Telehealth IT Security: What Arizona Practices Need to Get Right

Telehealth in Arizona: The Post-Pandemic Reality

Telehealth went from a convenience to a lifeline during the pandemic, and Arizona embraced it wholeheartedly. Medical practices across Phoenix, Tucson, Flagstaff, and rural communities expanded virtual care options to serve patients who could not—or preferred not to—visit in person. Now, years later, telehealth is not going away. It has become a permanent part of how Arizona practices deliver care.

But the rapid adoption came with a security gap. Many practices stood up telehealth capabilities quickly, using whatever tools were available, and never went back to properly secure them. That gap is a liability—both for patient privacy and for regulatory compliance.

This guide covers what Arizona medical practices need to get right about telehealth IT security, from HIPAA requirements to practical technical controls.

Arizona’s Telehealth Landscape in 2026

Arizona has been proactive about telehealth regulation. The state expanded telehealth definitions and payer parity requirements, making it easier for providers to offer and get reimbursed for virtual visits. Arizona’s telemedicine laws allow practitioners to establish patient-provider relationships via telehealth, and most major insurers in the state now cover virtual visits at rates comparable to in-person care.

This means more practices are offering telehealth—not just large health systems, but small primary care offices, behavioral health providers, specialty clinics, and dental practices. The volume of protected health information (PHI) flowing through telehealth channels has grown substantially, and so has the attack surface.

Arizona practices also face state-specific requirements. The Arizona 45-day breach notification law creates a tight timeline for reporting security incidents. If your telehealth platform is breached, you have just 45 days to notify affected patients—one of the shortest windows in the country.

HIPAA Requirements for Telehealth Platforms

HIPAA does not have a separate set of rules for telehealth. The same Privacy Rule, Security Rule, and Breach Notification Rule that govern in-person care apply to virtual visits. But the way those rules translate into technical requirements changes significantly when care is delivered through a screen.

Business Associate Agreements (BAAs)

Any telehealth platform that transmits, stores, or processes PHI is a business associate under HIPAA. That means the platform vendor must sign a Business Associate Agreement (BAA) with your practice. This is not optional.

Common consumer video tools—standard video chat apps, social media video calls, consumer messaging platforms—do not offer BAAs and are not HIPAA-compliant. While HHS temporarily relaxed enforcement of this requirement during the COVID emergency, that discretion has ended. Practices using non-compliant platforms are now fully exposed to HIPAA enforcement actions.

Verify that your telehealth platform vendor has signed a BAA with your practice. If they have not, or will not, switch platforms immediately. Our HIPAA compliance guide for medical practices covers the full scope of BAA requirements.

Encryption Standards

HIPAA requires that electronic PHI (ePHI) be protected during transmission. For telehealth, this means end-to-end encryption for video, audio, and messaging. The telehealth platform should encrypt data using AES-256 or equivalent standards, and the encryption should be active by default—not something a user has to enable manually.

Pay attention to the details. Some platforms encrypt data in transit but not at rest. Some encrypt the video stream but not the chat messages sent during a session. Some store session recordings without encryption. Each of these gaps represents a potential HIPAA violation.

Access Controls and Authentication

HIPAA’s Security Rule requires unique user identification, automatic logoff, and access controls for systems handling ePHI. For telehealth platforms, this translates to several specific requirements:

Every provider and staff member should have their own login credentials—no shared accounts. Multi-factor authentication should be enforced for all provider logins. Sessions should time out after a defined period of inactivity. And access logs should record who connected, when, and for how long.

The recent changes to the HIPAA Security Rule have placed even greater emphasis on access management, making these controls more important than ever.

Video vs. Audio-Only Compliance Differences

Not all telehealth visits are video calls. Audio-only telehealth—essentially phone consultations—has become increasingly common, particularly for behavioral health, chronic disease management, and follow-up visits. Arizona Medicaid (AHCCCS) and most commercial payers now reimburse for audio-only visits in many clinical scenarios.

From a compliance perspective, audio-only visits carry similar HIPAA obligations. The phone system or platform used for audio-only telehealth must still protect PHI. Standard landlines are generally considered acceptable because they transmit data over circuit-switched networks. But Voice over IP (VoIP) systems, which transmit audio as data packets over the internet, require encryption.

If your practice uses a VoIP phone system for telehealth calls, verify that the system encrypts call audio. Many basic VoIP setups do not enable encryption by default. This is an often-overlooked compliance gap that could surface during an audit or a HIPAA security risk assessment.

Securing Provider Home and Remote Setups

Telehealth has shifted the security perimeter. When providers conduct virtual visits from home, the practice’s security controls no longer fully apply. Home networks, personal devices, and shared spaces all introduce risks that did not exist when every visit happened in a clinical setting.

Network Security

Home Wi-Fi networks are typically less secure than office networks. Providers conducting telehealth from home should use a dedicated network segment (a separate SSID on their router) or a managed VPN connection back to the practice’s network. The Wi-Fi password should be strong and unique, and the router firmware should be current.

