What Happens to Your Data After a Telehealth Visit: A 2026 Privacy Primer
HIPAA coverage, what covered entities can and can't do with your PHI, the de-identification question, and what to look for in a privacy policy before you share your medical history.
When you complete a telehealth intake, you're sharing medical history, conditions, medications, and sometimes sensitive diagnoses with a company that may have different data practices than your hospital or primary care physician. Here's what you should know about where your telehealth health data goes.
HIPAA and telehealth
HIPAA (the Health Insurance Portability and Accountability Act) applies to telehealth platforms that are "covered entities" — providers, health plans, and healthcare clearinghouses — and their business associates. Most legitimate telehealth platforms are covered entities or business associates and must follow HIPAA's privacy and security rules: minimum necessary disclosure, no selling of PHI, data security standards.
Direct-to-consumer health apps, wellness apps, and platforms that explicitly operate as 'wellness' rather than healthcare may not be HIPAA-covered entities. If a platform doesn't present itself as a healthcare provider and doesn't issue prescriptions through licensed providers, it may not have HIPAA obligations. The Yale study found several platforms in this gray zone.
What happens to your data at telehealth platforms
HIPAA-covered telehealth platforms can share your information with: (1) business associates (labs, pharmacies, billing companies) under Business Associate Agreements that require HIPAA compliance; (2) other providers for treatment purposes; (3) you, on request. They cannot sell your PHI to advertisers or third parties for marketing purposes without specific authorization.
What to look for in a platform's privacy policy:
- Explicit HIPAA compliance statement and covered entity status
- No statement that de-identified data is sold or licensed for research or advertising
- Clear explanation of what business associates can access your data
- Right to access your medical records on request
The de-identification question
HIPAA allows platforms to use "de-identified" data for any purpose, including research and product development, without patient authorization. True HIPAA de-identification under Safe Harbor or Expert Determination standards is robust — but "de-identified" claims vary in rigor. Read privacy policies carefully for language about de-identified data use.
Verified telehealth providers
Established HIPAA-compliant healthcare platform with clear privacy practices.
Paid link Get started →Transparent data practices, HIPAA-covered healthcare provider.
Paid link Get started →