Resources / Start a digital clinic

What Makes a Telehealth Platform HIPAA Compliant?

Short answer: A HIPAA compliant telehealth platform is one that signs a business associate agreement (BAA), protects electronic health information with the administrative, physical and technical safeguards the HIPAA Security Rule requires, limits who can see patient data, logs access, encrypts data in storage and in transit, supports breach notification and keeps tracking tools off sensitive pages. HHS does not certify software as HIPAA compliant, so compliance depends on how the platform and your brand operate together.

Every founder building a digital clinic hears the phrase HIPAA compliant telehealth platform, and almost every vendor claims it. The problem is that HIPAA is not a badge or a product feature. It is a set of federal rules about how certain organizations use, protect and disclose health information, and those rules apply to people and processes as much as to software.

This guide explains when HIPAA applies to a telehealth business, what a telehealth BAA should include, which safeguards matter most, how tracking pixels fit in, and the questions to ask any platform before you trust it with patient data.

What makes a telehealth platform HIPAA compliant?

HIPAA’s rules come from the U.S. Department of Health and Human Services (HHS) and are enforced by its Office for Civil Rights (OCR). Three rules matter most for telehealth:

  • The Privacy Rule sets limits on how protected health information (PHI) can be used and disclosed, and gives patients rights over their information.
  • The Security Rule requires safeguards to protect electronic PHI (ePHI).
  • The Breach Notification Rule requires notice to patients, HHS and sometimes the media after a breach of unsecured PHI.

HHS does not endorse or recognize private “HIPAA certifications” for software. A vendor can undergo third-party audits, which can be useful evidence, but no seal makes a platform compliant on its own. What makes a telehealth platform HIPAA compliant is a combination of a signed BAA, real safeguards that match a documented risk analysis, and workflows that let your brand meet its own obligations.

Does HIPAA apply to your telehealth business?

HIPAA applies to covered entities and their business associates. Covered entities are health plans, health care clearinghouses and health care providers that conduct certain standard electronic transactions, such as billing insurance. Business associates are people or companies that create, receive, maintain or transmit PHI on behalf of a covered entity.

In a telehealth model, the roles can look like this:

Party Typical HIPAA role What that means
Medical group or provider practice Often a covered entity Must follow the Privacy, Security and Breach Notification Rules
Telehealth platform Usually a business associate Must sign a BAA and follow the Security Rule for ePHI
Pharmacy Often its own covered entity Handles PHI under its own HIPAA obligations
Your brand or management company Often a business associate, depending on structure Needs BAAs and safeguards for any PHI it touches
Email, SMS, support and hosting vendors Business associates or subcontractors if they handle PHI Need BAAs, or must be kept away from PHI

Some cash-pay telehealth models fall partly outside HIPAA. That does not mean health data is unregulated. The FTC’s Health Breach Notification Rule and state consumer health data laws can apply instead, as covered below. Your structure also depends on corporate practice of medicine rules, so read about the MSO and PC model for telehealth and confirm your roles with a healthcare attorney.

What is a telehealth BAA and what should it include?

A business associate agreement is the written contract HIPAA requires between a covered entity and a business associate, and between a business associate and its subcontractors. According to HHS, the contract must, among other things:

  • Establish the permitted and required uses and disclosures of PHI.
  • Prohibit uses or disclosures beyond what the contract or the law allows.
  • Require appropriate safeguards, including compliance with the Security Rule for ePHI.
  • Require reporting of any use or disclosure not allowed by the contract, including breaches of unsecured PHI.
  • Require subcontractors that handle PHI to agree to the same restrictions.
  • Support patient rights, such as access to and amendment of their information.
  • Make internal practices and records available to HHS when needed to determine compliance.
  • Require return or destruction of PHI at the end of the relationship, where feasible.
  • Allow termination if the business associate violates a material term.

