Choosing a telehealth platform: the ten requirements that actually matter

Most telehealth platform evaluations score the wrong things. Video quality, calendar sync and the look of the patient app get weighted heavily, and they are close to interchangeable across serious vendors. The requirements that decide whether you can operate lawfully in a given state, and whether you can leave the vendor later, rarely appear on the scorecard.

Here are the ten we actually score, in the order that a failure hurts.

1. State gating on the patient’s location

Licensure follows the patient. The platform has to know where the patient is at the time of the encounter and refuse to route them to a provider not licensed there. A system that gates on the patient’s billing address, or on nothing, will eventually connect an unlicensed provider to a patient and produce a board complaint rather than a support ticket. Our position on the underlying rule is at licensure follows the patient.

Ask to see the enforcement, not the setting.

2. The good faith exam workflow

The exam is where most aesthetics and weight-management programs are actually assessed. The platform has to capture it as a distinct, timestamped clinical act tied to the prescriber, rather than as a form the patient completed. If the workflow lets a patient move to treatment with an intake questionnaire and no recorded clinician judgment, the software has built your compliance failure for you. See good faith exams.

3. Asynchronous support that matches state rules

Where state law permits a store-and-forward encounter, the platform should support it properly, with the artifact retained. Where it does not, the platform should block it for patients in that state. A single global setting for async is the wrong shape for a national program.

4. A business associate agreement you can actually get

If you are a covered entity, the vendor holds protected health information and needs an agreement, with flow-down terms to its own subcontractors. Ask who signs it, how long it takes, and whether the terms are negotiable. A vendor that treats this as an obstacle is telling you something. See who in your stack needs one.

If you are not a covered entity, you still want the security and breach terms. The analysis is at HIPAA for med spas.

5. Data export, tested before you sign

The question is not whether export exists. It is what comes out, in what format, how long it takes and what it costs. Charts, images, messages, audit logs and the association between them. Run the export during the trial. A platform you cannot leave is a platform that will price like it.

6. Audit logging you can read

Who accessed which record, when, and from where. Retained long enough to matter, exportable, and legible without the vendor’s help. This is the first thing requested after an incident and the thing most often discovered to be thin.

7. Identity proofing

For both sides. Verifying that the patient is who they say they are, and that the clinician account belongs to the credentialed person. Shared logins at the clinic end defeat every audit log in item six, and they are common.

8. E-prescribing and PDMP integration

If you prescribe, the prescribing path has to be integrated rather than parallel. A platform where the encounter lives in one system and the prescription is written in another produces records that do not reconcile, which is a problem the first time anyone reads them together. Controlled substances raise the bar further.

9. Role separation that matches your structure

In a PC-MSO arrangement the professional entity holds the chart and the management company does not. The platform should be able to express that: clinical records reachable by the clinical entity, operational data by the management side, and an access model that does not require everyone to be an administrator.

10. Breach obligations written to the right regime

The contract should name the notification timelines and who tells whom. Those differ depending on whether you are covered by HIPAA or by the FTC’s rule, so the agreement should reflect the regime that actually applies to you rather than a generic clause.

What this means for you

Score the platform on items one, two and five first, because state gating and the exam workflow decide whether you can operate at all, and export decides whether the decision is reversible. Run the data export during the trial rather than trusting the answer, and ask to watch the licensure gate refuse an out-of-state patient rather than reading the feature list. Get the vendor agreement in front of counsel before the commercial terms are agreed, since that is the only moment you have leverage. And write down which breach regime applies to you before you sign, because the contract should be built to it. Most of the pain in this category comes from switching later, and everything above is chosen to make switching survivable.

Frequently asked questions

What matters most when choosing a telehealth platform?

Whether it gates encounters on the patient’s location against provider licensure, whether it captures the good faith exam as a distinct clinical act, and whether you can export your data on the way out. Those three decide legality and reversibility. Video quality rarely differentiates serious vendors.

Does a telehealth platform need a business associate agreement?

If your clinic is a HIPAA covered entity, yes. The platform creates, receives, maintains or transmits protected health information on your behalf, which is the definition in 45 CFR § 160.103. It should also flow the terms down to its subcontractors.

How do I test a platform’s data export?

Run it during the trial rather than asking about it. Look at what actually comes out: charts, images, messages and audit logs, the links between them, the format, the time it takes and any charge. That is what leaving will look like.

What should the platform do about state licensure?

It should identify the patient’s location at the time of the encounter and prevent routing to a provider not licensed in that state. Ask to see the gate refuse an out-of-state patient, because a configurable setting is not the same as an enforced rule.

Why does audit logging matter so much?

It is the first thing requested after an incident, and it is only useful if it records who accessed which record from where, is retained long enough, and can be exported and read without the vendor’s assistance. Shared clinician logins undermine it entirely.


This is general information, not legal advice. Rules vary by state and change. Confirm your own facts with counsel.

Share this article with a friend

Reviewed by Victor D. Cruz, MD, founder of MDside, licensed in Florida (ME117105) and New York. Last reviewed 2026-09-20.