ijbhealthcare

Evidence-based clarity for everyday mental well-being.

Therapy & Digital Care

Teletherapy platform security: essential privacy checks

Most teletherapy marketing looks reassuring on the surface. Padlock icons in the corner of a homepage, “HIPAA-compliant” badges beside the login button, promises that sessions are secure and confidential.

Teletherapy platform security: essential privacy checks

The phrases appear so often together that patients can read them as one complete guarantee. In practice, privacy depends on a stack of contracts, technical safeguards, and everyday habits. Some of those protections are easy to misunderstand, and some sit outside the patient’s control.

That gap between promise and mechanism is where the real questions begin. Before settling into a virtual session and talking through a difficult week, it helps to know what the platform actually protects, what it only claims to protect, and what you may need to manage yourself.

The myth of HIPAA certification and the reality of BAA compliance

Lists of teletherapy platforms often repeat the same terms: HIPAA-compliant, encrypted, secure infrastructure. But the U.S. Department of Health and Human Services does not issue a formal seal endorsing these claims. There is no government-issued HIPAA certification for software products. Compliance is not a badge a vendor earns once and displays indefinitely. It depends on how an organization handles protected health information and on the obligations it accepts.

One important part of that arrangement is the Business Associate Agreement (BAA). When a vendor handles protected health information on behalf of a covered provider, HIPAA generally requires the provider and vendor to enter into a BAA. The agreement sets out the vendor’s responsibilities, including safeguards for the data and procedures for reporting breaches. Without an applicable agreement, a website’s privacy promise does not give the provider the same contractual protection.

A “HIPAA-compliant” label matters less than a signed agreement that covers the services actually handling your information.

The vendor chain can be longer than it looks. A practice might have a BAA with its electronic health record provider, then use separate companies for video, billing, transcription, or scheduling. Each service that handles protected health information may need its own agreement. A BAA with the EHR vendor does not automatically cover every other tool connected to the practice’s workflow.

Patients rarely have access to the full contract stack, and they should not be expected to audit it themselves. Still, a provider should be able to explain which services handle patient information and how those vendors are covered. When evaluating a digital therapy platform, ask whether the practice has executed the relevant agreements for the tools used in care, not simply whether the platform uses HIPAA language in its marketing.

The timeline around pandemic-era telehealth enforcement is worth getting right. The COVID-19 public health emergency expired on May 11, 2023, but the telehealth enforcement-discretion transition period continued for 90 days. It ended on August 9, 2023. That distinction matters because temporary flexibility did not disappear on the day the emergency ended. Providers and vendors had a transition period to return to the applicable requirements.

For patients who began therapy during the pandemic, the practical question is whether the current service arrangement is clear and properly documented. The existence of an older account or a familiar video link does not tell you whether every tool in the current workflow is covered.

Technical safeguards: encryption standards for video and data at rest

Encryption is one of the most common words in telehealth marketing, but the claim needs context. Two different things may be encrypted: data in transit, such as live video, audio, and chat, and data at rest, such as stored records, transcripts, and clinical notes. A platform can protect one category more strongly than the other.

For data in transit, end-to-end encryption (E2EE) means that content is encrypted on one authorized device and decrypted on another. The service relaying the call should not be able to read the content. Other platforms use transport-layer encryption, such as TLS, to protect information moving between a user’s device and the provider’s servers. That protects the connection, but the service may still be able to access the unencrypted content on its systems.

Neither phrase tells the whole story on its own. A platform should be able to explain whether video calls are end-to-end encrypted, whether it can access session content, and what happens if a session is recorded or transcribed. Those details affect the actual privacy arrangement, especially when a service offers automated notes, captions, or other features that process conversation content.

For stored information, ask what encryption standard protects the data at rest and how the encryption keys are managed. AES-256 is a widely used standard, but the name alone is not a full security assessment. The surrounding controls matter too: who can access the keys, how access is monitored, and whether recordings or transcripts are retained at all. If a vendor only says that information is “encrypted,” ask which data is covered and where the protection applies.

Encryption can protect a conversation in transit, but it cannot decide who is allowed to open the record afterward.

A platform may retain the ability to access encrypted information for operational purposes, depending on its design and the service it provides. That is different from a system in which only the participants hold the keys. The distinction does not automatically make one model appropriate and the other unsafe, but patients should not have to infer the answer from a padlock icon.

The same questions apply to mental health apps that sit alongside video visits. Messaging, mood tracking, homework, and appointment reminders can create additional stores of sensitive information. Check whether those features are part of the same system, whether they are covered by the provider’s agreements, and how long the information is kept. “Secure video” does not necessarily describe the privacy of the app’s other functions.

Identity and access management: MFA and role-based controls

Encryption protects information from being read in transit or at rest. Identity and access controls determine who can sign in and what they can do once they are there.

Multi-factor authentication (MFA) requires more than one kind of credential to access an account. A password combined with a code from an authenticator app is one common example. MFA can make a stolen or reused password less useful to an attacker. It is worth asking whether the platform offers it for both clinicians and patients, and whether administrators can require it for staff accounts.

Role-based access control (RBAC) limits what each user can see or change. A billing staff member may need access to payment information but not clinical notes. A clinician may need a patient’s record, while a system administrator may need technical access without routine access to clinical content. The principle is simple: each account should have the permissions required for its work, rather than broad access by default.

Other controls help keep accounts and sessions from remaining open unnecessarily. Automatic timeouts can close idle sessions, especially on shared devices. Login alerts, account recovery procedures, and checks on staff access can reduce the risk of unnoticed account misuse. Identity verification before care begins also matters, though the method should be proportionate and should not collect more information than the service needs.

