Doctor conducting a telehealth video call with a patient, surrounded by compliance and security icons.

Telehealth Compliance in 2026: HIPAA, DEA Prescribing Rules, and State Licensing Changes to Know

Telehealth Compliance in 2026: HIPAA, DEA Prescribing Rules, and State Licensing Changes to Know

By Nicole Statley CPCO, CPMA, CPC at Healthcare Compliance Pros

Telehealth is no longer a pandemic-era workaround, it's a permanent part of how care gets delivered. But 2026 is shaping up to be a pivotal year for the rules that govern it. The DEA has issued its fourth temporary extension of controlled-substance telemedicine flexibilities, Congress has extended key Medicare telehealth provisions through 2027, and HIPAA enforcement expectations for virtual care platforms continue to sharpen. If your practice offers telehealth, here's what actually changed, what didn't, and what you need to check before year-end.

The Big 2026 Update: DEA's Fourth Extension of Telemedicine Flexibilities

On December 31, 2025, the DEA and the U.S. Department of Health and Human Services (HHS) published the Fourth Temporary Extension of the COVID-19 Telemedicine Flexibilities for the Prescription of Controlled Medications in the Federal Register (90 FR 61301). The rule amends 21 CFR 1307.41 and 42 CFR 12.1 and is effective January 1, 2026, through December 31, 2026.

In plain terms: the flexibility that lets DEA-registered practitioners prescribe Schedule II-V controlled medications via telemedicine, without first conducting an in-person medical evaluation, remains in place for all of 2026. This is the fourth time DEA has extended this pandemic-era policy rather than letting it expire or finalizing a permanent replacement.

Why does DEA keep extending it instead of finalizing permanent rules? Timing matters here. When Medicare telehealth flexibilities briefly lapsed on October 1, 2025, fee-for-service telemedicine visits for Medicare beneficiaries dropped 24% in the first 17 days, with Medicare Advantage visits down 13%, according to research cited by HHS and reported by health law analysts. DEA cited exactly this kind of care disruption risk as a reason for extending the flexibilities rather than letting them lapse while a permanent framework is finalized.

What this extension does NOT change: the underlying legal requirements for controlled-substance prescribing still apply in full. Every prescription must still be issued for a legitimate medical purpose by a practitioner acting in the usual course of professional practice, using a real-time interactive telecommunications system, by a properly DEA-registered (or exempt) practitioner. State law requirements, including any state rules that are more restrictive than the federal flexibility, are also still fully in effect.

What the Flexibilities Actually Allow

It's easy to conflate several different telehealth rules that all changed around the same time. Here's the breakdown:

· DEA temporary flexibility (through 12/31/2026): Allows prescribing of Schedule II-V controlled substances via audio-video telemedicine without a prior in-person exam, subject to federal and state law.

· Buprenorphine-specific final rule (effective March 2025, now permanent): DEA and HHS finalized a separate rule expanding telemedicine prescribing of buprenorphine for opioid use disorder. This rule permits an initial six-month supply based on an audio-only encounter, after which an audio-video or in-person evaluation is required to continue. Unlike the broader flexibility, this rule is not temporary, it's a final, permanent regulation.

· Medicare's in-person mental health visit requirement (a separate CMS rule, not a DEA rule): This requirement, an in-person visit within six months before an initial telehealth mental health service, and at least once every 12 months after, is frequently confused with DEA's prescribing flexibility, but it's a completely different rule governing Medicare payment, not DEA prescribing authority. Congress has repeatedly delayed this requirement; under the Consolidated Appropriations Act, 2026, it will not take effect until January 1, 2028.

The practical takeaway for compliance staff: don't assume that because the DEA flexibility got extended, every other telehealth-adjacent rule moved on the same timeline. Track each one separately.

HIPAA Requirements for Telehealth Platforms

DEA's rules govern whether a prescription is legally valid. They say nothing about whether your telehealth platform protects patient privacy, that's HIPAA's job, and HHS's Office for Civil Rights (OCR) has been explicit about what's required.

Business Associate Agreements (BAAs). A BAA is only required when your vendor is more than a "conduit" for protected health information (PHI) meaning it creates, receives, transmits or maintains PHI beyond the brief moment it takes to transmit a call. If your telehealth platform stores recordings, transcripts, chat logs, or session data, it is acting as a business associate, and OCR guidance is clear that a signed BAA is required before you use it with patients. A plain phone call or basic video conduit that never touches or stores PHI may not require one but most commercial telehealth platforms do more than that, so verify this with each vendor rather than assuming.

Security Rule safeguards for electronic PHI. Once a telehealth session moves off a traditional landline and onto any electronic transmission (e.g., VoIP, a smartphone app, a video platform) the HIPAA Security Rule applies. That means your risk analysis needs to specifically evaluate:

· Whether the platform supports encrypted transmission

· Whether recordings or transcripts created during the session are encrypted at rest

· Whether the app or device requires authentication and auto-locks after inactivity

· Whether an unauthorized third party could intercept the session

Patient identity verification and privacy safeguards. OCR guidance also confirms that if a patient isn't already known to the provider, their identity must be verified, orally or in writing, before the visit. Providers are also expected to conduct sessions in a private setting whenever feasible, and to use reasonable safeguards (like lowered voices, no speakerphone) when privacy isn't fully achievable.

