minimum. The medium changes; the safeguard obligation does not.

Prove it with a risk analysis

Compliance you cannot show is compliance you cannot defend, so the platform belongs in a written risk analysis. ONC and OCR publish a free Security Risk Assessment tool built for small practices, which walks you through identifying where ePHI lives and the safeguards around each point 6. Add your video platform as an asset, note its BAA and its settings, and record the residual risks you accepted.

The risk analysis is the Security Rule's anchor requirement — every other safeguard flows from it 5, and it is the single document OCR asks for most often. For a telehealth-reliant solo practice, the entries that matter are the platform, its BAA, where recordings (if any) are stored, the devices you connect from, and the network you use. Redo it when something material changes — a new platform, a new device, a move to a home office — and keep each dated version.

When the platform is the breach

Plan for the platform failing, not just working. If a recording is exposed, an account is compromised, or ransomware encrypts stored ePHI, you are into breach analysis — and OCR's guidance presumes a ransomware event affecting ePHI is a reportable breach unless a documented risk assessment shows a low probability that the data was compromised 7. The documentation is what turns a presumption into a defensible conclusion.

Two pieces make this survivable. Keep the contingency plan that lets you reach patients and records if the platform is down or locked — a second scheduling channel and an offline copy of upcoming appointments. And keep the breach-analysis habit: for any suspected exposure, document what data was involved, who accessed it, whether it was actually acquired or viewed, and the mitigation. That record is both your notification decision and your evidence that you made it responsibly.

Common questions

No. Compliance is not a badge the product carries; it is the combination of a signed BAA, the settings you enable, and how you use the tool. A platform marketed as HIPAA-ready is non-compliant in your hands if you never executed the BAA or left recordings on a consumer cloud. Confirm the BAA and configuration yourself rather than relying on a marketing claim.

Yes, if the platform transmits or stores your patients' PHI, which a video visit does. The vendor is a business associate, and the BAA binds it to safeguard the data and report breaches to you. Free and personal tiers frequently offer no BAA; the healthcare plan of the same brand usually does. Keep the executed agreement in your compliance file.

Generally yes, with the same discipline. OCR has published audio-only guidance, and a call routed through software is a business-associate arrangement like any other, so the BAA and configuration analysis still applies. Verify identity, avoid PHI on voicemail and in shared spaces, and confirm separately that your payers cover audio-only for the service before relying on it.

Running visits from a personal rather than a healthcare account, recording to a consumer cloud, reusing a single meeting link across patients, skipping the waiting room, and leaving data-sharing add-ons like third-party analytics or transcription enabled. Each routes PHI outside the safeguards your BAA covers. Walk the settings when you adopt the platform and re-check them after major updates, which can reset defaults.

Document it in a risk analysis. Use the free Security Risk Assessment tool, list the platform as an asset alongside its BAA and settings, note where any recordings live, and record the risks you accepted. Redo and date it when something material changes. That written analysis, plus the executed BAA, is what you hand an investigator instead of an assurance.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth must run on HIPAA-compliant arrangements now that the COVID enforcement discretion has ended, including OCR's audio-only guidance.
  2. 2.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a video vendor transmitting or storing PHI is a business associate requiring a signed BAA.
  3. 3.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). linkThat a consumer app handling health data without a BAA can fall under the FTC Health Breach Notification Rule.
  4. 4.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe Security Rule's technical-safeguard requirements for ePHI that the platform's configuration must satisfy.
  5. 5.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards scaled to the practice and anchored in a risk analysis.
  6. 6.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC/OCR publish a free Security Risk Assessment tool sized for small practices to document the required risk analysis.
  7. 7.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise.

https://www.gale.care/for-providers/hip-video-platform-configuration · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)