Telehealth Security Requirements in 2026

The post-enforcement-discretion bar for telehealth: encrypted platform with a BAA, session controls, clinician endpoints, home networks, and SRA scope.

By Scott McAuley · Aug 20, 2026 · 10 min read

For about three years, telehealth security had an asterisk. The COVID public health emergency came with enforcement discretion: regulators announced they would look the other way while practices stood up video visits on whatever worked — FaceTime, consumer Zoom, whatever the patient could open. It was the right call for the moment, and it ended in 2023. The asterisk is gone.

What lingers is the habit. Plenty of practices built their telehealth workflow in 2020, confirmed it worked, and haven't seriously revisited it since — which means a workflow designed under an exemption is now operating under the full weight of the Security Rule. This article is the current bar, stated plainly: what the platform must be, what has to be true around the session, the clinician's device and network, recordings, and the risk-assessment expansion that most practices haven't caught up with. It expands the telehealth chapter of our complete HIPAA compliance and healthcare IT guide into working detail, and it ends with a readiness checklist you can walk this week.

The Era of "Whatever Works" Is Over

Start with the legal posture, because it frames everything else. During the public health emergency, OCR's enforcement discretion meant a practice using a non-compliant video tool in good faith wasn't going to be penalized. Since mid-2023, that protection is gone: telehealth is simply care delivered over technology, and every HIPAA requirement that applies to your EHR applies to it — encryption, access control, audit capability, business associate agreements, risk analysis.

The practical consequence: if your telehealth stack was chosen during the exemption and never re-evaluated, its compliance has been assumed, not established. That's not an accusation; it's a to-do list, and the rest of this article is the list.

The Platform: Encrypted, Under a BAA, Actually Configured

The foundation is the same three-part logic that governs every PHI-bearing system: a platform capable of compliance, an executed BAA, and configuration that turns capability into fact.

If your telehealth runs inside your EHR's integrated module, much of this is inherited from the EHR relationship — verify the BAA covers the telehealth component and move on. If it's a standalone tool someone chose in 2020, this section is where your review starts.

Session Access Controls: Who's Actually in the Room

A telehealth session is a clinical encounter, and the first question about any encounter is who's present. On video, that's an access-control problem with three specific answers:

One more participant question practices forget: the patient's side. A quick verbal confirmation — "are you somewhere private, is anyone with you" — documented in the note, is both good clinical practice and evidence that privacy was considered.

The Clinician Endpoint: Not the Family Laptop

Here's where telehealth security stops being a platform question and becomes an infrastructure one. The session is encrypted end to end — and then it terminates on a device. If that device is a shared family laptop with no disk encryption, no endpoint protection, a browser full of extensions, and three other household members on the same profile, the encrypted platform was a locked door on an unlocked house.

The defensible standard is practice-managed devices for anyone delivering care remotely: owned or controlled by the practice, disk-encrypted, screen-locked, running the same EDR and patching as the office machines, with MFA on everything that touches practice systems. That's not an exotic ask — it's the same cybersecurity baseline your office endpoints already meet, extended to where care is actually delivered. The gap is rarely technical capability; it's that home devices were grandfathered in during the emergency and nobody ever migrated them.

If truly personal devices must be used, the honest minimum is a managed enrollment profile that enforces encryption and lock policies, with practice data confined to managed apps — and a documented decision that this was chosen deliberately, not by drift.

The Network Between Home and Practice

The clinician's connection is the other half of the remote environment. Raw home Wi-Fi — the router the ISP installed years ago, default admin password, firmware never updated, shared with smart TVs and teenagers' devices — is nobody's idea of a clinical network.

The current expectation is a VPN or zero-trust access path back to practice systems: the EHR, file shares, and internal tools reached through an authenticated, encrypted channel that doesn't care how sketchy the underlying network is. Zero-trust patterns — where each application checks identity and device health per session — are increasingly the cleaner fit for hybrid care, because they protect the specific connections that matter without routing a patient's video stream through the office and back.

The point isn't the acronym; it's that "the clinician's home internet" should never be the security boundary. If your remote-access story is "they just log in from home," the network section of your next risk assessment already has its first finding.

Recordings: The Highest-Sensitivity PHI You Might Be Creating

Decide your recording policy on purpose, because a recorded telehealth session is about as sensitive as PHI gets — a patient, on camera, discussing their condition.

If you record — for documentation, training, or quality — then recordings need the full treatment: a defined storage location under your control (not a clinician's laptop downloads folder, not the platform's default cloud bucket unexamined), encryption, access limited to roles that need it, a retention rule, and patient awareness of the recording. If recordings feed the chart, they're part of the designated record set, with everything that implies.

