Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should healthcare organisations handle HIPAA privacy and…
Governance, Ownership & Risk

How should healthcare organisations handle HIPAA privacy and security controls when telehealth enforcement is relaxed during an emergency?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Healthcare organisations should keep HIPAA Security Rule safeguards in place even when enforcement is relaxed. That means using private, one to one communication methods where possible, avoiding public facing platforms for patient care, informing patients about privacy risks, and limiting disclosures to permitted treatment, legal, and public health purposes. Emergency flexibility changes enforcement, not the underlying duty to protect PHI.

How to preserve HIPAA controls when telehealth rules are relaxed

Emergency enforcement flexibility should be treated as a temporary accommodation, not a permission to lower the organisation’s privacy and security baseline. HIPAA still expects reasonable safeguards around confidentiality, integrity, access control, and minimum necessary use. The practical question is how to keep care moving while preserving those protections in the channels, devices, and workflows used for remote visits.

That usually means choosing communication methods that reduce exposure by default, while documenting when emergency conditions justify a narrower control set. The most defensible approach is to keep the same security intent even if some implementation details, such as platform choice or patient notice, must be adjusted to the emergency context.

What controls remain essential during telehealth

The Security Rule still anchors the response. Organisations should continue to apply access controls, authentication discipline, auditability, and transmission safeguards to telehealth workflows, even when enforcement discretion is broader. That includes using private one to one communications where possible, limiting session access to the intended participants, and avoiding routine reliance on public facing tools for patient care when a more protected option is available.

Privacy controls also remain important at the point of care. Patients should be informed of the privacy risks associated with the chosen communication method, especially when the emergency context forces a less ideal platform or setting. The goal is not perfection, but a conscious and documented tradeoff that keeps PHI exposure as low as reasonably practicable.

For remote care, the most material control failure is usually not the absence of a telehealth program, but the use of convenience tools without clear boundaries. A chat, video, or messaging channel that is easy to start can still create unnecessary disclosure if the organisation does not govern who can join, what information is shared, and how long the communication record is retained.

How to limit disclosures without interrupting care

Emergency operations should preserve the HIPAA permission to disclose PHI for treatment, legal, and public health purposes, while avoiding broader sharing that is not needed for the immediate clinical objective. In practice, that means aligning telehealth workflows with the minimum necessary principle, using only the information required for the encounter, and reserving broader disclosure decisions for cases where the purpose clearly fits a permitted use.

That balance matters because telehealth often expands the number of people, devices, and systems that can observe patient information. When the care model changes quickly, organisations should be especially careful about informal workarounds such as forwarding screenshots, using personal devices without controls, or inviting additional participants to resolve a workflow problem. Those shortcuts can erode the same protections that the emergency policy was meant to preserve.

One useful internal reference point for this kind of control mapping is Identity Security Regulatory Map, which helps align access and governance expectations across regulated environments. For broader control design, Ultimate Guide to NHIs, Regulatory and Audit Perspectives is also useful where organisations need audit-ready thinking about controlled access and accountability.

Risk and Threat Considerations

Relaxed enforcement can create a false sense that the privacy risk has also been relaxed. The real exposure is that emergency telehealth often increases reliance on consumer-grade channels, shared environments, and ad hoc workflows, which can expose PHI to unintended recipients or weaken the organisation’s ability to trace what was disclosed and why.

Failure mechanism: Staff may substitute convenience for control by using less secure communication paths, oversharing information, or failing to confirm who can hear or see the encounter.

Impact: The result can be avoidable PHI disclosure, weaker audit defensibility, patient trust loss, and greater difficulty showing that the organisation continued to apply reasonable safeguards during the emergency.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-3 — Access EnforcementTelehealth privacy depends on limiting who can access patient information and sessions.
IA-2 — Identification and Authentication (Organizational Users)Remote care still needs authenticated clinician access to patient information and systems.
AU-2 — Audit EventsEmergency telehealth needs traceability for disclosures and access to PHI.
Recommendation — Enforce least-privilege access to telehealth data and encounters. Require strong authentication for staff accessing telehealth systems. Log telehealth access and disclosure events for review and investigation.

Practitioner Guidance

What to prioritise: Keep the workflow secure first, then adjust only the minimum set of controls needed to deliver care. If the platform or device cannot support basic privacy expectations, treat that as a compensating-control problem rather than a reason to abandon safeguards.

What to verify: Confirm that telehealth staff know which tools are approved, how to set up a private session, when patient notice is required, and what disclosures are permitted for treatment, legal, and public health purposes. The test is not whether the emergency policy exists, but whether frontline teams can apply it consistently.

Practitioner takeaway: Emergency flexibility should narrow the compliance burden, not the protection of PHI; the safest telehealth model is the one that preserves privacy intent while documenting any temporary control tradeoffs.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org