Skip to main content
Resource Guide — Updated August 2026

Telehealth Security & Compliance Guide

Telehealth is now a permanent fixture of Australian healthcare delivery. This guide covers every security and compliance obligation you must meet — from platform selection and end-to-end encryption to patient consent, data sovereignty, and OAIC breach notification.

Telehealth in Australia: Scale and Obligation

Telehealth in Australia expanded at extraordinary speed during the COVID-19 pandemic and has since become a permanent feature of the Medicare Benefits Schedule. Services Australia reports that Medicare-subsidised telehealth consultations now represent over 20% of all GP consultations, with more than $2.5 billion in Medicare telehealth rebates paid annually. Allied health, mental health, and specialist services have all embraced telehealth MBS items as a permanent care delivery channel.

This scale creates proportional cybersecurity risk. Every telehealth consultation involves the real-time transmission of health information — symptoms, diagnoses, treatment plans, and in many cases highly sensitive mental health content — across internet infrastructure. If that infrastructure is not properly secured, patient privacy is at risk. If consultation recordings are stored without encryption on non-compliant platforms, you face a serious Notifiable Data Breach (NDB) exposure.

The Australian Digital Health Agency (ADHA) has published a telehealth security framework that outlines the minimum technical and governance requirements for Medicare-eligible telehealth services. Meeting these requirements is not just good practice — for providers integrated with My Health Records and the Healthcare Identifier Service, it is a contractual and regulatory obligation.

Telehealth Platform Selection: Security Matters

Not every video platform is appropriate for Medicare-eligible telehealth consultations. The platform you choose must meet minimum security standards: end-to-end encryption for video and audio, Australian data storage, session access controls, and no third-party advertising data use. The following platforms are commonly used in Australian healthcare:

CoviuRecommended

Coviu is an Australian-developed healthcare-specific telehealth platform. It uses end-to-end encryption for all consultations, stores session data in Australia, and integrates with HotDoc, Nookal, Cliniko, and other Australian practice management systems. Coviu publishes its security architecture and is aligned with ADHA requirements. It is the closest thing to a purpose-built, compliance-ready solution for Australian healthcare providers.

HotDoc TelehealthRecommended

HotDoc's integrated telehealth feature is designed for Australian GP and allied health practices already using HotDoc for appointment management. It offers encrypted video sessions with session data processed in Australian data centres, and integrates with Best Practice and Medical Director. Consent collection can be managed through the HotDoc patient portal.

MedipassAcceptable

Medipass is an Australian health payments and telehealth platform that handles both consultation billing and video delivery. Its security architecture includes encrypted connections and Australian data storage. Confirm the latest security specifications directly with the vendor before deployment, as platforms evolve.

Zoom (Consumer)Not Recommended Without Configuration

Standard consumer Zoom does not meet healthcare compliance requirements for Australian providers. Session recordings may be stored on Zoom's US-based servers by default. Zoom's standard terms permit data use for service improvement. If using Zoom, you must configure Zoom for Healthcare with Australian data residency, a BAA-equivalent data processing agreement, and recordings stored locally or on an Australian-compliant cloud service. This is complex to configure correctly and is not recommended for smaller practices.

Security Requirements for Video Consultations

A telehealth consultation that transmits health information must meet specific technical security standards to satisfy your Privacy Act obligations. The following controls are non-negotiable for any Medicare-eligible telehealth service:

End-to-End Encryption

Video and audio streams must be encrypted end-to-end, meaning only the clinician and patient can decrypt the content. Transport encryption (TLS) alone is not sufficient — the platform server must not be able to decrypt the consultation content.

Session Access Controls

Every consultation session must require authenticated entry — the patient should receive a unique session link and not be able to join without it. Waiting rooms with clinician admission control prevent uninvited attendees.

Participant Authentication

The clinician must be able to verify the patient's identity before beginning the consultation. A minimum check (date of birth, Medicare number confirmation) is required before transmitting clinical information.

Session Recording Controls

Recording must be disabled by default. If a session is recorded, both parties must be notified before recording begins. The recording must be stored in an encrypted, Australian-hosted location with access controls — not on a personal computer or non-clinical cloud service.

No Third-Party Data Sharing

The telehealth platform must not share consultation metadata or content with third-party advertising, analytics, or data broker services. Review the platform's privacy policy specifically for this provision before deployment.

Audit Logging

The platform must log consultation session records (date, time, participants, duration) in a form you can retrieve for OAIC investigations or professional conduct reviews. These records are health information and must be retained for the applicable statutory period.

Patient Consent for Telehealth: What Must Be Recorded

Patient consent for telehealth is both a clinical and a legal requirement. Under MBS telehealth rules, patients must consent to the telehealth modality. Under the Privacy Act, patients must understand how their health information will be captured, stored, and protected during a telehealth consultation.

Your consent record must document: the date consent was obtained, that the patient was informed of the telehealth modality, that the patient was informed of how data is stored and secured, and that the patient agreed to proceed. For psychology and mental health services, where extra-sensitive information is shared, your consent process should also specifically address session recording — confirming the patient's understanding of whether the session will be recorded, where that recording will be stored, and who will have access to it.