For many practices, the cleanest position is a written policy of not recording, enforced in platform settings — recording disabled at the tenant level, so the policy isn't one distracted click from being violated. Either answer can be right; having no answer is the only wrong one.

Your Risk Assessment Just Got Bigger

Now the section that ties it together, because every requirement above shares one root: telehealth expanded your environment, and your security risk assessment has to expand with it. The SRA that inventories the office — server closet, workstations, Wi-Fi — but says nothing about twelve clinicians delivering care from twelve homes is describing an environment you no longer operate. And this isn't a theoretical gap: remote setups have become a standard line of audit inquiry, precisely because so few practices updated their assessments after 2020. Auditors have noticed the lag; being on the wrong side of it is a bad place to be.

Concretely, your SRA's inventory phase now includes: who delivers care remotely, from where, on what device, over what connection, into which systems, with what session and recording settings. Each of those is an asset or a data flow; each gets the same threat-and-safeguard analysis as anything in the building. If you're using our step-by-step SRA walkthrough, this is a straightforward extension — the remote-work rows join the same inventory tables, and adopting telehealth is exactly the kind of material change that triggers a reassessment outside the annual cycle.

Where Hybrid Care Creates the Gaps

The pattern we see most in assessments isn't practices that ignored all of this — it's practices that solved it in the office and improvised it at home. The in-office telehealth cart is properly configured on the managed network; the same clinician's Tuesday-from-home sessions run on a personal laptop over house Wi-Fi with a reused meeting room. Same clinician, same patients, same platform — two entirely different security postures, and the audit finding lives in the second one.

Hybrid care also multiplies the front-of-house workflows around the visit: scheduling, reminders, intake, the "your clinician is running late" call. Each is a PHI-bearing channel with its own rules, and increasingly some of it is automated — practices adopting AI phone and front-desk automation should hold those tools to the same platform-BAA-configuration test as the video visit itself; Talos Automation's guide to AI voice agents for medical practices covers what compliant automation of those workflows looks like. The visit is one node in a workflow; secure the workflow.

The Practice-Readiness Checklist

Walk this list and mark each line done, scheduled, or documented-as-not-applicable:

Platform

Sessions

Endpoints

Network

Recordings

Risk assessment

Where This Lands

None of this is exotic security. It's the same discipline described in the full HIPAA guide — inventory what touches PHI, put agreements and controls around it, document that you did — applied to the fact that "what touches PHI" now includes living rooms. The practices that struggle aren't short on technology; they're running 2020 decisions in a 2026 enforcement environment.

This is daily work for our healthcare IT practice: we assess telehealth setups as part of the broader risk assessment, close the endpoint and network gaps, and leave the documentation an auditor asks for. If your telehealth stack hasn't had a hard look since the exemption era, the checklist above is the look — run it yourself, or run it with us.

Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.

Frequently Asked Questions

Can we still use Zoom or FaceTime for telehealth visits?

Not the consumer versions. Enforcement discretion for consumer video tools ended in 2023; telehealth now requires an encrypted platform under a signed BAA, which consumer FaceTime and personal Zoom accounts don't offer. Healthcare-grade tiers can qualify — with the BAA actually executed and the tenant configured, not just purchased.

What does HIPAA require for telehealth in 2026?

An encrypted platform with an executed BAA, session access controls (waiting rooms, authenticated per-visit links, no reusable or guessable URLs), practice-managed and secured clinician devices, VPN or zero-trust network access for remote work, a deliberate recording policy, and a security risk assessment whose scope covers every remote setup used to deliver care.

Do clinicians need practice-managed devices for telehealth at home?

It's the defensible standard. A shared family laptop offers none of the controls the Security Rule expects — managed encryption, EDR, patching, access separation. Practice-managed, encrypted, screen-locked devices with MFA into practice systems are what auditors expect behind every remote clinician; documented, managed personal-device enrollment is the honest minimum where that's impossible.

Are telehealth session recordings PHI?

Yes — unusually sensitive PHI, since they capture the patient discussing their condition on camera. Recording requires a controlled storage location, encryption, role-based access, a retention rule, and patient awareness. Many practices' cleanest answer is a written no-recording policy enforced by disabling recording in platform settings.

Does our risk assessment need to cover clinicians' home offices?

Yes. Home setups used for care delivery are part of your environment — devices, connections, and household context included — and an SRA that still describes only the office is incomplete on its face. Inventory who delivers care from where, on what, over what connection, and give those rows the same analysis as everything in the building. Auditors are asking.

About the Author

Scott McAuley is a Marine Corps veteran and 25-year IT executive. He is President & CEO of Texas Management Group, founder of Talos Automation, and creator of Talk Is Cheap, and was named IT Services CEO of the Year 2023. Full bio at scottmcauley.com →