A telehealth BAA should also be clear on practical details: how quickly the vendor will report a security incident, which subcontractors it uses, where data is hosted and what happens to data if you leave. A vendor that refuses to sign a BAA should not receive PHI. HHS guidance also makes clear that a cloud service provider that stores ePHI is a business associate even if the data is encrypted and the provider does not hold the key. The narrow “conduit” exception covers transmission services such as mail carriers and internet service providers, not vendors that store data.

HIPAA Security Rule safeguards for a HIPAA compliant telehealth platform

The Security Rule groups its requirements into three categories. A strong platform addresses all three, and your brand’s own workforce and devices need to follow them too.

Safeguard type Examples of what HIPAA expects What to look for in a platform
Administrative Risk analysis, risk management, a designated security official, workforce training, contingency planning A documented risk analysis, security policies, training and an incident response plan
Physical Facility access controls, workstation security, device and media controls Secure hosting environments and controls on devices that access ePHI
Technical Access control, audit controls, integrity controls, authentication, transmission security Role-based access, audit logs, multi-factor authentication and encryption in transit and at rest

The risk analysis is the foundation. HHS expects covered entities and business associates to assess risks to the confidentiality, integrity and availability of ePHI and to manage those risks. HHS also published a proposed update to the Security Rule in January 2025 that would make several safeguards more explicit, so check its current status when you review vendors.

Features to look for in a HIPAA compliant telehealth platform

  • Signed BAA covering the platform and its subcontractors.
  • Encryption of data in transit and at rest.
  • Role-based access so support staff, providers, pharmacy and marketing each see only what they need, which also supports HIPAA’s minimum necessary standard.
  • Multi-factor authentication for staff and provider accounts.
  • Audit logs that record who accessed or changed patient records and when.
  • Secure patient messaging inside the portal rather than over regular email or text.
  • Secure video from a vendor that signs a BAA, if your model uses live visits.
  • Backups and disaster recovery so records stay available.
  • Data export and deletion processes for patient requests and for the end of your contract.
  • Separation of marketing data from clinical data, with tracking tools kept off sensitive pages.

For a broader vendor comparison, see how to choose a white-label telehealth platform. If your model includes labs or connected devices, our guide to telehealth lab testing and wearables covers the extra data flows involved.

Video visits, messaging and the end of pandemic flexibilities

During the COVID-19 public health emergency, OCR relaxed enforcement for good-faith telehealth using everyday video tools. According to HHS, that notification of enforcement discretion expired on May 11, 2023, and the transition period ended on August 9, 2023. Today, video and messaging tools used for patient care should come from vendors that meet HIPAA requirements and sign BAAs.

For email and text, HHS guidance allows providers to communicate with patients by unencrypted email when the patient has been informed of the risks and prefers it, but the safer default is secure messaging inside your platform. Keep health details out of marketing texts and emails, and remember that SMS marketing also has TCPA consent rules.

Tracking pixels, analytics and HIPAA

Tracking technology is one of the biggest HIPAA risks for telehealth brands, because marketing teams want conversion data and intake flows are full of health information. In 2022, OCR issued a bulletin on the use of online tracking technologies by HIPAA-regulated entities. In June 2024, a federal court in Texas vacated part of that guidance, specifically the portion addressing tracking on unauthenticated public web pages that connect an IP address to a visit about a health condition, and HHS later withdrew its appeal.

That ruling did not make pixels safe everywhere. Pages behind a login, such as patient portals, and pages where patients enter health information, such as intake forms, still deserve strict treatment. Practical steps:

  • Inventory every tag, pixel and script on your site and in your intake flow.
  • Remove third-party marketing pixels from intake, portal and checkout pages unless your attorney approves a compliant setup.
  • Do not send health details, such as condition or treatment selections, into ad platform conversion events.
  • Use vendors that sign BAAs for any analytics that touch PHI.
  • Re-check after every site update, since new plugins often add tags.

Our guide to how to market a telehealth business covers how to measure campaigns while staying within these limits.

