Telehealth Security Basics: Protecting Virtual Visits Without Friction
A virtual visit puts clinical care on an unmanaged device, over a home network, in a room you cannot see. Securing the parts you control without making the visit unusable.
GuardsArm Team
Security Experts
Telehealth moved from marginal to core in a few months and the security model never caught up. A virtual visit involves an unmanaged patient device, a home network, a room you cannot see, and a clinician who may also be at home. Most of that is outside your control — which makes it important to be precise about the parts that are not.
Platform choices that matter
Not all of these are equally important, and the marketing tends to emphasise the wrong ones.
| Control | Actually matters because |
|---|---|
| BAA with the platform vendor | Non-negotiable; consumer video tools generally will not sign one |
| Encryption in transit | Baseline. End-to-end is better but not universally available with clinical features |
| Unique, non-guessable meeting identifiers | Sequential or reused IDs allow strangers to join |
| Waiting room enabled by default | The single most effective control against uninvited participants |
| Host controls | Lock the session once started, remove participants, mute |
| No recording by default | Recording should be a deliberate act, not the default state |
| Data residency | Matters where jurisdiction requires it |
Verifying it is the right patient
Video is reassuring and not proof. The workable approach mirrors any clinical identity check:
- Confirm two identifiers verbally at the start, as you would in person
- For a first virtual visit, consider linking the invitation to the patient portal account so identity is established through an already-proofed channel
- Confirm who else is in the room and that the patient consents to their presence — this is frequently skipped and is a genuine privacy issue
- Note the patient's location where it affects licensure or emergency response
Recording, consent and retention
If a consultation is recorded it becomes part of the record, with everything that implies.
Default to not recording. Where recording is clinically justified, treat the storage as clinical infrastructure rather than as a feature of the video platform, and give it a retention period in the schedule — see data retention and disposal.
The clinician side is the part you control
You cannot manage the patient's device. You can manage the clinician's, and that is where the concentrated risk sits — one compromised clinician endpoint exposes every consultation, not one.
- Managed device, full-disk encryption, current patches
- The clinical application reached over a controlled path, not a personal browser profile
- A private space requirement, written into policy, with headphones
- Screen sharing defaults that do not expose other patients' records — share a window, never the desktop
- Session lock on the clinician side, short timeout
That screen-sharing point causes real incidents. A clinician sharing a full desktop while the EHR is open on another monitor has disclosed other patients' information to the person on the call.
What to tell patients, and what not to
Patients cannot be managed, but they can be briefed — briefly, in the appointment confirmation rather than in a policy document:
- Join from a private space where you are comfortable discussing health
- Use your own device where possible, not a shared or work computer
- We will never ask for payment details during a clinical consultation
- We will never ask for your password — a caller who does is not us
- If something feels wrong, hang up and call the clinic on the published number
That fourth point matters more than the rest combined. Telehealth has created a convincing pretext for social engineering: a caller claiming to be from the hospital, referencing a real upcoming appointment, asking the patient to "verify" credentials or payment. Setting the expectation in advance is the only practical defence, because the patient cannot verify the caller.
When something goes wrong
Have an answer ready for the two realistic incidents:
An uninvited participant joined. Remove them, end and restart the session with a new identifier, record what was disclosed and when, and treat it as a potential privacy incident requiring assessment — not as an IT glitch.
A recording was made or stored incorrectly. Locate every copy including the platform's own retention, establish whether consent covered it, and assess disclosure. Platform-side copies are the ones most often missed.
Where to start
Check two settings on your platform: is the waiting room on by default, and is recording off by default. Both are single configuration changes, both are commonly wrong, and between them they cover the majority of practical telehealth privacy risk.
GuardsArm reviews telehealth deployments including platform configuration and clinician endpoint posture. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


