Blog

California Telehealth Compliance Requirements: Part 2

Posted by Heather Danesh | Jul 24, 2026 | 0 Comments

PART 2 OF 4: Consent, Privacy, and Documentation

The patient-facing obligations that telehealth adds.

Beyond licensure, California imposes specific requirements on how telehealth encounters are consented to, kept private, and documented. These obligations protect patients and, handled well, protect the practice. This post addresses informed consent, privacy and security, and the recordkeeping that ties them together.

Informed consent for telehealth

California requires that the patient give consent to the use of telehealth before care is delivered by that method. The consent should reflect that the patient understands and agrees to receive services via telehealth, and it must be documented in the patient's record. Consent may be verbal or written depending on the setting, but the fact and content of consent should always be recorded.

Privacy and security

Telehealth encounters are subject to the same privacy obligations as any other care, under HIPAA and California's own privacy laws, which are in some respects stricter. Key practices include:

  • Using a platform that supports HIPAA-compliant, encrypted communication and is covered by a business associate agreement.

  • Confirming the patient is in a private setting and conducting the visit from one as well.

  • Handling any recording of the visit, and its storage, in accordance with privacy law and patient consent.

Documentation

A telehealth encounter should be documented as thoroughly as an in-person visit, with a few additions specific to the modality: the patient's location during the visit, the type of telehealth used (for example, audio-video or audio-only), confirmation of consent, and the clinical rationale where the modality is relevant to the care decision.

California-specific privacy considerations

California's privacy landscape, including the Confidentiality of Medical Information Act and related laws, can impose obligations beyond federal HIPAA requirements. Providers should ensure their telehealth practices account for these state-level protections rather than assuming HIPAA compliance is sufficient on its own.

How West Coast Health Law Can Help

We help practices build compliant telehealth consent, privacy, and documentation protocols that satisfy both HIPAA and California's stricter state requirements.

West Coast Health Law offers a FREE consultation which you may schedule by clicking the button on our website.

This article is provided for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws change and every situation is different; consult a qualified attorney about your specific circumstances.

About the Author

Heather Danesh

Dr. Heather N. Danesh is a healthcare attorney specializing in practice startups, transitions, regulatory compliance, and corporate healthcare governance. She provides strategic legal support to medical and dental practices, ensuring compliance with healthcare regulations and managing complex legal issues related to mergers, acquisitions, and practice formation.

Comments

There are no comments for this post. Be the first and Add your Comment below.

Leave a Comment