Guide
Telehealth transcription: documenting virtual visits without breaking HIPAA
By the exma team · September 21, 2026 · 8 min read
TL;DR: A telehealth visit's audio is PHI the moment it identifies a patient — the platform being a video call instead of an in-person exam room changes nothing about that. The video-conferencing tool, and any AI scribe or transcription service added to the call, both need a signed BAA and the same encryption, access-control, and no-training standards as any other vendor touching clinical audio. The convenience of a general-purpose video or note-taking app is exactly where telehealth compliance most often quietly breaks.
PHI doesn't care what platform the visit happened on
HIPAA's definition of protected health information is about the content — identifiable health information — not the medium it travels through. A telehealth visit conducted over a dedicated platform, a phone call, or a consumer video app all produce the same kind of PHI as an in-person exam room conversation. Providers who would never dream of letting an unvetted vendor into a physical exam room sometimes treat the software stack behind a video visit as an afterthought — which is exactly backwards, since that software stack is now standing in the room.
Two vendors in every telehealth visit, both need a BAA
A typical telehealth visit involves at least two pieces of third-party software handling PHI: the video-conferencing platform carrying the call, and — increasingly — an AI scribe or transcription tool drafting the visit note. Both are business associates the moment they process the visit's audio or video, and both need a signed Business Associate Agreement before they're used for a clinical visit. We cover the general BAA and vendor-diligence standard in is AI transcription HIPAA-compliant — the telehealth-specific wrinkle is that it's easy to get the platform right and still overlook the second vendor.
Why the video app you already use for personal calls usually isn't the right one
Many mainstream consumer video-calling apps either don't offer a BAA at all, or only make one available on a specific paid healthcare tier that's easy to miss when a team signs up for the free or standard plan. Using an account without a signed BAA for a clinical visit is a violation regardless of how strong that platform's encryption actually is — the missing BAA is the problem, not the technology.
Consent to telehealth isn't consent to record
Informed consent to receive care via telehealth — required in most states before the first virtual visit — is a separate question from consent to record and transcribe that visit. State recording-consent laws generally apply to a telehealth call the same way they'd apply to any recorded conversation. The safer practice is to disclose that the visit is being recorded and transcribed as its own explicit step, and document that disclosure, rather than assuming the general telehealth consent form already covers it.
The telehealth-specific vendor checklist
| Question | Applies to |
|---|---|
| Signed BAA on the plan actually in use (not just available)? | Video platform + transcription/scribe tool |
| Encryption in transit and at rest? | Both |
| No training on visit audio or transcripts? | Both |
| Recording-consent disclosure given and documented? | Practice workflow, independent of vendor |
| Retention and deletion controlled by the practice? | Both |
This is the same underlying diligence as the full 12-point security checklist for any confidential audio — telehealth just adds a second vendor to check and a consent step that's easy to assume is already covered.
Frequently asked questions
Is a telehealth visit recording PHI?
Yes — any audio or video that identifies the patient and relates to their health is PHI, regardless of whether the call ran over a dedicated platform, phone, or a general video app.
Does the video platform need a BAA?
Yes, since it transmits PHI on the provider's behalf. Many consumer apps only offer a BAA on a specific paid tier — verify it's actually signed on the plan in use.
Can an AI scribe join the visit to draft the note?
Only if it's also covered by a BAA and meets the same encryption, access-control, and no-training standards — adding an uncovered tool creates the same violation as an uncovered video platform.
Does telehealth consent cover recording the visit?
Not automatically — recording-consent law is separate from informed consent to telehealth care. Disclose and document the recording separately.
This article is general information, not legal advice. HIPAA obligations for telehealth depend on your role, your state's telehealth and recording-consent rules, and your specific data flows — consult your privacy officer or counsel.
Transcription built for the virtual visit
exma encrypts audio and transcripts in transit and at rest and signs BAAs for telehealth use, with data-use and retention terms set in your agreement — built for the same diligence a telehealth platform needs. Try it in your browser.
Create your free workspace