Learn about HIPAA and radiology and imaging (PACS, RIS & teleradiology platforms), Telehealth, Health technology startups, and more, through the Frequently Asked Questions (FAQs) below. Please schedule a free consultation, if you are looking for experienced professionals to help you comply with HIPAA, conduct a HIPAA Security Analysis, and for other customized services.
Table of Contents
How does HIPAA apply to radiology and imaging?
Radiology practices and imaging centers carry a significant HIPAA compliance burden because they generate and store large volumes of sensitive ePHI, including DICOM images, radiology reports, and patient demographic information, across specialized systems such as PACS, RIS, and teleradiology platforms. All three Security Rule safeguard categories apply: physical safeguards must protect imaging equipment and server infrastructure; technical safeguards such as access controls, audit logging, and encrypted data transmission are critical given the volume and sensitivity of data transferred within and between facilities; and administrative safeguards, including risk analysis, workforce training, and BAAs with cloud PACS vendors, AI diagnostic tool providers, and teleradiology services, are equally essential. The integration of AI into radiology workflows adds compliance considerations around data access for model training, audit logging of AI-assisted decisions, and the security of AI infrastructure.
How does HIPAA apply to health technology startups?
Health technology startups building products or services that involve PHI are most commonly business associates, and in some cases covered entities themselves, making HIPAA compliance both a legal obligation and a commercial prerequisite. A startup developing an EHR platform, clinical decision support tool, medical billing application, or patient communication system will almost certainly handle ePHI and must comply with HIPAA accordingly. Healthcare provider clients routinely require evidence of compliance, including executed BAAs and documented security policies, before purchasing or integrating software that touches patient data. Core compliance activities include designating privacy and security officers, conducting a documented security risk analysis, training all relevant employees on HIPAA, executing BAAs with sub-processors and cloud providers, and maintaining documentation of all compliance decisions. Early compliance investment also positions startups for subsequent certifications such as SOC 2, ISO 27001, or HITRUST that larger health system partners commonly require.
Does HIPAA apply to telehealth and audio-only services?
Telehealth platforms and services operated by or on behalf of covered entities are fully subject to HIPAA, including services delivered via video, audio-only channels, and remote patient monitoring technologies. Telehealth vendors that handle ePHI are business associates and require BAAs. The COVID-19 public health emergency, which ended May 11, 2023, prompted OCR to issue temporary enforcement discretion permitting certain non-HIPAA-compliant consumer communication tools for telehealth, but those accommodations expired with the public health emergency. In its 2022 guidance on audio-only telehealth, OCR confirmed that covered providers may deliver services via audio-only channels in compliance with the applicable HIPAA rules. As of 2026, all telehealth providers must ensure their platforms include encrypted transmission, proper access controls, and properly executed BAAs.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties