Compliance Briefing — HHS OCR eases HIPAA enforcement for telehealth
HHS Office for Civil Rights announced it would exercise enforcement discretion during the COVID-19 emergency, allowing providers to use non-public-facing remote communication tools for telehealth without HIPAA penalties. Covered entities still must inform patients about privacy risks and limit data sharing to the minimum necessary.
Executive briefing: On , OCR issued a Notification of Enforcement Discretion for telehealth. Providers could use consumer video tools such as FaceTime or Skype to deliver telehealth in good faith without facing HIPAA penalties during the COVID-19 emergency.
Why it matters
- Continuity of care: clinicians could rapidly expand virtual visits without waiting for business associate agreements on new platforms.
- Risk tolerance: OCR still expected providers to avoid public-facing apps and to enable encryption when available.
- Temporary scope: the discretion applied only during the declared public health emergency and did not waive HIPAA entirely.
Operator actions
- Document platforms: Record which communication tools are used under the discretion and the safeguards enabled (encryption, access controls).
- Patient notice: Inform patients about privacy risks when using consumer-grade video tools and obtain consent.
- Limit sharing: Restrict disclosures to the minimum necessary and disable recording unless clinically required.
- Transition plan: Prepare migration to HIPAA-aligned telehealth platforms once the emergency period ends.
Continue in the Compliance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Third-Party Risk Oversight Playbook — Zeph Tech
Operationalize OCC, Federal Reserve, EBA, and MAS outsourcing expectations with lifecycle controls, continuous monitoring, and board reporting.
-
Compliance Operations Control Room — Zeph Tech
Implement cross-border compliance operations that satisfy Sarbanes-Oxley, DOJ guidance, EU DORA, and MAS TRM requirements with verifiable evidence flows.
-
SOX Modernization Control Playbook — Zeph Tech
Modernize Sarbanes-Oxley (SOX) compliance by aligning PCAOB AS 2201, SEC management guidance, and COSO 2013 controls with data-driven testing, automation, and board reporting.




