Teletherapy can be private, but only when both the provider and the client hold up their end. The legal floor comes from HIPAA and a signed Business Associate Agreement between your clinician and their video platform. Beyond that, privacy depends on ordinary choices: picking a provider that's actually HIPAA-covered, sitting in a room where no one else can hear you, and staying off public Wi-Fi. Skip any of those three, and the encryption on the back end stops mattering much.
TL;DR:
- HIPAA applies only if the provider is a covered entity and has a signed Business Associate Agreement with their platform, especially when storing or transmitting session data.
- Privacy risks include environmental factors like overheard conversations or shared devices, which are often underestimated by clinicians and clients alike.
- A platform's marketing claim of being "HIPAA-compliant" doesn't guarantee security; verified encryption, BAAs, and strict access controls are necessary.
- Clients should confirm identity, ensure a private setting, and avoid public Wi-Fi to prevent common, preventable privacy breaches during sessions.
- Clinicians must implement ongoing risk assessments, staff training, and clear incident response plans to operationalize privacy and prevent small mistakes from escalating.
Table of Contents
- Teletherapy Privacy and Where HIPAA Actually Applies
- Informed Consent and the Ethics Behind Virtual Sessions
- What a Secure Teletherapy Platform Needs to Have
- Your Session, Your Space: A Privacy Checklist Before You Log On
- How Clinicians Should Run a Privacy-First Practice
- What the Research Says About Where Teletherapy Actually Breaks Down
- Privacy Isn't a Feature. It's a Practice.
- Ready for Privacy-First Virtual Care? Here's What Kin-wellness Offers
- Sources
- FAQ
Teletherapy Privacy and Where HIPAA Actually Applies
HIPAA applies whenever a licensed mental health professional or the practice employing them qualifies as a "covered entity," meaning they bill insurance electronically or otherwise transmit health information electronically in connection with a covered transaction. Once that's true, the clinician has to comply with three linked federal rules: the Privacy Rule, the Security Rule, and the Breach Notification Rule. Each governs a different piece of confidentiality in teletherapy.
The Privacy Rule controls who can see or receive your protected health information (PHI) and under what circumstances. The Security Rule requires administrative, physical, and technical safeguards for any PHI stored or transmitted electronically, things like encrypted video, access controls, and audit logs. The Breach Notification Rule sets timelines for notifying affected patients, media, and the Department of Health and Human Services (HHS) in case of unauthorized PHI exposure, with exact deadlines varying by circumstance and jurisdiction.
Here's where it gets specific. Any vendor that creates, receives, maintains, or transmits PHI on a clinician's behalf, the video platform, the scheduling software, the transcription tool, has to sign a Business Associate Agreement (BAA) with that clinician. A BAA is a contract that legally obligates the vendor to protect PHI the same way the clinician must. Not every vendor needs one, though. "Conduit" vendors, internet service providers or basic phone carriers that transmit data without accessing its content, are generally exempt. A video platform that stores session recordings or chat logs is not a conduit; it's a business associate, full stop.
One nuance surprises a lot of people: audio-only telehealth can still be HIPAA compliant. HHS guidance confirms the Security Rule applies whenever ePHI moves electronically, including over VoIP or a therapy app's call feature, not just during video sessions. A phone call over a traditional landline carrier typically falls outside Security Rule requirements because the carrier is a conduit, but the same call routed through an app that stores metadata or transcripts brings that app back under HIPAA's technical safeguards.
During the COVID-19 public health emergency, OCR exercised temporary enforcement discretion, allowing providers to use popular video apps even without a signed BAA, as long as they acted in good faith. That discretion has ended. Providers are expected to meet full HIPAA obligations now, which means the BAA question isn't optional anymore.
Patients also have enforceable rights under this framework:
- The right to access and request copies of your records
- The right to request corrections to inaccurate information
- The right to be notified if a breach involving your PHI occurs
- The right to file a complaint with HHS Office for Civil Rights if you believe those rights were violated
State laws can add another layer on top of HIPAA. Some states impose stricter consent or breach-notification timelines than the federal baseline, and telehealth-specific licensure rules vary by where the client is physically located during the session, not just where the clinician is licensed. That's a separate compliance question worth understanding if you're doing teletherapy across state lines.
Informed Consent and the Ethics Behind Virtual Sessions
Signing a BAA and encrypting video traffic satisfies the law. It doesn't satisfy the ethics. Clinical ethics guidance is blunt about this: technical compliance and ethical practice are related but not identical, and a clinician who treats the BAA as the finish line is missing half the job.
Informed consent for teletherapy has to go further than a general therapy consent form. It should spell out:
- The specific privacy risks unique to virtual sessions, including the possibility that someone in the client's home could overhear or see the screen
- The clinician's recording policy, and whether either party is permitted to record sessions
- The technology's limits, including what happens if the connection drops mid-session or the platform experiences an outage
- An emergency plan that accounts for the fact that the clinician may not know exactly where the client is sitting
That last point matters more than most people realize. A therapist treating someone in a mental health crisis needs a verified physical address, not just a phone number, in case emergency services need to be dispatched. Verifying location and identity at the start of treatment, and periodically afterward if a client changes locations frequently, is now considered standard practice rather than excessive caution.