Security controlWhat it doesWhy it matters to patients
Multi-factor authenticationAdds a second credential to the sign-in processMakes a stolen password less likely to be enough for account access
Role-based access controlLimits users to the records and functions needed for their rolesReduces unnecessary access to clinical information
Automatic session timeoutEnds an idle login after a set periodHelps prevent access from an unattended device
SOC 2 Type II reportAssesses specified operational controls over a defined periodOffers a useful signal about security practices, but does not replace HIPAA obligations

SOC 2 Type II is not a substitute for a BAA or a guarantee that a service is right for therapy. It can provide information about a vendor’s operational controls over time, while HIPAA obligations concern the handling of protected health information. The two address different questions. A practice can consider both when assessing a service, but neither label should end the conversation.

Patients can also take a few steps on their own accounts: use a unique password, enable MFA when available, and avoid staying signed in on a device other people use. These measures cannot compensate for weak platform controls, but they reduce avoidable exposure at the user end.

Audit trails and patient record integrity

Encryption and access controls can limit exposure. Audit trails help show what happened when someone accessed a record. A useful trail records events such as viewing, editing, downloading, or sharing information, along with details that help the organization investigate unusual activity.

The quality of the log matters. If the same users whose actions are being recorded can alter or erase entries without detection, the trail is less useful. Tamper-evident storage and restricted administrative access can make records more trustworthy. Detailed event types also help distinguish a routine view from an export or disclosure.

For a patient, audit trails have practical value if there is a concern that information was accessed improperly. HIPAA provides a formal right to request an accounting of certain disclosures, subject to the rule’s conditions and exceptions. A provider should be able to explain how such a request can be made and who handles it. The platform may support the process, but the provider remains an important point of contact.

Logs are not a complete privacy solution. They do not prevent every inappropriate access, and they may not make the information visible to patients in real time. Their value is in accountability: an organization can investigate activity, identify patterns, and respond when access does not match a person’s role or care relationship.

When comparing services, ask who reviews unusual access, how long audit information is retained, and whether the practice can respond to a patient’s request about disclosures. A vague answer does not prove a system is unsafe, but it leaves an important part of the protection unexplained.

Patient-led privacy: mitigating environmental risks during sessions

A well-designed platform cannot control the room at the other end of the call. Teletherapy privacy also depends on devices, surroundings, and household routines. This is the part of the system that patients can influence most directly, although no one should be blamed for circumstances they cannot change.

Voice-activated speakers, cameras, and other connected devices may listen for commands or process audio in the background. Turning them off or moving to another room before a session can reduce the chance that a private conversation is captured by an unrelated device. Headphones can help keep the clinician’s voice from carrying through a shared space, though they do not prevent others from overhearing the patient.

A few habits can make the session more private:

  • Choose a room with a closed door when possible. If that is not available, consider another private location, such as a parked car, while taking safety and connectivity into account.
  • Turn off nearby smart speakers and voice-activated devices. Check whether a connected camera or other device has an active microphone.
  • Use a trusted internet connection. Public Wi-Fi can expose users to risks; a personal hotspot may be a better option when a private network is unavailable.
  • Use a personal device with current software and a supported browser. Shared or borrowed devices may retain account details, downloads, or session history.
  • If you are in an unfamiliar place or using an unfamiliar device, confirm who is on the call before discussing sensitive information.

These steps are not a replacement for the provider’s safeguards. They are the local layer of privacy, alongside the platform’s technical controls and the practice’s contractual responsibilities. A patient should be able to ask for practical adjustments, such as using audio only or rescheduling, if the environment is not private enough for a session.

Privacy is a chain, not a badge

Teletherapy security depends on several layers working together: agreements with vendors, sound technical safeguards, appropriate access controls, reliable records of system activity, and a private enough setting for the conversation. A platform’s marketing may point toward those protections, but it cannot confirm that each one is in place.

When evaluating teletherapy platform security features for patient privacy, focus on specifics. Ask which vendors handle the information and whether the provider has the necessary agreements in place. Find out how video and stored records are protected, whether MFA and role-based access are available, and how access is logged. Ask how to request information about disclosures. Then consider what can be changed in the room and on the device used for the session.

No single answer settles every privacy question. What matters is whether the provider can explain the system clearly and whether its safeguards match the sensitivity of mental health care. A badge is easy to display. A coherent privacy practice takes work.

FAQ

Is there an official HIPAA certification for teletherapy software?
No, the U.S. Department of Health and Human Services does not issue a formal seal or government-certified HIPAA badge for software products.
What is a Business Associate Agreement (BAA) and why does it matter?
A BAA is a contract that outlines a vendor's responsibilities for safeguarding protected health information. It provides necessary contractual protection for the provider and patient when a third-party service handles sensitive data.
Does end-to-end encryption mean my therapy session is completely private?
End-to-end encryption protects data in transit, but it does not guarantee privacy for stored records or transcripts. You should ask the platform if they can access session content or if they retain recordings after the call.
What is the difference between SOC 2 Type II and HIPAA compliance?
SOC 2 Type II assesses a vendor's operational controls over a period of time, whereas HIPAA obligations specifically concern the handling of protected health information. Neither label serves as a complete substitute for the other.
How can I protect my privacy during a teletherapy session?
You can improve privacy by using a private room, turning off nearby smart speakers, using a secure internet connection, and ensuring you are using a personal device with updated software.