Compliance & risk
HIPAA-compliant telehealth for independent practices
Post-PHE, telehealth must run on a HIPAA-compliant platform with a signed BAA. The OCR enforcement discretion for consumer video tools ended in 2023. Non-compliant use (FaceTime, personal Zoom, WhatsApp) is now enforceable. Native EHR video or a purpose-built telehealth platform is the safe choice.
By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology
Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.
This guide covers the post-PHE compliance requirements for independent practice telehealth in 2026.
Platform requirements
- HIPAA-compliant platform with signed BAA
- End-to-end encryption or transport-layer encryption confirmed
- Audit logging of session start/end
- Access controls (unique login, MFA)
- Recording only with explicit patient consent + secure storage
Patient workflow
- Written consent for telehealth on file
- Verify patient identity at start of visit
- Confirm patient location for licensure + billing
- Document visit type appropriately (audio-only vs video)
- Post-visit summary to patient portal or secure message
State licensure
The provider must be licensed in the state where the patient is physically located at the time of the visit. Interstate Medical Licensure Compact (IMLC) simplifies this in participating states. Confirm state before every visit — patients traveling across state lines are a common compliance trap.
Billing and coding
Post-2024, most payers have codified telehealth coverage but rules vary — modifier 95, place of service 10 (home) vs 02 (elsewhere), and audio-only telephone codes. Confirm each major payer's current policy annually.
Related buyer guide
Deeper vendor evaluation: ehr →