The Question on the Call
"We just need Zoom plus a booking page, right? How hard can it be?"
That's a paraphrase of the first question almost every telehealth founder asks me. And the honest answer is that the video part is about the easiest thing in the whole build. You can have two people talking to each other in an afternoon.
What takes the time is everything around it. As of today, September 29, 2026, the federal permission for a clinician to prescribe a controlled medication over video without ever seeing the patient in person runs out on December 31, 2026. That's 93 days away. The rule meant to replace it has been a proposal since January 2025 and a final version has been sitting in White House review since late August.
Meanwhile, Medicare's telehealth flexibilities have lapsed twice in the last twelve months and are now extended to December 31, 2027. So if you are building for a practice that bills Medicare, your app is resting on a date about 458 days out.
This article is the version of that answer I wish every founder read before the first call. It covers the verified status of each rule (with the status word that matters: proposed, final, extended or lapsed), the features a real telehealth app needs, which video vendors will sign a BAA, and what it costs using only the price bands we publish.
If you are still at the stage of picking a team, start with our ranking of healthcare app development companies, which scores firms only on what you can check. This one assumes you have decided to build.
Telehealth Is Not a Video App
A telehealth app is a scheduling, eligibility, documentation and prescribing system that happens to include video. That is the model shift, and it changes nearly every decision downstream.
The wrong model goes like this. A competent person thinks of telehealth as a video call with a login in front of it. So they pick a video tool, add a calendar, bolt on Stripe and call it done. That app works beautifully in a demo.
Then it meets real patients. A patient in Nevada books a clinician licensed only in California. A psychiatrist wants to send a Schedule II prescription and the app has no path for it. The practice asks where recordings are stored and nobody knows whether the storage bucket is covered by a BAA. The billing team asks which place of service code to use, and the visit note never captured whether the patient was at home.
None of those are video problems. They are rules problems, and every one of them has to be answered in the data model before the first screen is drawn.
Here is the everyday version. Opening a restaurant is not mostly about the stove. The stove matters, and a bad one ruins dinner, but the health permit, the liquor license, the supplier contracts and the reservation book decide whether you get to cook at all. Telehealth is the same. Video is the stove.
So the right model: treat the rules as first-class data. The patient's location at the time of the visit, the clinician's licenses, the visit modality (audio-video or audio-only), the payer, and whether the encounter involves a controlled substance are all fields that drive what the app allows. And because the rule dates keep moving, those allowances should live in configuration that an administrator can change, not in code that needs a release.
Controlled Substances: The Real Status
As of September 29, 2026, DEA-registered practitioners can still prescribe Schedule II to V controlled medications through an audio-video telemedicine visit without a prior in-person evaluation, and that permission expires December 31, 2026.
Some background first, because the whole thing rests on a 2008 law. The Ryan Haight Online Pharmacy Consumer Protection Act generally requires an in-person medical evaluation before a controlled substance prescription, with an exception for what the statute calls the practice of telemedicine. The DEA's own special registration proposal describes it that way in its summary.
During the pandemic, DEA waived the in-person requirement. When the public health emergency ended, it did not let the waiver drop. Instead it issued a series of temporary extensions. The current one is the fourth temporary extension, published December 31, 2025 jointly with HHS and effective January 1, 2026 through December 31, 2026.
Under it, a practitioner can prescribe Schedule II to V over audio-video without ever seeing the patient in person, and can use audio-only for Schedule III to V medications approved for opioid use disorder. That is the status word: extended. Temporary, dated, and not permanent.
Now the part people get wrong. The rule meant to replace the extensions, Special Registrations for Telemedicine and Limited State Telemedicine Registrations, was published as a proposed rule on January 17, 2025. Comments closed March 18, 2025. It would create three types of special registration and add heightened prescription, recordkeeping and reporting duties.
It is still a proposal. According to McDermott's tracking, DEA sent a final version to the White House Office of Information and Regulatory Affairs on August 25, 2026. That review typically takes up to 90 days, which would put publication around late November. The text under review is not public. So nobody outside the government knows yet whether the final rule looks like the 2025 proposal.
Worth a moment of perspective: Congress told DEA in the 2018 SUPPORT Act to set up a special registration by October 2019. We are nearly seven years past that deadline.
