Compliance & risk

HIPAA-compliant telehealth for independent practices

Post-PHE, telehealth must run on a HIPAA-compliant platform with a signed BAA. The OCR enforcement discretion for consumer video tools ended in 2023. Non-compliant use (FaceTime, personal Zoom, WhatsApp) is now enforceable. Native EHR video or a purpose-built telehealth platform is the safe choice.

By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology

Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.

This guide covers the post-PHE compliance requirements for independent practice telehealth in 2026.

Platform requirements

  • HIPAA-compliant platform with signed BAA
  • End-to-end encryption or transport-layer encryption confirmed
  • Audit logging of session start/end
  • Access controls (unique login, MFA)
  • Recording only with explicit patient consent + secure storage

Patient workflow

  • Written consent for telehealth on file
  • Verify patient identity at start of visit
  • Confirm patient location for licensure + billing
  • Document visit type appropriately (audio-only vs video)
  • Post-visit summary to patient portal or secure message

State licensure

The provider must be licensed in the state where the patient is physically located at the time of the visit. Interstate Medical Licensure Compact (IMLC) simplifies this in participating states. Confirm state before every visit — patients traveling across state lines are a common compliance trap.

Billing and coding

Post-2024, most payers have codified telehealth coverage but rules vary — modifier 95, place of service 10 (home) vs 02 (elsewhere), and audio-only telephone codes. Confirm each major payer's current policy annually.

Related buyer guide

Deeper vendor evaluation: ehr