HIPAA Compliance for Telehealth: The Complete MSP Guide for 2026
TLDR: Telehealth has become permanent — and so has HIPAA enforcement. The COVID-era enforcement waivers expired in May 2023, meaning every video visit, remote monitoring session, and secure messaging exchange must now comply with the full HIPAA Security Rule. For MSPs serving healthcare clients, telehealth adds a second compliance surface: BAAs with platform vendors, technology asset inventories, annual security risk analyses, and the 2026 Security Rule updates. Here's what you need to know — and how to package it as a recurring service.
The telehealth boom didn't end with the pandemic. The U.S. telehealth market reached $52.77 billion in 2025 and is projected to reach $65.35 billion in 2026 ([Towards Healthcare, 2025](https://www.towardshealthcare.com/insights/us-telehealth-market-sizing)), with 18.4% of commercially insured patients filing at least one telehealth claim in Q1 2026 alone ([Axis Intelligence, 2026](https://axis-intelligence.com/telehealth-statistics/)). Remote care is now a standard delivery channel, not a pandemic workaround.
For MSPs, that growth is a two-sided opportunity: a fast-expanding client vertical and a compliance surface too complex for most healthcare providers to manage without technical help.
Telehealth platforms transmit protected health information (PHI) across video calls, secure messaging systems, remote patient monitoring devices, and cloud storage — each of which must comply with HIPAA's Security Rule, Privacy Rule, and Breach Notification Rule. OCR completed 22 enforcement actions in 2024, collecting nearly $10 million in settlements ([HHS OCR, 2024](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html)). Healthcare breaches now cost an average of $10.1 million per incident — the highest of any industry ([Censinet, 2025](https://censinet.com/perspectives/hipaa-enforcement-cases-lessons-learned)). Telehealth providers sitting outside a documented compliance program are exposed to both.
The COVID Waiver Is Gone — Full Enforcement Is Here
During the public health emergency, HHS exercised enforcement discretion allowing telehealth providers to use non-HIPAA-compliant platforms like standard FaceTime and Zoom. That discretion expired on May 11, 2023. OCR has made clear there will be no further extensions.
Since that date, every telehealth session must comply with the full HIPAA Security Rule, Privacy Rule, and Breach Notification Rule. OCR's Risk Analysis Initiative produced seven enforcement actions in its first six months — all focused on organizations that failed to conduct a proper Security Risk Analysis ([Feldesman LLP, 2025](https://www.feldesman.com/ocrs-new-security-risk-analysis-initiative-results-in-seven-enforcement-actions-in-first-six-months/)). OCR has also reported a 264% increase in ransomware-related breaches since 2018 ([HHS OCR, 2024](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html)), and telehealth providers — who expanded their digital footprint rapidly in 2020-2023 — are precisely the organizations with the most unaddressed exposure.
If your healthcare clients are running telehealth without a documented compliance program, they are currently out of compliance.
What Makes Telehealth HIPAA Compliance Different
A standard HIPAA compliance program covers the clinic's EHR, billing systems, and on-premises infrastructure. Telehealth adds a second, more distributed attack surface:
- **Video conferencing platforms** — Zoom for Healthcare, Doxy.me, Teladoc, and similar require a signed Business Associate Agreement and end-to-end encryption verification before going live
- **Remote patient monitoring (RPM) devices** — wearables and home monitoring hardware generate continuous ePHI streams transmitted over patient home networks
- **Patient-facing mobile apps** — installed on consumer devices outside the organization's MDM control, often with no MFA enforcement
- **Asynchronous messaging systems** — secure patient portals and text consultation tools that retain PHI at rest
- **Cloud storage for session recordings and clinical notes** — cloud environments used by telehealth platforms require their own security assessment independent of the EHR
Each layer adds new vendor risk, additional BAA obligations, and controls your client must document. The vendor list is longer and less HIPAA-fluent than a typical EHR ecosystem.
The Four Core HIPAA Requirements for Telehealth Clients
1. Business Associate Agreements with Every Platform Vendor
Any vendor whose platform stores, transmits, or processes PHI on behalf of your telehealth client is a Business Associate under HIPAA — and must sign a BAA before going live. This includes the video platform, the RPM device manufacturer, the patient portal vendor, and the cloud hosting provider. A breach without a current BAA in place exposes the covered entity to additional enforcement liability on top of the incident itself.