Consent shouldn't be a one-time signature either. The strongest teletherapy practices treat consent as a conversation that gets revisited when circumstances change, a new device, a move to a new state, a shift from individual to family sessions where more people are in the room.
Pro Tip: Ask your therapist directly what happens if your internet cuts out mid-session. A clinician who has a clear answer, a backup phone number, a fallback platform, has already thought through the scenario. One who hasn't, probably hasn't thought through much else either.
Clinicians should also build in a habit of asking, at the start of each session, whether the client is somewhere private and whether anyone else can hear. It's a thirty-second question that catches problems before they become breaches. This single practice, more than any encryption standard, closes the gap between what the law requires and what actual confidentiality in teletherapy demands.
What a Secure Teletherapy Platform Needs to Have
A platform can call itself "HIPAA-compliant" in its marketing without actually being one. That phrase has no legal certification body attached to it, so the burden falls on the clinician, and to some extent the patient, to verify what's actually happening under the hood.
The technical baseline for online therapy security includes:
- End-to-end or transport-layer encryption (TLS) for video, audio, and chat during transmission
- Encryption at rest for any stored session data, recordings, or transcripts
- Multi-factor authentication for clinician and administrative logins
- Role-based access controls limiting who inside a practice can view which records
- Audit logs that track who accessed what PHI and when
- Automatic session logout after inactivity
On the contractual side, a legitimate vendor will sign a BAA without hesitation. That agreement should also address subcontractors: if the video vendor uses a third-party cloud host or AI transcription service, that obligation has to flow down to them too. HHS is explicit that any subcontractor touching PHI needs its own BAA in the chain. Retention and deletion clauses matter as well: how long does the platform keep session recordings, and can the clinician force permanent deletion on request?
Red flags are usually easy to spot once you know to look. A vendor that refuses to sign a BAA is disqualifying, no exceptions. A privacy policy vague about where data is stored or how long it's retained deserves a follow-up question. And any platform whose terms mention using session data for advertising, analytics resale, or "product improvement" in broad, undefined language should be treated with real suspicion in a mental health context. General-purpose video chat apps not built for healthcare often fall into this last category, even when they're encrypted well.
Your Session, Your Space: A Privacy Checklist Before You Log On
Most teletherapy privacy failures aren't sophisticated hacks. They're a roommate walking in, a laptop speaker turned up too loud, or a coffee shop Wi-Fi network with no password. HHS patient guidance focuses on exactly these ordinary, preventable risks rather than exotic cyberattacks.
Before the session:
- Pick a private room with a door that closes, ideally not shared living space where family or roommates pass through.
- Update your device's software so security patches are current before you connect.
- Use headphones so audio doesn't carry beyond the room, even with a closed door.
- Connect via a private home network or cellular data, never public Wi-Fi at a café, airport, or gym.
During the session:
- Confirm your provider's identity if anything about the login or platform feels different from usual.
- Do a quick scan of your own space and mention if someone else might walk in.
- Avoid sending PHI through chat or unencrypted email even if the platform's video call itself is secure.
- Never record the session unless both you and your clinician have explicitly agreed to it in writing.
After the session:
- Log out completely, especially on a shared or work device.
- Clear any browser sessions or cached video tabs if you used a public or shared computer.
- Avoid storing session screenshots, and if you must keep notes, store them somewhere password-protected.
Pro Tip: If you ever suspect someone overheard part of a session, tell your therapist at the start of the next one. It's not an awkward confession, it's information your clinician needs to adjust the treatment plan and, if necessary, document a potential exposure.
If you think a genuine breach occurred, whether a platform glitch exposed your data or a third party accessed your records without authorization, contact your provider directly first, then file a complaint with HHS OCR if the response feels inadequate. Reviewing how to prepare for your first therapy session is a good place to build these habits before they become urgent.
How Clinicians Should Run a Privacy-First Practice
Patient habits only go so far if the practice behind the platform hasn't done its own homework. Operationalizing HIPAA compliance for teletherapy starts with a documented security risk assessment, not a one-time checkbox but an ongoing inventory of where PHI lives, how it moves, and what could go wrong at each step.
That assessment should feed into a handful of concrete deliverables:
- Signed BAAs with every vendor that touches PHI, reviewed annually
- Written policies covering identity verification, a no-recording default, and an emergency location protocol
- Device-level encryption and endpoint protection on any computer or tablet used for sessions
- Role-based access reviews so former staff or contractors lose PHI access immediately upon departure
- A documented incident response plan with named responsibilities and notification timelines
Small practices sometimes assume rigorous compliance is only realistic for large health systems. Evidence on compliance ROI suggests otherwise: a tightly scoped risk assessment paired with a clear incident response plan delivers most of the protective value, even for solo or small-group practices, without requiring an enterprise security budget.
