Records and privacy

Telehealth privacy questions to ask before enrolling

Before enrolling in telehealth, ask what information is collected, who provides the clinical care, where records and messages are stored, how the patient portal works, whether third parties support the service, how pharmacy or insurance information is handled, and how to request or share your records.

Start with what is collected

Telehealth can involve intake forms, identity information, symptoms, medication lists, photos or files when clinically appropriate, portal messages, payment details, pharmacy details, device information, and visit records. Ask which information is required for care and which information is optional.

Telehealth.HHS.gov says telehealth appointments, messages, related health information, and billing information can be protected by HIPAA. It also notes that state privacy laws may apply in some situations, including entities outside HIPAA's coverage. That is why a useful privacy review looks at the whole care path, including the portal, payment flow, pharmacy path, follow-up messages, and record requests.

Questions to ask before enrolling

  • Who provides the clinical care and who supports the technology?
  • What information is collected during intake?
  • Where will visit notes, messages, and documents be available?
  • How do I request my records?
  • Can I ask for records to be sent to another healthcare provider?
  • How are pharmacy and insurance details handled, and if I pay in full myself, can I request the limited HIPAA restriction on disclosures to my health plan for payment or healthcare operations when the legal conditions are met?
  • What happens if I use a shared device or shared email account?

Also ask how long routine messages may take, which channel should be used for medication questions, and which channel should never be used for urgent symptoms. Privacy is easier to protect when you know where the service expects sensitive questions to go.

How HIPAA sharing can work

HIPAA does not require every disclosure to have a separate patient authorization. HHS explains that covered entities may use or disclose protected health information for treatment, payment, and healthcare operations, with limits and protections. Treatment sharing can include coordination among healthcare providers.

Some categories have extra rules. HHS explains that 42 CFR Part 2 protects certain substance-use-disorder patient records and allows disclosure through specific permissions and exceptions. HHS says psychotherapy notes usually require individual authorization before disclosure, with few exceptions. Ask which rules apply to the specific service and record.

That permission is not the same as unlimited sharing. It also is not the same as automatic record transfer to every clinician you see. Ask how the service handles coordination with your existing healthcare professionals. If privacy is a major concern, ask what disclosures are required for payment, pharmacy processing, safety, legal compliance, or care coordination before you begin.

Protect your side of the visit

Privacy also depends on your environment. Use a private space for live visits when possible, wear headphones if that helps, avoid public Wi-Fi for sensitive tasks when you can, and think about who can see notifications on your devices. HHS consent guidance includes practical privacy steps such as finding a place to be alone for certain visits.

For records coordination, read will my PCP see my telehealth prescription?

Common questions

Does HIPAA apply to every health app?

No. HIPAA applies to covered entities and their business associates. Some health apps, app features or vendors may fall under other privacy laws or policies instead. Ask who is collecting your information and which privacy rules apply.

Is telehealth private if I use a patient portal?

A portal can support secure communication, but you still need good account habits and should understand what information appears there and who can access it.

Can providers share information with each other?

In many treatment situations, HIPAA permits covered providers to share protected health information without a separate authorization. Actual sharing depends on systems, workflows, laws, and the reason for sharing.

References

  1. Privacy laws and policy guidance
  2. Uses and disclosures for treatment, payment, and health care operations
  3. Obtaining informed consent
  4. Requesting restrictions on PHI use or disclosure
  5. Understanding Confidentiality of Substance Use Disorder Patient Records or Part 2
  6. Does HIPAA permit disclosure of psychotherapy notes to or through an HIO?

Sources checked on October 1, 2026.