For MSPs, telehealth BAA management is more complex than a standard HIPAA engagement. The vendor list is longer, the platforms evolve faster, and BAAs signed at launch frequently become stale as vendor terms change. A structured BAA management program with an annual review cadence is the right model for any client running telehealth services.
2. Annual Security Risk Analysis Covering the Full Telehealth Stack
OCR's Risk Analysis Initiative is not coincidental. Failure to conduct a documented, comprehensive Security Risk Analysis (SRA) is the single most common finding in enforcement actions — and for telehealth clients, the SRA must cover every digital touchpoint: video platform configuration, patient device management, network security at the point of care, and cloud access controls.
Omitting the telehealth stack from the SRA is itself a compliance failure, regardless of how thorough the EHR assessment was. The 2026 HIPAA Security Rule updates added specific requirements: annual SRA cycle, technology asset inventory, and defined encryption standards for data at rest and in transit — all of which apply to telehealth operations with full force.
3. Multi-Factor Authentication and Access Controls
The 2026 Security Rule explicitly requires MFA for all accounts with access to ePHI. For telehealth providers, this is operationally complex: clinicians log in from home offices, hotel networks, and mobile devices — exactly the high-risk contexts MFA is designed to address. Enforcement via Microsoft Entra ID Conditional Access policies satisfies HIPAA technical safeguards and cyber insurance carrier requirements simultaneously.
4. Incident Response and Breach Notification Readiness
A telehealth breach has different failure modes than a clinic breach. PHI can be exposed through a session recording stored in an unencrypted cloud bucket, a remote monitoring device compromised over a patient's home network, or an unsecured messaging thread left in an unapproved app. The breach notification clock starts at discovery — not when legal finishes the review.
Telehealth clients need an incident response plan that specifically addresses video platform data exposure, RPM device compromise, and patient app incidents. How your client responds also directly affects their cyber liability coverage.
Common Telehealth HIPAA Gaps MSPs Find at Onboarding
In practice, telehealth clients arrive with predictable compliance gaps:
- **No BAAs with platform vendors** — or BAAs signed at launch that were never updated after vendor service terms changed
- **Non-compliant video platforms still in use** — clinical staff using standard Zoom or FaceTime for patient consultations three years after the waiver expired
- **Missing technology asset inventories** — no documented list of which devices, apps, and services touch ePHI
- **SRA covering the EHR only** — the risk analysis doesn't include the video platform, RPM vendor, or patient portal
- **Inadequate staff training** — clinicians conducting sessions from shared household devices or in locations visible to family members
- **Stale breach response plans** — IR plans drafted in 2021 that don't account for the telehealth-specific attack surface
Each gap is a billable remediation item for MSPs with a structured HIPAA practice.
Packaging Telehealth HIPAA Compliance as a Recurring Service
Telehealth compliance is not a one-time project. Vendor landscapes shift, regulatory requirements update, and clients add new care modalities continuously. The right packaging is a recurring monthly or quarterly program — not a project with a handoff.
A productive structure for telehealth HIPAA clients:
Onboarding (months 1-3): Technology asset discovery across all telehealth touchpoints, BAA audit and gap remediation, Security Risk Analysis covering the full stack, risk register, and initial policy documentation aligned to the 2026 Security Rule.
Quarterly ongoing: Security posture assessment against the CIS Controls baseline, BAA review for new vendors, training completion tracking, and a white-label compliance report for the client's leadership team or cyber liability carrier.
Annual: Full HIPAA risk analysis renewal (now required annually under the 2026 Security Rule), breach response tabletop exercise, and updated technology asset inventory.
Nuronus automates the compliance tracking, risk scoring, and white-label reporting that make this model scalable across a portfolio of telehealth clients without adding headcount. Start with a free account covering up to two clients with all features — no credit card required. Or run a security assessment to benchmark where a prospective telehealth client stands before you scope the engagement.
Telehealth is one of the fastest-growing client verticals for MSPs — and one of the most compliance-dense. The MSPs building a structured HIPAA program for telehealth now will own this market as the client base continues to expand. Visit Nuronus HIPAA Compliance for MSPs to see how we support every step of the telehealth compliance lifecycle, from the initial SRA through annual renewal and reporting.
Ready to Add Compliance Services to Your MSP?
Free forever for 2 clients. All features included. No credit card required.
Get Started FreeBrett Coffin
Founder, Nuronus
20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.