Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

HIPAA · Digital health & life sciences

HIPAA Readiness for Virtual Care & Telehealth Platforms

HIPAA readiness for a Canadian virtual care platform starts the moment a US clinic, payer or health system hands over a Business Associate Agreement to sign. Signing it makes the platform directly liable under the Security Rule, with its own risk analysis, safeguards and 60-day breach clock running alongside PHIPA and provincial obligations already in place. Direct-to-consumer platforms without a covered-entity relationship face a different exposure entirely, through the FTC's Health Breach Notification Rule. We build the program around whichever path actually applies.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the BAA actually commits the platform to

Signing a Business Associate Agreement is the start of a set of concrete obligations, not a formality that closes out the sales conversation.

Permitted uses and the minimum necessary standard

PHI received from the US customer may only be used and disclosed as the BAA allows, limited to the minimum information needed for each task, a narrower standard than a general PHIPA relationship might assume.

Administrative, physical and technical safeguards

Access controls, encryption decisions, workforce training and contingency planning all need to be mapped specifically to the systems that actually hold US patient data, not assumed to be covered by existing PHIPA controls.

Subcontractor flow-down

Any video, transcription or support vendor that touches the same PHI needs its own BAA with matching terms, since the platform's obligations to its US customer extend through its own sub-processor chain.

The documented risk analysis

An accurate, organization-wide assessment of risks to electronic PHI is a required Security Rule safeguard and typically the first document an investigation asks for.

Return or destruction of PHI at contract end

The BAA sets out what happens to US patient data when the relationship ends, and the platform needs a real process for meeting that commitment, not just a clause on paper.

Regulatory map

The specific HIPAA mechanics this niche runs into

Three provisions do most of the work once a US contract is signed.

Business associate contract terms

Federal rules set out what a BAA must contain: permitted uses, required safeguards, subcontractor flow-down and what happens to PHI when the relationship ends.

Primary source →

The business associate's breach notification duty

A business associate must notify the covered entity of a breach of unsecured PHI, and BAAs commonly set that notice window at up to 60 days so the covered entity can meet its own downstream deadlines.

Primary source →

Administrative safeguards: risk analysis and training

A documented risk analysis and workforce training are required administrative safeguards under the Security Rule, expected to be current and specific to the systems actually holding PHI.

Primary source →

The FTC's Health Breach Notification Rule for DTC apps

A direct-to-consumer telehealth app with no covered-entity relationship falls outside HIPAA entirely, but the FTC's rule imposes its own breach notification duty on consumer health apps.

Read our guide →

What goes wrong

What HIPAA exposure looks like for a telehealth platform specifically

The concrete risk here is not abstract; it has already played out for a comparable mental-health telehealth product.

  • Ad-pixel sharing on intake and booking pages

    The FTC's order against BetterHelp addressed a mental-health telehealth service sharing consumer data, including sensitive intake information, with advertising platforms through pixels placed on its booking flow.

    Source →

  • A DTC app assuming HIPAA covers it when it doesn't

    A platform selling directly to US consumers with no covered entity in the relationship is not a HIPAA business associate, which means the safeguards it needs are shaped by FTC expectations, not the Security Rule.

  • A sub-processor breach without a matching BAA

    A video or transcription vendor that was never asked to sign its own BAA leaves the platform exposed to a breach it cannot contractually push responsibility back onto.

  • A risk analysis written for PIPEDA, not the Security Rule

    A Canadian privacy program built around PIPEDA and PHIPA is a strong foundation, but it does not automatically produce the specific, documented risk analysis HIPAA's Security Rule requires.

Our hipaa for virtual care & telehealth platforms

What our HIPAA readiness covers for a virtual care platform

Built for a Canadian team that already runs a PHIPA and PIPEDA program and now needs the US-specific layer on top.

Studying with video online lesson at home
  1. Gap analysis against your existing Canadian program

    A comparison of your current PHIPA and PIPEDA posture against HIPAA's three rules, so you know precisely what is missing before a US customer asks.

  2. Security risk analysis

    The Security Rule's required risk analysis, documented in the form OCR and US procurement teams expect, with a prioritized remediation plan.

  3. BAA and subcontractor readiness

    Review of the BAA you are being asked to sign and the subcontractor agreements you need with your own video, transcription and support vendors.

  4. Policy development for the US-facing environment

    HIPAA-aligned policies written for a Canadian operating context, not a US template with the letterhead swapped.

  5. Staff training on the added regime

    Role-based training for engineering, clinical and support staff so the added US expectations are understood, not just filed alongside existing PHIPA training.

How the engagement runs

From signed BAA to evidence package

Sequenced so the platform can answer a US customer's questions with confidence, not just a signed contract.

  1. Step 1

    Scope

    We map where US patient data enters, lives and leaves your systems, which contracts govern it, and which vendors touch it.

  2. Step 2

    Assess

    We run the security risk analysis and compare current practices against the Privacy, Security and Breach Notification Rules.

  3. Step 3

    Remediate

    Gaps close in priority order, policies, safeguards, subcontractor BAAs, training, with your team doing the work and ours directing it.

  4. Step 4

    Prove

    We assemble the evidence package US customers and auditors expect, and keep it current as your vendors and patient base change.

What it costs

What shapes HIPAA readiness cost for a virtual care platform

Cost depends on how many US covered entities you serve, how many sub-processors need their own BAAs, and how mature your existing PHIPA and PIPEDA program already is. A platform with a documented Canadian privacy program closes HIPAA-specific gaps faster than one building policies and safeguards from nothing.

A direct-to-consumer platform with no covered-entity relationship needs different work entirely, focused on FTC Health Breach Notification Rule exposure rather than BAA mechanics, which changes the scope significantly. We scope the engagement after confirming which path applies and quote from there.

Virtual Care & Telehealth Platforms: HIPAA questions, answered

You are now directly liable under the Security Rule, which means a documented risk analysis, safeguards mapped to the systems holding that clinic's PHI, and matching BAAs with any of your own sub-processors that touch the same data. Waiting until an incident or audit to build these puts you in breach of the agreement you already signed.

Not directly. HIPAA reaches you through a covered-entity relationship, and a pure direct-to-consumer product without one is not a business associate. It is not unregulated, though: the FTC's Health Breach Notification Rule imposes its own breach notification obligations on consumer health apps outside HIPAA's scope.

It gives you a real head start, since many controls, access management, training, breach response, overlap substantially. It is not a substitute, though: HIPAA adds specific requirements such as the formal documented risk analysis, the BAA chain with its own subcontractor terms, and the defined 60-day breach mechanics, none of which PHIPA compliance produces automatically.

Most US health systems want to see a current risk analysis, documented safeguards mapped to where their patients' PHI will live, and evidence of workforce training before finalizing a BAA. A SOC 2 report with HIPAA-mapped controls often speeds this conversation considerably.

Yes, if any of your patients are US-based or your product markets to US consumers, since the FTC's enforcement in this area specifically targeted a telehealth booking and intake flow sharing sensitive data with advertising platforms. Review any marketing or analytics tags on intake pages regardless of which regime technically governs the underlying health data.

No, the two run in parallel rather than one overriding the other. PHIPA requires notifying Canadian patients at the first reasonable opportunity, which in practice is usually faster than a BAA's 60-day outer limit, so an incident touching both patient populations needs both clocks tracked and met on their own terms.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.