Mandatory website ADA compliance starts on May 11, 2027Are you compliant?

BlogHIPAA Compliance

HIPAA Compliance for Telehealth Landing Pages: What's Different


James Thompson
By James Thompson
Published on: September 9, 2026
Read time: 5 min
HIPAA ComplianceHIPAA-aware website practices for a healthcare provider

A telehealth landing page isn't a brochure. It's the front door to an actual clinical encounter, and HIPAA treats it that way even if your website builder doesn't.

Most practices apply the same website standards to their telehealth scheduling page that they apply to their "About Us" page. That's the mistake. A page where a patient picks a time, enters symptoms, and gets routed into a live video visit handles protected health information at every step, well before the visit begins.

The Platform Itself Needs a BAA, Not Just a Good Reputation

Not every video conferencing tool is built for healthcare, and a polished interface doesn't mean HIPAA compliance. Before a telehealth vendor touches a single patient, confirm they'll sign a Business Associate Agreement, and confirm the plan you're actually paying for includes it. Several major platforms offer a HIPAA-eligible tier as a paid add-on, not a default, and practices routinely discover this only after the fact.

If a visit is recorded, for training, for documentation, for any reason, that requires clear, affirmative patient consent before recording starts, not a line buried in your intake paperwork from six months ago. Default recording settings are a common and entirely avoidable HIPAA gap.

The Waiting Room Chat Log Nobody Thinks About

Most telehealth platforms include a waiting room or pre-visit chat feature, where a patient might type a quick note while waiting: a symptom update, a medication question. That chat log is PHI, and it needs the same retention and access controls as anything in the patient's chart, not the informal handling a chat window implies.

Tracking Pixels: Legally Unsettled, Not Actually Optional in Practice

This one deserves a direct explanation rather than a simplified rule, because the rule genuinely changed mid-stream.

In December 2022, HHS issued guidance stating that tracking tools, like Meta Pixel and Google Analytics, could constitute an impermissible PHI disclosure if used on healthcare pages, including public, unauthenticated ones like a scheduling or symptom-intake page. In June 2024, a federal court in Texas ruled that HHS had exceeded its authority by applying that guidance to unauthenticated public pages and vacated that portion of it. The part of the guidance covering authenticated pages, like a patient portal, remained in effect.

In plain terms: the legal requirement to avoid pixel tracking on a public telehealth landing page is currently unsettled, not confirmed law. That is not the same as safe.

A telehealth intake page, where a patient may describe symptoms before ever logging into anything authenticated, is precisely the kind of page this dispute is about. Our recommendation, regardless of how the legal question eventually resolves, is to treat it as protected. Don't run standard marketing pixels on any page where a patient could plausibly enter health information, whether or not that page currently sits inside a gray zone. The legal question may still be moving. The patient trust question isn't.

Appointment Reminders Carry More Than a Date and Time

A reminder that says "your telehealth visit for [condition] is confirmed for 2 pm," sent by unencrypted text or email, discloses PHI to whoever else has access to that phone or inbox. Confirm your reminder system supports HIPAA-compliant messaging, and keep the message itself generic if it doesn't.

What to Actually Check This Week

Confirm your telehealth vendor's BAA is signed and covers the specific plan tier you're using, not just the vendor's brand name. Check whether session recording defaults to on or off, and turn it off if it does. Review what happens to waiting room chat messages after a visit ends. Audit your landing and intake pages for tracking pixels, and remove them from anything a patient could reach before authenticating. Check your appointment reminder content for anything more specific than a time and a generic confirmation.

The Bottom Line

A telehealth landing page carries more PHI exposure than practices usually account for, precisely because it doesn't look like a clinical tool. The legal guardrails around parts of it are still being litigated. The patient's expectation of privacy isn't waiting on the outcome.

Have you actually reviewed your telehealth scheduling page for tracking pixels, or has it never come up because it doesn't look like the kind of page that would have them?

Download the HIPAA website checklist

Questions Practice Owners Ask Us About Telehealth and HIPAA

Does my video conferencing platform need to be HIPAA compliant specifically?
Yes. It needs a signed Business Associate Agreement, and that coverage often depends on the specific paid tier you're subscribed to, not just the vendor's general reputation for security.
Is it legal to use Meta Pixel or Google Analytics on my telehealth scheduling page?
It's legally unsettled. HHS guidance from December 2022 restricted this, but a federal court partially vacated that guidance for public, unauthenticated pages in June 2024. Given the uncertainty, we recommend removing tracking pixels from any page where a patient could enter health information, regardless of the current legal status.
Do I need patient consent to record a telehealth visit?
Yes, explicit and affirmative consent before recording begins, not something implied by prior paperwork or a general terms-of-service agreement.
Is the waiting room chat feature on telehealth platforms covered by HIPAA?
Yes. Any message a patient sends through that feature, including pre-visit chat, is treated as protected health information and needs the same access and retention controls as the rest of the visit record.
Can I text or email appointment reminders that mention a patient's condition?
Not safely, unless your messaging system is HIPAA-compliant. A generic confirmation without clinical detail is the safer default if it isn't.
James Thompson
James Thompson

James Thompson is a UX and Product Design Leader with over 20 years of experience driving multi-million dollar revenue growth through user-centric design. A Nielsen Norman Group UX Master Certified practitioner, James specializes in digital transformation, heuristic evaluations, and modular design systems. He has led UX design for HIPAA-compliant, patient-facing platforms and ADA/WCAG-compliant healthcare products, translating complex regulatory requirements into interfaces that support both clinical workflows and diverse patient populations.

Ready for a website that earns trust and books more patients?

Mederi Digital builds healthcare websites that are accessible, private, and made to convert. Grab a free 30-minute strategy call and we'll map the quickest wins for your practice.

Book a free strategy call

Ready to see what your website is telling you?

See your accessibility, privacy-risk, and speed signals in one dashboard, ranked by what to fix first. Set up in minutes.