Join our Newsletter — 33% off our NHI Course

What are the signs that telehealth use is drifting into bad faith handling of PHI?

Bad faith usually shows up when providers use public facing apps for care, disclose information beyond treatment needs, or use PHI for marketing, fraud, or other improper purposes. It can also appear when organizations ignore state ethics rules or fail to warn patients about privacy risks. These behaviors signal that telehealth convenience is overriding lawful privacy practice.

When telehealth convenience crosses into bad faith PHI handling

Bad faith is less about a single technical misstep and more about an organisation’s intent and handling patterns. When care platforms are chosen or operated in ways that deliberately widen exposure, reuse PHI outside the care relationship, or suppress patient notice, the issue shifts from convenience into privacy misuse. That usually shows up in the workflows, disclosures, and business purpose behind the encounter.

The clearest indicator is not whether telehealth is used, but whether the organisation behaves as if privacy is optional. If a provider cannot explain why PHI is in a public-facing tool, why more data is collected than treatment requires, or why patients were not clearly warned about the privacy tradeoff, the handling model deserves scrutiny. The concern is governance failure with patient harm potential, not mere technology choice.

For telehealth, lawful handling depends on a narrow treatment purpose, transparent notice, and controls that keep PHI within the minimum necessary boundary. When those boundaries are repeatedly ignored, the pattern suggests the platform is being used to extract, repurpose, or monetize patient information rather than simply deliver care. That is the practical line between clumsy operations and bad faith conduct.

Behavioural signs that the handling model is drifting

One sign is the use of consumer or public-facing apps for encounters without a credible privacy rationale or clear patient warning. Another is collecting, sharing, or retaining PHI beyond what is needed for the visit, especially when the excess data appears to support analytics, advertising, cross-selling, or other non-treatment goals. A third is repeated disregard for state ethics rules, consent expectations, or internal privacy reviews.

Look closely at whether the organisation can separate treatment use from secondary use. If intake forms, chat transcripts, video metadata, or location data are routed into broader business systems without clear limits, the handling model may be overreaching. The same concern applies when disclosure language is vague, patient notices are buried, or staff are told to treat privacy objections as friction rather than a control requirement.

  • Public-facing tools are used where a private care channel would be expected.
  • PHI collection exceeds the minimum needed for diagnosis, treatment, or follow-up.
  • Patients are not plainly told how their information is exposed or reused.
  • Disclosures appear to support marketing, fraud, or unrelated business activity.

What the pattern usually means for privacy governance

When these signals cluster, the problem is usually not one bad vendor choice, but weak governance over purpose, disclosure, and retention. Telehealth creates legitimate pressure to move quickly, but that does not excuse using convenience as a cover for poor privacy boundaries. If the business model depends on broad reuse of PHI, the organisation should expect regulatory, contractual, and reputational consequences.

This is where transparency matters most. A patient can only make a meaningful privacy judgment if the platform’s purpose, risks, and limits are clearly explained. If the organisation fails to disclose material privacy tradeoffs, or if its stated practices do not match actual data flows, the handling is drifting toward bad faith even before a formal breach occurs.

Risk and Threat Considerations

Bad faith PHI handling increases the chance of unauthorized disclosure, overcollection, and secondary use that patients did not meaningfully accept. It also creates a trust gap that makes later remediation harder, because the concern is not only exposure but the possibility that disclosure was designed into the workflow.

Failure mechanism: Public-facing telehealth tools, excessive data collection, vague notices, and repurposed PHI can bypass the minimum necessary standard and move information into broader business or third-party systems.

Impact: The result can be privacy harm, regulatory scrutiny, patient complaints, and loss of trust, especially when PHI is used for marketing, fraud, or other improper purposes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AR-4 — Privacy Notice Telehealth PHI handling depends on clear notice about data use and disclosure.
AU-6 — Audit Record Review, Analysis, and Reporting Repeated misuse of PHI is best detected by reviewing logs and disclosure patterns.
AC-6 — Least Privilege Bad faith handling often widens access beyond treatment needs.
Recommendation — Ensure patients receive clear notice on how telehealth PHI is collected, used, and shared. Review telehealth logs for excess disclosure, unusual access, and non-treatment data flows. Limit PHI access to the minimum roles and systems needed for care delivery.
GDPR Art.5 — Principles relating to processing of personal data The question turns on purpose limitation, minimization, and lawful handling of sensitive health data.
Art.9 — Processing of special categories of personal data Health information requires heightened protection when telehealth processing expands beyond treatment.
Art.32 — Security of processing Bad faith handling often appears alongside weak controls over PHI disclosure and retention.
Recommendation — Apply purpose limitation and data minimization to telehealth PHI processing. Restrict telehealth health-data processing to a lawful basis and explicit safeguards. Implement safeguards that keep telehealth PHI confidential and appropriately controlled.
OWASP API Security Top 10 API6 — Unrestricted Access to Sensitive Business Flows Telehealth misuse can route PHI into business flows beyond the care encounter.
API8 — Security Misconfiguration Public-facing telehealth apps often fail when privacy settings and exposure limits are wrong.
Recommendation — Constrain API and workflow paths that move PHI outside treatment operations. Harden telehealth app settings so PHI is not exposed through misconfiguration.

Practitioner Guidance

What to verify: Check whether the encounter channel, notice language, and downstream data use all match the stated treatment purpose. If the platform cannot clearly justify each PHI flow, assume the privacy story is incomplete.

Decision rule: If a telehealth workflow depends on exposing more PHI than the visit requires, treat that as a control problem first and a technology problem second. The question is whether the business process can be constrained, not whether the tool is merely convenient.

Practitioner takeaway: The best indicator of bad faith is a mismatch between stated care purpose and actual information handling, especially when the organisation resists narrowing access, disclosure, or reuse.