In March 2020, a solo family physician who had never conducted a video visit was, within a matter of weeks, seeing most of her patient panel over whatever video tool she could get working. A cardiology group that had piloted telehealth with a handful of patients a year earlier was suddenly running dozens of virtual visits a day. Across the country, practices that had spent years cautiously evaluating “HIPAA-compliant” video platforms skipped straight to whatever was already installed on a patient’s phone — FaceTime, Skype, whatever worked. That compressed timeline is the defining fact of telehealth in 2020: adoption that might have unfolded over several years happened in a matter of weeks, and security and privacy planning had to catch up after the fact rather than before.

Federal utilization data later documented Medicare telehealth use climbing more than a hundredfold from its pre-pandemic weekly baseline by late April 2020, and state Medicaid programs reported similarly steep increases. That surge was necessary and, for many patients, the only way to safely access care during a public health emergency. It also created a set of security and privacy questions that practices are now working through in real time: which video tools are acceptable, how protected health information (PHI) is exposed on home networks and personal devices, and what “compliant” telehealth actually requires once the emergency-era flexibilities eventually end.

This article lays out where things stand as of mid-2020: what the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has said about enforcement during the COVID-19 public health emergency, where the real security exposure sits in a typical video visit, and what practices should weigh when selecting or continuing to use a telehealth platform. It is general background information, not legal, compliance, or medical advice — organizations should consult qualified counsel or a compliance professional for guidance specific to their situation.

OCR’s Notification of Enforcement Discretion

On March 17, 2020, OCR announced that, effective immediately, it would exercise enforcement discretion and not impose penalties for noncompliance with the HIPAA Privacy, Security, and Breach Notification Rules against covered health care providers in connection with the good-faith provision of telehealth during the COVID-19 nationwide public health emergency. HHS published the formal notification in the Federal Register on April 21, 2020, and posted accompanying FAQs on HHS.gov.

What the discretion actually covers

A few points from OCR’s own guidance are worth stating precisely, because “HIPAA doesn’t apply to telehealth right now” is not an accurate summary of the policy:

  • The discretion applies only to covered health care providers, and only to the good-faith provision of telehealth. It does not create a blanket exemption from HIPAA, and OCR has been explicit that it can still pursue cases that are not good faith.
  • It applies to telehealth for any medical purpose, not only COVID-19-related care — a routine follow-up visit conducted over video during the emergency falls under the same discretion as a visit related to potential COVID-19 symptoms.
  • OCR named non-public-facing video communication applications — including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, Zoom, and Skype — as products a provider could use in good faith without risking a penalty for the underlying technology’s lack of a signed business associate agreement (BAA) or other typical HIPAA safeguards.
  • OCR was equally explicit about what remains off-limits: public-facing platforms such as Facebook Live, Twitch, TikTok, and similar applications should not be used for telehealth, because they are designed for public broadcast rather than private communication.
  • The discretion is tied to the duration of the declared public health emergency. OCR’s FAQs note it will end when the Secretary of HHS declares the emergency over (or lets the declaration expire), at which point normal HIPAA enforcement resumes.

What this does not change

The enforcement discretion is a statement about how OCR will exercise its penalty authority during an emergency — it is not a redesign of the underlying Security Rule. The obligation to conduct a risk analysis, apply reasonable safeguards, and protect ePHI in transit and at rest still describes the standard providers are expected to work toward, even while OCR has said it won’t penalize good-faith gaps tied specifically to the sudden switch to remote care. Providers that can obtain a HIPAA-compliant video platform and BAA quickly are still better positioned than those relying indefinitely on personal consumer apps, and OCR’s own FAQ material encourages providers to notify patients of the privacy risks associated with third-party apps and to enable any available encryption and privacy settings.

Where the Security Risk Actually Lives in a Video Visit

“Telehealth security” tends to get discussed as if the video call itself were the whole picture. In practice, the exposure runs across several distinct layers, and a platform that handles one layer well may still leave others open.