Two other DEA rules are final and in force, and they are easy to confuse with the proposal. The buprenorphine telemedicine rule and the VA continuity of care rule were both published January 17, 2025. Their effective dates were delayed to March 21, 2025 under the regulatory freeze, and then delayed again to December 31, 2025, when they took effect.
The buprenorphine rule lets a practitioner, after reviewing the prescription drug monitoring program data for the state where the patient is during the visit, prescribe an initial six-month supply of Schedule III to V opioid use disorder medications through audio-only means, split across several prescriptions. That is permanent, not tied to the December deadline.
| Rule | Status on September 29, 2026 | Date that matters | What it means for the app |
|---|---|---|---|
| DEA fourth temporary extension | Extended (temporary) | Expires December 31, 2026 | Remote Schedule II to V prescribing without a prior in-person visit still allowed |
| DEA special registration | Proposed January 17, 2025; final version under OIRA review since August 25, 2026 | Not published | Nothing to build to yet; design for it |
| DEA buprenorphine rule | Final, in force | Effective December 31, 2025 | Six-month initial OUD supply by audio-only after a PDMP check |
| DEA VA continuity rule | Final, in force | Effective December 31, 2025 | Relevant only to VA practitioners |
| Medicare telehealth flexibilities | Extended by statute | Through December 31, 2027 | Home visits, audio-only and therapist billing still paid |
| CY 2026 PFS telehealth changes | Final, in force | January 1, 2026 | Frequency limits removed; virtual direct supervision by audio and video |
| OCR telehealth enforcement discretion | Expired | Transition ended August 9, 2023 | Every vendor touching PHI needs a BAA |
| HIPAA Security Rule update | Proposed only | The 2003 rule still governs | Build to the current rule, watch the proposal |
What does this mean for the build? You cannot code to a final special registration rule that doesn't exist. But you can design for the shape of it. The 2025 proposal leaned heavily on the patient's state, the prescriber's registrations, PDMP checks and reporting. An app that already captures patient location per visit, stores each prescriber's state registrations, logs PDMP review and can export prescribing records is most of the way there, whatever the final text says.
And put a kill switch on it. If the temporary extension lapses on January 1, 2027 without a replacement, you want an administrator to be able to switch off controlled substance prescribing for patients without a qualifying in-person visit, the same day, without shipping code.
Medicare: Extended, Not Permanent
Medicare telehealth flexibilities are extended by statute through December 31, 2027, after lapsing twice. That is the verified state from CMS's telehealth FAQ updated February 26, 2026.
The history matters because it tells you how fragile this is. The flexibilities lapsed on October 1, 2025, when the government shut down without a funding bill carrying the health extenders. The shutdown ended November 12, 2025, after 43 days, and the bill that ended it restored the flexibilities retroactively and ran them to January 30, 2026, according to APTA's summary.
They expired again on January 31, 2026. Then, on February 3, 2026, H.R. 7148, the Consolidated Appropriations Act, 2026, ended a short partial shutdown and extended them through December 31, 2027, as Health Law Diagnosis reported. Reports say the few days of gap were also covered retroactively; I could only confirm that from secondary summaries, so treat it as reported.
Here is what CMS says holds through December 31, 2027:
- Beneficiaries can receive Medicare telehealth anywhere in the United States and territories, including at home.
- Physical therapists, occupational therapists, speech-language pathologists and audiologists can furnish Medicare telehealth.
- Audio-only telehealth at home is allowed.
- Federally qualified health centers and rural health clinics can bill non-behavioral telehealth using HCPCS G2025.
- The in-person visit requirement for mental health telehealth does not apply until after December 31, 2027.
And on January 1, 2028, unless Congress acts again, beneficiaries will generally need to be in a medical facility in a rural area for non-behavioral telehealth, and the therapist categories drop off. Behavioral health keeps its home and geographic freedom permanently, under the Consolidated Appropriations Act, 2021.
A few things became permanent through CMS's own rulemaking in the CY 2026 physician fee schedule final rule. The FAQ says CMS permanently removed telehealth frequency limits on subsequent inpatient and nursing facility visits and critical care consultations from January 1, 2026. It also allows virtual direct supervision through real-time audio and video (not audio-only) for services without a 010 or 090 global surgery indicator. And teaching physicians can be virtually present only when the service itself is furnished as telehealth.
