HIPAA-Compliant Telehealth Platform: How to Evaluate One (2026)

A HIPAA-compliant telehealth platform is one that implements the administrative, physical and technical safeguards required by the HIPAA Security Rule, and whose vendor will sign a Business Associate Agreement (BAA) accepting liability for the protected health information it handles. One point is widely misunderstood and worth stating plainly: there is no such thing as HIPAA certification. No government body certifies platforms. Any vendor describing itself as "HIPAA certified" is describing something that does not exist.
This guide covers what the rule actually requires of a platform, the checklist to put to every vendor, and where a video-consultation platform and a device-integrated clinical platform stop being comparable.
What HIPAA actually requires of a platform
The HIPAA Security Rule sets out three families of safeguards. It describes obligations and outcomes, not a list of approved products — which is why no product can be "certified" against it.
- Technical safeguards — encryption in transit and at rest, named access control, logging of access and actions, authentication mechanisms, and data integrity controls.
- Administrative safeguards — a documented risk analysis, a designated security official, workforce training, and incident-response and breach-notification procedures.
- Physical safeguards — controlled physical access to servers and workstations, and media disposal procedures.
The BAA: the thing buyers forget to ask for first
A vendor that stores or processes patient health information is a business associate under HIPAA. Without a signed BAA, the covered entity is out of compliance no matter how good the platform's engineering is. So the BAA is the first document to request — before any product demo. Ask for it in writing, and check that it covers the vendor's own subprocessors, the hosting provider in particular.
The checklist to put to every vendor
- Is a signed BAA available, and in which languages?
- Where is data hosted, can you choose the region, and is there an on-premise option?
- What encryption in transit and at rest — specific versions and algorithms, not "bank-level encryption".
- Is access named and logged, and can you export the audit trail?
- Which independent certifications does the vendor actually hold? ISO 27001 is third-party audited and verifiable; HIPAA is not.
- How is medical device data handled? An ECG trace or an auscultation recording is protected health information exactly as a consultation note is.
- What happens in a breach — how quickly are you notified, and who notifies patients?
Video platform or clinical platform: the distinction that decides the shortlist
Most platforms marketed as HIPAA-compliant are secure video-conferencing tools. They carry the conversation. They do not capture a clinical examination.
If the requirement is a remote conversation, a compliant video platform is enough. If the remote physician needs to examine the patient — auscultation, ECG, vitals, imaging — the platform must also receive device data, timestamp it and write it to the patient record. That is a different compliance surface, because device output is protected health information in its own right, and a platform that only carries video simply has nowhere to put it.
Where Promotal MedConnect sits
MedConnect is a clinical teleconsultation platform: video, connected-device data, the patient record, documentation and billing on one screen. On compliance, here is what is documented and verifiable:
- ISO 27001:2022 — information security management system.
- HIPAA — BAA available in English and French.
- GDPR and HDS (French health-data hosting certification).
- EU data residency, with an on-premise deployment option.
- TLS 1.3 in transit, AES-256 at rest, role-based access and audit logs.
- CE marking on every integrated medical device.
Clinically, a 12-lead ECG auto-uploads to the patient record in about five seconds, and the Skeeper SM-300 digital stethoscope streams low-latency auscultation live. The full compliance posture is published on the compliance page, and the architecture on the platform page.
Frequently asked questions
Is there a HIPAA certification for telehealth platforms? No. No government body certifies HIPAA compliance. Compliance rests on implementing the Security Rule's safeguards and holding a signed BAA. A vendor claiming to be "HIPAA certified" is at best referring to a private audit, which carries no regulatory weight.
Does GDPR compliance make a platform HIPAA-compliant? No. The two overlap substantially on encryption, auditability and data minimisation, but HIPAA adds its own requirements, including the BAA and specific breach-notification timelines. GDPR compliance is a strong starting point, not an equivalence.
Does medical device data fall under HIPAA? Yes. An ECG trace, an auscultation recording or a set of vitals tied to an identifiable patient is protected health information, and must be encrypted, logged and covered by the BAA exactly as a consultation note is.
Does data have to be hosted in the United States to satisfy HIPAA? No. HIPAA imposes safeguards, not data localisation. EU hosting is compatible with HIPAA provided the technical safeguards and the BAA are in place — and it can simplify GDPR compliance at the same time.
How long does a compliant deployment take? At MedConnect, deployment typically takes two to four weeks depending on the number of sites, the hardware configuration and any integration or data-residency requirements. Ask any vendor for a written timeline that includes BAA signature.
To compare a full configuration, see the telehealth kit, review pricing, or request a demo.
Ready to discover MedConnect?
Request a personalized demo and see how the platform adapts to your practice.
Request a demo