Now accepting new patients | Insurance accepted | Self-pay & HSA eligible | Membership optional | Telehealth only (Maryland)

Blog

Stop Telehealth Privacy Breaches: Anchor Health’s Evidence Based Playbook

Stop Telehealth Privacy Breaches: Anchor Health’s Evidence Based Playbook

The biggest telehealth privacy concerns come down to four things: unauthorized access to your health records, insecure or misconfigured video platforms, accidental disclosure when someone else is in earshot, and unauthorized recording of your visit. Before your next appointment, confirm your provider uses a HIPAA-covered portal or encrypted platform, look for a private room, and check that your device has basic security protections turned on. Those three checks solve most of the risk before the visit even starts.


TL;DR:

  • Using a HIPAA-covered platform, a private environment, and enabling device security measures prevent most privacy risks before a telehealth visit begins.
  • Environmental, technical, and operational risks consistently cause privacy failures, with operational gaps like missed consent, improper staff training, or lack of signed BAAs being most damaging.
  • Breaches can lead to serious harm such as identity theft, discrimination, or financial loss, and they also carry significant legal penalties and reputational damage for providers.
  • Patients should verify secure connections, use strong authentication, and ask about recordings and data storage practices to minimize exposure risks.
  • Providers must conduct regular risk analyses, ensure vendor compliance through BAAs, and implement staff training and policies to uphold telehealth privacy and security effectively.

Table of Contents

Where Telehealth Privacy And Security Breaks Down

Privacy failures in telehealth rarely trace back to one dramatic hack. A 2023 systematic review of 18 studies grouped the causes into three categories that keep resurfacing: environmental, technical, and operational factors, and the pattern holds across specialties and platforms alike, according to the systematic review published in PMC. Understanding these three buckets tells you where to actually focus your attention, instead of worrying about everything at once.

Environmental risk is the simplest to picture and the easiest to underestimate. A patient sits at the kitchen table while a roommate walks through. A teenager takes a mental health visit from a shared bedroom. A provider, working from home, sits in front of a cluttered background that makes the patient wonder who else might overhear. Research published in the AJMC Journal found that patients trust providers more when the visit looks and feels like it’s happening in a professional setting, not an improvised one. That single detail, staging your environment, does more for perceived privacy than most technical fixes.

Technical risk covers the mechanics of transmission and storage: video apps that aren’t properly encrypted, connections over public Wi-Fi, malware sitting on an old laptop, or session recordings and transcripts stored without adequate access controls. Any weak point along that chain, from your router to the vendor’s server, can expose protected health information.

Operational risk is the quietest of the three, and often the most damaging. It shows up as a missing consent process for recordings, a front-desk team that never verifies patient identity before a visit, staff who haven’t been trained on what “minimum necessary” access means, or a vendor contract that never included a signed business associate agreement. A platform can carry every security certification on the market and still leak private information if nobody trained the staff using it.

The recurring finding across this research is that technology alone doesn’t solve telehealth confidentiality issues. A perfectly encrypted platform doesn’t help if:

  • A staff member emails a video link to the wrong patient
  • Nobody asks whether the session is being recorded
  • A caregiver joins the call without the patient’s knowledge or consent
  • The provider’s vendor never signed a business associate agreement
  • A patient joins from a public coffee shop on unsecured Wi-Fi

Each of these operational gaps sits outside what most people picture when they hear “video visit privacy.” That’s exactly why they get overlooked, and why they show up again and again in reviews of real-world telehealth incidents.

HIPAA, HHS, And OCR: What The Rules Actually Require

HIPAA is still the governing framework for telehealth privacy in the United States, and it applies whether your visit happens by video, secure chat, or phone. Covered entities, meaning most healthcare providers and their business partners, must apply “reasonable safeguards” to protect electronic protected health information (ePHI). That includes access controls, audit logs, and limiting who can see your data to the minimum necessary for your care, according to Telehealth.

Here’s a nuance most patients never hear explained clearly: audio-only visits are not automatically exempt from HIPAA. The Office for Civil Rights’ guidance on audio-only telehealth clarifies that a traditional landline call generally falls outside HIPAA’s Security Rule, because it isn’t electronic transmission in the way the rule defines it. But a call placed over VoIP, a smartphone app, or any internet-based audio service is a different matter. That call, and any resulting recordings or transcripts, falls squarely under Security Rule obligations.

