The HIPAA Privacy Rule is the federal regulation that governs how Protected Health Information (PHI) may be used and disclosed by covered entities and their business associates. It defines patient rights and the permitted purposes for sharing health information.
What it covers
Minimum necessary use of PHI, notice of privacy practices, patient rights to access and amend records, conditions for marketing communications, and disclosure for treatment, payment, and healthcare operations.
How telehealth operations have to comply
Provide a notice of privacy practices. Honor patient access and amendment requests. Restrict use of PHI to minimum necessary. Document business associate relationships. The platform should make these workflows operational, not aspirational.