Join our Newsletter — 33% off our NHI Course

Good Faith Telehealth

Good faith telehealth is care delivered with an honest effort to protect privacy and security using the best controls available under emergency conditions. It generally includes private one to one communication, patient awareness of privacy risks, and avoiding public facing platforms for clinical interactions. It is judged by intent and practical safeguards, not perfection.

What Good Faith Telehealth Means in Practice

Good faith telehealth is not a technology label, it is a standard of conduct. The clinician is expected to use reasonable privacy and security safeguards that fit an emergency setting, even when the encounter cannot match normal in-person conditions.

That matters because the term is judged by intent and practical safeguards, not perfection. The core question is whether the care was delivered using the best controls available at the time, with a real effort to reduce exposure for the patient and the consultation itself.

Privacy and Security Expectations During Remote Care

The privacy baseline is simple: telehealth should be conducted in a way that reduces inadvertent exposure of protected health information and preserves the confidentiality of the interaction. A private one to one setting is the clearest indicator, while public or visibly shared environments weaken that protection.

Security expectations usually include avoiding public-facing platforms for clinical discussions, limiting who can overhear the session, and making sure the patient understands the privacy trade-offs of the channel being used. For emergency care, the aim is risk reduction under constraints, not a false promise of perfect confidentiality.

These expectations align naturally with privacy and access control principles in the NIST Privacy Framework and the processing safeguards in EU General Data Protection Regulation (GDPR), especially where health information requires stronger handling discipline.

How Good Faith Is Judged

Good faith is an evidence-based judgment about the circumstances, not a demand for ideal tooling. A reviewer looks at whether the clinician made an honest effort to use the safest feasible approach, considered the privacy setting, and avoided obviously poor choices that were under their control.

That makes context important. Emergency conditions, limited device options, network constraints, and patient access barriers can all influence what is reasonable, but they do not erase the need for basic safeguards. The standard is practical diligence, not hindsight perfection.

This is why emergency telehealth policy often focuses on documented intent, reasonable safeguards, and proportionate handling of risk rather than rigid platform rules. The same logic appears in broader control models such as NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST Cybersecurity Framework 2.0, where governance is tied to risk-appropriate protection, not absolute uniformity.

Common Misunderstandings About Emergency Telehealth

One common mistake is treating “good faith” as permission to ignore privacy altogether. It is not. The concept allows flexibility when conditions are constrained, but it still assumes the provider takes reasonable steps to protect the interaction and does not knowingly choose an unsafe setup when a safer one is available.

Another misunderstanding is assuming the term only applies to video platforms. It also covers voice calls, messaging-based encounters, and hybrid workflows when those are used in a clinically necessary way and with awareness of their privacy limitations. The issue is the quality of the safeguards, not the medium itself.

For teams building telehealth policy, a useful external reference point is the NIST Privacy Framework, because it reinforces the idea that privacy risk must be managed proportionately to the setting and the data involved.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Telehealth good faith depends on context, constraints, and governance.
PR.AA-05 — Physical and Logical Access Permissions Private one-to-one care relies on limiting who can access the session and data.
PR.DS-01 — Data-at-Rest Protection Telehealth communication can expose sensitive health information that needs protection.
Recommendation — Define telehealth privacy expectations around the clinical context and emergency operating conditions. Restrict session access to the minimum necessary participants and systems. Protect telehealth data with appropriate confidentiality controls across storage and transmission.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Good faith telehealth favors limiting exposure and unnecessary access.
AU-2 — Event Logging Emergency telehealth benefits from traceable evidence of what controls were used.
Recommendation — Limit telehealth access paths and participant privileges to the minimum needed. Log telehealth access and session-relevant security events.