Is Telehealth HIPAA Compliant? How Your Health Data Is Protected

By: Joseph Isagba FNP
Medically reviewed by: Brittney Afram FNP

Is Telehealth HIPAA Compliant? How Your Health Data Is Protected

Yes, when your telehealth visit is with a HIPAA-covered healthcare provider. Your visit, records and messages are then protected health information under federal law, with the same protections as an in-person appointment. The catch is that HIPAA protects data based on who holds it, not on whether it’s medical. A symptom-checker app, a fitness tracker, or even some cash-only providers may not be covered at all.

What HIPAA actually covers

HIPAA applies to “covered entities” (health plans, healthcare clearinghouses, and healthcare providers that carry out certain electronic transactions, mainly insurance billing) and to their “business associates,” the vendors that handle patient data on their behalf.

Three rules do most of the work:

  • The Privacy Rule limits who can see and share your health information.
  • The Security Rule requires administrative, physical and technical safeguards for electronic health data.
  • The Breach Notification Rule requires that you be told if your data is exposed, without unreasonable delay and no later than 60 days after the breach is discovered.

Where HIPAA stops

Who holds your data Covered by HIPAA?
A telehealth provider that bills insurance Yes
That provider’s video, records and messaging vendors Yes, as business associates under a signed agreement
Your health insurer Yes
A provider that is cash-only and never bills insurance Not necessarily (see below)
A symptom-checker or wellness app you download yourself Usually no
A fitness tracker or smartwatch No
A period or fertility tracking app Usually no
Your employer, acting as your employer No

A nuance for self-pay telehealth

HIPAA coverage for a provider is triggered by conducting standard electronic transactions, typically insurance claims and eligibility checks. A provider that only takes card payments and never bills insurance may not technically be a HIPAA covered entity.

That doesn’t leave you unprotected. Licensed clinicians owe a professional duty of confidentiality regardless. Many states have their own medical privacy laws, some broader than HIPAA. And the Federal Trade Commission can act against any company whose privacy practices don’t match its promises. Many cash-pay services also choose to follow HIPAA voluntarily.

It’s still worth asking directly: “Are you a HIPAA covered entity, and if not, do you follow HIPAA anyway?”

A compliant platform vs. FaceTime

A compliant telehealth platform has four things a consumer video app doesn’t:

  • A business associate agreement: a signed contract making the vendor legally responsible for protecting your data
  • Encryption of your data in transit and in storage
  • Access controls, so only authorized staff can see your records
  • Audit logs that record who accessed what, and when

During the COVID-19 emergency, regulators temporarily allowed providers to use everyday apps like FaceTime and Skype. That enforcement discretion ended in 2023. Consumer apps don’t come with business associate agreements, so if a provider asks to switch to FaceTime today, treat it as a red flag.

Who can see your records

With a covered provider, your information can be used for treatment, payment and running the practice, under a “minimum necessary” standard. In practice, the people who see it are:

  • Your provider and the care team involved in your visit
  • The pharmacy that fills your prescription
  • You

Your employer, advertisers and family members don’t see it unless you authorize it, apart from narrow exceptions such as certain legal processes and public health reporting.

Where privacy actually leaks

The biggest risks usually aren’t hackers breaking into the video call.

Tracking technology on health websites. Advertising pixels on booking pages and portals can send details, such as the condition page you visited, to ad platforms. Federal regulators warned healthcare organizations about this in 2022. A court later narrowed that guidance for public, non-login webpages, but tracking on patient portals and booking flows remains an active enforcement risk.

Health apps outside HIPAA. In 2023 the FTC took action against GoodRx, with a $1.5 million civil penalty, for sharing users’ health information with advertising platforms. It also reached a $7.8 million settlement with BetterHelp over sharing consumers’ mental health information with advertisers. Neither case needed HIPAA.

Data breaches. In 2024, large healthcare breaches affected more than 286 million individuals’ records.

Your own devices. Shared family computers, screenshots, and visit summaries forwarded by ordinary email.

Your rights under HIPAA

With a covered provider, you can:

  • Get a copy of your records, normally within 30 days
  • Ask for corrections to information you believe is wrong
  • Get a list of certain disclosures of your information
  • Stop your health plan from being told about a service you paid for in full out of pocket
  • Choose how you’re contacted, for example at a different address or number
  • File a complaint with the HHS Office for Civil Rights, generally within 180 days

What’s changing

In December 2024, regulators proposed the biggest update to the HIPAA Security Rule in two decades, which would make encryption and multi-factor authentication explicit requirements. Final action has since been pushed back to July 2027 at the earliest. The current rules remain fully in force in the meantime.

Protecting yourself during a visit

  • Find a private space where you won’t be overheard
  • Use a secure home network rather than public Wi-Fi
  • Join through the provider’s official portal or link, not a link forwarded by someone else
  • Keep health details out of ordinary email and text where possible
  • Log out when you finish, especially on shared devices

Questions to ask before you book

  • Are you a HIPAA covered entity? If not, do you follow HIPAA voluntarily?
  • Do your video and messaging vendors sign business associate agreements?
  • Is my data encrypted?
  • Do you use advertising trackers on booking or condition pages?
  • How do I get a copy of my records?
  • Where is your privacy notice?

One more tip: there is no official “HIPAA certification.” A badge claiming one doesn’t mean anything.

How QuickCare365 handles your data

[EDITORIAL PLACEHOLDER. Confirm QuickCare365’s HIPAA status with counsel, then replace this section with verified specifics: covered-entity status or voluntary compliance, encryption, BAAs with platform vendors, and record retention.]

What the site currently states: QuickCare365 uses a secure, integrated electronic health record system and a patient portal. Visit summaries can be downloaded and shared with your other providers, and prescriptions are sent electronically to the pharmacy you choose.

Frequently asked questions

Is my telehealth visit confidential? Yes. Licensed providers owe you confidentiality, and HIPAA adds federal protection when the provider is a covered entity.

Can my employer find out? Not from your provider without your authorization. Even with an employer-sponsored telehealth benefit, employers typically see aggregate usage, not your individual visits.

Is FaceTime HIPAA compliant? Not for healthcare providers. The pandemic-era allowance ended in 2023.

Does HIPAA cover health apps? Usually not, unless the app is offered by or on behalf of a covered provider or health plan.

Can my telehealth records be shared with my regular provider? Yes, with your permission. You can usually download your visit summary and pass it on, or ask the service to send it directly.

What happens to my records if I stop using a service? Providers keep medical records for periods set by state law, and the same protections apply for as long as the records are held.

Questions about privacy before you book? Read our privacy policy or contact our team.

Leave a Reply

Your email address will not be published. Required fields are marked *

Your Journey to QuickCare365 Telehealth Consulting service starts here.