One more distinction that trips up remote monitoring products. CMS's FAQ explains that remote monitoring, chronic care management and similar non-face-to-face services are not on the Medicare Telehealth Services List, and the telehealth statute's restrictions don't apply to them. So an RPM feature does not live or die on the 2027 date. It follows its own billing rules.
For the app, this means three fields: place of service (CMS says POS 02 for telehealth outside the home, POS 10 for the home), modality, and the patient's location. Capture them per visit. When the 2028 rules or a new extension land, your billing logic reads a date table instead of needing a rebuild.
HIPAA and the BAA on Video
Since August 9, 2023, a provider using a video platform that handles protected health information needs a business associate agreement with that vendor.
During the pandemic, HHS's Office for Civil Rights said it would not penalize providers for using everyday video tools in good faith. According to OCR's telehealth guidance, that enforcement discretion expired at 11:59 p.m. on May 11, 2023, and a 90-day transition period ended at 11:59 p.m. on August 9, 2023.
So the free consumer video tool that got a practice through 2020 is not acceptable now unless the vendor signs a BAA. And the BAA question does not stop at the video stream. It covers every vendor that stores, transmits or processes PHI: recording storage, transcription, chat, SMS reminders, email, forms, e-signature, error tracking, analytics and the hosting underneath all of it.
To be clear, a BAA is necessary, not sufficient. It makes the vendor responsible for its part. It does not make your app compliant. Access control, audit logs, encryption, risk analysis and retention are still yours. The cloud side of that we covered in which hosting providers sign a BAA, and I won't repeat it here.
One status note, because people keep getting it wrong. The HIPAA Security Rule update HHS proposed in January 2025 is still only a proposal. The 2003 Security Rule governs today. Building toward the proposal (encryption everywhere, MFA, asset inventory) is sensible, but don't tell a client it is law.
Licensure and Where the Patient Is
The clinician generally needs to be licensed in the state where the patient is located during the visit, not where the clinician sits. Each state sets its own exceptions, so the app has to treat this as data per state.
The Interstate Medical Licensure Compact helps physicians get there faster. Its site lists 44 member states plus two territories and 59 licensing boards, and describes a voluntary, expedited pathway to licensure for qualified physicians.
The word that matters is expedited. The compact is not a multistate license. A physician still holds a separate license in each state, with its own renewal date. Nurses, psychologists and counselors have their own compacts with different member lists, which I haven't verified here.
For the app, this is a simple rule with a painful failure mode: at booking, compare the patient's stated location against the clinician's active licenses and hide slots that don't match. Then check again at the start of the visit, because patients travel. If the location changed, the clinician should see it before the call connects.
Store license expiry dates and alert 60 days out. An expired license in one state quietly turns a whole set of future bookings into problems.
The Feature Stack
A telehealth app needs eight features to be usable in a real practice: video, scheduling, intake, e-prescribing, payments, messaging, documentation and, for chronic care, remote monitoring. Most should be bought, a few must be built.
| Feature | What it must do | Build or buy | Where it usually breaks |
|---|---|---|---|
| Video visit | Join from a link, waiting room, reconnect, audio-only fallback | Buy a video API under a BAA | Recording turned on by default and stored outside the BAA |
| Scheduling | Check license state, visit type, provider calendar | Build rules, buy calendar sync | Booking a clinician in a state they are not licensed in |
| Intake | Structured history, consent, red flags | Build | Free text that nobody reads before the visit |
| E-prescribing | Send to pharmacy; EPCS with two factors | Buy a certified vendor | Trying to build EPCS in house |
| Payments | Copay, self-pay, card on file | Buy, keep PHI out of descriptions | Diagnosis text inside a payment memo |
| Messaging | Secure async follow-up | Buy under a BAA or build on your own stack | SMS carrying clinical detail |
| Remote monitoring | Device readings, thresholds, review queue | Mix | Readings nobody is assigned to review |
| Documentation | Visit note, location of patient, modality | Build or EHR integration | Missing the patient location field auditors ask for |
Video: WebRTC underneath, a vendor on top
WebRTC is the open browser standard that carries almost all modern video calls. You can run it yourself, but then you own the signaling server, the TURN relays that get calls through hospital firewalls, recording, and the uptime and security of all of it. For most teams that is a bad trade. A video API that signs a BAA gives you the same WebRTC with somebody else carrying the pager.
Must-haves: a waiting room, reconnect on network change, an audio-only fallback (which Medicare pays for at home through 2027), recording off by default, and no patient names in room identifiers.