Statistic to know: OCR has been explicit that breaches of protected health information can lead to real, lasting harm, not just inconvenience. Exposed records have led to medical or financial identity theft, personal embarrassment, and even discrimination against affected patients, according to OCR’s analysis of health information technology risks. That’s the practical stake behind every safeguard discussed in this article.

Business associate agreements (BAAs) matter more than most patients realize. Any vendor that creates, receives, maintains, or transmits ePHI on a provider’s behalf, think video platform vendors, transcription services, or cloud storage providers, needs a signed BAA in place. A vendor acting as a “mere conduit,” like an internet service provider that never actually accesses the content, typically does not need one.

The division of responsibility here is worth stating plainly:

  • Providers are responsible for platform selection, encryption, staff training, BAAs, and documented policies.
  • Patients are responsible for their own device security, choosing a private space, and using the tools (like patient portals and multi-factor authentication) that providers make available.

Neither side can fully cover for the other. A HIPAA-compliant portal doesn’t help if a patient logs in from a public library computer with no privacy screen, and a diligent patient can’t compensate for a provider that never trained its staff.

Your Pre-Visit and In-Visit Privacy Checklist

Most privacy protection in telehealth happens before the visit even starts. The following steps, drawn from HHS’s own patient guidance, take a few minutes and meaningfully cut your exposure.

  1. Connect on your own device, on your own network. Avoid public Wi-Fi at coffee shops or libraries; use your home network or a personal hotspot instead. Keep your operating system, browser, and antivirus software updated, since outdated software is one of the easiest entry points for malware.
  2. Lock down your account. Use a strong, unique password for your patient portal, turn on multi-factor authentication if it’s offered, and set your device to lock automatically when idle.
  3. Choose your physical space deliberately. A closed door, headphones instead of speakerphone, and a room where family members aren’t likely to walk through all matter more than people expect. If you’re setting up a room specifically for recurring visits, keep it consistent so it becomes second nature.
  4. Silence anything that listens. Smart speakers, voice assistants, and even some smart TVs can pick up audio in the background. Turn them off or move to another room before the visit starts.
  5. Verify before you click. Confirm that appointment links and portal messages come from your actual provider’s domain, not a look-alike address. Phishing attempts targeting telehealth patients tend to spike around appointment times, since scammers know when patients expect a message.
  6. Ask about recording, every time. If a session is recorded for any reason, ask where that recording is stored, how long it’s kept, and who can access it. Unsanctioned recordings create files that sit entirely outside your medical record, easy to duplicate, share, or lose track of, according to HHS’s data privacy guidance for patients.
  7. Skip unnecessary identifiers in chat. If your visit includes a text or chat function, avoid typing your Social Security number, full address, or other identifiers unless the provider specifically requests them through a secure form.

Pro Tip: Keep a small sign, even a sticky note, on your door during telehealth visits. It sounds simple, but a visible signal that a session is in progress prevents more accidental walk-ins than any lock ever will.

If you’re arranging visits on behalf of someone else, the privacy considerations shift slightly. Attending a visit as a caregiver means being explicit with the provider about who’s in the room and why, so consent and confidentiality stay documented rather than assumed.

How Providers Should Structure Privacy And Security Operations

Patient habits only go so far if the provider’s own house isn’t in order. A sound telehealth privacy program starts with a documented, telehealth-specific risk analysis, not a generic IT security checklist borrowed from an in-person practice. Best-practice guidance from telehealth.hhs.gov recommends reviewing this analysis on a regular cycle, since new platforms, new staff, and new threats all shift the risk picture over time.

Vendor management deserves particular attention. Any platform vendor that touches ePHI needs a signed BAA, and providers should ask direct questions about a vendor’s security posture rather than accepting marketing claims at face value: How is data encrypted at rest and in transit? What audit logs exist? How quickly are vulnerabilities patched?

