A PT at a remote VA clinic downloads a free video-calling app mid-shift to save five minutes between two telehealth visits. The app seems simple enough, offers clear video, and takes seconds to set up. But by lunchtime, that single choice has created a reportable incident at her facility. The app carries no signed Business Associate Agreement with the VA. It doesn't meet encryption standards. It hasn't been authorized under her agency's information security framework. One clinic coordinator, one shortcut, one moment of pressure, and now the compliance office is involved.
Telehealth is reshaping how federal physical therapists deliver care to service members, veterans, and federally insured patients. It extends access across geographic distance, reduces return-to-duty delays, and keeps mission-ready patients in motion. Yet telehealth's convenience creates real compliance risk if clinicians don't know where the guardrails are. The Health Insurance Portability and Accountability Act (HIPAA), overlaid with federal agency-specific security rules, sets a baseline that many clinicians underestimate. This guide will help federal PTs run a quick compliance check before any telehealth visit: confirm the platform has a signed BAA and authorization-to-operate coverage, verify encryption and multi-factor authentication are active, and document informed consent and identity verification on every session.
What are the new telehealth rules for 2026?
Congress has repeatedly extended Medicare telehealth flexibilities originally enacted under the CARES Act through continuing resolutions, affecting reimbursement parity for federally insured patients seen via telehealth. The DEA's telehealth prescribing flexibilities for controlled substances, extended multiple times since the COVID-19 public health emergency ended, still require an in-person evaluation before certain prescriptions unless a qualifying exception applies. DoD and VA telehealth directives are being updated to align internal policy with these statutory changes, so PT clinicians should confirm current guidance with their facility's compliance office rather than relying on general Medicare rules. HHS Office for Civil Rights has ended its COVID-era telehealth HIPAA enforcement discretion, meaning federal telehealth platforms are now expected to meet full HIPAA Security Rule requirements.
Understanding military physical therapy standards and requirements is essential, since DoD telehealth policy updates roll out incrementally across service branches and commands.
What are the HIPAA requirements for telehealth?
The HIPAA Security Rule requires three safeguard categories for any system transmitting protected health information during a telehealth visit: administrative, physical, and technical. Any third-party telehealth vendor must operate under a signed Business Associate Agreement before a federal PT clinic can route patient video, audio, or messaging data through its platform. Encryption in transit and at rest, along with unique user authentication, functions as an effectively mandatory technical safeguard. Federal facilities layer HIPAA on top of the Privacy Act of 1974 and agency-specific directives, so a platform can be HIPAA-compliant in general terms yet still fail a facility's internal authorization to operate.
Your facility's EHR team can clarify which platforms carry both the Business Associate Agreement and the required authorization before you schedule the first session. As we detail in our resources on federal electronic health records systems, the authorization-to-operate document is distinct from a general vendor contract and must be reviewed by your compliance office.
What is the new HIPAA rule in 2026?
HHS's proposed update to the HIPAA Security Rule would eliminate the current addressable category and make nearly every listed safeguard mandatory. The proposal would require multi-factor authentication for any system holding electronic protected health information, network segmentation, and an annual independent audit of technical controls. Covered entities would need to maintain a current technology asset inventory and network map, and restore access to patient data within a defined window following an outage or attack. Federal PT clinics should track the rule's finalization through their agency privacy office, since federal systems typically fold updated HIPAA benchmarks into their own authorization-to-operate renewal cycles.
"Healthcare remains among the most frequently targeted sectors for data breaches, a trend cited as a driving factor behind stronger federal technical safeguard requirements."
What are the 4 domains of telehealth?
Telehealth modalities serve different clinical purposes, and each carries its own compliance footprint. Live video, or synchronous care, replicates a real-time PT evaluation or follow-up and is the modality most federal telehealth PT visits currently use. Store-and-forward, or asynchronous transmission, lets a PT review recorded video of a home exercise attempt or a photo of a healing incision without a live connection. Remote patient monitoring uses connected devices such as wearable activity trackers to feed objective mobility data into a return-to-duty file between visits. Mobile health apps deliver home exercise programs and adherence tracking directly to a patient's phone, extending care between scheduled sessions.
- Live video: A PT conducts a real-time shoulder range-of-motion assessment via secure platform, documents findings, and adjusts the home program on the spot.
- Store-and-forward: A service member at a forward location records themselves performing assigned exercises, uploads the video to the secure portal, and the PT reviews it hours later to confirm form and provide feedback.
