<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=6627804&amp;fmt=gif">

HIPAA and Telehealth Video: What Changed When Enforcement Discretion Ended

Ben Morrison
Post by Ben Morrison
September 18, 2026
HIPAA and Telehealth Video: What Changed When Enforcement Discretion Ended

The HIPAA enforcement discretion that let providers use consumer video apps for telehealth expired on August 9, 2023. It ran out at the close of a 90-day transition period. Since that date, the same HIPAA rules apply to telehealth video. They are the Privacy, Security, and Breach Notification Rules that were in force before the public health emergency.

The key detail is what expired. The rules did not change during the pandemic. What changed was one choice at the Office for Civil Rights. It would not enforce those rules against providers who used noncompliant tools in good faith. That choice ended. The rules never went anywhere.

Many practices still run telehealth on tools they picked in 2020. Those conditions no longer exist. This article sets out what HHS asks for now. It links each primary source.

Key Takeaways

  • The telehealth enforcement discretion ended August 9, 2023, after a 90-day transition period announced in April 2023.
  • What expired was enforcement discretion, not a rule change. The underlying HIPAA rules were never suspended.
  • A video platform is not HIPAA compliant on its own. Compliance depends on a business associate agreement, the right settings, and how the covered entity uses it.
  • Audio-only telehealth is telehealth. HHS has its own guidance for it. That puts the phone system inside the telehealth compliance picture.
  • Practices still using consumer apps chosen in 2020 are working under rules that expired three years ago.

What HHS actually did, in sequence

March 2020. OCR issued a Notification of Enforcement Discretion for Telehealth Remote Communications. It said OCR would not impose penalties for noncompliance with HIPAA rules. That shield covered health care providers who used non-public-facing remote communication tools in good faith. It applied to telehealth during the emergency.

That notice named consumer apps as tools that would not draw enforcement. It also flagged a limit. Public-facing platforms, such as live streaming services, stayed outside the shield.

April 2023. OCR announced the end of the COVID-19 public health emergency notifications of enforcement discretion. It set a 90-day transition period. The notice appears in the Federal Register as document 2023-07824.

August 9, 2023. The transition period ended. From that date, the ordinary HIPAA rules apply to telehealth without exception.

OCR's own framing is the line worth quoting. Some people think the rules loosened and then tightened. The rules stayed the same throughout. What OCR suspended was its own choice to enforce them.

One point gets lost. Enforcement discretion was never a safe harbor for later years. It only covered the window it named. A practice that leaned on it in 2021 has no cover for a visit held today. The tool can be the same one. The date is what counts.

Current HHS guidance on the subject lives on the HIPAA and Telehealth page.

What "HIPAA compliant video" actually means

No video platform is HIPAA compliant as a property of the software. Compliance is a state of the covered entity's practice. The platform is one input to it.

Three things have to be true.

A business associate agreement is in place, and it covers the service in use. HHS specifies what a business associate contract must contain. The list runs long. It names permitted uses and disclosures, required safeguards, breach reporting, and access to records for the Secretary. It also covers what happens to protected health information once the contract ends.

A signed agreement with a vendor has limits. It may not cover each product that vendor sells. Ask which services it names.

Here is where practices get caught. A group signs one agreement for a video product. A year later it turns on the same vendor's voicemail service. Nobody goes back to the paper. The new service was never named in it.

The platform is set up correctly. Recording defaults and retention periods are settings you choose. So are waiting room behavior, checks on who joins, and access controls. Set up with no care, a compliant platform causes a breach. A noncompliant one does the same.

Daily use matches the safeguards. A session held in a shared space is a problem no vendor setting prevents. So is one joined from an unsecured personal device. So is one recorded without an authorized purpose.

In practice, a vendor can supply two of the three. The third belongs to the practice.

panterra-hipaa-compliant-video-conferencing-requirements

The audio-only telehealth connection most practices miss

Audio-only telehealth is telehealth. HHS has issued its own guidance on audio-only telehealth. That guidance tracks the Privacy, Security, and Breach Notification Rules. It sits with the HHS OCR telehealth resources.

That has a result most practices have not worked through. If audio-only telehealth is a covered service, it runs on the phone system. Which puts the phone system inside the telehealth compliance picture, not next to it.

The questions that follow are concrete:

  1. Is voice named in the business associate agreement with your phone provider?
  2. Does that agreement name voicemail and call recording on their own? Or does everyone just assume they count?
  3. If a provider takes a telehealth visit by phone and records it, where does the recording live? Who can pull it back? Under what retention rule?