Beyond the contract, a handful of policies separate a mature telehealth operation from a vulnerable one:

  • A clear identity verification process before every visit begins
  • Explicit, documented consent procedures for any recording
  • A retention and deletion schedule for recordings, transcripts, and chat logs
  • A written incident response plan that names who does what during a breach
  • Session timeout rules and access controls tied to staff roles, not blanket permissions

Technical controls back up those policies: encryption in transit and at rest, multi-factor authentication for staff logins, activity logging for audits, and a consistent patching schedule for every device that touches patient data.

None of it works without people. Staff training closes the gap that technology alone can’t, since a HIPAA-compliant platform is only as strong as the person using it correctly, a point echoed in research on telemedicine privacy preservation. Practices that track training completion alongside incident reports get a much clearer picture of where their actual weak points sit, rather than assuming a signed vendor contract is the finish line.

The Technical Controls That Actually Reduce Risk

Not all encryption is equal, and the difference matters more than most vendor pitches let on. End-to-end encryption means only the two parties on the call can decrypt the content; transport layer encryption (like standard TLS) protects data in transit but may still leave it decrypted on a server somewhere in between. Ask directly which one a platform uses, and whether that protection extends to recordings and transcripts stored afterward, not just the live video stream.

Authentication is the next layer. Multi-factor authentication, device trust settings, and automatic session timeouts each close off a different way an unauthorized person could get into an account. Single sign-on can simplify staff access, but only when it’s paired with strong underlying credential policies, not used as a shortcut around them.

Statistic to know: Reviews of telehealth risk factors consistently flag inadequate data security and unreliable internet access as top technical concerns across studies, alongside environmental and operational gaps, according to the systematic review in PMC. Technical weakness isn’t a rare edge case; it’s one of three consistently documented failure points.

Before trusting any platform with sensitive visits, a few questions cut through the marketing language:

  • Does the vendor sign a BAA, and does that agreement cover recordings and transcripts specifically?
  • What’s the patch and vulnerability disclosure cycle?
  • Are audit logs available for review, and by whom?
  • How are recordings stored, encrypted, and eventually deleted?
  • What’s the consent workflow for a session someone wants to record?

Emerging privacy-preserving techniques, like encrypted computation methods that allow data processing without fully decrypting it, are being explored in telemedicine research as a longer-term mitigation for some of these exposures. They’re not yet standard in consumer-facing telehealth platforms, but they signal where the field is heading as digital health security risks continue to evolve.

If You Suspect A Privacy Breach, Act Fast

Speed matters more than perfection here. If something feels wrong, whether a strange login notification or a recording you never consented to, move through these steps right away.

  1. Write down what happened. Note the date, time, platform, and anything unusual you noticed, while the details are still fresh.
  2. Change your passwords immediately, starting with your patient portal and email, and enable multi-factor authentication if you haven’t already.
  3. Contact your provider directly and ask for their designated privacy or security contact, not just the general front desk line.
  4. Revoke app permissions tied to the telehealth platform and remove any shared files or recordings you have access to delete.
  5. File a complaint with OCR if you believe protected health information was mishandled; the Office for Civil Rights complaint portal accepts details on the provider, the platform, and the nature of the exposure.

Providers face their own checklist on the other side: contain the exposure, preserve logs for forensic review, follow breach notification timelines under HIPAA, and communicate plainly with affected patients rather than downplaying what happened. Clear, fast communication after a breach tends to preserve more trust than silence ever does.

How Anchor Health Builds Privacy Into Every Visit

Anchor Health delivers primary care entirely through secure video visits, and privacy isn’t an add-on to that model. It’s built into how the Anchored Care℠ᴵᴾ approach works day to day. Because visits run longer and providers stay consistent over time, patients aren’t repeating sensitive history to a new face every visit, which on its own reduces how many people ever touch a given piece of health information.

Patient-facing guidance reflects the same operational habits recommended throughout this article. Anchor Health publishes clear direction on how telehealth prescriptions are handled securely, what caregivers should know before joining a visit, and how to set up a private, secure account for an elderly parent who may need extra help navigating a portal for the first time.