Training matters just as much as paperwork. Staff, including anyone handling scheduling or billing, should understand what counts as PHI, how to recognize a phishing attempt, and what to do in the first hour after a suspected breach. A written incident response template, who gets notified, in what order, within what timeframe, turns a chaotic scramble into a repeatable process. Clinicians managing telepsychiatry caseloads in particular should build emergency planning into onboarding, not as an afterthought after something goes wrong.

What the Research Says About Where Teletherapy Actually Breaks Down
A systematic review analyzing 18 empirical studies on telehealth privacy and security sorted the risk into three consistent categories: environmental, technology, and operational. Understanding which bucket a risk falls into helps decide what to fix first.
| Risk category | What it looks like in practice | Highest-impact mitigation |
|---|---|---|
| Environmental | Family members overhearing, shared devices, public spaces used for sessions | Room scans at session start, headphone use, private-space policy in consent |
| Technology | Unencrypted platforms, missing BAAs, outdated apps, weak authentication | Vendor BAA verification, encryption in transit and at rest, MFA |
| Operational | Poor staff training, no incident response plan, inconsistent identity checks | Documented risk assessment, written policies, workforce training |
Environmental risk is the one clinicians most often underestimate, because it feels like the patient's problem rather than the provider's. But the same review makes clear that clinicians share responsibility for managing it, through consent conversations, session-start check-ins, and simple room-scan habits, rather than assuming the client will self-police.
Technology risk gets the most attention publicly because it's the easiest to market against ("bank-level encryption!"), but it's also the category where formal contracts, BAAs, encryption standards, do most of the real work with the least ongoing effort once they're in place.
Operational risk is the slowest to fix and the most consequential to skip. A missed workforce training session or an undocumented offboarding process doesn't cause a breach by itself, but it removes the safety net that catches other failures before they become one.
Prioritizing fixes by likelihood times impact usually means: address environmental habits first because they're common and cheap to fix, lock down technology contracts second because they're foundational but slower to change, and build operational discipline continuously because it's what prevents small mistakes from compounding.
Privacy Isn't a Feature. It's a Practice.
Teletherapy privacy gets treated too often as a specification sheet, encryption standard here, BAA there, as if checking enough boxes eliminates the risk. It doesn't. The research backs this up: the biggest exposures aren't sophisticated breaches, they're a roommate walking through a room or a session held on a coffee shop Wi-Fi network. That's not a technology failure. It's a habit failure, and habits require ongoing attention from both sides of the screen.
What Kin-wellness has learned operationalizing this for adults across California and Arizona is that privacy protections only hold up when they're built into the rhythm of care, not bolted onto the intake paperwork. That means identity checks that don't feel interrogative, consent conversations that get revisited rather than signed once and forgotten, and vendor relationships where the BAA isn't a formality but an active commitment.
If you're evaluating a provider, ask direct questions: Who signs your BAAs? What happens if my connection drops during a crisis conversation? Can I request my records deleted? A provider with clear, specific answers has actually built the infrastructure. One who deflects probably hasn't.
— Dakota
Ready for Privacy-First Virtual Care? Here's What Kin-wellness Offers
Kin-wellness was built for adults juggling demanding careers, caregiving, and clinical needs, working professionals, parents, executives, and healthcare workers, who need outpatient mental health care that fits into a real schedule without cutting corners on confidentiality. Services include individual therapy, group and family sessions, EMDR (in-person or via telehealth), and medication management, all delivered by licensed clinicians who handle insurance billing directly so you're not navigating that alone.

Sessions run through platforms backed by signed BAAs, and clinicians are trained to verify identity, confirm a private setting, and walk through consent as an ongoing conversation rather than a one-time form. If you're comparing providers and want a clearer picture of what that actually looks like day to day, explore Kin-wellness's services and reach out to schedule an initial consultation.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- Telehealth and HIPAA | HHS
- Privacy and Security Risk Factors Related to Telehealth Services – A Systematic Review
- Telehealth Ethics: Ensuring Client Privacy in Virtual Therapy
FAQ
Can a therapist share my personal information with others?
Only with your authorization or under specific legal exceptions, such as imminent safety risk, required reporting, or a court order; otherwise HIPAA's Privacy Rule restricts disclosure of your protected health information.
Is telehealth HIPAA compliant?
Telehealth can be HIPAA compliant when the provider and any vendor handling PHI meet Privacy, Security, and Breach Notification Rule requirements, including a signed BAA with the platform. Compliance isn't automatic just because a session happens over video.
Is virtual therapy confidential?
Virtual therapy is confidential when both the platform meets HIPAA safeguards and the client takes basic environmental precautions, like using a private space and avoiding public Wi-Fi. Confidentiality depends on behavior as much as technology.
What is the 7 day rule for telehealth?
There is no universal federal "7 day rule" for telehealth privacy under HIPAA; breach notification timelines vary depending on circumstances and jurisdiction, and some state laws and specific program rules may impose shorter windows, so check your state's requirements directly.
