Also on CyberFence: CyberFence's industry directory for other professions · CyberFence for Teams for business VPN with BAA and SSO .

Male healthcare provider with glasses smiling during a video call with a patient on a MacBook laptop in a warm wood-paneled home office with medical binders on shelves, natural window light

Telehealth has become a standard care delivery model for millions of patients and tens of thousands of providers. Psychiatrists seeing patients from their home office. Physical therapists guiding exercise sessions via video. Nurse practitioners prescribing via remote visits. Dietitians tracking patient progress through secure messaging. In every one of these interactions, protected health information is flowing across an internet connection — over whatever network the provider happens to be using.

HIPAA doesn't pause for telehealth. The same transmission security requirements that apply to a hospital's electronic health record system apply to the video visit a provider conducts from their kitchen table. The Security Rule's addressable transmission security standard requires that PHI transmitted over open networks be encrypted. For telehealth providers working from home networks, clinic hotspots, or anywhere else that isn't a managed, enterprise-grade network, a VPN is the practical mechanism that satisfies that requirement.

What HIPAA Requires for Telehealth Transmission Security

HIPAA's Security Rule (45 CFR § 164.312(e)) addresses the transmission of electronic PHI (ePHI). Specifically:

  • Transmission Security (§ 164.312(e)(1)) — Covered entities must implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network. This is a required standard, not addressable.
  • Encryption and Decryption (§ 164.312(e)(2)(ii)) — Implement a mechanism to encrypt and decrypt ePHI whenever deemed appropriate. This is addressable — meaning if you don't implement it, you must document why it's not reasonable and appropriate, and what equivalent alternative measure you're using instead. For a provider transmitting patient health information over a home internet connection, the documentation burden for not encrypting would be difficult to support.

The HHS guidance on telehealth security has consistently emphasized that providers must use encrypted connections when transmitting PHI remotely. A home Wi-Fi network, clinic public hotspot, or hotel internet connection is an open network for HIPAA purposes. PHI transmitted over these networks without encryption violates the spirit and typically the letter of the Security Rule's transmission security requirement.

In practice, this means telehealth providers working from home need two layers of encryption: the telehealth platform's own encryption (Zoom for Healthcare, Doxy.me, Teladoc, etc. provide this for the video stream), and a VPN that encrypts all other traffic on the connection — EHR logins, patient messaging, prescription platforms, insurance portals, and any other system accessed during a remote work session.

What Telehealth Providers Transmit and Access Remotely

The clinical encounter itself is only part of the security picture. A telehealth provider's remote work session typically involves:

  • EHR access — Epic, Cerner, athenahealth, eClinicalWorks, Practice Fusion. The EHR login and session contain the complete patient record for every patient seen during that session. EHR credentials are a top target for healthcare-sector phishing attacks specifically because they provide access to PHI at scale.
  • Telehealth platform — Zoom for Healthcare, Doxy.me, Teladoc, Amwell, SimplePractice, TheraNest (for behavioral health). The platform credentials and session management controls are separate from the video encryption itself — a compromised account could be used to impersonate the provider, access scheduled visit records, or expose patient contact information.
  • Prescription platforms — DEA-registered electronic prescribing systems (Surescripts, DoseSpot, DrFirst) used to prescribe controlled and non-controlled medications during telehealth visits. Prescription system credentials provide access to patient medication histories and prescription records.
  • Patient messaging — Secure patient messaging through the EHR portal or a standalone platform (Klara, Spruce, OhMD). Message content may include PHI, medication questions, lab results, and patient-reported symptoms.
  • Insurance and billing portals — Payer portals for authorization requests, claims submission, and eligibility verification. These portals contain patient insurance information, procedure codes, and claims history.
  • Lab and diagnostic portals — LabCorp, Quest Diagnostics, and hospital system lab portals accessed to review test results and upload orders during telehealth visits.

Each of these platforms has its own login, its own session, and its own connection. All of them flow over the same home network connection. A VPN encrypts all of this traffic before it reaches the home router — the internet service provider and anyone monitoring the local network see only encrypted data to the VPN server, not which healthcare systems are being accessed or what patient data is in transit.

HIPAA-Aligned Encryption for Every Telehealth Session

CyberFence encrypts all EHR access, patient messaging, and prescription platform sessions with AES-256-GCM encryption. US-operated, zero logs, HIPAA-aligned. Works on your laptop, tablet, and phone simultaneously.

See Plans →

The Home Network Security Gap

Most telehealth providers working from home are connecting through residential internet service — Comcast, Spectrum, AT&T, or similar ISPs — over consumer-grade routers that haven't been configured for security. These routers use default or simple passwords, run outdated firmware, and provide no encryption for the traffic flowing through them beyond what each individual application provides.