E-prescribing and EPCS
Controlled substance e-prescribing has its own federal rules in 21 CFR Part 1311. To sign a controlled substance prescription, the application must require two of three factors: something the practitioner knows, a biometric, or a hard token separate from the computer, meeting FIPS 140-2 Level 1 if it is a token. The application also needs a third-party audit (or a DEA-approved certification) before it is used for controlled substances, repeated whenever related functions change or every two years.
On top of that, the CMS EPCS program requires prescribers to send at least 70 percent of their Medicare Part D Schedule II to V prescriptions electronically, with an exemption for prescribers who issue 100 or fewer qualifying prescriptions a year.
I would not build EPCS in house for a first telehealth product. The audit cycle alone is a permanent cost. Integrate a certified e-prescribing vendor, and spend your effort on the rules around it: who can prescribe what, to whom, in which state, under which DEA pathway.
Scheduling and intake
Scheduling is where the rules live: license state, visit type, payer, modality, new versus established patient. Intake is where safety lives. Structured questions with deterministic red flags beat a free text box every time, because a clinician can scan structured answers in seconds.
Payments and messaging
Payments are easy to buy and easy to leak through. Keep diagnosis and visit reason out of payment descriptions and receipts. Messaging should be in-app and under a BAA; SMS should carry a link and nothing clinical.
Remote patient monitoring
RPM means device readings, thresholds and, most importantly, a named person who reviews the queue. The FDA question comes in here. Scheduling, video and payments are not medical devices. Software that analyzes physiological signals for a clinical purpose can be. FDA updated its general wellness and clinical decision support guidance in January 2026; per Honigman's summary, non-invasive readings such as blood pressure or oxygen saturation can fall under general wellness when intended only for wellness, not a medical purpose. A clinical RPM product is a medical purpose by definition, so write the intended use down and get it reviewed before you add any interpretation logic.
Whether this ships as a native app or a cross-platform one depends mostly on the patient population and device features. For a patient app that is mostly video, forms and payments, a hybrid build in React Native or Flutter usually covers iOS and Android with one codebase. If the product leans on Bluetooth devices, HealthKit or background monitoring, native iOS development earns its cost.
Video Vendors That Sign a BAA
Twilio Video, Daily, Amazon Chime SDK, Vonage and Zoom all publish HIPAA or BAA terms, and every one has a condition attached.I checked each on September 29, 2026. These are the vendors' own statements, not independent audits.
| Vendor | BAA terms seen | Condition | Note |
|---|---|---|---|
| Twilio Video | HIPAA eligible, Twilio signs a BAA | Security or Enterprise Edition | End of life reversed October 2024 |
| Daily | Signs a BAA at no additional cost | Paid Healthcare add-on, paid plan | Add-on price on Daily's pricing page; check it |
| Amazon Chime SDK | On AWS HIPAA eligible services list | AWS BAA in place | List dated September 3, 2026 |
| Vonage | Says it signs BAAs for its APIs | Confirm scope and region | Page blocks automated readers |
| Zoom | BAA offered on qualifying healthcare plans | Plan dependent | Source post dates from 2021; confirm current terms |
Twilio first, because it confuses people. Twilio announced an end of life for Programmable Video, and a lot of telehealth teams migrated away. Then, per Twilio's Video FAQ, it reversed that decision in October 2024 and committed to Video as a standalone product. The same FAQ says Video is HIPAA eligible and Twilio signs a BAA. Its HIPAA page adds the catch: a BAA requires Security Edition or Enterprise Edition.
Daily's documentation says HIPAA use requires its paid Healthcare add-on on a paid plan, and that Daily signs a BAA at no additional cost beyond that. The add-on's price is on Daily's pricing page; I only saw it quoted secondhand, so I'm not printing it.
Amazon Chime SDK appears on AWS's HIPAA eligible services list, which means it can carry PHI under an AWS BAA. That is attractive if the rest of your stack is on AWS. The trade is that you build more of the UI yourself.
Vonage's HIPAA page blocks automated readers, so I'm relying on its search listing, which says Vonage signs BAAs for its communications APIs. Confirm the scope and region in writing. And Zoom's own post said small US practices could accept a BAA online on a qualifying plan, but that post dates from 2021, so check the current terms.
