PART 2 OF 4: Consent, Privacy, and Documentation
The patient-facing obligations that telehealth adds.
Beyond licensure, California imposes specific requirements on how telehealth encounters are consented to, kept private, and documented. These obligations protect patients and, handled well, protect the practice. This post addresses informed consent, privacy and security, and the recordkeeping that ties them together.
Informed consent for telehealth
California requires that the patient give consent to the use of telehealth before care is delivered by that method. The consent should reflect that the patient understands and agrees to receive services via telehealth, and it must be documented in the patient's record. Consent may be verbal or written depending on the setting, but the fact and content of consent should always be recorded.
Privacy and security
Telehealth encounters are subject to the same privacy obligations as any other care, under HIPAA and California's own privacy laws, which are in some respects stricter. Key practices include:
-
Using a platform that supports HIPAA-compliant, encrypted communication and is covered by a business associate agreement.
-
Confirming the patient is in a private setting and conducting the visit from one as well.
-
Handling any recording of the visit, and its storage, in accordance with privacy law and patient consent.
Documentation
A telehealth encounter should be documented as thoroughly as an in-person visit, with a few additions specific to the modality: the patient's location during the visit, the type of telehealth used (for example, audio-video or audio-only), confirmation of consent, and the clinical rationale where the modality is relevant to the care decision.
California-specific privacy considerations
California's privacy landscape, including the Confidentiality of Medical Information Act and related laws, can impose obligations beyond federal HIPAA requirements. Providers should ensure their telehealth practices account for these state-level protections rather than assuming HIPAA compliance is sufficient on its own.
How West Coast Health Law Can Help
We help practices build compliant telehealth consent, privacy, and documentation protocols that satisfy both HIPAA and California's stricter state requirements.
West Coast Health Law offers a FREE consultation which you may schedule by clicking the button on our website.
This article is provided for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws change and every situation is different; consult a qualified attorney about your specific circumstances.
Comments
There are no comments for this post. Be the first and Add your Comment below.
Leave a Comment