PD Geek

Telehealth Security: What Your Platform's BAA Doesn't Cover

← Back to Blog

THERAPY · Jan 16, 2026 · 5 min read

Zoom Healthcare signed a BAA. You're still not compliant. Here's what telehealth security actually requires beyond the platform.

Telehealth Security: Beyond the Platform BAA

Your telehealth platform signed a BAA. That's necessary but nowhere near sufficient.

What the BAA Actually Covers

When Zoom Healthcare, Doxy.me, or SimplePractice Telehealth provides a BAA, they're promising to:

Protect their infrastructure:

  1. Encrypt video streams
  2. Secure their servers
  3. Control employee access
  4. Maintain audit logs
  5. Report breaches on their end

What they explicitly don't cover:

  1. Your end of the connection
  2. Your waiting room setup
  3. Your documentation practices
  4. Your device security
  5. Who's in the room with you
  6. What happens after the session

The "Both Ends" Problem

Telehealth security requires securing both ends of the connection:

Your Device ←→ Platform Servers ←→ Patient Device

  1. Your Device = Your job
  2. Platform Servers = Their job
  3. Patient Device = Not your job (but you should educate)

The platform secures the middle. You secure your end. The patient secures theirs (with your guidance).

Your End: What Needs Securing

1. Physical environment

Before every session:

☐ Door closed and locked

☐ No one can overhear

☐ No one can see screen

☐ Smart speakers/assistants disabled

☐ Phone notifications silenced

2. Device security

Your telehealth device needs:

☐ Full disk encryption

☐ Updated operating system

☐ Endpoint protection (antivirus)

☐ Auto-lock after 5 minutes

☐ No saved patient data locally

3. Network security

Your connection requires:

☐ Private, secured WiFi (WPA3/WPA2-Enterprise)

☐ No public WiFi ever

☐ Consider wired connection for reliability

☐ VPN if working remotely (hotel, etc.)

4. Account security

Your platform login needs:

☐ Unique, strong password

☐ MFA enabled (always)

☐ Not shared with anyone

☐ Not saved in browser on shared devices

Common Telehealth Security Failures

1. The coffee shop therapist

  1. Working from Starbucks WiFi
  2. Anyone can intercept traffic
  3. Background noise audible to patient
  4. Screen visible to strangers
  5. Violation: Multiple HIPAA sections

2. The family office

  1. Telehealth from home office
  2. Kids walk in during sessions
  3. Spouse can hear through wall
  4. Alexa listening in the corner
  5. Violation: §164.530(c) - Safeguards

3. The shared device

  1. Using family iPad for telehealth
  2. Other family members have access
  3. Browser saves login credentials
  4. Patient info accessible to kids
  5. Violation: §164.312(a) - Access controls

4. The documentation gap

  1. Session happens on Zoom
  2. Notes typed into SimplePractice
  3. No documentation of telehealth-specific consent
  4. No record of identity verification
  5. Violation: §164.530(j) - Documentation

Telehealth-Specific Requirements

Beyond standard HIPAA, telehealth requires:

1. Telehealth-specific consent

  1. Risks unique to video sessions
  2. Technology requirements
  3. Privacy limitations at patient's end
  4. Emergency protocols

2. Identity verification

  1. How do you confirm it's the patient?
  2. What if video is off?
  3. Document your process

3. Location documentation

  1. Where is the patient?
  2. Different state = different laws
  3. Emergency services need to know location

4. Technology troubleshooting plan

  1. What if video fails?
  2. Backup contact method
  3. How to continue session securely

5. Emergency protocols

  1. Patient in crisis via telehealth
  2. How to reach local emergency services
  3. Document patient's physical location

Platform Comparison: What's Actually Included

Feature

Zoom Healthcare

Doxy.me

SimplePractice

BAA

✓

✓

✓

Encryption

✓

✓

✓

Waiting room

✓

✓

✓

Your device security

✗

✗

✗

Your network security

✗

✗

✗

Physical environment

✗

✗

✗

Consent forms

Template

Template

Integrated

Identity verification

Manual

Manual

Manual

Documentation

✗

✗

Integrated

All platforms handle their side. None handle yours.

The Waiting Room Isn't Enough

"But I use a waiting room!"

Waiting rooms prevent:

  1. Patients joining early
  2. Wrong person in session
  3. Session hijacking (Zoombombing)

Waiting rooms don't prevent:

  1. Insecure connections
  2. Compromised devices
  3. Eavesdropping at your end
  4. Lack of documentation

Technical Setup Checklist

Before offering telehealth:

Device Setup:

☐ Dedicated device or user account for telehealth

☐ Full disk encryption enabled

☐ Auto-lock set to 5 minutes

☐ Camera cover for when not in use

☐ Endpoint protection installed and updated

Network Setup:

☐ Private, encrypted WiFi (not shared/public)

☐ Router firmware updated

☐ Guest network separated

☐ Consider wired connection

Platform Setup:

☐ BAA signed and filed

☐ MFA enabled on account

☐ Waiting room enabled

☐ Recording disabled (unless consented)

☐ Screen sharing limited to host

Physical Setup:

☐ Private room with locking door

☐ No line-of-sight to screen from outside

☐ Smart speakers removed or disabled

☐ Sound isolation (white noise, closed windows)

Documentation Requirements

For every telehealth session, document:

  1. Consent obtained (date, method)
  2. Identity verified (how)
  3. Patient location (city, state minimum)
  4. Technology used (platform, version)
  5. Any technical issues (for quality assurance)
  6. Privacy confirmed (patient's environment appropriate)

Patient Education

Your responsibility includes educating patients:

Provide written guidance on:

  1. Using private space for sessions
  2. Avoiding public WiFi
  3. Using headphones
  4. Keeping device updated
  5. What to do if disconnected

Document that you provided this guidance.

The Compliance Reality

Telehealth compliance requires:

Layer

Who's Responsible

Platform servers

Vendor

Platform software

Vendor

Your device

You

Your network

You

Your environment

You

Your documentation

You

Patient education

You

The BAA covers maybe 30% of the compliance picture.

Bottom Line

Your telehealth platform is a tool. Tools don't make you compliant - processes do.

A signed BAA means:

  1. The platform won't be the weak link
  2. You're covered if they get breached
  3. Nothing about your end of the connection

Actual telehealth compliance requires:

  1. Secure device
  2. Secure network
  3. Private environment
  4. Proper documentation
  5. Patient education
  6. And yes, a platform with a BAA

Not sure if your telehealth setup is actually compliant? We help therapy practices secure the entire telehealth workflow, not just the platform. Get Free Assessment

Need Help With Your Practice’s Security?

Free assessment, no obligation, real answers.

Get Free Assessment

(469) 306-9520 • Serving Dallas-Fort Worth

PD Geek is an operating brand of Pleasant Digital, LLC. © 2026 Pleasant Digital, LLC. Contact PD Geek through the Contact page.

Dental Practices · Therapy & Counseling · Churches & Nonprofits · Blog · Privacy Policy · Terms of Service