Behind the scenes, that translates into the same controls this article recommends for any serious telehealth operation: documented risk analysis, signed BAAs with platform vendors, identity verification before visits, and staff training that treats privacy as an ongoing practice rather than a one-time checkbox. Insurance acceptance and optional membership tiers don’t change any of that baseline. Every visit, regardless of how it’s billed, runs through the same secure infrastructure and the same privacy expectations.

Do Telehealth Privacy Rules Differ By State Or Country?

HIPAA sets the federal floor, but it’s not the ceiling. States can, and often do, layer on stricter privacy requirements, particularly around mental health records, minors’ consent, and genetic information. A state law that offers stronger protection than HIPAA generally takes precedence for that specific requirement, while HIPAA continues to govern everything else.

Licensing adds another layer entirely separate from privacy law. A provider generally needs to be licensed in the state where the patient is physically located during the visit, not just where the practice is based. That’s a structural reason telehealth practices, including Anchor Health, often operate within a defined state footprint rather than claiming to serve patients everywhere.

Outside the United States, the differences widen considerably. The European Union’s General Data Protection Regulation (GDPR) treats health data as a special category requiring heightened protection, with rules around cross-border data transfer that have no real HIPAA equivalent. Other countries maintain their own health privacy frameworks, some strict, some far looser than the American standard.

The practical takeaway for patients: don’t assume the privacy rules you’ve read about in one context apply everywhere. If you’re receiving care across a state line, or from a provider based in another country, ask directly which framework governs your specific visit.

What Happens To Your Data After The Visit Ends

The video call ending isn’t where your data’s journey stops. Most platforms retain visit records, chat logs, and sometimes recordings for a defined period, and that retention window varies significantly by vendor and by state medical record requirements. Some practices keep records for years to meet legal retention rules; recordings of the video session itself, when they exist at all, often follow a much shorter and stricter retention schedule.

Third-party access is the part patients ask about least and should ask about most. A telehealth platform may share data with subcontractors for functions like cloud storage, transcription, or analytics. Each of those subcontractors, if they touch protected health information, should fall under the same BAA framework covering the primary vendor. If a platform can’t clearly explain who touches your data downstream, that’s a legitimate reason for concern.

Deletion practices matter just as much as retention. Ask whether “deleted” data is actually purged or simply marked inactive in a system that retains it elsewhere. Secure deletion, meaning the data is unrecoverable, not just hidden from your view, should be part of any vendor’s documented practice.

A patient portal’s privacy settings are worth checking directly rather than assuming defaults are protective. Reviewing what a portal shares with linked apps or family accounts takes a few minutes and closes a gap most patients never think to check.

Protecting Privacy For Elderly Patients And Minors

Vulnerable populations face privacy risks that standard guidance doesn’t fully address. Elderly patients often need help setting up accounts, which means a family member or caregiver frequently has account access alongside the patient. That access needs clear boundaries: who can see visit summaries, who can schedule appointments, and whether the patient retains override control over their own account. Setting up telehealth for an elderly parent the right way means building those boundaries in from day one, not adding them after a problem surfaces.

Minors present a different set of questions entirely. Consent laws around adolescent health information, particularly for mental health, reproductive health, and substance use, vary by state and can restrict what a parent is legally entitled to see, even when they’re the one managing the account. Establishing pediatric telehealth care means understanding those boundaries ahead of time, so a teenager’s confidential conversation with a provider stays confidential where the law requires it.

Both groups share a common thread: someone other than the patient often holds meaningful account or logistical control. That arrangement is often necessary and appropriate, but it only stays privacy-protective when everyone involved understands exactly what they can see, what they can’t, and why the line is drawn where it is.

A telehealth privacy failure isn’t just an embarrassment; it carries real legal exposure. HIPAA violations are enforced through OCR, and penalties scale with the level of negligence involved, ranging from corrective action plans for minor, unintentional lapses to significant financial penalties for willful neglect that a provider fails to correct.

Beyond federal penalties, providers can face state-level enforcement and, increasingly, civil lawsuits from patients whose information was exposed. The harms OCR has documented, medical or financial identity theft, personal embarrassment, and even discrimination tied to exposed health information, translate directly into damages a patient can pursue.