- Remote patient monitoring: A veteran recovering from knee surgery wears a connected activity tracker that automatically feeds step count and gait symmetry data into the clinic's EHR between appointments, triggering alerts if progression stalls.
- Mobile health apps: A patient downloads the clinic's authorized app to access their home exercise program, logs completion, and receives a reminder notification the next morning.
Research documents that telehealth modalities improve access to rehabilitation care for patients facing geographic or mobility barriers to in-person visits. As detailed in our guide to telemedicine physical therapy in federal healthcare systems, each modality requires the same core compliance safeguards, BAA, authorization, encryption, multi-factor authentication, regardless of which data transmission method your clinic chooses.
Identity and access management protects patient data across cloud-based systems
Role-based access control limits which staff, such as a treating PT versus a records clerk, can open a given patient's telehealth session notes or recording. Federal telehealth platforms hosted in the cloud must carry a FedRAMP authorization at the appropriate impact level before a DoD or VA facility can route protected health information through them. Multi-factor authentication on every clinician login, paired with automatic session timeout after a set period of inactivity, is treated as a baseline identity control. Audit logs recording every access to a patient's telehealth record should be reviewed on a defined schedule, since undetected excess access is a common finding in federal privacy audits.
What are HIPAA-compliant telehealth platforms?
Platforms purpose-built for federal use, such as VA Video Connect and telehealth modules integrated into MHS GENESIS, are pre-authorized for protected health information because they already carry the required agreement and cloud authorization. Consumer video tools like a personal video-calling account are not appropriate for a clinical telehealth visit involving patient data, since neither carries a signed Business Associate Agreement with the federal facility. A clinic evaluating any new platform should confirm three things before first use: a signed BAA is on file, the facility's authorization to operate covers this specific tool, and encryption is enabled by default. Using a non-approved app for even a single call creates a reportable incident at most federal facilities regardless of whether patient data was actually exposed.
- Signed BAA on file: Confirm with your compliance office that a Business Associate Agreement exists and is current. Request a copy if you're unsure.
- ATO coverage confirmed: Ask your information security office whether this specific platform holds an authorization-to-operate that covers your facility and patient population.
- Encryption enabled by default: Test the platform before your first patient session. Verify that the system encrypts data in transit (SSL/TLS) and at rest, and does not prompt you to opt in to encryption.
"Telehealth platforms used for clinical care should offer secure, encrypted connections and should not rely on standard consumer video-calling apps that lack safeguards for protected health information."
Telehealth regulations differ by state, but federal PTs often practice under a separate exemption
Civilian PTs delivering telehealth across state lines generally need a license in the patient's state or participation in the PT Compact. PTs employed by a federal agency typically practice under a federal supremacy exemption that allows a single active state license to cover care delivered to federal beneficiaries nationwide, regardless of the patient's physical location. This exemption applies to federal employment and federal beneficiaries specifically; a federally employed PT seeing patients outside that scope is still bound by ordinary state telehealth licensure rules. Facilities should keep documentation of the federal exemption basis on file, since a state licensing board unfamiliar with the carve-out may otherwise question a telehealth encounter during an audit.
Clarity on your own licensure posture is part of the compliance foundation. Review the detail in our resource on federal scope of practice for physical therapists to confirm your exemption status and document it in your facility's compliance file.
Documentation and informed consent close the compliance loop
Informed consent for a telehealth PT visit should be documented before the first session and should name the specific risks of remote care, including the limits of a virtual exam and the plan for a technology failure mid-session. Clinicians should verbally confirm the patient's identity and current physical location at the start of every telehealth visit, both for safety planning and to support the licensure exemption described above. Sharing telehealth norms with the patient in the first minute of a visit, such as confirming they are in a private room and that the session is not being recorded unless separate consent was obtained, reduces the most common documentation gaps found in federal telehealth audits. Session notes should record the modality used alongside clinical content, since the modality itself is an auditable compliance data point.
Documentation practices matter as much as technology choices. A simple template checklist, identity verified, location confirmed, consent obtained, modality recorded, takes thirty seconds to complete and protects both the patient and your facility during an audit.
Bringing secure telehealth into daily practice
The details above might seem like overhead. They're not. A federal PT working within compliant systems builds patient trust, reduces liability exposure, and contributes to mission-ready outcomes. Point clinicians in your facility to your privacy or information security office as the authoritative source before adopting any new telehealth tool. Readiness and quality care depend on secure systems as much as clinical skill, and enhancing quality care throughout the entire field starts with getting the compliance basics right on every visit. Connect with peers who navigate these challenges daily and find resources at federalpt.org.
