What does HIPAA require of a telehealth brand owner?
If the brand's company handles patient health information for the medical practice, and almost every telehealth brand does, it is a HIPAA business associate: a company that works with protected health information (PHI) on behalf of a healthcare provider. That status comes with duties. The brand must sign a business associate agreement (BAA) with the practice, follow the HIPAA Security Rule for any patient data it touches (a written risk analysis, access controls, encryption, staff training, and written policies), report breaches to the practice, and sign BAAs with its own vendors that handle patient data, such as email, SMS, and support tools. The medical practice is the covered entity and carries the full Privacy Rule duties to patients. Marketing tools are where brands most often slip: a pixel that sends health information from intake or account pages to an ad platform can be an unauthorized disclosure. On Tessic Health, a BAA is signed with every client before any patient data moves, and an independent auditor examines the platform's controls every year for SOC 2 Type II.
Reviewed September 11, 2026 · 8 min read
In short
- A brand that handles patient data for the practice is a HIPAA business associate.
- Sign a BAA with the practice and with every vendor that touches patient data.
- Run a written risk analysis and keep HIPAA records for six years.
- Keep health information out of ad pixels and tracking scripts.
- Health data outside HIPAA still falls under FTC and state privacy laws.
On this page
Who is who under HIPAA
HIPAA assigns duties by role. A covered entity is a healthcare provider, health plan, or clearinghouse. A business associate is any company that handles PHI on a covered entity's behalf.
| Party | HIPAA role | Main duties | On Tessic Health |
|---|---|---|---|
| The medical practice (the PC) | Covered entity | Privacy Rule, Security Rule, breach notification, patient rights such as access to records, and a notice of privacy practices | Held in a structure drafted for the client's ownership; PHI belongs to the client's clinic |
| The brand's company (the MSO) | Business associate | A BAA with the practice, Security Rule safeguards, breach reports to the practice, BAAs with its own vendors, and using only the PHI a task needs | The client's company, responsible for its own marketing tools and staff access |
| The platform | Business associate | The same duties, for the systems it runs | A BAA signed with every client before any PHI moves |
| Vendors that touch PHI (email, SMS, hosting, help desk) | Subcontractor business associates | A BAA with whoever hired them, and the same safeguards | Tessic's subprocessors are bound by equivalent agreements and reviewed every year |
| Ad platforms and most analytics tools | Not business associates | They generally will not sign a BAA, so PHI must not reach them | The brand controls its own tags; PHI stays out of them |
The legal definitions are in 45 CFR 160.103. How the brand's company and the medical practice split their roles is explained in Do I need a medical license to start a telehealth company?
Start here
Do I need a medical license to start a telehealth company?
No. Licensed clinicians own the medical practice and the founder's company owns the business. Here is exactly who needs which license, and how the two companies fit together.
Read the guideThe brand owner's HIPAA checklist
Sign the BAA with the practice
The BAA sets what the brand may do with PHI, the safeguards it must keep, how fast it reports a breach, and what happens to the data when the relationship ends.
Run a written risk analysis
The Security Rule requires an honest review of where PHI lives in the brand's systems, what could go wrong, and how each risk is handled. Update it whenever systems change.
Name a security official and write the policies
One named person owns HIPAA security. Written policies cover access, passwords, devices, remote work, and incident response.
Limit and log access
Give each employee access only to the PHI their job needs, require multi-factor authentication, remove access the day someone leaves, and keep logs of who viewed what.
Encrypt
Encrypt PHI in transit and at rest, on laptops and phones as well as servers.
Train the team
Everyone who can see PHI gets HIPAA training when hired and on a regular schedule after that, with a record kept each time.
Sign BAAs with vendors
Any tool that stores or processes PHI needs a BAA before patient data goes in: email and SMS platforms, help desks, e-signature tools, and cloud storage. No BAA means no PHI in that tool.
Audit the marketing tags
Review every pixel, tag, and conversion tool on intake, checkout, and account pages. Remove anything that sends health information to an ad or analytics vendor that has not signed a BAA, unless the patient has given written HIPAA authorization.
Plan for a breach
Write down who does what when data is exposed, and rehearse it. Under the BAA, the brand reports breaches to the practice.
Keep the paperwork
HIPAA requires policies, risk analyses, and related records to be kept for six years.
Pixels, tracking, and ad data
A pixel is a small piece of code from an ad or analytics company that reports what visitors do on a website. On an ordinary store it counts purchases. On a telehealth intake form it can report that an identifiable visitor answered questions about their weight, medications, or sexual health, and that is a disclosure of PHI to a company that has not signed a BAA.
The HHS Office for Civil Rights has issued guidance on online tracking technologies for HIPAA-regulated businesses. In American Hospital Association v. Becerra, a federal court in Texas vacated part of it: the part that treated tracking on public pages, which anyone can view without logging in, as a HIPAA disclosure. Pages behind a login, patient portals, and forms that collect health information are still covered, and those are the pages a telehealth brand runs its sign-up flow through.
The FTC has acted on the same problem outside HIPAA, bringing cases against GoodRx, BetterHelp, and Cerebral for sharing consumers' health information with advertising platforms. The working rule for a brand: no third-party ad or analytics tags on intake, checkout, or account pages unless the vendor has signed a BAA or the patient has given HIPAA authorization, and no health details in the conversion events sent back to ad platforms. What rules apply when you advertise GLP-1 weight loss drugs covers the claims side of the same campaigns.