How I'd pick: if you want prebuilt video UI fast, Daily or Zoom's SDK. If you already run on Twilio for SMS, Twilio Video keeps one BAA and one bill. If you are all-in on AWS, Chime SDK. In every case, wrap the vendor behind your own interface so a switch costs weeks, not a rewrite. Twilio's reversal is exactly why.
The Closest Things We Have Built
To be clear up front: we have not shipped a video-first telehealth product with controlled substance prescribing. What we have shipped are the parts around it, under a BAA, and two projects are the closest real builds.
Wisdom Tooth Clinic Miami: intake, scheduling and voice under a BAA
For Dr. Peter K. Cudjoe's oral surgery practice in Miami, we built what we called Zero Front Desk. It is not telehealth. It is the closest real build we have for the intake, scheduling and patient-voice parts of a telehealth app.
A bilingual English and Spanish voice agent on Retell AI plays a recording notice and an AI disclosure before any speech recognition starts, because Florida requires all-party consent. The scheduling agent books only through signed, opaque offer tokens, so it cannot invent a slot that doesn't exist.
Intake red flags (bisphosphonates, anticoagulants, cardiac history, sedation risk) are deterministic TypeScript. The model only summarizes, with the patient's name stripped, and runs on OpenAI under a BAA. Data sits in Supabase with the HIPAA add-on and row-level security from the first migration, on Vercel Pro under a BAA, with Open Dental behind an adapter, Stedi for 270/271 eligibility checks, and Twilio, Paubox, Dropbox Sign and Stripe around it.
Two things went wrong and are worth telling. We found 47 booking links pointing at a hostname with no DNS, fixed them, and added a check that every link resolves. And prompts edited in a vendor console drifted from what we had tested, so prompts now live versioned in the repo. We run nine custom CI gates, including PHI scanning. It took 31 days from first commit to live booking. The performance numbers in that project are targets, not results, and I won't report outcomes.
Clinique CGSA: HIPAA scheduling and a staff app
For Clinique CGSA, a medical psychology clinic with 51 to 200 employees, we built a HIPAA-compliant scheduling system and an internal mobile app for staff, alongside social media management. Behavioral health is the part of telehealth with the most permanent Medicare footing, and scheduling for a clinic that size is where licensure and visit-type rules bite first.
What carries over to telehealth: the adapter boundary around the EHR, deterministic rules for anything safety-related, prompts and rules in version control, and CI checks that fail the build on PHI in the wrong place. What doesn't: video and EPCS, which in a telehealth build are vendor integrations we would scope separately. For how we approach regulated builds in general, see our healthcare industry page.
What It Costs
Using Frenchy Digital's published bands, a telehealth app with video, scheduling, intake and payments usually starts in our top MVP tier of $55,000 to $75,000 or more, and adding e-prescribing and EHR integration moves it into our $70,000 to $180,000 platform band.
These are the only numbers I'll use, because they are the ones we publish and stand behind:
| Engagement | Published range | Timeline | Typical telehealth fit |
|---|---|---|---|
| Discovery and audit | $9k to $22k | 2 to 4 weeks | Rules map, vendor BAAs, data model |
| MVP tier 1 | $15k to $25k | Scope dependent | Clickable prototype or single-flow pilot |
| MVP tier 2 | $30k to $50k | Scope dependent | Scheduling and intake, video via vendor, one role |
| MVP tier 3 | $55k to $75k+ | Scope dependent | Video, scheduling, intake, payments, patient and clinician apps |
| Multi-workflow platform with integration | $70k to $180k | 9 to 16 weeks | Adds e-prescribing vendor, EHR integration, messaging, RPM |
| Enterprise, multi-site or regulated build | $180k to $420k+ | 14 to 24 weeks | Multi-state group, controlled substance workflows, audit tooling |
| Native iOS | $50k to $250k+ | Scope dependent | Device-heavy RPM or HealthKit |
Let me do the arithmetic out loud, because it's the easiest way to sanity check any quote. Senior time at Frenchy Digital is $150 to $225 an hour. A $70,000 platform build is therefore about 311 hours at the top rate ($70,000 divided by $225) or about 467 hours at the bottom rate. Spread over 9 weeks, that's roughly 35 to 52 hours a week, which is one senior engineer plus part of a second.
At the other end, a $420,000 regulated build over 24 weeks is $17,500 a week. A $180,000 one over 14 weeks is about $12,900 a week. So the weekly burn in the regulated band is roughly 1.4 times the bottom end, not ten times. The extra money mostly buys more weeks, not a bigger team.
