Back to Blog
Application Security
8 min read

Telehealth Security Basics: Protecting Virtual Visits Without Friction

A virtual visit puts clinical care on an unmanaged device, over a home network, in a room you cannot see. Securing the parts you control without making the visit unusable.

GuardsArm Team

Security Experts

November 27, 2025

Telehealth security

Telehealth moved from marginal to core in a few months and the security model never caught up. A virtual visit involves an unmanaged patient device, a home network, a room you cannot see, and a clinician who may also be at home. Most of that is outside your control — which makes it important to be precise about the parts that are not.

Unmanaged both ends
Patient devices always, clinician devices often
Recordings are records
A recorded consultation is PHI with storage, consent and retention obligations
Friction has a cost
A patient who cannot join has not received care

Platform choices that matter

Not all of these are equally important, and the marketing tends to emphasise the wrong ones.

ControlActually matters because
BAA with the platform vendorNon-negotiable; consumer video tools generally will not sign one
Encryption in transitBaseline. End-to-end is better but not universally available with clinical features
Unique, non-guessable meeting identifiersSequential or reused IDs allow strangers to join
Waiting room enabled by defaultThe single most effective control against uninvited participants
Host controlsLock the session once started, remove participants, mute
No recording by defaultRecording should be a deliberate act, not the default state
Data residencyMatters where jurisdiction requires it
The waiting room is the control
Nearly every publicised telehealth intrusion involved joining a session directly. A waiting room where the clinician admits each participant by name defeats that entirely, costs seconds, and requires no patient-side change.

Verifying it is the right patient

Video is reassuring and not proof. The workable approach mirrors any clinical identity check:

  • Confirm two identifiers verbally at the start, as you would in person
  • For a first virtual visit, consider linking the invitation to the patient portal account so identity is established through an already-proofed channel
  • Confirm who else is in the room and that the patient consents to their presence — this is frequently skipped and is a genuine privacy issue
  • Note the patient's location where it affects licensure or emergency response

Recording, consent and retention

If a consultation is recorded it becomes part of the record, with everything that implies.

Lifecycle of a recorded consultationConsent precedes capture; the recording is then stored, retained and disposed of under the same rules as any other clinical record.Consentexplicit, recordedCaptureclinical purpose onlyStoreencrypted, access-controlledRetainper scheduleDisposeverified
Consent requirements vary by jurisdiction — some require all parties to agree.

Default to not recording. Where recording is clinically justified, treat the storage as clinical infrastructure rather than as a feature of the video platform, and give it a retention period in the schedule — see data retention and disposal.


The clinician side is the part you control

You cannot manage the patient's device. You can manage the clinician's, and that is where the concentrated risk sits — one compromised clinician endpoint exposes every consultation, not one.

  • Managed device, full-disk encryption, current patches
  • The clinical application reached over a controlled path, not a personal browser profile
  • A private space requirement, written into policy, with headphones
  • Screen sharing defaults that do not expose other patients' records — share a window, never the desktop
  • Session lock on the clinician side, short timeout

That screen-sharing point causes real incidents. A clinician sharing a full desktop while the EHR is open on another monitor has disclosed other patients' information to the person on the call.


What to tell patients, and what not to

Patients cannot be managed, but they can be briefed — briefly, in the appointment confirmation rather than in a policy document:

  • Join from a private space where you are comfortable discussing health
  • Use your own device where possible, not a shared or work computer
  • We will never ask for payment details during a clinical consultation
  • We will never ask for your password — a caller who does is not us
  • If something feels wrong, hang up and call the clinic on the published number

That fourth point matters more than the rest combined. Telehealth has created a convincing pretext for social engineering: a caller claiming to be from the hospital, referencing a real upcoming appointment, asking the patient to "verify" credentials or payment. Setting the expectation in advance is the only practical defence, because the patient cannot verify the caller.


When something goes wrong

Have an answer ready for the two realistic incidents:

An uninvited participant joined. Remove them, end and restart the session with a new identifier, record what was disclosed and when, and treat it as a potential privacy incident requiring assessment — not as an IT glitch.

A recording was made or stored incorrectly. Locate every copy including the platform's own retention, establish whether consent covered it, and assess disclosure. Platform-side copies are the ones most often missed.


Where to start

Check two settings on your platform: is the waiting room on by default, and is recording off by default. Both are single configuration changes, both are commonly wrong, and between them they cover the majority of practical telehealth privacy risk.

GuardsArm reviews telehealth deployments including platform configuration and clinician endpoint posture. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.