exma Try exma free

Guide

Telehealth transcription: documenting virtual visits without breaking HIPAA

By the exma team · September 21, 2026 · 8 min read

TL;DR: A telehealth visit's audio is PHI the moment it identifies a patient — the platform being a video call instead of an in-person exam room changes nothing about that. The video-conferencing tool, and any AI scribe or transcription service added to the call, both need a signed BAA and the same encryption, access-control, and no-training standards as any other vendor touching clinical audio. The convenience of a general-purpose video or note-taking app is exactly where telehealth compliance most often quietly breaks.

PHI doesn't care what platform the visit happened on

HIPAA's definition of protected health information is about the content — identifiable health information — not the medium it travels through. A telehealth visit conducted over a dedicated platform, a phone call, or a consumer video app all produce the same kind of PHI as an in-person exam room conversation. Providers who would never dream of letting an unvetted vendor into a physical exam room sometimes treat the software stack behind a video visit as an afterthought — which is exactly backwards, since that software stack is now standing in the room.

Two vendors in every telehealth visit, both need a BAA

A typical telehealth visit involves at least two pieces of third-party software handling PHI: the video-conferencing platform carrying the call, and — increasingly — an AI scribe or transcription tool drafting the visit note. Both are business associates the moment they process the visit's audio or video, and both need a signed Business Associate Agreement before they're used for a clinical visit. We cover the general BAA and vendor-diligence standard in is AI transcription HIPAA-compliant — the telehealth-specific wrinkle is that it's easy to get the platform right and still overlook the second vendor.

The common gap: a practice signs a BAA with its telehealth platform, then a clinician independently adds a convenient AI note-taking extension to the call that was never vetted or covered by any agreement. The platform being compliant doesn't make the add-on compliant.

Why the video app you already use for personal calls usually isn't the right one

Many mainstream consumer video-calling apps either don't offer a BAA at all, or only make one available on a specific paid healthcare tier that's easy to miss when a team signs up for the free or standard plan. Using an account without a signed BAA for a clinical visit is a violation regardless of how strong that platform's encryption actually is — the missing BAA is the problem, not the technology.

Informed consent to receive care via telehealth — required in most states before the first virtual visit — is a separate question from consent to record and transcribe that visit. State recording-consent laws generally apply to a telehealth call the same way they'd apply to any recorded conversation. The safer practice is to disclose that the visit is being recorded and transcribed as its own explicit step, and document that disclosure, rather than assuming the general telehealth consent form already covers it.

The telehealth-specific vendor checklist

What to verify for each tool touching a telehealth visit
QuestionApplies to
Signed BAA on the plan actually in use (not just available)?Video platform + transcription/scribe tool
Encryption in transit and at rest?Both
No training on visit audio or transcripts?Both
Recording-consent disclosure given and documented?Practice workflow, independent of vendor
Retention and deletion controlled by the practice?Both

This is the same underlying diligence as the full 12-point security checklist for any confidential audio — telehealth just adds a second vendor to check and a consent step that's easy to assume is already covered.

Frequently asked questions

Is a telehealth visit recording PHI?

Yes — any audio or video that identifies the patient and relates to their health is PHI, regardless of whether the call ran over a dedicated platform, phone, or a general video app.

Does the video platform need a BAA?

Yes, since it transmits PHI on the provider's behalf. Many consumer apps only offer a BAA on a specific paid tier — verify it's actually signed on the plan in use.

Can an AI scribe join the visit to draft the note?

Only if it's also covered by a BAA and meets the same encryption, access-control, and no-training standards — adding an uncovered tool creates the same violation as an uncovered video platform.

Does telehealth consent cover recording the visit?

Not automatically — recording-consent law is separate from informed consent to telehealth care. Disclose and document the recording separately.

This article is general information, not legal advice. HIPAA obligations for telehealth depend on your role, your state's telehealth and recording-consent rules, and your specific data flows — consult your privacy officer or counsel.

Transcription built for the virtual visit

exma encrypts audio and transcripts in transit and at rest and signs BAAs for telehealth use, with data-use and retention terms set in your agreement — built for the same diligence a telehealth platform needs. Try it in your browser.

Create your free workspace