Most practices have a video vendor they have checked. They also have a phone vendor they have not. The second one now carries clinical traffic.

Voice is the quiet part of this. A practice buys a phone system for the front desk. Then a provider starts taking visits on it, and nobody reopens the contract.

What to do if you are still on a tool chosen in 2020

This is a short exercise, done in order. It does not need a project.

  1. Step 1. List each tool you now use for a clinical encounter. Include video platforms and phone lines. Include voicemail and any messaging used with patients. Include the shadow tools, because they are the risk.
  2. Step 2. For each tool, ask whether a business associate agreement exists. Not whether the vendor "supports HIPAA." Whether a signed agreement exists and which services it names.
  3. Step 3. For anything without an agreement, decide: replace or execute one. Some consumer platforms offer a compliant tier with an agreement. Some do not offer one at all. The answer sets the path.
  4. Step 4. Write down the settings you chose. Recording defaults, retention, and access control, on paper. This is what an auditor asks for and what nobody has.
  5. Step 5. Re-check the phone system. Because of the audio-only point above, this is the step people skip most often. It is also the one most likely to matter.

One practice can work through all five steps in an afternoon. A group with ten sites will need a week. Most of that week goes to tracking down who signed what.

Nothing here needs a large budget. It needs an inventory, which is a different problem.

panterra-hipaa-compliant-video-conferencing-timeline

A note on messaging

Text messaging deserves a direct statement. Vendor marketing here is often misleading.

SMS is not compliant with HIPAA on its own, on any platform. Standard text messaging crosses carrier networks. Those networks sit outside the covered entity's control. They sit outside any business associate relationship too. Some vendors call SMS HIPAA compliant. They are dressing up a limit of the transport as a product feature.

That is not a criticism of any one vendor. It is a property of the transport. Practices that need to reach patients in writing should ask three things. What is the exact mechanism? What does the agreement name? What consent does it rest on? A compliance label on a messaging feature answers none of that. Patients still expect a text back. The workable answer is a path the practice can name and defend, not a ban that nobody follows.

Related reading

Three pieces that pick up where this one stops — same audience, adjacent decision.

What a Healthcare Contact Center Actually Does · Behavioral Health Practices and Communication Confidentiality · Running Phones for 11 Clinics With a Team of Two

Frequently Asked Questions

Is FaceTime HIPAA compliant for telehealth?

Consumer video applications were permitted under enforcement discretion during the public health emergency. That discretion ended August 9, 2023. Without a business associate agreement covering the service, use for telehealth is not consistent with HIPAA requirements.

When did the telehealth enforcement discretion end?

August 9, 2023, at the end of a 90-day transition period. OCR announced the expiration in April 2023 and it was published in the Federal Register as document 2023-07824.

Did HIPAA rules change for telehealth?

No. The rules stayed the same throughout. What OCR suspended, and later restored, was enforcement against providers using noncompliant tools in good faith during the emergency.

Does audio-only telehealth require a business associate agreement?

HHS has issued specific guidance on conducting audio-only telehealth consistent with the HIPAA Rules. Where a communications vendor handles protected health information, a business associate contract with the provisions HHS specifies applies. Confirm which services your agreement names.

What makes a video platform HIPAA compliant?

Nothing about the platform alone. Compliance requires an executed business associate agreement covering the service, appropriate configuration of recording, retention, and access controls, and clinical use consistent with those safeguards.

Is SMS HIPAA compliant?

Standard SMS is not inherently compliant on any platform, because the transport crosses networks outside a business associate relationship. Confirm the specific mechanism and agreement rather than relying on a vendor compliance label.

Quick Answers

  • Enforcement discretion ended: August 9, 2023.
  • What expired: the choice not to enforce, not the rules themselves.
  • A compliant video platform needs: a business associate agreement naming the service, the right settings, and clinical practice that matches.
  • Audio-only telehealth is telehealth, which puts the phone system inside the compliance picture.
  • SMS is not inherently HIPAA compliant on any platform.
Ben Morrison
Post by Ben Morrison
September 18, 2026
Ben Morrison leads marketing at PanTerra Networks, where he focuses on how businesses research, evaluate, and buy cloud communications technology. He has spent more than 20 years in technology marketing, working with UCaaS providers, IT channel partners, and enterprise technology companies. His work covers growth marketing, demand generation, and channel strategy across the UCaaS and IT services industries. He began his career in telecommunications at Qwest Communications. Ben writes about the buying decisions behind business communications: what platforms cost, how to compare them, and which questions matter before a contract is signed.

Comments