Telehealth Security for Behavioral Health: How to Vet a Platform Before You Trust It

Person with a headset sits at a wooden desk, taking notes while a laptop shows a video call screen.

Updated September 2026 for the 42 CFR Part 2 rule now in effect.

Telehealth stopped being a pandemic workaround years ago. For behavioral health and substance use disorder (SUD) treatment, it is now a core delivery channel: intake screenings, individual therapy, group sessions, medication-assisted treatment (MAT) check-ins, and family sessions all happen over video. That shift moved a lot of protected health information (PHI) onto platforms that were never chosen with a security review in mind. Someone signed up for a video tool, it worked, and it stuck.

That is the gap worth closing. The clinical value of telehealth is settled. The security and compliance posture behind it, at most facilities, is not. Aida Keehner, Founder and CEO of Atruent, puts it plainly: “The platform your clinicians love is a business associate handling some of the most sensitive PHI in medicine. If you cannot answer basic questions about how it protects that data, you have a risk you are not managing.”

Why behavioral health telehealth carries extra weight under HIPAA and 42 CFR Part 2

Behavioral health organizations have more reason than most healthcare providers to ask those questions.

HIPAA-covered healthcare organizations and their business associates have obligations to protect PHI under HIPAA and HITECH.

Behavioral health and addiction treatment programs that are federally assisted and hold themselves out as providing SUD care carry a second layer: 42 CFR Part 2. A 2024 final rule, with compliance required as of February 16, 2026, brought Part 2 closer to HIPAA. Patients can now give a single consent for treatment, payment, and operations. HIPAA’s breach notification rules apply to Part 2 records. And HHS’s Office for Civil Rights now enforces Part 2 with the same civil penalties, complaints, and investigations it uses for HIPAA.

But Part 2 still has protections that go beyond HIPAA. Patient consent is required for many uses and disclosures HIPAA permits without it, SUD counseling notes require separate consent, and Part 2 records generally cannot be used in legal proceedings against a patient without the patient’s consent or a qualifying court order. A breach of SUD records can expose a patient to stigma, employment consequences, or legal problems in ways that many other healthcare disclosures may not.

That raises the bar for telehealth specifically. A session recording, a chat transcript, a stored screen share, or even metadata showing that a specific person attended an addiction-treatment appointment can be protected information. Under Part 2, anything that identifies someone as a patient is protected, and exposing it can trigger breach notification. The platform is not a neutral pipe. It is a place where confidential records are created, transmitted, and sometimes retained.

What to look for in a HIPAA- and Part 2-ready telehealth platform

Consumer-grade video tools and “free” telehealth tiers are where much of the risk lives. When you evaluate a platform, whether it is Doxy.me, a tool built into your EHR, or something a clinician found on their own, get straight answers on these points.

  • A signed Business Associate Agreement (BAA). No BAA, no PHI. The free tier of a platform often doesn’t include one even when the paid tier does. If Part 2 applies, determine whether the vendor also qualifies as a Qualified Service Organization (QSO) and make sure the agreement includes the required Part 2 protections. Do not assume a HIPAA BAA by itself satisfies the QSOA requirements.

  • Encryption in transit and at rest. Look for modern encryption in transit, such as TLS 1.2+ and DTLS-SRTP for video, and strong encryption such as AES-256 for stored recordings, chat logs, and files. FIPS 140-validated cryptographic modules provide an additional assurance worth looking for. True end-to-end encryption is stronger still, but it often disables cloud recording, transcription, and AI features, so know which mode you’re running.

  • Clear data retention and recording policies. Know whether sessions are recorded, where recordings live, who can access them, and how 42 CFR Part 2 consent is handled before anything is captured.

  • Access controls and audit logging. Unique logins per user, role-based access, multi-factor authentication, and logs that show who accessed what and when.

  • Data location and subcontractors. Where the data is hosted, and which downstream vendors touch it, both of which flow into your own compliance obligations.

  • AI scribes and transcription. If the platform or an add-on offers ambient note-taking or transcription, confirm the BAA covers it, how Part 2 consent is handled, whether session data is used to train models, and how long transcripts are kept.

  • Group session controls. Waiting rooms, host controls, blocking recording by participants, and display names that don’t identify people.

Consider Doxy.me, a common choice in behavioral health. It is browser-based, simple for patients, and offers a BAA even on its free plan for individual providers. A multi-clinician facility, though, typically needs a clinic-level agreement and admin controls. And no BAA makes a platform automatically compliant in your environment. The right plan tier has to be in place, and your own workflows (recording, note-taking, screen sharing) have to line up with Part 2.

A capable platform can still be used non-compliantly.

For MAT programs, one more moving part belongs on your radar. DEA’s telemedicine flexibilities for prescribing controlled substances are extended through December 31, 2026, while DEA continues work on a permanent special-registration framework. Track both alongside your privacy obligations.

The risks that show up in real facilities

Personal laptop on a kitchen table starting a telehealth session, with a personal phone showing notifications beside it.
A session launched from a personal laptop at the kitchen table, with a personal phone buzzing beside it, is exactly the kind of gap a telehealth inventory should catch.

The failure modes we see are rarely exotic. They are ordinary operational gaps:

  • Clinicians using personal accounts or a consumer video app because it was faster than the sanctioned tool.