How to Store Consent Records Correctly

Telehealth consent records are health information and must be stored in your practice management system — not in a personal email inbox, a shared Google Doc, or a paper folder. The consent record should be linked to the patient's clinical record with a date stamp. Consent records must be retained for the same period as other health records under state and territory legislation (typically 7 years from the last consultation for adults, 7 years from the patient's 18th birthday for children).

Data Sovereignty: Where Patient Data Must Reside

Under APP 8 of the Privacy Act, transferring patient health information to an overseas server requires either explicit patient consent or a determination that the overseas recipient is bound by privacy protections substantially similar to Australia's. For most healthcare providers, the practical answer is: keep all telehealth data in Australia.

This means: consultation video recordings must be stored on Australian servers; session metadata (patient name, date, consultation notes) must be stored in an Australian data centre; and any platform you use must contractually commit to Australian data residency for your account's data. When evaluating a telehealth platform, ask the vendor directly: "Where are consultation recordings stored?" and "Where is our patient data processed and stored?" Get the answer in writing.

The ADHA requires that any platform integrated with My Health Records stores all associated health data within Australia. This requirement cascades to telehealth platforms connected to the My Health Record system.

Network Security for Telehealth Delivery

The network over which a telehealth consultation is delivered is as important as the platform used. A clinician conducting a consultation over a home Wi-Fi network using a consumer router bought from JB Hi-Fi with unchanged default credentials is transmitting sensitive patient information over an unsecured channel — regardless of whether the platform itself uses end-to-end encryption.

Enterprise vs Consumer Router

At the clinic, use a business-grade router/firewall (Cisco Meraki, Fortinet, Ubiquiti UniFi) with a separate SSID for clinical workstations and a separate guest/patient network. Home clinicians should use a router running current firmware, with WPA3 encryption enabled, and a unique, strong Wi-Fi password.

VPN for Remote Clinicians

Clinicians conducting telehealth consultations from outside the clinic must connect via a VPN to the practice network first. This ensures that the session metadata and clinical notes accessed during the consultation are transmitted securely.

Wired Connection Preferred

Wired Ethernet connections are more stable and more secure than Wi-Fi for telehealth consultations. For clinic-based telehealth rooms, wire the consultation workstation directly to the switch rather than relying on Wi-Fi.

Separate Telehealth VLAN

In larger practices running multiple concurrent telehealth sessions, configure a dedicated VLAN for telehealth workstations. This improves both security (isolating telehealth from general admin traffic) and quality (dedicated bandwidth prioritisation).

Session Recording: When It Is Allowed and How to Store It

Recording a telehealth consultation is sometimes clinically useful — for review, supervision, or patient education. However, session recordings are health information of the most sensitive kind, and their management requires strict controls.

Recording requires explicit, informed consent from the patient before the session begins.

The patient must be informed of the purpose of the recording, who will access it, and how long it will be retained.

Recordings must be stored encrypted, in an Australian-hosted location, with access restricted to the treating clinician and authorised supervisors.

Recordings must not be stored on personal cloud accounts (personal Dropbox, personal Google Drive, personal iCloud).

Retention periods: follow state/territory health records legislation. Typically 7 years from last consultation; for children, 7 years from their 18th birthday.

A patient may request access to their consultation recording — you must have a process to respond to this request within 30 days.

If a recording is accidentally exposed (e.g., stored on a compromised server), this is a Notifiable Data Breach requiring OAIC notification.

My Health Records and Telehealth Integration

Providers integrated with My Health Record may upload telehealth consultation summaries — similar to any other consultation summary. These uploads are subject to the same security obligations as all My Health Record interactions: they must be made through conformant clinical software, using healthcare provider credentials authenticated through PRODA, with audit logging of all access and uploads.

Do not upload telehealth session recordings to My Health Record. Only structured clinical documents — consultation summaries, referrals, specialist letters, and similar — are appropriate for My Health Record upload. For detailed obligations under the My Health Records Act 2012, see our My Health Records security compliance guide.

Incident Response for Telehealth Breaches

A telehealth data breach — whether a session recording exposed on a misconfigured server, a consultation intercepted over an unsecured network, or a platform provider breach exposing patient session metadata — is an eligible data breach under the NDB scheme if it is likely to result in serious harm to any affected individual.

Given the sensitive nature of telehealth content (particularly mental health consultations), the OAIC is likely to view any unauthorised exposure of telehealth session content as causing serious harm. Your incident response plan must specifically address telehealth breach scenarios: who to call, how to assess whether a breach is notifiable, and how to notify patients who had consultations on the affected platform.

You have 30 days from becoming aware of a suspected breach to complete your NDB assessment and notify the OAIC. For a full incident response framework, see our medical ransomware prevention and incident response guide.

Related Resources

Is Your Telehealth Platform Compliant?

ShieldForce reviews telehealth platform configurations, consent processes, and network security for Australian healthcare providers. Book a free assessment today.

Book a Free Telehealth Security Review

References

Author: ShieldForce Editorial Team

Published: August 2026 | Last Updated: August 2026

See our full author credentials