Join our Newsletter — 33% off our NHI Course

Virtual Visiting

Virtual visiting is the use of secure video or mobile communication to let patients connect with relatives and care teams without physical presence. In healthcare settings, it supports continuity of care and contact while reducing infection risk, provided the workflow protects privacy and prevents residual data on devices.

What Virtual Visiting Is

Virtual visiting is a care-access workflow, not a clinical treatment in itself. It connects patients, relatives, and care teams through secure video or mobile communication so contact can continue when physical presence is limited.

The term is usually used in hospitals, long-term care, and other controlled healthcare environments where the objective is to preserve social contact and continuity of care while keeping the interaction bounded, recorded only as needed, and aligned to local privacy rules.

Why Virtual Visiting Exists

Virtual visiting became important because healthcare organisations need ways to maintain human contact during isolation, restricted visiting hours, high-acuity care, or infection-control constraints. It is especially useful when bedside access is difficult but communication still matters to recovery, consent discussions, family support, or reassurance.

It also changes the workflow around the visit itself. A successful virtual visit depends on scheduling, device availability, clinician or ward support, and a clear rule for who may join, what may be discussed, and whether the session is meant for a one-off conversation or an ongoing communication channel.

Privacy, Data Handling, and Care Workflow

Virtual visiting is only as safe as the surrounding device and communication workflow. Because it can involve patient images, voice, family discussions, and care updates, the process should protect confidentiality and prevent leftover data from persisting on shared or mobile devices.

That means the practical security concern is not just the video session, but the full lifecycle around it, including account access, session setup, device reuse, notifications, screenshots, cached media, and whether the platform stores call content or metadata. NIST Privacy Framework is a useful reference when a virtual visiting process must balance communication with data minimisation and privacy risk.

How Virtual Visiting Differs From Ordinary Video Calls

Virtual visiting is more constrained than consumer video chat because it is meant to operate inside a healthcare governance model. The user experience may look similar, but the expected controls are different: access should be intentional, the participant list should be appropriate to the patient, and the organisation should know how the session is started, supervised, and closed.

For that reason, secure deployment patterns matter. Healthcare teams often need managed authentication, least-privilege access, and clear session boundaries when the service is tied to protected clinical workflows. NIST SP 800-53 Rev 5 Security and Privacy Controls supports that design thinking by covering access control, identification and authentication, auditability, and system integrity. When the visit channel is delivered over a tightly controlled trust model, NIST Privacy Framework helps explain why data handling and disclosure limits belong in the design, not as an afterthought.

Risk and Threat Considerations

Virtual visiting introduces real confidentiality and operational risk because the interaction may expose sensitive health information to the wrong person, persist on a shared device, or be intercepted through weak account and session controls. The main concern is not the concept itself, but poor execution of the workflow around it.

Failure mechanism: Weak access control, reused devices, unmanaged guest links, or residual media on tablets and phones can let other people view, replay, or access a visit after it ends. In healthcare settings, that can become a privacy incident even when the call itself was well-intentioned.

Impact: The result can be unauthorised disclosure of patient information, loss of trust, avoidable complaints, and in some cases a reportable data protection failure. Where the process is tightly managed, the same workflow can reduce isolation and support care continuity without creating unnecessary exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 provides the primary governance reference for this term.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Virtual visiting depends on controlled access for staff managing patient communications.
AC-6 — Least Privilege Limited access reduces who can initiate, join, or manage sensitive care conversations.
AU-2 — Event Logging Logging supports review of session setup, access, and administrative actions in a care channel.
Recommendation — Enforce strong user authentication for staff who create, approve, or supervise virtual visits. Restrict virtual visiting access to the minimum roles needed for the workflow. Log virtual visiting access and administration events for later review.