When a psychiatrist logs into their EHR from home to document a telehealth session, that EHR session travels from their laptop through the home router to the ISP's network. The ISP can see the destination of every connection — which healthcare systems are being accessed, when, and for how long. On a home network with multiple family members and devices, a compromised device anywhere on the same network can potentially monitor or interfere with other network traffic. Consumer ISPs are not business associates under HIPAA and are not required to protect PHI that flows through their networks.

A VPN creates an encrypted tunnel from the provider's device directly to the VPN server, bypassing the home router's visibility and the ISP's logging entirely. From the moment of connection, all traffic — EHR sessions, telehealth platform connections, patient messaging — is encrypted and invisible to the home network infrastructure.

Clinic Hotspots and Hybrid Telehealth Settings

Many telehealth providers aren't working exclusively from home — they're conducting remote visits from clinic waiting rooms, shared workspace settings, or hotspot connections while traveling between locations. These environments introduce risks that a home network doesn't have: other people on the same network, unknown network configuration, and no control over who else might be monitoring traffic.

A clinic's patient waiting room Wi-Fi — used because the provider's exam room is occupied — is a shared network that patients, visitors, and anyone in range can access. An attacker on the same network can potentially monitor unencrypted traffic from other devices. When a telehealth provider logs into their EHR or prescription platform from this network without VPN encryption, those credentials travel over a network they don't control.

CyberFence auto-connects on untrusted networks — when the provider's device connects to a clinic hotspot, hotel Wi-Fi, or coffee shop internet, the VPN activates before any application opens. The EHR login is encrypted from the first moment, without requiring the provider to manually remember to enable VPN protection.

The Phishing Risk for Telehealth Platforms

Healthcare was identified as the top phishing target sector in multiple 2026 cybersecurity reports. Telehealth providers receive a specific category of healthcare phishing: fake communications impersonating telehealth platforms, EHR vendors, and health system IT departments.

Common attack patterns targeting telehealth providers include:

  • Fake "Zoom for Healthcare security alert" emails requiring immediate re-verification of credentials
  • Spoofed EHR vendor messages (Epic, Cerner, athenahealth) claiming account lockout or security update
  • Fake DEA electronic prescribing system alerts requiring credential confirmation
  • Spoofed payer portal notifications claiming authorization expiration requiring immediate login

CyberFence's Web Shield DNS filtering blocks known phishing domains before the browser renders the page. When a telehealth provider clicks a link in one of these emails, Web Shield checks the domain against threat intelligence databases and blocks the connection if the domain is flagged as a phishing or malware site — regardless of whether the link was clicked on a laptop, phone, or tablet.

What CyberFence Provides for Telehealth Providers

  • AES-256-GCM encryption on all connections — home networks, clinic hotspots, hotel Wi-Fi, anywhere a telehealth session or EHR access occurs
  • EHR and telehealth platform login protection — credentials for Epic, Cerner, athenahealth, Doxy.me, SimplePractice, and other platforms are encrypted in transit and invisible to network observers
  • Prescription platform security — DEA-registered electronic prescribing connections encrypted through the VPN tunnel
  • Web Shield DNS filtering — blocks phishing domains impersonating telehealth platforms, EHR vendors, and insurance portals
  • Auto-connect on untrusted networks — activates automatically on clinic hotspots, hotel Wi-Fi, and other non-home networks before any healthcare application opens
  • Zero-log policy — no records of which patients were seen, which platforms were accessed, or what PHI was in transit; consistent with HIPAA minimum necessary standards
  • US-operated infrastructure — data stays under US jurisdiction and US law; relevant for HIPAA Business Associate considerations and data sovereignty requirements
  • All devices covered — laptop, iPad, and phone all protected under one plan; covers every device used in a telehealth workflow

Telehealth has extended the reach of healthcare into places the HIPAA Security Rule wasn't originally written to address — home offices, satellite clinics, rural provider residences, and mobile care settings. The Security Rule still applies to all of them. Encrypting every connection used to access patient data is the practical implementation of transmission security in a world where care delivery happens everywhere.

Protect Every Patient Session — Start Your Free Trial

Download CyberFence from the App Store or Google Play. AES-256-GCM encryption, Web Shield phishing protection, auto-connect on clinic and home networks, zero logs. Try it free — HIPAA-aligned from day one.

View Plans →

Want to go deeper? Read how CyberFence protects other regulated industries , the CyberFence Teams product page , or CyberFence plans and pricing .