Then there are running costs that are not ours: video minutes, the video vendor's healthcare tier, the e-prescribing vendor's per-prescriber fee, hosting under a BAA, and EPCS audits if you ever build that part yourself. Get each vendor's current price in writing; I haven't printed them because they change and several are quote-only.
We send a fixed-price phased proposal within 5 business days of discovery, give a 30-day post-launch warranty, and transfer full source code and IP ownership. If you want to test the idea before committing to a platform, our MVP tiers are the cheaper way in.
A Worked Scenario
This is a scenario, not a client. It shows how the rules turn into scope.
Say a behavioral health group has twelve clinicians across California, Arizona and Nevada. Half of their patients are on Medicare. Two psychiatrists prescribe ADHD medication, which is Schedule II. They want a patient app for video visits, intake and payments, plus a clinician web app.
Step one, the rules map. Behavioral health telehealth at home is permanently allowed for Medicare, and the mental health in-person requirement is deferred until after December 31, 2027. Good. But the Schedule II prescribing depends on the DEA extension that ends in 93 days. So the app needs an in-person visit field per patient, a switch for the post-extension regime, and a report listing which patients would lose remote prescribing if the switch flips.
Step two, licensure. Three states, twelve clinicians, so up to 36 license records to track. Booking filters on patient location. Visit start re-confirms it.
Step three, vendors. Video API under a BAA, a certified e-prescribing vendor with EPCS, hosting under a BAA, an SMS provider under a BAA with no clinical text in messages, and payments with no diagnosis in descriptions. That's five vendor agreements before a line of product code.
Step four, scope and cost. Video, scheduling, intake and payments alone would sit in our $55,000 to $75,000+ MVP tier. Add the e-prescribing integration, the license engine, the rules switch and EHR sync, and it becomes a multi-workflow platform: $70,000 to $180,000, 9 to 16 weeks. With a $9,000 to $22,000 discovery first, the realistic all-in range for this scenario is roughly $79,000 to $202,000 before vendor fees.
And the timeline math is the uncomfortable part. Starting discovery in October, a 2 to 4 week discovery plus a 9 to 16 week build lands somewhere between late December and March. In other words, the app likely launches after the DEA extension has either been replaced, extended again or lapsed. That is exactly why the rules switch is in scope.
Numbers I Won't Print
I chased the usual telehealth cost and market figures and would not print any of them.
The most common is a line like "a telehealth app costs $40,000 to $300,000." Variations of it appear on dozens of agency blogs. None that I found showed a sample, a scope definition or a method; most were written by agencies selling the build. A range that wide with no scope attached tells you nothing. So I used only our own published bands, with the scope next to each.
The second is telehealth market size ("$X billion by 2030"). Those numbers come from paywalled analyst reports whose methods I can't read. They also don't help you decide anything about your app.
The third is patient preference surveys ("X percent of patients prefer telehealth"). The ones that surfaced were vendor surveys. And vendor video quality or uptime claims are the vendors' own figures, so they don't appear here as fact either.
What I did print are dates and rule text from the Federal Register, CMS, eCFR and HHS, plus vendor terms clearly labeled as the vendor's own statements.
What Could Go Wrong
The biggest risk in a telehealth build is a rule date moving after you have hard-coded it.Here are the ones I'd plan for, and what each costs.
- The DEA extension lapses on January 1, 2027 with no final rule. Cost: remote controlled substance prescribing stops for patients without a qualifying in-person visit. Mitigation: the admin switch and the affected-patient report.
- The final special registration rule differs from the 2025 proposal. Cost: rework of prescriber onboarding and reporting. Mitigation: keep prescribing rules in configuration, and budget a small follow-up phase.
- Congress does not extend Medicare flexibilities past December 31, 2027. Cost: non-behavioral home visits for Medicare patients stop being paid. Mitigation: a date table in billing logic and a report of affected visit types.
- A vendor changes its product or BAA terms. Cost: a migration. Mitigation: wrap vendors behind your own interface, as Twilio's end of life announcement and reversal showed.
- PHI leaks into a vendor without a BAA. Cost: a breach assessment and possibly notification. Mitigation: CI checks, no clinical text in SMS, room names and payment memos.