Practices should also consider whether providers’ home internet connections are reliable enough for telehealth. A dropped connection mid-visit is not just an inconvenience—it can compromise care quality and patient trust.

Device Management

The devices providers use for telehealth should be managed by the practice, not personal devices used for everything from patient consultations to social media. Managed devices can be configured with appropriate security controls: full-disk encryption, automatic screen locking, endpoint detection and response capabilities, and remote wipe in case of loss or theft.

If your practice allows providers to use personal devices for telehealth, establish clear BYOD policies that specify minimum security requirements. These should include device encryption, automatic updates, strong passcodes, and the ability for the practice to remotely remove practice data from the device.

Physical Environment

HIPAA’s Privacy Rule applies to telehealth conversations just as it does to in-person ones. Providers should conduct telehealth visits from a private space where conversations cannot be overheard by family members, roommates, or others. Background noise and visible information in the camera frame can inadvertently disclose PHI.

This seems basic, but it is one of the most commonly violated aspects of telehealth privacy. Practices should include physical environment requirements in their telehealth policies and train providers accordingly. Our post on cybersecurity training covers how to build effective security awareness across your team.

Technical Controls Every Arizona Practice Needs

Beyond platform selection and remote setup policies, several technical controls are essential for secure telehealth operations.

Endpoint Protection

Every device used for telehealth—whether in the office or at home—should have advanced endpoint protection. Traditional antivirus is insufficient. Modern endpoint security uses behavioral analysis to detect threats that signature-based tools miss, including fileless malware, credential theft attempts, and unauthorized remote access.

Network Monitoring

Your practice’s network should be monitored for unusual activity. This includes monitoring for unauthorized devices connecting to the network, unusual data transfers, and connections to known malicious addresses. A managed cybersecurity solution can provide 24/7 monitoring without requiring in-house security expertise.

Secure Messaging

Telehealth often extends beyond the video visit itself. Providers send follow-up instructions, patients share symptoms, and staff coordinate scheduling—all of which may involve PHI. Every messaging channel used for these communications must be encrypted and HIPAA-compliant. Standard text messaging and consumer email are not compliant channels for PHI.

Session Recording and Storage

If your practice records telehealth sessions for documentation purposes, those recordings are ePHI and must be stored, encrypted, access-controlled, and retained according to your records retention policy. Storage should meet HIPAA standards, and access should be limited to authorized personnel.

Arizona-Specific Telehealth Regulations to Know

Beyond HIPAA, Arizona practices should be aware of state-specific telehealth requirements:

Informed Consent: Arizona law requires that providers obtain informed consent before delivering telehealth services. This consent should document that the patient understands the nature and limitations of telehealth and agrees to receive care virtually. Many practices integrate this into their patient intake process, but make sure your consent forms specifically address telehealth.

Prescribing via Telehealth: Arizona allows prescribing via telehealth, including for controlled substances in certain circumstances, but practitioners must comply with both state and DEA requirements. The technology platform used must support the documentation requirements for prescribing.

Cross-State Licensing: Providers must be licensed in the state where the patient is located at the time of the telehealth visit. Arizona practices treating patients who may be traveling or snowbirds who spend part of the year elsewhere need to be aware of these boundaries.

Breach Notification: As mentioned, Arizona’s 45-day breach notification timeline is aggressive. Practices need incident response plans that specifically account for telehealth-related breaches, which may involve different systems and data flows than traditional clinical operations.

Building a Telehealth Security Program

Securing telehealth is not a one-time project. It requires ongoing attention as platforms update, threats evolve, and regulations change. A strong telehealth security program includes:

Annual Risk Assessments: Your HIPAA risk assessment should specifically evaluate telehealth risks—platform security, remote provider setups, data flows, and third-party vendor compliance.

Policy Documentation: Telehealth-specific policies should cover acceptable platforms, remote work requirements, incident response procedures, and patient consent processes.

Regular Training: Providers and staff need training specific to telehealth security, not just general HIPAA awareness. This should cover secure connection practices, privacy during virtual visits, and how to report suspected security incidents.

Vendor Management: Review your telehealth vendor’s security practices annually. Request updated SOC 2 reports or security attestations, verify that BAAs are current, and confirm that the vendor’s security posture meets your requirements.

Get Your Telehealth Security Right

Telehealth is a permanent part of healthcare delivery in Arizona, and the security requirements are only getting stricter. Practices that invest in proper security infrastructure now will be better positioned for regulatory changes, better protected against breaches, and more trusted by their patients.

Asteroid IT provides specialized IT support for Arizona medical practices, including telehealth security assessments, platform evaluations, and ongoing compliance monitoring. We understand HIPAA inside and out, and we build IT environments that let you focus on patient care instead of worrying about security gaps.

Schedule a free telehealth security assessment to identify gaps in your current setup and get a clear remediation plan.

Scroll to Top