Anywhere in which health care information is electronically leaving the four walls of your practice should be housed in a HIPAA-compliant platform. You should audit and assess your practice for HIPAA adherence throughout the process of engaging with a patient, including:
![](/getmedia/1d5155a6-b3d2-47eb-a85d-340431fb1109/hipaa-call-icon.png)
Patient Making an Appointment
Likely compliant examples include
- Scheduling using online platforms hosted by a secure vendor with whom you have executed a BAA
- Scheduling by phone call
- Maintaining local (e.g., not cloud-based) or paper schedules and records
Likely noncompliant examples include
- Scheduling via texting, voicemail, or email, if not using platforms hosted by a secure vendor with whom you have executed a BAA
- Maintaining an online calendar of appointments with any identifiable patient information on a platform with which you have not executed a BAA
![](/getmedia/ae8207a6-ca09-4894-a2e4-aa314ec81161/hipaa-clipboard-icon.png)
Collecting Patient Information (medical history, payment information, consent to treatment and Notice of Privacy Practices)
Likely compliant examples include
- Collecting patient information using online platforms hosted by a secure vendor with whom you have executed a BAA
- Collecting patient information on forms maintained locally or on paper
Likely noncompliant examples include
- Collecting or maintaining patient information via texting, voicemail, or email, if not using platforms hosted by a secure vendor with whom you have executed a BAA
- Maintaining patient information on a platform with which you have not executed a BAA
![](/getmedia/c249fe85-5367-4771-a17f-2241276c896a/hipaa-care-delivery-icon.png)
Delivering Care
Likely compliant examples include
- Delivering telehealth using online platforms hosted by a secure vendor with whom you have executed a BAA
- Delivering audio-only telehealth through phone calls (not using online audio services providers, like FaceTime with whom you do not have a BAA)
- Seeing patients in person
Likely noncompliant examples include
- Delivering telehealth using FaceTime Audio, Google Voice, or any other voice over IP (VoIP) provider with whom you have not executed a BAA
- Delivering telehealth in public places where others can hear either the clinician or the patient
![](/getmedia/80cbcbfb-b125-435a-a5c2-091943cd601a/hipaa-records-icon.png)
Maintaining Health Records
Likely compliant examples include
- Maintaining patient information using in an EHR or other platform hosted by a vendor with whom you have executed a BAA
- Maintaining patient information on paper forms maintained locally or on paper
Likely noncompliant examples include
- Maintaining patient information on a platform with which you have not executed a BAA
- Maintaining patient information in physically unrestricted environments, including in an unlocked office or on a computer without a password
![](/getmedia/941a1817-455f-4c5f-83a3-9b938e6db2dd/hipaa-rx-delivery-icon.png)
Sending Prescriptions
Likely compliant examples include
- Sending electronic prescriptions through a platform hosted by a vendor with whom you have executed a BAA
- Faxing prescriptions
Likely noncompliant examples include
- Texting, emailing, or leaving voicemails to transmit prescriptions if not through platforms with whom parties have executed a BAA
![](/getmedia/b96addad-4317-4ad6-b17e-48f6863de5f2/hipaa-mailed-bill-icon.png)
Billing the Patient’s Insurance
Likely compliant examples include
- Using a secure online portal to transmit billing data to the patient’s payer
- Faxing billing data
Likely noncompliant examples include
- Texting, emailing, or leaving voicemails to transmit billing data if not through platforms with whom parties have executed a BAA
![](/getmedia/2c7c88df-5c47-4e50-8ff1-6744872bae87/hipaa-biling-icon.png)
Collecting Payment from the Patient (co-pay or out-of-pocket)
Likely compliant examples include
- Collecting payments through a secure online portal with which you have executed a BAA
- Collecting cash or checks
Likely noncompliant examples include
- Using consumer-facing money transfer apps (e.g., Venmo, CashApp) to collect payments
![](/getmedia/5c92f503-c2ea-4b27-8328-aab5bd491556/hipaa-messaging-icon.png)
Communicating with the Patient about Any Component of Their Care or Condition
Likely compliant examples include
- Communicating through secure online portals with whom you have executed a BAA
- Communicating via audio-only phone calls
Likely noncompliant examples include
- Texting, emailing, or leaving voicemails to communicate with the patient if not through platforms with whom parties have executed a BAA