# HIPAA-Compliant Telehealth Platform: Evaluation Guide 2026

> How to evaluate a HIPAA-compliant telehealth platform: the Security Rule safeguards, the BAA, a vendor checklist, and why no platform can be &#34;HIPAA certified&#34;.

[  Back to blog ](/en/blog)
# HIPAA-Compliant Telehealth Platform: How to Evaluate One (2026)
P  Promotal MedConnect   August 17, 2026    8 min read      [Image: HIPAA-Compliant Telehealth Platform: How to Evaluate One (2026)]
A **HIPAA-compliant telehealth platform** is one that implements the administrative, physical and technical safeguards required by the HIPAA Security Rule, and whose vendor will sign a *Business Associate Agreement* (BAA) accepting liability for the protected health information it handles. One point is widely misunderstood and worth stating plainly: **there is no such thing as HIPAA certification.** No government body certifies platforms. Any vendor describing itself as "HIPAA certified" is describing something that does not exist.

This guide covers what the rule actually requires of a platform, the checklist to put to every vendor, and where a video-consultation platform and a device-integrated clinical platform stop being comparable.

## What HIPAA actually requires of a platform

The HIPAA Security Rule sets out three families of safeguards. It describes obligations and outcomes, not a list of approved products — which is why no product can be "certified" against it.

- **Technical safeguards** — encryption in transit and at rest, named access control, logging of access and actions, authentication mechanisms, and data integrity controls.

- **Administrative safeguards** — a documented risk analysis, a designated security official, workforce training, and incident-response and breach-notification procedures.

- **Physical safeguards** — controlled physical access to servers and workstations, and media disposal procedures.

## The BAA: the thing buyers forget to ask for first

A vendor that stores or processes patient health information is a *business associate* under HIPAA. Without a signed BAA, the covered entity is out of compliance no matter how good the platform's engineering is. So the BAA is the first document to request — before any product demo. Ask for it in writing, and check that it covers the vendor's own subprocessors, the hosting provider in particular.

## The checklist to put to every vendor

- **Is a signed BAA available**, and in which languages?

- **Where is data hosted**, can you choose the region, and is there an on-premise option?

- **What encryption** in transit and at rest — specific versions and algorithms, not "bank-level encryption".

- **Is access named and logged**, and can you export the audit trail?

- **Which independent certifications** does the vendor actually hold? ISO 27001 is third-party audited and verifiable; HIPAA is not.

- **How is medical device data handled?** An ECG trace or an auscultation recording is protected health information exactly as a consultation note is.

- **What happens in a breach** — how quickly are you notified, and who notifies patients?

## Video platform or clinical platform: the distinction that decides the shortlist

Most platforms marketed as HIPAA-compliant are secure video-conferencing tools. They carry the conversation. They do not capture a clinical examination.

If the requirement is a remote conversation, a compliant video platform is enough. If the remote physician needs to *examine* the patient — auscultation, ECG, vitals, imaging — the platform must also receive device data, timestamp it and write it to the patient record. That is a different compliance surface, because device output is protected health information in its own right, and a platform that only carries video simply has nowhere to put it.

## Where Promotal MedConnect sits

MedConnect is a clinical teleconsultation platform: video, connected-device data, the patient record, documentation and billing on one screen. On compliance, here is what is documented and verifiable:

- **ISO 27001:2022** — information security management system.

- **HIPAA** — BAA available in English and French.

- **GDPR** and **HDS** (French health-data hosting certification).

- **EU data residency**, with an on-premise deployment option.

- **TLS 1.3** in transit, **AES-256** at rest, role-based access and audit logs.

- **CE marking** on every integrated medical device.

Clinically, a [12-lead ECG](https://promotal-medconnect.com/en/connected-ecg) auto-uploads to the patient record in about five seconds, and the [Skeeper SM-300 digital stethoscope](https://promotal-medconnect.com/en/electronic-stethoscope) streams low-latency auscultation live. The full compliance posture is published on the [compliance page](https://promotal-medconnect.com/en/telehealth-compliance), and the architecture on the [platform page](https://promotal-medconnect.com/en/software/telehealth-platform).

## Frequently asked questions

**Is there a HIPAA certification for telehealth platforms?** No. No government body certifies HIPAA compliance. Compliance rests on implementing the Security Rule's safeguards and holding a signed BAA. A vendor claiming to be "HIPAA certified" is at best referring to a private audit, which carries no regulatory weight.

**Does GDPR compliance make a platform HIPAA-compliant?** No. The two overlap substantially on encryption, auditability and data minimisation, but HIPAA adds its own requirements, including the BAA and specific breach-notification timelines. GDPR compliance is a strong starting point, not an equivalence.

**Does medical device data fall under HIPAA?** Yes. An ECG trace, an auscultation recording or a set of vitals tied to an identifiable patient is protected health information, and must be encrypted, logged and covered by the BAA exactly as a consultation note is.

**Does data have to be hosted in the United States to satisfy HIPAA?** No. HIPAA imposes safeguards, not data localisation. EU hosting is compatible with HIPAA provided the technical safeguards and the BAA are in place — and it can simplify GDPR compliance at the same time.

**How long does a compliant deployment take?** At MedConnect, deployment typically takes two to four weeks depending on the number of sites, the hardware configuration and any integration or data-residency requirements. Ask any vendor for a written timeline that includes BAA signature.

To compare a full configuration, see the [telehealth kit](https://promotal-medconnect.com/en/telehealth-kit), review [pricing](https://promotal-medconnect.com/en/pricing), or [request a demo](https://promotal-medconnect.com/en/contact).

##  Related articles
[ [Image: Alternative à Healphi : comment comparer les deux mallettes]
Alternative à Healphi : comment comparer les deux mallettes

6 min read
](/en/blog-posts/alternative-healphi-comparaison-mallette-telemedecine)[ [Image: Home Telehealth Kits vs Clinical Telehealth Kits: Which One Does Your Organisation Need?]
Home Telehealth Kits vs Clinical Telehealth Kits: Which One Does Your Organisation Need?

7 min read
](/en/blog-posts/home-vs-clinical-telehealth-kit-what-organisations-need)[ [Image: Alternative à Parsys : gamme d'urgence ou plateforme clinique intégrée]
Alternative à Parsys : gamme d'urgence ou plateforme clinique intégrée

6 min read
](/en/blog-posts/alternative-parsys-comparaison-valise-telemedecine)
##  Discover our telehealth solutions
[
Telehealth platform

Video consultation, AI scribe, patient records
](/en/software/telehealth-platform) [
Telehealth cart

Integrated diagnostic devices
](/en/telehealth-cart) [
Diagnostic equipment

Connected ECG, stethoscope, dermatoscope
](/en/diagnostic-equipment)
###  Ready to discover MedConnect?

Request a personalized demo and see how the platform adapts to your practice.
[ Request a demo  ](/en/contact)