  • Sessions on unmanaged personal or home devices: no MDM, no endpoint protection, no encryption, shared family logins.

  • Recordings saved to a local desktop or a personal cloud drive that no one is tracking.

  • Screen sharing that exposes other patients’ records.

  • Appointment reminders by text or email that name the SUD program, which can reveal that someone is a patient.

  • Tracking pixels and analytics scripts on scheduling or intake pages, as the FTC’s 2023–2024 actions against BetterHelp, Cerebral, and Monument showed.

  • No BAA on file, or a BAA that covers the vendor but not the specific integration in use.

  • Wi-Fi and network segments that mix clinical traffic with guest and personal devices.

  • Sessions held without confirming the patient’s identity, location, or privacy. Location also matters for crisis response.

Any one of these can turn a routine telehealth session into a reportable incident. None of them require a sophisticated attacker. They happen when no one owns the review of the workflow.

How this connects to CARF and accreditation

These controls also matter beyond HIPAA compliance.

For CARF-accredited organizations and those pursuing accreditation, information security is not a side conversation. CARF’s standards for services delivered through information and communication technologies (ICT) cover telehealth directly, including privacy, informed consent, and security protocols. Surveyors look for evidence that those risks are being managed. Executed BAAs, a documented platform-selection rationale, access controls, and clear recording and retention policies all help demonstrate that. The same documentation supports your HIPAA and Part 2 obligations at the same time.

The goal is not to make telehealth harder. It is to make the tool you already rely on defensible.

Why now

The enforcement picture has changed. OCR now handles Part 2 complaints and can impose penalties. Its HIPAA enforcement has focused heavily on missing or inadequate risk analyses. And HHS’s proposed HIPAA Security Rule update would make MFA, encryption, and technology asset inventories mandatory. Final action on that rule is now projected for July 2027, though agenda dates can shift. These controls are fast becoming the baseline auditors and cyber insurers expect.

A practical starting point

You do not need to rip out your current platform to make progress. Start with a short inventory:

  1. List every video and messaging tool clinicians actually use, including the unofficial ones.

  2. Confirm which have executed BAAs and which plan tier is in effect.

  3. Document recording, retention, and consent handling for each, mapped against 42 CFR Part 2.

  4. Check the devices and networks sessions run on, not just the software.

  5. Close the gaps in priority order, starting with anything handling PHI without a BAA.

  6. Fold telehealth into your HIPAA risk analysis, ongoing risk management, and incident response plan.

  7. Confirm your Notice of Privacy Practices was updated for Part 2 by the February 16, 2026 deadline.

If that inventory turns up gaps, the next step is usually not replacing everything. It is determining which risks can be corrected through configuration, policy, device management, or vendor changes. Atruent helps behavioral health organizations across the Baltimore-DC corridor work through that process, translating HIPAA, HITECH, 42 CFR Part 2, and CARF expectations into a telehealth setup that clinicians can use without second-guessing the risk. If you are not sure where your platforms stand, that inventory is a good first conversation.

This article is general information, not legal advice. Confirm your specific obligations with qualified counsel.

Unique Differentiation

We’re a globally diverse, QMCS-certified cybersecurity provider with programs purpose-built for nonprofit success.

Through our #AtruCommunity initiative, we go beyond securing systems. We volunteer alongside your teams, amplify your mission through our platforms, and build relationships that feel more like partnerships than vendor agreements. Our team, representing over 10 countries, brings culturally aware, mission-aligned solutions that reflect the communities you serve.

At Atruent, every nonprofit partner has direct access to our leadership, personalized strategies that respect your goals and budget, and a team that shows up with passion, accountability, and heart. We don’t just protect nonprofits, we champion them.

Quantified Value

Our partnership delivers measurable impact, not just in security, but in mission effectiveness. With SOC 2 Type 2 compliance and guaranteed one-hour response times, Atruent provides enterprise-grade protection tailored to nonprofit realities. The stakes are high: the average cyber breach costs nonprofits over $200,000, resources that should be fueling programs, not recovering from crises.

We take a proactive approach. In 16 years, our clients have experienced zero major data breaches. Our 24/7/365 monitoring safeguards donor data, volunteer records, and beneficiary information, so you can focus on serving your community with confidence.
Through our #AtruCommunity initiative, we go even further, volunteering our time, amplifying your mission through our networks, and building partnerships that extend beyond the tech. The result? Stronger security, lower risk, and more resources redirected to what matters most: your mission.

Relevancy

In today’s digital-first world, nonprofits face growing cybersecurity threats that can jeopardize their ability to serve. With over 60% of nonprofits experiencing cyberattacks, and many lacking the resources to respond, trusted, mission-aligned partners are more essential than ever.

Atruent brings both technical expertise and heart. As a globally diverse, QMCS-certified cybersecurity provider, we understand the unique pressures nonprofits face. Through our #AtruCommunity initiative, we go beyond protection, we amplify your mission, volunteer alongside your teams, and treat every partnership as a shared purpose. Because when we protect your digital infrastructure, we’re protecting your ability to create lasting change.

Let’s Talk

7061 Deepage Dr.,
Suite 103 & 104,
Columbia MD 21045