Short answer: Yes. Telehealth providers are covered entities under HIPAA in exactly the same way as any in-person medical practice — the mode of delivering care doesn't change the underlying obligation. What changes is the specific risk profile: telehealth introduces video platform vendors that need their own Business Associate Agreements, and care happening outside a controlled clinical environment, both of which need to be addressed directly in your risk assessment and policies.
The baseline obligation doesn't change
If you're providing clinical care and transmitting health information electronically for billing or other standard transactions, you're covered, whether that care happens in an exam room or over video. Telehealth doesn't create an exception to HIPAA; it adds specific new places where PHI moves that a traditional in-person practice doesn't have to think about in the same way.
What's specifically different about telehealth compliance
Your video platform needs a BAA. Not every video conferencing tool is built or configured to handle PHI appropriately, and using a platform without a signed Business Associate Agreement in place is a direct compliance gap, regardless of how secure the platform seems in general use. This is one of the most common gaps in telehealth practices — using a familiar consumer video tool without confirming its HIPAA posture first.
The session itself happens in an uncontrolled environment. In a clinical office, you control the physical space. In a telehealth session, the patient could be in a car, a shared living space, or anywhere with an internet connection — and your own staff conducting a session need clear guidance on things like ensuring they're in a private space themselves and confirming the patient understands the privacy limitations of wherever they're calling from.
Recordings, if made, need their own handling policy. If sessions are recorded for any reason, that recording is PHI and needs the same protections, storage security, and retention policy as any other patient record.
Cross-state practice can raise separate licensing considerations. This isn't a HIPAA issue specifically, but it often comes up in the same conversation — providing telehealth care to a patient in a different state can raise its own licensing questions independent of, but often discussed alongside, HIPAA compliance.
What a telehealth-specific risk assessment should cover
Beyond the standard risk assessment components, a telehealth practice should specifically evaluate: which video platform is used and whether it's covered by a BAA, how session data and any recordings are stored, what guidance staff have for conducting sessions privately and securely, and how patient identity is verified at the start of a virtual visit.
Getting this right for your practice
If you provide telehealth services, in whole or as part of a hybrid practice, and want a clear picture of where your specific setup stands, Truvidence's free risk assessment accounts for telehealth-specific factors like video platform coverage and remote session handling, not just the standard in-office checklist.