Privacy

What Happens to Your Data After a Telehealth Visit: A 2026 Privacy Primer

HIPAA coverage, what covered entities can and can't do with your PHI, the de-identification question, and what to look for in a privacy policy before you share your medical history.

7 min read 2026 · virtualhealthvisits.com

When you complete a telehealth intake, you're sharing medical history, conditions, medications, and sometimes sensitive diagnoses with a company that may have different data practices than your hospital or primary care physician. Here's what you should know about where your telehealth health data goes.

HIPAA and telehealth

HIPAA (the Health Insurance Portability and Accountability Act) applies to telehealth platforms that are "covered entities" — providers, health plans, and healthcare clearinghouses — and their business associates. Most legitimate telehealth platforms are covered entities or business associates and must follow HIPAA's privacy and security rules: minimum necessary disclosure, no selling of PHI, data security standards.

What HIPAA doesn't cover

Direct-to-consumer health apps, wellness apps, and platforms that explicitly operate as 'wellness' rather than healthcare may not be HIPAA-covered entities. If a platform doesn't present itself as a healthcare provider and doesn't issue prescriptions through licensed providers, it may not have HIPAA obligations. The Yale study found several platforms in this gray zone.

What happens to your data at telehealth platforms

HIPAA-covered telehealth platforms can share your information with: (1) business associates (labs, pharmacies, billing companies) under Business Associate Agreements that require HIPAA compliance; (2) other providers for treatment purposes; (3) you, on request. They cannot sell your PHI to advertisers or third parties for marketing purposes without specific authorization.

What to look for in a platform's privacy policy:

  • Explicit HIPAA compliance statement and covered entity status
  • No statement that de-identified data is sold or licensed for research or advertising
  • Clear explanation of what business associates can access your data
  • Right to access your medical records on request

The de-identification question

HIPAA allows platforms to use "de-identified" data for any purpose, including research and product development, without patient authorization. True HIPAA de-identification under Safe Harbor or Expert Determination standards is robust — but "de-identified" claims vary in rigor. Read privacy policies carefully for language about de-identified data use.

Verified telehealth providers

Sesame Care$175 commission

Established HIPAA-compliant healthcare platform with clear privacy practices.

Get started →
Wellorithm$350 commission

Transparent data practices, HIPAA-covered healthcare provider.

Get started →
Medical disclaimer: This content is informational and does not constitute medical advice. Always consult a licensed provider before starting any treatment. Affiliate disclosure: Links labeled "Paid link" are paid partnerships. This site earns a commission at no cost to you.