Updated September 2026 for the 42 CFR Part 2 rule now in effect.
Telehealth stopped being a pandemic workaround years ago. For behavioral health and substance use disorder (SUD) treatment, it is now a core delivery channel: intake screenings, individual therapy, group sessions, medication-assisted treatment (MAT) check-ins, and family sessions all happen over video. That shift moved a lot of protected health information (PHI) onto platforms that were never chosen with a security review in mind. Someone signed up for a video tool, it worked, and it stuck.
That is the gap worth closing. The clinical value of telehealth is settled. The security and compliance posture behind it, at most facilities, is not. Aida Keehner, Founder and CEO of Atruent, puts it plainly: “The platform your clinicians love is a business associate handling some of the most sensitive PHI in medicine. If you cannot answer basic questions about how it protects that data, you have a risk you are not managing.”
Why behavioral health telehealth carries extra weight under HIPAA and 42 CFR Part 2
Behavioral health organizations have more reason than most healthcare providers to ask those questions.
HIPAA-covered healthcare organizations and their business associates have obligations to protect PHI under HIPAA and HITECH.
Behavioral health and addiction treatment programs that are federally assisted and hold themselves out as providing SUD care carry a second layer: 42 CFR Part 2. A 2024 final rule, with compliance required as of February 16, 2026, brought Part 2 closer to HIPAA. Patients can now give a single consent for treatment, payment, and operations. HIPAA’s breach notification rules apply to Part 2 records. And HHS’s Office for Civil Rights now enforces Part 2 with the same civil penalties, complaints, and investigations it uses for HIPAA.
But Part 2 still has protections that go beyond HIPAA. Patient consent is required for many uses and disclosures HIPAA permits without it, SUD counseling notes require separate consent, and Part 2 records generally cannot be used in legal proceedings against a patient without the patient’s consent or a qualifying court order. A breach of SUD records can expose a patient to stigma, employment consequences, or legal problems in ways that many other healthcare disclosures may not.
That raises the bar for telehealth specifically. A session recording, a chat transcript, a stored screen share, or even metadata showing that a specific person attended an addiction-treatment appointment can be protected information. Under Part 2, anything that identifies someone as a patient is protected, and exposing it can trigger breach notification. The platform is not a neutral pipe. It is a place where confidential records are created, transmitted, and sometimes retained.
What to look for in a HIPAA- and Part 2-ready telehealth platform
Consumer-grade video tools and “free” telehealth tiers are where much of the risk lives. When you evaluate a platform, whether it is Doxy.me, a tool built into your EHR, or something a clinician found on their own, get straight answers on these points.
-
A signed Business Associate Agreement (BAA). No BAA, no PHI. The free tier of a platform often doesn’t include one even when the paid tier does. If Part 2 applies, determine whether the vendor also qualifies as a Qualified Service Organization (QSO) and make sure the agreement includes the required Part 2 protections. Do not assume a HIPAA BAA by itself satisfies the QSOA requirements.
-
Encryption in transit and at rest. Look for modern encryption in transit, such as TLS 1.2+ and DTLS-SRTP for video, and strong encryption such as AES-256 for stored recordings, chat logs, and files. FIPS 140-validated cryptographic modules provide an additional assurance worth looking for. True end-to-end encryption is stronger still, but it often disables cloud recording, transcription, and AI features, so know which mode you’re running.
-
Clear data retention and recording policies. Know whether sessions are recorded, where recordings live, who can access them, and how 42 CFR Part 2 consent is handled before anything is captured.
-
Access controls and audit logging. Unique logins per user, role-based access, multi-factor authentication, and logs that show who accessed what and when.
-
Data location and subcontractors. Where the data is hosted, and which downstream vendors touch it, both of which flow into your own compliance obligations.
-
AI scribes and transcription. If the platform or an add-on offers ambient note-taking or transcription, confirm the BAA covers it, how Part 2 consent is handled, whether session data is used to train models, and how long transcripts are kept.