For a practice, a breach also carries reputational cost that outlasts any fine. Patients choose ongoing, relationship-based care in part because they trust a provider to guard sensitive information over years, not just a single visit. A single mishandled recording or misdirected email can undo that trust far faster than it was built. That’s the real stake behind every safeguard covered in this article: not just regulatory compliance, but the ongoing relationship a telehealth practice depends on to function at all.

Where To Go Deeper On Telehealth Privacy

For readers who want to go straight to the primary sources rather than a summary, three are worth bookmarking. HHS’s OCR guidance hub covers federal rules on telehealth privacy and audio-only visits, plus the complaint portal if you ever need it. Telehealth.hhs.gov’s patient resources translate those rules into plain, practical tips for anyone attending a visit. And the PMC systematic review of telehealth privacy risk factors is the clearest single source for understanding exactly why environmental, technical, and operational gaps keep showing up across so many studies.

If you’re weighing telehealth providers and want a sense of what questions to ask before you commit, Anchor Health’s guide to choosing telehealth primary care walks through the practical considerations, privacy included, that matter most for a family deciding where to root their ongoing care. And if phishing attempts around appointment reminders are a concern, Scancompliant is a useful resource for spotting messages that don’t actually come from your provider.

What Gets Overstated, And What Doesn’t

The conventional advice on telehealth privacy overweights the platform and underweights the room. Vendors compete on encryption certifications and compliance badges, and those things matter, but the research keeps landing on the same conclusion: environmental and operational failures cause at least as much damage as technical ones. A patient in a shared apartment with no closed door is often more exposed than a patient on a slightly outdated but still HIPAA-covered platform.

If I had to prioritize one thing for readers to fix first, it wouldn’t be a password manager. It would be the five seconds it takes to ask “is this being recorded, and where does it go?” That single question, asked consistently, closes one of the most overlooked gaps in telehealth confidentiality: recordings that exist entirely outside anyone’s medical record. Technology will keep improving. The habit of asking that question won’t become obsolete.

— Paule

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

Blog & Information Disclaimer

Last Updated: May 23, 2026

The information provided on the Anchor Health website (https://myanchorhealthpc.com/), including but not limited to blog posts, articles, newsletters, graphics, and other materials (collectively, the "Content"), is for general informational and educational purposes only.

By accessing and using this website, you acknowledge and agree to the following terms and conditions:

The Content on this website is not intended to be a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician, nurse practitioner, or other qualified health provider with any questions you may have regarding a medical condition. Never disregard professional medical advice or delay in seeking it because of something you have read on this website.

Reading, interacting with, or sharing the Content on this website does not establish a patient-provider relationship between you and Anchor Health or any of its clinicians, including Paule Valery Joseph, PhD, MBA, CRNP, FAAN. A formal patient-provider relationship is only established after you have completed the formal intake process, signed our clinical consent forms, and participated in a secure clinical consultation.

If you are experiencing a medical emergency, call 911 or seek emergency medical services immediately.

Anchor Health is a primary care practice and does not provide emergency or crisis intervention services through its website or blog.

While Anchor Health strives to provide thoughtful, evidence-based information grounded in our Anchored Care℠ model, healthcare is a rapidly evolving field. We make no representations or warranties, express or implied, about the completeness, accuracy, reliability, or suitability of the information contained in the Content. Any reliance you place on such information is strictly at your own risk.

Anchor Health is a telehealth practice providing services to patients physically located within the state of Maryland. The information provided on this blog is intended for residents of Maryland and is governed by the laws and regulations of that state. Accessing this information from outside of Maryland does not imply that our clinicians are licensed to practice medicine or provide consultations in your jurisdiction.

Content related to Weight & Metabolic Health, including discussions of GLP-1 medications or other medical therapies, is provided for educational context regarding our clinical approach. Prescriptions and specific medical recommendations are only made following a comprehensive clinical evaluation, diagnostic testing, and shared decision-making within a formal patient-provider relationship.

This website may contain links to external websites that are not provided or maintained by or in any way affiliated with Anchor Health. Please note that Anchor Health does not guarantee the accuracy, relevance, timeliness, or completeness of any information on these external websites.

To the fullest extent permitted by law, Anchor Health, its owners, and its employees shall not be liable for any direct, indirect, incidental, consequential, or punitive damag

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare