Telehealth Basics
Telehealth Privacy and Your Health Information
Short answer
In the US, health information shared with covered telehealth providers is generally protected under HIPAA, which sets rules for how that information can be used, stored, and shared. Beyond the legal baseline, it's worth checking each provider's own privacy policy, since practices around data sharing and marketing use can vary even among companies that are technically compliant.
Key facts
- HIPAA scope
- Applies to covered entities and their business associates
- What we collect on this site
- Only what's needed to route research inquiries; see our policy
- What we don't do
- We do not provide medical advice or store clinical records
- Provider policies
- Vary — review each provider's own privacy policy
What HIPAA does and doesn't cover
The Health Insurance Portability and Accountability Act (HIPAA) sets federal rules for how certain health information is protected by 'covered entities' — generally healthcare providers, health plans, and healthcare clearinghouses — and their business associates. Telehealth companies that provide clinical care typically fall under these rules when handling patient health information.
It's worth understanding that HIPAA is a floor, not a ceiling. It restricts certain uses and disclosures of health information, but companies can still have very different practices around things like using de-identified data for research, marketing communications, or third-party analytics, within what the law permits.
What to check in a provider's privacy policy
When reviewing a telehealth provider, look at their privacy policy for specifics: what information is collected, whether it's shared with advertisers or data brokers, how long it's retained, and what rights you have to access or delete it. A policy that specifically addresses health information, rather than only general website data, is a good sign of a provider that has thought carefully about the topic.
If a company's policy is unclear or you can't find a clear answer, it's reasonable to contact their support team directly and ask before sharing personal health details.
Video call and messaging security basics
Legitimate telehealth platforms typically use encrypted video and messaging tools designed to meet healthcare privacy requirements, rather than general-purpose consumer video chat apps. If a provider asks you to use a video platform not designed for healthcare, that's worth asking about directly.
On your end, using a private network and a device you control (rather than a shared or public computer) is a simple way to reduce risk during a telehealth visit.
What this site collects and does not collect
This site is an independent research and comparison resource — it is not a telehealth provider and does not deliver clinical care. We do not collect or store medical records, and we are not the party providing any care you may pursue with a telehealth company you find through this site.
Any general contact or usage information collected through this site is handled according to our own privacy policy, which we encourage you to review. If you choose to visit or sign up with a telehealth provider, that provider's own privacy policy — not this site's — governs how your health information is handled once you're in their system.
Practical steps to protect your own privacy
Beyond what providers are required to do, you can take your own steps: use strong, unique passwords for any telehealth account, avoid sharing account access, and periodically review what information you've provided to different services. If you stop using a provider, you can ask them directly about their data retention and deletion practices.
It's also reasonable to ask a provider, before your first visit, exactly who will have access to your visit notes and any prescriptions issued.
Limitations to keep in mind
- This guide explains general principles; it is not legal advice about HIPAA or privacy law.
- Privacy practices vary by company and can change, so always check a provider's current policy directly.
- Rules can differ for services that are not classified as HIPAA-covered entities.
Questions worth asking before you pay
- Is my health information shared with any third parties?
- How long is my data retained after I stop using the service?
- Who can access my visit notes and prescription history?
- What video or messaging platform is used, and is it healthcare-specific?
Frequently asked questions
Does HIPAA apply to every telehealth app?
It applies to covered entities and their business associates handling protected health information. Not every health-related app or wellness tool is a HIPAA-covered entity, so it's worth checking directly.
Does this website store my medical information?
No. This site is a research resource, not a healthcare provider, and does not collect or store medical records. Any information you share directly with a telehealth provider is governed by that provider's own privacy policy.
Can telehealth companies sell my health data?
HIPAA restricts many uses and disclosures of protected health information, but exact practices differ by company. Review the specific provider's privacy policy for details on data sharing.
Is video-based telehealth as private as an in-person visit?
It can be, when conducted over encrypted, healthcare-appropriate platforms in a private location. Using a public or shared device or network can reduce that privacy.