Telehealth platforms: the BAA plus the settings that matter
Summary
No video product is 'HIPAA compliant' on its own — compliance is a combination of a signed business-associate agreement, the settings you enable, and how you use it. Since the COVID enforcement discretion ended, a consumer or free-tier app with no BAA no longer qualifies. Get the BAA, turn on encryption and a waiting room, use a business account, and record the platform in your risk analysis so you can prove the configuration.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Is my video platform HIPAA compliant?
Not by itself — 'HIPAA compliant' is not a property a video product carries out of the box. It is the combination of three things you control: a signed business-associate agreement with the vendor, the security settings you actually turn on, and the way you use the tool session to session. Since OCR's COVID-era enforcement discretion ended, a consumer app with none of that no longer passes 1Ref 1HHS Office for Civil Rights (2026).HIPAA and Telehealth.That telehealth must run on HIPAA-compliant arrangements now that the COVID enforcement discretion has ended, including OCR's audio-only guidance..
That reframes the question you should be asking. Instead of 'is this platform compliant,' ask 'do I have a BAA for it, is it configured to safeguard PHI, and can I show both?' A well-known telehealth platform for private practice can be non-compliant in your hands if you never signed the BAA or left recording pointed at a consumer cloud. A lesser-known one can be compliant if you did the opposite. The product name is the least important variable.
The BAA is the threshold question
Before any setting matters, confirm the vendor will sign a business-associate agreement and that you have actually executed it. A video vendor that transmits or stores your patients' PHI is a business associate, and the BAA is the contract that binds it to safeguard that data and to notify you of a breach 2Ref 2HHS Office for Civil Rights (2026).Business Associates.That a video vendor transmitting or storing PHI is a business associate requiring a signed BAA.. No BAA means the platform is not a HIPAA-compliant option, regardless of how its marketing page reads.
Two traps catch solo practices here:
- The free or personal tier usually has no BAA. Many platforms offer a BAA only on a paid healthcare plan. The consumer version of the same brand is a different product for compliance purposes.
- A tool with no BAA is not lawless — it is governed elsewhere. A consumer app handling health data with no BAA can fall under the FTC's Health Breach Notification Rule instead 3Ref 3Federal Trade Commission (2026).Health Breach Notification Rule.That a consumer app handling health data without a BAA can fall under the FTC Health Breach Notification Rule.. That does not make it a compliant clinical tool; it means a breach there still carries a federal notification duty, just under a different regulator.
Keep the executed BAA in your compliance file. If you cannot find it, you do not have it.
The settings that actually matter
A BAA sets the legal floor; the configuration is what actually protects PHI, and the Security Rule requires technical safeguards to match 4Ref 4Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The Security Rule's technical-safeguard requirements for ePHI that the platform's configuration must satisfy.. Most exposure in telehealth comes not from the platform's encryption but from how the session is set up and joined. Walk the settings below once when you adopt a platform, and re-check them after any major update, because updates sometimes reset defaults.
- Encryption on, end to end where offered. Confirm transport encryption is enabled, not merely available.
- Waiting room and per-session links. A unique link per visit plus a waiting room prevents the wrong person joining or a reused link exposing a later patient.
- Business account, not personal. Run visits from the healthcare account tied to your BAA, never a personal login.
- Recording off, or pointed at compliant storage. Do not record to a consumer cloud. If you record, the storage is itself PHI and needs its own safeguards.
- MFA and auto-lock. Multi-factor sign-in, and a screen that locks when you step away.
- Disable data-sharing extras. Turn off analytics, AI transcription add-ons, or chat features that route content outside the BAA's scope.
These are administrative, physical, and technical safeguards scaled to a solo practice 5Ref 5HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards scaled to the practice and anchored in a risk analysis. — proportional to your size, but not optional. The same discipline extends past the platform: your office networks and your practice email are part of the same perimeter, and a hardened video call over an open network is only half-secured.
Audio-only and phone visits
Audio-only visits can be HIPAA-compliant, and OCR has published specific guidance on them 1Ref 1HHS Office for Civil Rights (2026).HIPAA and Telehealth.That telehealth must run on HIPAA-compliant arrangements now that the COVID enforcement discretion has ended, including OCR's audio-only guidance.. A standard telephone call over the traditional phone network is generally treated differently from an app that transmits voice over the internet, which is a business-associate arrangement like any other software. The practical rule: if the audio runs through software or a platform, the BAA-and-configuration analysis applies exactly as it does to video.
Two cautions for a solo practice leaning on audio-only. First, confirm your payers actually cover audio-only for the service before you rely on it clinically and financially; coverage and the privacy analysis are separate questions. Second, apply the same identity and setting discipline — verify who is on the line, avoid speakerphone in shared space, and do not leave PHI on voicemail beyond the minimum. The medium changes; the safeguard obligation does not.
Prove it with a risk analysis
Compliance you cannot show is compliance you cannot defend, so the platform belongs in a written risk analysis. ONC and OCR publish a free Security Risk Assessment tool built for small practices, which walks you through identifying where ePHI lives and the safeguards around each point 6Ref 6Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR publish a free Security Risk Assessment tool sized for small practices to document the required risk analysis.. Add your video platform as an asset, note its BAA and its settings, and record the residual risks you accepted.
The risk analysis is the Security Rule's anchor requirement — every other safeguard flows from it 5Ref 5HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards scaled to the practice and anchored in a risk analysis., and it is the single document OCR asks for most often. For a telehealth-reliant solo practice, the entries that matter are the platform, its BAA, where recordings (if any) are stored, the devices you connect from, and the network you use. Redo it when something material changes — a new platform, a new device, a move to a home office — and keep each dated version.
When the platform is the breach
Plan for the platform failing, not just working. If a recording is exposed, an account is compromised, or ransomware encrypts stored ePHI, you are into breach analysis — and OCR's guidance presumes a ransomware event affecting ePHI is a reportable breach unless a documented risk assessment shows a low probability that the data was compromised 7Ref 7HHS Office for Civil Rights (2016).FACT SHEET: Ransomware and HIPAA.That a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise.. The documentation is what turns a presumption into a defensible conclusion.
Two pieces make this survivable. Keep the contingency plan that lets you reach patients and records if the platform is down or locked — a second scheduling channel and an offline copy of upcoming appointments. And keep the breach-analysis habit: for any suspected exposure, document what data was involved, who accessed it, whether it was actually acquired or viewed, and the mitigation. That record is both your notification decision and your evidence that you made it responsibly.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth must run on HIPAA-compliant arrangements now that the COVID enforcement discretion has ended, including OCR's audio-only guidance.
- 2.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a video vendor transmitting or storing PHI is a business associate requiring a signed BAA.
- 3.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). link ✓That a consumer app handling health data without a BAA can fall under the FTC Health Breach Notification Rule.
- 4.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The Security Rule's technical-safeguard requirements for ePHI that the platform's configuration must satisfy.
- 5.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards scaled to the practice and anchored in a risk analysis.
- 6.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR publish a free Security Risk Assessment tool sized for small practices to document the required risk analysis.
- 7.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. link ✓That a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise.
https://www.gale.care/for-providers/hip-video-platform-configuration · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.