BAA Generator
HomeBAA for Telehealth
Telehealth & Virtual Care

HIPAA Business Associate Agreement for Telehealth Providers

By BAA Generator Editorial  ·  Updated Apr 19, 2026  ·  5 min read

Need a BAA right now?

Generate my BAA → See pricing →

Key Takeaways

Direct answer: Telehealth providers must comply with full HIPAA requirements, including executing BAAs with every vendor who handles patient PHI. The COVID-era enforcement discretion period ended in May 2023. Video platforms, EHRs, scheduling tools, and billing companies all require signed BAAs before accessing patient data.

Telehealth exploded during COVID — and with it, HIPAA compliance shortcuts became normalized. The enforcement discretion period that let providers use FaceTime or standard Zoom ended on May 11, 2023. Since then, full HIPAA requirements apply. If your telehealth practice is still using non-compliant video tools or operating without BAAs, this is what you need to fix.

Which Telehealth Providers Are Subject to HIPAA?

Any healthcare provider who delivers clinical services via telehealth and transmits health information electronically is subject to HIPAA as a covered entity. This includes:

If you or your platform employs licensed clinicians who interact with patients and bill for services, HIPAA applies.

Video Platform BAA Requirements

This is the most common compliance gap in telehealth. Not every video tool qualifies for HIPAA use:

Platforms That Can Sign a BAA

Platforms That Cannot Sign a BAA

Full Telehealth Vendor BAA Checklist

Beyond your video platform, a complete telehealth operation involves multiple vendors who all need BAAs:

Remote Patient Monitoring (RPM) BAA Considerations

RPM adds additional complexity. Device manufacturers, data aggregation platforms, and monitoring software companies are all potential business associates if they handle PHI. For RPM specifically:

When in doubt, execute a BAA. The cost of an unnecessary BAA is zero. The cost of a missing required BAA can be substantial.

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Frequently Asked Questions

Does a telehealth provider need a HIPAA BAA?
Yes — telehealth providers are healthcare providers subject to HIPAA if they transmit health information electronically. Any vendor platform used to conduct video visits, store patient records, or process billing for telehealth encounters must sign a Business Associate Agreement before accessing patient PHI. This includes video conferencing platforms, EHRs, billing companies, and cloud storage services.
Can I use regular Zoom for telehealth?
No — standard Zoom accounts (free, Pro, or Business+) are not HIPAA compliant and cannot be used for telehealth sessions involving PHI. You must use Zoom for Healthcare or an eligible Business/Enterprise Zoom plan with HIPAA mode enabled and a signed BAA. Alternatives include Doxy.me (free HIPAA BAA for individual providers), Teladoc, or similar dedicated telehealth platforms.
What is the difference between a telehealth platform's BAA and my practice's BAA with vendors?
A telehealth platform (like Teladoc or Doxy.me) may provide a BAA covering its own infrastructure. But your practice also needs BAAs with every other vendor that accesses patient PHI — your EHR, billing company, cloud storage, IT provider, and more. The telehealth platform's BAA only covers that specific platform, not all the other business associates in your ecosystem.
Did the COVID telehealth HIPAA enforcement discretion period end?
Yes — the HHS Office for Civil Rights enforcement discretion policy for telehealth that was in effect during the COVID-19 public health emergency ended on May 11, 2023. Since that date, telehealth providers must comply with full HIPAA requirements, including executing BAAs with video platforms and other technology vendors. Using non-HIPAA-compliant platforms without BAAs is no longer permitted under any enforcement discretion policy.

Vendor BAA guides for this specialty

Twilio Video Doxy.me Zoom for Healthcare RingCentral AWS