Telehealth Security: What Your Platform's BAA Doesn't Cover
THERAPY · Jan 16, 2026 · 5 min read
Zoom Healthcare signed a BAA. You're still not compliant. Here's what telehealth security actually requires beyond the platform.
Telehealth Security: Beyond the Platform BAA
Your telehealth platform signed a BAA. That's necessary but nowhere near sufficient.
What the BAA Actually Covers
When Zoom Healthcare, Doxy.me, or SimplePractice Telehealth provides a BAA, they're promising to:
Protect their infrastructure:
- Encrypt video streams
- Secure their servers
- Control employee access
- Maintain audit logs
- Report breaches on their end
What they explicitly don't cover:
- Your end of the connection
- Your waiting room setup
- Your documentation practices
- Your device security
- Who's in the room with you
- What happens after the session
The "Both Ends" Problem
Telehealth security requires securing both ends of the connection:
Your Device ←→ Platform Servers ←→ Patient Device
- Your Device = Your job
- Platform Servers = Their job
- Patient Device = Not your job (but you should educate)
The platform secures the middle. You secure your end. The patient secures theirs (with your guidance).
Your End: What Needs Securing
1. Physical environment
Before every session:
☐ Door closed and locked
☐ No one can overhear
☐ No one can see screen
☐ Smart speakers/assistants disabled
☐ Phone notifications silenced
2. Device security
Your telehealth device needs:
☐ Full disk encryption
☐ Updated operating system
☐ Endpoint protection (antivirus)
☐ Auto-lock after 5 minutes
☐ No saved patient data locally
3. Network security
Your connection requires:
☐ Private, secured WiFi (WPA3/WPA2-Enterprise)
☐ No public WiFi ever
☐ Consider wired connection for reliability
☐ VPN if working remotely (hotel, etc.)
4. Account security
Your platform login needs:
☐ Unique, strong password
☐ MFA enabled (always)
☐ Not shared with anyone
☐ Not saved in browser on shared devices
Common Telehealth Security Failures
1. The coffee shop therapist
- Working from Starbucks WiFi
- Anyone can intercept traffic
- Background noise audible to patient
- Screen visible to strangers
- Violation: Multiple HIPAA sections
2. The family office
- Telehealth from home office
- Kids walk in during sessions
- Spouse can hear through wall
- Alexa listening in the corner
- Violation: §164.530(c) - Safeguards
3. The shared device
- Using family iPad for telehealth
- Other family members have access
- Browser saves login credentials
- Patient info accessible to kids
- Violation: §164.312(a) - Access controls
4. The documentation gap
- Session happens on Zoom
- Notes typed into SimplePractice
- No documentation of telehealth-specific consent
- No record of identity verification
- Violation: §164.530(j) - Documentation
Telehealth-Specific Requirements
Beyond standard HIPAA, telehealth requires:
1. Telehealth-specific consent
- Risks unique to video sessions
- Technology requirements
- Privacy limitations at patient's end
- Emergency protocols
2. Identity verification
- How do you confirm it's the patient?
- What if video is off?
- Document your process
3. Location documentation
- Where is the patient?
- Different state = different laws
- Emergency services need to know location
4. Technology troubleshooting plan
- What if video fails?
- Backup contact method
- How to continue session securely
5. Emergency protocols
- Patient in crisis via telehealth
- How to reach local emergency services
- Document patient's physical location
Platform Comparison: What's Actually Included
Feature | Zoom Healthcare | Doxy.me | SimplePractice |
BAA | ✓ | ✓ | ✓ |
Encryption | ✓ | ✓ | ✓ |
Waiting room | ✓ | ✓ | ✓ |
Your device security | ✗ | ✗ | ✗ |
Your network security | ✗ | ✗ | ✗ |
Physical environment | ✗ | ✗ | ✗ |
Consent forms | Template | Template | Integrated |
Identity verification | Manual | Manual | Manual |
Documentation | ✗ | ✗ | Integrated |
All platforms handle their side. None handle yours.
The Waiting Room Isn't Enough
"But I use a waiting room!"
Waiting rooms prevent:
- Patients joining early
- Wrong person in session
- Session hijacking (Zoombombing)
Waiting rooms don't prevent:
- Insecure connections
- Compromised devices
- Eavesdropping at your end
- Lack of documentation
Technical Setup Checklist
Before offering telehealth:
Device Setup:
☐ Dedicated device or user account for telehealth
☐ Full disk encryption enabled
☐ Auto-lock set to 5 minutes
☐ Camera cover for when not in use
☐ Endpoint protection installed and updated
Network Setup:
☐ Private, encrypted WiFi (not shared/public)
☐ Router firmware updated
☐ Guest network separated
☐ Consider wired connection
Platform Setup:
☐ BAA signed and filed
☐ MFA enabled on account
☐ Waiting room enabled
☐ Recording disabled (unless consented)
☐ Screen sharing limited to host
Physical Setup:
☐ Private room with locking door
☐ No line-of-sight to screen from outside
☐ Smart speakers removed or disabled
☐ Sound isolation (white noise, closed windows)
Documentation Requirements
For every telehealth session, document:
- Consent obtained (date, method)
- Identity verified (how)
- Patient location (city, state minimum)
- Technology used (platform, version)
- Any technical issues (for quality assurance)
- Privacy confirmed (patient's environment appropriate)
Patient Education
Your responsibility includes educating patients:
Provide written guidance on:
- Using private space for sessions
- Avoiding public WiFi
- Using headphones
- Keeping device updated
- What to do if disconnected
Document that you provided this guidance.
The Compliance Reality
Telehealth compliance requires:
Layer | Who's Responsible |
Platform servers | Vendor |
Platform software | Vendor |
Your device | You |
Your network | You |
Your environment | You |
Your documentation | You |
Patient education | You |
The BAA covers maybe 30% of the compliance picture.
Bottom Line
Your telehealth platform is a tool. Tools don't make you compliant - processes do.
A signed BAA means:
- The platform won't be the weak link
- You're covered if they get breached
- Nothing about your end of the connection
Actual telehealth compliance requires:
- Secure device
- Secure network
- Private environment
- Proper documentation
- Patient education
- And yes, a platform with a BAA
Not sure if your telehealth setup is actually compliant? We help therapy practices secure the entire telehealth workflow, not just the platform. Get Free Assessment
Need Help With Your Practice’s Security?
Free assessment, no obligation, real answers.
(469) 306-9520 • Serving Dallas-Fort Worth