-
Group session controls. Waiting rooms, host controls, blocking recording by participants, and display names that don’t identify people.
Consider Doxy.me, a common choice in behavioral health. It is browser-based, simple for patients, and offers a BAA even on its free plan for individual providers. A multi-clinician facility, though, typically needs a clinic-level agreement and admin controls. And no BAA makes a platform automatically compliant in your environment. The right plan tier has to be in place, and your own workflows (recording, note-taking, screen sharing) have to line up with Part 2.
A capable platform can still be used non-compliantly.
For MAT programs, one more moving part belongs on your radar. DEA’s telemedicine flexibilities for prescribing controlled substances are extended through December 31, 2026, while DEA continues work on a permanent special-registration framework. Track both alongside your privacy obligations.
The risks that show up in real facilities
The failure modes we see are rarely exotic. They are ordinary operational gaps:
-
Clinicians using personal accounts or a consumer video app because it was faster than the sanctioned tool.
-
Sessions on unmanaged personal or home devices: no MDM, no endpoint protection, no encryption, shared family logins.
-
Recordings saved to a local desktop or a personal cloud drive that no one is tracking.
-
Screen sharing that exposes other patients’ records.
-
Appointment reminders by text or email that name the SUD program, which can reveal that someone is a patient.
-
Tracking pixels and analytics scripts on scheduling or intake pages, as the FTC’s 2023–2024 actions against BetterHelp, Cerebral, and Monument showed.
-
No BAA on file, or a BAA that covers the vendor but not the specific integration in use.
-
Wi-Fi and network segments that mix clinical traffic with guest and personal devices.
-
Sessions held without confirming the patient’s identity, location, or privacy. Location also matters for crisis response.
Any one of these can turn a routine telehealth session into a reportable incident. None of them require a sophisticated attacker. They happen when no one owns the review of the workflow.
How this connects to CARF and accreditation
These controls also matter beyond HIPAA compliance.
For CARF-accredited organizations and those pursuing accreditation, information security is not a side conversation. CARF’s standards for services delivered through information and communication technologies (ICT) cover telehealth directly, including privacy, informed consent, and security protocols. Surveyors look for evidence that those risks are being managed. Executed BAAs, a documented platform-selection rationale, access controls, and clear recording and retention policies all help demonstrate that. The same documentation supports your HIPAA and Part 2 obligations at the same time.
The goal is not to make telehealth harder. It is to make the tool you already rely on defensible.
Why now
The enforcement picture has changed. OCR now handles Part 2 complaints and can impose penalties. Its HIPAA enforcement has focused heavily on missing or inadequate risk analyses. And HHS’s proposed HIPAA Security Rule update would make MFA, encryption, and technology asset inventories mandatory. Final action on that rule is now projected for July 2027, though agenda dates can shift. These controls are fast becoming the baseline auditors and cyber insurers expect.
A practical starting point
You do not need to rip out your current platform to make progress. Start with a short inventory:
-
List every video and messaging tool clinicians actually use, including the unofficial ones.
-
Confirm which have executed BAAs and which plan tier is in effect.
-
Document recording, retention, and consent handling for each, mapped against 42 CFR Part 2.
-
Check the devices and networks sessions run on, not just the software.
-
Close the gaps in priority order, starting with anything handling PHI without a BAA.
-
Fold telehealth into your HIPAA risk analysis, ongoing risk management, and incident response plan.
-
Confirm your Notice of Privacy Practices was updated for Part 2 by the February 16, 2026 deadline.
If that inventory turns up gaps, the next step is usually not replacing everything. It is determining which risks can be corrected through configuration, policy, device management, or vendor changes. Atruent helps behavioral health organizations across the Baltimore-DC corridor work through that process, translating HIPAA, HITECH, 42 CFR Part 2, and CARF expectations into a telehealth setup that clinicians can use without second-guessing the risk. If you are not sure where your platforms stand, that inventory is a good first conversation.
This article is general information, not legal advice. Confirm your specific obligations with qualified counsel.