Telehealth ABA: the enforcement pass expired and nobody told you
The COVID-era permission to use FaceTime and consumer Zoom for telehealth ended in 2023. What the ordinary rules require now, what to ask your platform, and the half of the session you do not control.
Last verified: 2026-07-12
In March 2020, OCR announced it would not impose penalties for good-faith use of everyday communication technologies for telehealth. Clinics moved onto FaceTime and consumer Zoom in a weekend, kept children in services, and did the right thing under impossible conditions.
That notification of enforcement discretion ended in 2023. The rules did not change during the pandemic. Enforcement of them paused, and then it resumed, and a lot of clinics never noticed the second half. If your telehealth setup was assembled in 2020 and has not been revisited, it was built under a permission that no longer exists.
Here is what the ordinary rules actually require, which is less than people fear and more than most clinics currently do.
“The rules did not change during the pandemic. Enforcement of them paused, and then it resumed, and a lot of clinics never noticed the second half.”
The platform is a vendor, and the vendor needs paper
A telehealth platform transmits the session, and usually stores something: chat, recordings, scheduling data, sometimes clinical notes. That makes it a business associate (45 CFR 160.103), and you may disclose PHI to it only under a signed BAA (45 CFR 164.308(b)). No exception exists for video, and none ever did; during the discretion period OCR simply chose not to penalize the gap.
The practical translation is a procurement rule, not a philosophy: the tier matters. Consumer tiers of general video products typically do not sign BAAs. Healthcare or enterprise tiers of the same products typically do, sometimes only on request or on a specific plan. A product that will not sign is telling you its product is not for PHI. There is no configuration that fixes that, and “we turned on end-to-end encryption” does not substitute for the contract, because the badge is not the instrument.
Transmission itself has to be protected (45 CFR 164.312(e)): encryption in transit is addressable in name and unavoidable in practice, and every credible platform provides it. Ask for it in writing anyway, along with where the data is stored and how long they keep it.
The recording is the part that bites
A recorded telehealth session is the single most sensitive artifact your clinic produces: a child’s face, a family’s voice, a home’s interior, and a clinical conversation, all in one file that cannot be meaningfully de-identified.
Everything in session recordings applies here with extra force, because telehealth makes recording frictionless. One click, and the file lands wherever the platform puts it by default, or on the clinician’s laptop. The rules are the same: recording goes to a BAA-covered destination, never a personal drive or a camera roll; access is by role; retention is a decision you make and enforce; and consent is written, specific, and obtained before the camera runs. If the recording is destined for anything beyond treatment, payment, or operations (training, a conference talk, marketing), that requires an authorization, not the intake consent.
Your side of the call
Telehealth turns wherever the clinician sits into a workstation, and 45 CFR 164.310(b) and (c) apply to it:
The room. Sessions happen where they cannot be overheard, and screens face away from doors and windows. This is the whole reason a home-office policy exists: a BCBA conducting a session from a kitchen with a spouse working at the table has created an incidental disclosure problem that no encryption addresses.
The device. Encrypted, auto-locking, work profile if it is personal, no session content stored locally.
The connection. Home wifi is generally fine when the platform encrypts the session, which every serious one does. Public wifi at a coffee shop is not a place from which to run a child’s therapy session, and that deserves to be a stated rule rather than an assumed one.
The waiting room. Use the platform’s virtual waiting room and admit clients deliberately. A family dropping into a session where the previous family is still on screen is a disclosure, and it is an entirely preventable one.
Their side of the call, which is not yours
Here is the reassurance clinics need and rarely hear: you are not responsible for the family’s environment. HIPAA governs you and your business associates. It does not reach into a parent’s living room, does not require you to secure their wifi, and does not make you liable because a sibling wandered through the frame.
What you owe them is candor. Tell families, in writing, at the start of telehealth: sessions are private on our side, we cannot control who is present or who can overhear on your side, here is what we recommend (a quiet room, headphones, a device only you use), and here is how to tell us if that is not possible. Then document that you told them. The Privacy Rule’s tolerance for incidental disclosures (45 CFR 164.502(a)(1)(iii)) assumes you applied reasonable safeguards, and the reasonable safeguard on the family’s side is exactly this: information, offered honestly, and a way to raise a problem.
A note that matters more in ABA than in most specialties: some families are in conflict, and some are unsafe. A parent who asks to have telehealth sessions at a particular time, or through a particular device, or without the other parent’s knowledge, may be making a confidential communications request (45 CFR 164.522(b)), and you must accommodate reasonable requests. Build a way for that request to be made quietly.
The ten-minute audit
Three questions. Do you have a signed BAA from your telehealth platform, and can you produce it today? Where do recordings land right now, by default, and who can reach them? And when was your telehealth policy last written, as opposed to last assumed?
If the answers point back to a decision made in a scramble in 2020, that is not a failure; it was the correct decision then. It is simply a decision that has outlived the rule that permitted it, and revisiting it is an afternoon’s work.
The short version
- OCR's telehealth enforcement discretion, which allowed everyday video apps, ended in 2023; the ordinary Security Rule requirements apply and always did.
- Your telehealth platform receives and often stores PHI, which makes it a business associate that needs a signed BAA.
- The consumer tier of a video product generally will not sign a BAA; the healthcare or business tier usually will, and that is your procurement answer.
- Recording a telehealth session creates the most sensitive artifact you hold, and it has to land in a BAA-covered system, not a laptop or a camera roll.
- You cannot control the family's side of the call, and you are not required to, but you should say so plainly and document that you did.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Transmission security45 CFR 164.312(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Definitions, including business associate45 CFR 160.103https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Business associate contracts, Security Rule45 CFR 164.308(b)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Workstation use and workstation security45 CFR 164.310(b) and (c)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310
- Uses and disclosures: general rules, including incidental disclosures45 CFR 164.502https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- HHS telehealth and HIPAA guidanceHHS.gov, Office for Civil Rightshttps://www.hhs.gov/hipaa/for-professionals/special-topics/telehealth/index.html
The platform, the recording, and the room.
Telehealth touches three things at once: a vendor, an artifact, and a workstation in someone's home. WiseUpHIPAA holds the BAAs, the retention decisions, and the policies behind them, and shows you honestly what is covered.