Why is building still the right call despite all this? Because each of these risks is bounded. None of them destroys the app; each turns into a configuration change or a small phase of work, if the app was designed for it. The expensive failure is the app that hard-coded 2026's rules and needs a rewrite in 2027.
For the mobile security side of this (secure storage, certificate pinning, session handling), our sibling piece on mobile app security requirements goes further than I can here.
Limitations
This article reflects what I could verify on September 29, 2026, and several things could not be verified.
- The DEA final special registration rule is not public. Nothing here predicts its content.
- The Federal Register, HHS and several vendor pages block automated readers. Where that happened, I relied on the Federal Register's data service or search listings, as noted in the sources.
- Retroactive coverage for the few days between January 31 and February 3, 2026 was confirmed only in secondary summaries.
- Vendor BAA terms are the vendors' own statements on the day checked. Zoom's source is a 2021 post.
- State telehealth, consent and prescribing laws vary and were not surveyed state by state. Nurse, psychology and counseling compacts were not checked.
- FDA's January 2026 guidance was read through a law firm summary; the date of the guidance itself is reported as January 6, 2026.
- Nothing here is legal advice. A healthcare regulatory lawyer should review your prescribing and billing design.
Three Things This Week
If you are planning or running a telehealth app, here is what I would do before Friday.
- List every patient on a controlled substance prescribed remotely without an in-person visit, and decide now what happens to each on January 1, 2027 if the DEA extension lapses.
- List every vendor that touches a visit, including SMS, email, forms, recording and error tracking, and write down which ones have a signed BAA. Anything without one comes out of the PHI path this week.
- Check that your app stores the patient's location, the modality and the place of service for every visit. If it doesn't, that is the first ticket in the next sprint.
Then check the dates again in November. They will probably have moved.
Planning a Telehealth App?
Book a discovery call. We map the visit flow, the vendors that need a BAA and the rule dates your app depends on, then send a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Apt 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1Federal Register, Fourth Temporary Extension of COVID-19 Telemedicine Flexibilities for Prescription of Controlled Medications (December 31, 2025)↗
- 2Federal Register, Special Registrations for Telemedicine and Limited State Telemedicine Registrations, proposed rule (January 17, 2025)↗
- 3Federal Register, Expansion of Buprenorphine Treatment via Telemedicine Encounter, final rule (January 17, 2025)↗
- 4Federal Register, Continuity of Care via Telemedicine for Veterans Affairs Patients, final rule (January 17, 2025)↗
- 5Federal Register, delay of effective dates for the buprenorphine and VA telemedicine rules to December 31, 2025 (March 24, 2025)↗
- 6McDermott Will & Schulte, DEA appears close to finalizing telemedicine special registration (OIRA review, 2026)↗
- 7CMS, Telehealth FAQ updated February 26, 2026↗
- 8APTA, Government shutdown ended: telehealth flexibilities extended until January 30, 2026↗
- 9Health Law Diagnosis, Consolidated Appropriations Act, 2026 and Medicare telehealth flexibilities↗
- 10HHS OCR, HIPAA and telehealth (enforcement discretion expiry and transition period)↗
- 11Twilio, Video FAQ (end of life reversal and HIPAA eligibility)↗
- 12Twilio, HIPAA compliance and BAA edition requirements↗
- 13Daily, HIPAA compliance for healthcare (Healthcare add-on and BAA)↗
- 14AWS, HIPAA eligible services reference (includes Amazon Chime SDK)↗
- 15Vonage, HIPAA compliance for communications APIs (blocks automated readers)↗
- 16Zoom, small healthcare practices and HIPAA licenses (2021 blog post)↗
- 17eCFR, 21 CFR Part 1311, requirements for electronic orders and prescriptions↗
- 18CMS, EPCS Program getting started quick reference guide↗
- 19Interstate Medical Licensure Compact Commission↗
- 20Honigman, FDA's updates to general wellness and clinical decision support policies (January 2026)↗
Related Articles You May Find Helpful
- EHR Integration for Apps: FHIR, SMART on FHIR and ONC Rules 2026
- 10 Security Requirements for a Secure Mobile App in 2026
- Top 10 Healthcare App Development Companies 2026: #1 Frenchy Digital
- HIPAA Compliant App Hosting 2026: Which Clouds Sign a BAA
- Healthcare App Development 2026: AI Diagnostics and Remote Monitoring

