A telehealth visit can be both private and HIPAA compliant, but it's worth knowing what those terms actually mean.
HIPAA compliance means that, if your healthcare provider is a covered entity under U.S. law, they are responsible for protecting your health information. This generally includes:
- Using technology with appropriate security safeguards (such as encryption).
- Limiting who can access your medical information.
- Having policies for handling and storing your health information.
- In many cases, having a signed Business Associate Agreement (BAA) with the telehealth platform if it handles protected health information on the provider's behalf.
As a patient, here are practical ways to improve your privacy:
- Ask what platform they're using. It's reasonable to ask whether the telehealth service is HIPAA compliant and whether it's intended for medical use.
- Join from a private location. Choose a room where others can't overhear your conversation.
- Use a secure internet connection. Your home Wi-Fi is generally preferable to public Wi-Fi. If you must use public Wi-Fi, consider using your cellular data instead.
- Protect your device. Keep your phone, tablet, or computer updated, use a screen lock, and avoid sharing the device during your appointment.
- Check who's present. At the beginning of the visit, you can ask the clinician to identify anyone else in the room and let them know if someone is with you.
- Ask about recording. If the visit will be recorded, your provider should explain why and how the recording will be used and stored. You can also ask whether the visit is being recorded if you're unsure.
- Review the provider's privacy notice. It should explain how your health information is used and protected.
Some questions you can ask your provider before the visit include:
- "Is this telehealth platform HIPAA compliant?"
- "Is the video session encrypted?"
- "Will this visit be recorded?"
- "Who will have access to my information?"
- "How are my medical records and video data stored?"
One thing to keep in mind is that no online system can guarantee absolute security. Even well-designed healthcare systems carry some risk. HIPAA compliance means appropriate safeguards are in place to reduce those risks and protect your information, not that breaches are impossible.
If your appointment is with a healthcare provider outside the United States, HIPAA may not apply. In that case, ask what privacy laws or regulations govern your visit and how your information is protected.