The transmission channel

This is the layer OCR’s guidance focuses on most directly: is the audio/video stream encrypted between the two endpoints, and could it be intercepted in transit? Most mainstream video platforms — including the consumer apps named in OCR’s notification — use some form of transport encryption by default. The bigger practical risk at this layer is less about cryptography and more about who else is on the call: a misconfigured “waiting room” or an easily-guessed meeting link can let an uninvited party join a session that was never designed to be public.

The endpoints

A video visit runs on two devices, and neither is guaranteed to be secured to the same standard as equipment inside a clinic. On the provider side, a clinician working from a home laptop may be on a personal device without the endpoint protection, automatic patching, or disk encryption that an IT department would normally enforce on clinic hardware. On the patient side, the device and network are entirely outside the provider’s control — a shared family computer, an unpatched phone, or an open home Wi-Fi network all sit upstream of any privacy protection the video platform itself provides.

The environment

Telehealth also has a physical privacy dimension that has no equivalent in a records system: who else is in the room, on either end of the call, during a sensitive conversation. A clinician taking a call from a shared home office, or a patient discussing a diagnosis from a kitchen table with family members nearby, introduces a form of exposure that has nothing to do with encryption and everything to do with where the visit physically happens.

Storage and downstream data

PHI generated during a telehealth visit doesn’t disappear when the call ends. Recordings (if the platform or provider records visits), chat transcripts, screen-shared documents, and any notes entered into the platform’s own interface all need to be accounted for — including where they’re stored, who can access them, and how long they’re retained. A video platform can be reasonably secure for the live call itself and still create risk if recordings sit in a vendor’s default storage without a clear retention and access policy.

Metadata and the broader environment

Video calls are frequently one piece of a larger digital interaction that also touches scheduling systems, patient portals, e-prescribing tools, and payment processing — each with its own access controls and its own potential points of failure. Evaluating “telehealth security” in isolation from the rest of that stack tends to miss how PHI actually flows through a virtual visit end to end.

Baseline Security Practices for Video Visits

Federal cybersecurity guidance issued during the 2020 shift to remote work — including material from the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) — points to a consistent set of baseline practices that apply directly to telehealth, even though it was written for remote work generally rather than healthcare specifically:

  • Enable meeting-level access controls. Unique meeting IDs or links per visit, waiting rooms, and host-controlled admission reduce the chance of an uninvited participant joining a session.
  • Turn on available encryption settings. Many platforms ship with encryption available but not enabled by default, or with a choice between encryption levels — verifying the setting is on is a five-minute task with an outsized payoff.
  • Patch and update client software. Video conferencing clients, like any other software, receive security fixes; running an outdated client can leave known vulnerabilities exposed on either end of the call.
  • Secure the endpoint, not just the app. Device-level protections — screen locks, disk encryption, current operating system patches, and reputable endpoint protection — matter as much for a telehealth workstation as for any other system that touches PHI.
  • Use organizational rather than personal accounts where possible. A practice-managed account tied to a business associate agreement gives an organization visibility and control that an individual clinician’s personal consumer account does not.
  • Train staff on the human factors. Verifying attendee identity at the start of a call, choosing a private location, and knowing how to end a session if an unauthorized party appears are procedural safeguards that no platform setting can substitute for.

These are consistent with the broader “secure telework” guidance CISA and NIST published as remote work expanded in 2020, and they apply whether the “worker” in question is an employee accessing a corporate network or a clinician conducting a video visit from a home office.

Platform Selection Criteria

For practices evaluating telehealth platforms — whether moving off a stopgap consumer app or choosing among several purpose-built options — a few criteria consistently separate platforms suited for sustained clinical use from those suited only for emergency-era stopgaps.

Willingness to sign a business associate agreement

If a vendor will not sign a BAA, it is not a HIPAA-compliant option for handling PHI, full stop, regardless of what security features it advertises. Many mainstream video platforms offer a healthcare-specific tier that includes a BAA and additional controls (audit logging, admin-managed encryption settings, integration with clinical systems); their general consumer tier typically does not qualify, even though the underlying software may look identical to the end user.