Breach notification: what happens if something goes wrong

Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI. Breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets there. HHS must be notified within 60 days for breaches affecting 500 or more people, and through an annual report for smaller breaches. Business associates must notify the covered entity of breaches they discover.

Your platform’s BAA should spell out how quickly it reports incidents to you, and your brand should have a written response plan that names who does what.

Beyond HIPAA: FTC and state health data laws

If some of your health data falls outside HIPAA, other rules may apply. The FTC’s Health Breach Notification Rule covers vendors of personal health records and related entities not covered by HIPAA, and the FTC has said an unauthorized disclosure, such as sharing health data with an ad platform without authorization, can count as a breach. States have also passed consumer health data laws. Washington’s My Health My Data Act, for example, requires consent before collecting and sharing consumer health data and allows private lawsuits. Our telehealth compliance checklist covers these rules in more detail.

Questions to ask a HIPAA compliant telehealth platform vendor

  • Will you sign a BAA, and does it cover all subcontractors that touch PHI?
  • When did you last complete a security risk analysis, and do you have third-party audit reports?
  • Is data encrypted in transit and at rest?
  • Do you support role-based access, multi-factor authentication and audit logs?
  • How quickly will you notify us of a security incident or breach?
  • Where is patient data hosted, and who can access it?
  • How do you keep marketing tools away from intake and portal data?
  • How do patients request access to or copies of their records?
  • What happens to our patient data if we end the contract?

What your brand still owns

Even the best platform cannot make your business compliant alone. Your brand still needs its own policies, workforce training, BAAs with every vendor that touches PHI, secure devices, a breach response plan and document retention. HIPAA requires required policies and documentation to be kept for six years. Ask a healthcare attorney to confirm your role and obligations before launch.

How WellieMD helps

WellieMD is a white-label telehealth platform built with HIPAA safeguards at its core, and we sign a business associate agreement with the brands we work with. We build it with you: branded intake, a licensed provider network, licensed 503A pharmacy routing, payments and subscriptions, refills, labs and wearables, secure patient workflows and LegitScript-ready builds. We also help you plan the pieces your brand owns, like vendor BAAs and keeping marketing tags off sensitive pages. To see how the platform handles patient data, book a demo with WellieMD.

Frequently asked questions

Is there an official HIPAA certification for telehealth platforms?

No. HHS does not endorse or recognize private HIPAA certifications. Third-party security audits can be useful evidence of a vendor’s practices, but compliance depends on a signed BAA, real safeguards and how your business operates.

What is a telehealth BAA?

A telehealth BAA is a business associate agreement between a covered entity, or a business associate, and a vendor that handles PHI for it. HHS requires it to set permitted uses of PHI, require safeguards and require breach reporting, among other terms. Never send PHI to a vendor that will not sign one when it is required.

Can I use regular video or email tools for telehealth?

The pandemic enforcement flexibilities ended in 2023, so tools used for patient care should come from vendors that meet HIPAA requirements and sign BAAs. HHS allows unencrypted email with patients who are warned of the risks and prefer it, but secure in-platform messaging is the safer default.

Are tracking pixels allowed on a telehealth website?

A 2024 court decision vacated part of HHS’s tracking guidance for unauthenticated public pages, but pixels on intake forms, portals and checkout pages can still expose health information. Keep marketing tags off sensitive pages and review your setup with a healthcare attorney.

Does HIPAA apply if my telehealth brand is cash-pay only?

It depends on your structure and roles. Some cash-pay models fall partly outside HIPAA, but the FTC Health Breach Notification Rule and state consumer health data laws may apply instead. A healthcare attorney can map which rules cover each part of your business.

This guide is general information, not legal advice. Talk with a healthcare attorney about your specific model and obligations. Prescription products require evaluation by a licensed provider.

Sources

See How a Digital Clinic Runs on WellieMD

Intake to refill, live, in 30 minutes.

Book A Demo