Who has to be told after a breach, and when
Deadlines run from the day the breach is discovered, or should have been discovered with reasonable diligence.
| Who is told | By whom | Deadline |
|---|---|---|
| The medical practice | The brand's company, as a business associate | Without unreasonable delay and no later than 60 days, or sooner if the BAA says so |
| Affected patients | The practice | Without unreasonable delay and no later than 60 days |
| HHS | The practice | Within 60 days when 500 or more people are affected; otherwise in a yearly log due within 60 days after the calendar year ends |
| Local media | The practice | Within 60 days when more than 500 residents of one state are affected |
From the HIPAA Breach Notification Rule, 45 CFR Part 164, Subpart D.
Health data outside HIPAA
Some health information a brand collects never enters the medical record, such as answers to a marketing quiz before any visit. Other laws cover it:
- The FTC Act, which the FTC has used against companies that shared health data with advertisers against their own privacy promises.
- The FTC's Health Breach Notification Rule, which requires health apps and similar services outside HIPAA to notify consumers and the FTC after an unauthorized disclosure, including sharing with advertisers.
- Washington's My Health My Data Act, which requires consent before collecting or sharing consumer health data and lets consumers sue.
- Other state privacy laws with special rules for sensitive health data.
- The safe standard is to treat every piece of health information the brand collects as if HIPAA applied to it.
Does HIPAA apply to cash-pay telehealth?
HIPAA's rules attach to a healthcare provider that conducts standard electronic transactions, such as billing insurance or checking insurance eligibility electronically. Most telehealth practices do at least one of these, which makes them covered entities and their vendors business associates. A practice that is strictly cash-pay may fall outside the definition.
That rarely changes what a brand should do. Cash-pay practices still face the FTC Act, the Health Breach Notification Rule, state health privacy laws, and state medical records laws, and pharmacies, labs, and partners expect HIPAA-grade handling regardless. LegitScript also checks HIPAA compliance when it reviews a telehealth brand; see how to get approved for Meta and Google ads. Build to HIPAA from the first patient.
Where the platform's duties stop and the brand's begin
A platform can run HIPAA-grade systems and still cannot control what a brand puts on its own website or which of the brand's staff can export a patient list. On Tessic Health, a BAA is signed with every client before any PHI moves, data is encrypted with TLS 1.2+ in transit and AES-256 at rest, every access to patient data is written to an audit log no one can edit, and PHI belongs to the client's clinic and is portable at any time. The brand owns its marketing tools and its staff's access. Details are on the security page, and who owns the patients covers what happens to the records if a brand ever leaves.
COMMON QUESTIONS
What founders ask next.
- Is my brand a covered entity or a business associate?
- Usually a business associate. The medical practice that treats patients is the covered entity. The brand's company, which runs the website, intake, billing, and support for the practice, handles PHI on the practice's behalf, which makes it a business associate with HIPAA duties and liability of its own.
- Do I need a BAA with my email or SMS provider?
- Yes, if patient information passes through it. Appointment reminders, refill notices, and messages that mention a treatment all contain PHI. Use a vendor that will sign a BAA, and keep marketing tools that will not sign one away from patient data entirely.
- Can I use the Meta pixel on my telehealth site?
- Not on pages that collect or reveal health information, such as intake forms, checkout, and the patient portal, unless patients have given HIPAA authorization. Meta does not sign BAAs. A common setup keeps pixels on public marketing pages only and sends conversion events that contain no health details.
- What happens after a breach?
- The brand reports it to the practice as the BAA requires, and no later than 60 days after discovery. The practice notifies affected patients within 60 days, reports to HHS, and alerts local media when more than 500 residents of one state are affected. Document every step, because regulators will ask for the record.
- Who handles HIPAA on Tessic Health?
- Both parties, each for its own part. Tessic signs a BAA with every client before any PHI moves and runs the platform's controls: encryption, quarterly access reviews, audit logging, annual penetration testing, and incident response. The brand is responsible for its own marketing tools, its own vendors, and which of its staff can see patient data.
- Does HIPAA apply to cash-pay telehealth?
- Sometimes not, strictly speaking: HIPAA covers providers that conduct standard electronic transactions such as insurance billing. But cash-pay brands still face the FTC Act, the FTC's Health Breach Notification Rule, and state health privacy laws such as Washington's My Health My Data Act, and partners expect HIPAA-grade handling. Build to HIPAA either way.
KEEP READING
The next questions on the list.
- Read the answer
Start here
Do I need a medical license to start a telehealth company?
- Read the answer
Ownership
Who owns the patients on a white-label telehealth platform?
- Read the answer
Launch planning
What do I need before my telehealth clinic sees its first patient?
- Read the answer
Advertising
How do I get my telehealth brand approved for Meta and Google ads?
- Read the answer
Ownership
What happens to my clinic if I leave my telehealth platform?
- Read the answer
Advertising
What can I legally say in weight loss marketing?
SOURCES
- eCFR: 45 CFR 160.103, HIPAA definitions (covered entity, business associate)
- eCFR: 45 CFR Part 164, Subpart D, breach notification
- Holland & Knight: American Hospital Assn. v. Becerra and the HHS tracking guidance
- FTC: Enforcement action against GoodRx for sharing health data with advertisers
- FTC: Health Breach Notification Rule
- Washington Attorney General: My Health My Data Act
Reviewed September 11, 2026. Tessic Health guides are general information for founders, not legal advice. Laws, agency guidance, and ad platform policies change; confirm the specifics for your business with health-care counsel. Tessic Health claims restate what tessichealth.com publishes on its pricing, platform, and security pages.