Encryption and access control defaults

Look for platforms where strong defaults — encryption enabled, waiting rooms on, meeting locks available — are the out-of-the-box configuration rather than settings an individual clinician has to remember to enable on every call.

Administrative visibility

A platform intended for ongoing clinical use should give an organization’s administrators the ability to see and manage account-level settings across all users, rather than leaving security configuration up to each individual clinician’s personal account.

Data handling and retention transparency

Vendor documentation should make clear where call data, recordings, and chat logs are stored, how long they’re retained, and what access the vendor’s own staff have to that content.

Integration fit

A platform that integrates cleanly with existing scheduling and documentation workflows reduces the number of separate systems staff have to manage — and, in turn, the number of places PHI has to be manually copied between systems, each of which is its own point of potential exposure.

Independent authority resources

For organizations building out a telehealth security program, both HHS’s telehealth.hhs.gov privacy and security best-practice guide and NIST’s National Cybersecurity Center of Excellence (NCCoE) have published telehealth-specific privacy and security guidance aimed at healthcare delivery organizations, and CISA has published general guidance for securing video conferencing that applies directly to clinical video visits.

The Road Ahead

The current OCR enforcement discretion is explicitly temporary, tied to the COVID-19 public health emergency declaration. Practices that adopted telehealth quickly in 2020 using whatever tools were available should treat this period as a transition rather than a permanent arrangement: moving toward platforms with signed BAAs, organization-managed accounts, and documented security configurations positions a practice to keep offering telehealth on solid footing once emergency-era flexibilities are no longer in effect. The underlying lesson of 2020’s telehealth surge is less about any single platform and more about treating a video visit as what it is — a clinical encounter that happens to run over the internet, carrying the same obligation to protect patient information as any other channel a practice uses.

Frequently Asked Questions

What is OCR’s Notification of Enforcement Discretion for telehealth?

It’s a policy HHS’s Office for Civil Rights announced on March 17, 2020, stating it would not impose HIPAA penalties on covered health care providers for the good-faith provision of telehealth during the COVID-19 public health emergency, including use of certain non-public-facing video apps that otherwise might not meet typical HIPAA safeguards.

Does the enforcement discretion mean HIPAA no longer applies to telehealth?

No. It means OCR has said it won’t penalize good-faith gaps tied to the emergency shift to telehealth, not that HIPAA’s underlying requirements have been suspended. Providers are still expected to apply reasonable safeguards, and the discretion applies only for the duration of the declared public health emergency.

Which video platforms did OCR name as acceptable during the emergency?

OCR’s notification named non-public-facing applications such as Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, Zoom, and Skype as tools providers could use without risking a penalty tied to the platform’s own compliance posture. Public-facing platforms like Facebook Live, Twitch, and TikTok were explicitly excluded because they broadcast publicly rather than communicate privately.

What’s the biggest security risk in a typical telehealth visit?

Risk is distributed across several layers rather than concentrated in one: the transmission channel, the security of each endpoint device, the physical privacy of each participant’s location, and how any recordings or chat logs are stored afterward. A platform that secures the video stream well can still leave PHI exposed through an unpatched endpoint or an unmanaged recording.

What should a practice look for when choosing a telehealth platform?

Key criteria include whether the vendor will sign a business associate agreement, whether strong security settings (encryption, waiting rooms, meeting locks) are enabled by default, whether administrators have organization-wide visibility into account settings, and whether the vendor documents where call data and recordings are stored and for how long.

Where can practices find authoritative telehealth security guidance?

HHS’s telehealth.hhs.gov site, NIST’s National Cybersecurity Center of Excellence, and CISA’s published guidance on securing video conferencing all offer resources aimed specifically at securing remote and virtual-care technology, in addition to OCR’s own HIPAA and telehealth FAQ pages on HHS.gov.