Skip to main content
Compliance 4 min read

A HIPAA Compliance Checklist for Telehealth Practices

No platform can make your practice HIPAA compliant on its own. Here is what the software is responsible for, what you remain responsible for, and how to tell the difference.

By The Blink Session Team · Updated August 3, 2026

This article is general information for practice owners, not legal advice. HIPAA obligations depend on your organisation and your circumstances, and state law adds requirements on top of the federal floor. Consult a qualified attorney or compliance professional about your specific situation.

The most common misconception in telehealth compliance is the phrase "HIPAA compliant software." Software can provide safeguards that make compliance achievable. It cannot be compliant on your behalf, because most of what HIPAA requires is about your organisation's conduct, not your vendor's feature list.

Splitting the responsibility explicitly is the fastest way to find your actual gaps.

What your platform should provide

Treat these as requirements when evaluating any telehealth vendor:

  • A Business Associate Agreement. Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and you need an executed BAA with them. A vendor unwilling to sign one cannot be used for PHI. Consumer video tools generally fall in this category.
  • Encryption in transit and at rest. Session traffic and stored data should both be encrypted.
  • Access controls. Unique accounts per person, no shared logins, and permissions scoped by role so a scheduler cannot browse clinical records.
  • Audit logging. A record of who accessed what and when, which you will need if you ever have to investigate an incident.
  • A waiting room or equivalent. Nobody should be able to walk into a session unannounced.
  • Clear data retention and deletion behaviour. You should know how long data persists and how it is removed.

What remains yours

This is the longer list, and the one practices tend to neglect:

Administrative safeguards

  • A documented risk analysis, kept current rather than done once.
  • Written policies and procedures covering how your practice handles PHI.
  • Workforce training, delivered and documented, including for contractors.
  • A designated privacy and security official. In a small practice this is usually the owner, and that is fine, but it needs naming.
  • A breach notification procedure written before you need it.
  • BAAs with every other vendor that touches PHI: your EHR, your billing service, your cloud storage, your transcription tool.

Physical safeguards

  • A private space for sessions where conversations cannot be overheard. This includes your own home office if you work remotely.
  • Device security: full-disk encryption, screen locks, and no PHI on unencrypted personal devices.
  • Secure disposal of anything physical, including printed notes and old hardware.

Technical practice

  • Strong unique passwords and multi-factor authentication wherever offered.
  • Working over a secured network, not open public Wi-Fi.
  • Prompt removal of access when someone leaves.

Telehealth-specific issues worth attention

Session recording consent. Recording a therapy session requires informed consent from the client or their legal guardian, documented before you record. State wiretapping law adds a separate layer here: several states require every participant to consent, not just one. Confirm the rules for your state and the client's state, since in telehealth those may differ.

The client's own environment. You cannot control whether a client takes a counseling session in a room with other people present, but you can raise it. Ask at intake whether they have private space, and address it directly when they do not.

Cross-state licensure. Not a HIPAA issue, but it sits in the same bucket of things telehealth practices get wrong. You generally need to be licensed where the client is located at the time of service. Verify before treating anyone across a state line.

Identity verification. Have a documented approach to confirming you are speaking with the person you believe you are, particularly for a first appointment.

Minimum necessary. Share only the PHI a given task requires. Screen sharing is a frequent offender: sharing an entire desktop with another client's chart visible in a window is a disclosure. Share a single application instead.

A reasonable order to work through this

  1. Execute BAAs with every vendor touching PHI, starting with your telehealth platform.
  2. Complete a written risk analysis and keep it current.
  3. Write your policies, then actually train your team on them and record that you did.
  4. Fix the physical layer: private space, device encryption, screen locks.
  5. Enable multi-factor authentication and remove shared logins.
  6. Write your breach notification and incident response procedure.
  7. Document your recording consent process, if you record at all.
  8. Set a recurring calendar reminder to review the whole thing annually.

Compliance is a continuing practice rather than a project with an end date. A practice that has done the work above and reviews it yearly is in a substantially better position than one that bought software described as HIPAA compliant and assumed the problem was handled.

Run this on a platform built for therapy

Blink Session gives you interactive materials, secure video, scheduling, and documentation in one place.

Is Zoom HIPAA Compliant?

Zoom's free and standard paid plans are not HIPAA compliant, and the healthcare plan is a separate p...