Bottom line: a "HIPAA-compliant" video app is not a checkbox you tick once. It's a signed BAA, a documented risk analysis covering that specific technology, a documented identity-verification process, and ongoing monitoring; not a one-time platform selection.

State-by-State Considerations

Federal flexibilities set a ceiling, not a floor. States can and do impose stricter requirements, and providers are bound by whichever rule is more restrictive.

Licensure follows the patient, not the provider. The general rule across nearly all states: a provider must be licensed in the state where the patient is physically located at the time of the telehealth visit regardless of where the provider is sitting. There is no blanket federal exception to this for private-sector telehealth (VA and a few narrow state carve-outs aside).

Licensure compacts can speed up , but don't eliminate, multi-state licensing.

· The Interstate Medical Licensure Compact (IMLC) offers an expedited licensing pathway for physicians and currently includes roughly 44 states, Washington D.C., and Guam as participating jurisdictions, though a handful have passed legislation but not yet implemented it. The compact speeds up the process of obtaining a license in each additional state; it does not create one portable multistate license.

· The Nurse Licensure Compact (NLC) works differently: it grants a true multistate license, allowing RNs and LPN/VNs to practice across all NLC member states without applying for a separate license in each one. As of recent counts, 43 jurisdictions participate in the NLC.

Because compact membership changes as states join, exit, or delay implementation, verify current status directly with the compact commission or state board before relying on it for a specific patient encounter.

PDMP checks before controlled-substance prescribing. Many states mandate that prescribers query their Prescription Drug Monitoring Program before issuing certain controlled-substance prescriptions, commonly opioids and benzodiazepines, and at defined intervals thereafter (often every 90 days for continuing therapy). These mandates exist independently of the DEA telemedicine flexibility and apply whether the visit was in-person or virtual. If your practice prescribes controlled substances via telehealth across multiple states, you need a documented process for checking the correct state PDMP(s) every time.

What Happens When the Flexibilities Expire?

The current DEA extension runs through December 31, 2026 and that date is fixed unless DEA issues another extension or a final rule before then. DEA has been working toward a permanent framework since January 2025, when it proposed "Special Registrations for Telemedicine and Limited State Telemedicine Registrations." That proposal would create dedicated registration categories for telemedicine prescribers and platforms, along with new PDMP-checking and state telemedicine registration requirements. As of mid-2026, that rule remains proposed, not final. DEA's own regulatory agenda has listed a final rule as anticipated later in 2026, but the agency has not committed to specific final terms, and further delay or a fifth extension remains possible.

This is exactly why practices shouldn't build their entire telehealth prescribing workflow around the assumption that flexibilities will simply keep getting renewed. A prudent approach:

· Document your current reliance on the temporary flexibility so you know exactly which patients and prescriptions depend on it

· Build a process for verifying identity, checking PDMPs, and documenting legitimate medical purpose that would hold up even if a permanent, stricter registration system replaces the flexibility

· Assign someone on your compliance team to monitor the Federal Register and DEA announcements through the rest of 2026, this is a fast-moving area, and the rules you rely on today could change before the year is out

A 2026 Telehealth Compliance Checklist

Use this as a working checklist, not a one-time audit:

· BAA signed and current with every telehealth vendor that creates, receives, transmits or stores PHI

· Documented risk analysis covering your specific telehealth technology stack (encryption, access controls, session storage)

· PDMP check completed and documented before any controlled-substance prescription, per the rules of the state where the patient is located

· State medical licensure (or applicable compact participation) current and verified for every state where your patients are physically located during visits

· Documented patient consent and identity-verification workflow for telehealth encounters

· Staff trained specifically on telehealth-related HIPAA safeguards and prescribing requirements, not just general HIPAA training

· A designated person or team responsible for monitoring DEA, HHS, and CMS telehealth rule changes through the remainder of 2026

How HCP Supports Telehealth Compliance

Healthcare Compliance Pros helps telehealth providers, behavioral health practices, and primary care groups translate fast-moving federal rules into workable policies. That includes HIPAA risk analyses, BAA review support, telehealth-specific staff training, and ongoing monitoring of DEA and HHS regulatory activity so your team isn't caught off guard by the next extension or the eventual permanent rule.

Conclusion and Next Steps

The core message for 2026 is continuity with a deadline: the DEA flexibility that lets you prescribe controlled substances via telemedicine without a prior in-person visit is still in place, but only through December 31, 2026, and it sits alongside separate HIPAA and state licensure obligations that haven't gone anywhere. Treat this as three distinct compliance tracks: prescribing authority, privacy and security, and licensure. Monitor all three, because a change in one doesn't mean a change in the others.

Ready to make sure your telehealth program holds up under all three? Schedule a telehealth compliance review with Healthcare Compliance Pros.

FAQ

Q: Does the DEA's extension mean telemedicine prescribing flexibilities are permanent now?
No. The Fourth Temporary Extension runs only through December 31, 2026. DEA has proposed a permanent "Special Registration for Telemedicine" framework, but as of this writing that rule has not been finalized. Confirm current status before assuming the flexibility will continue past 2026.

Q: If my video platform is marketed as "HIPAA-compliant," does that mean I'm automatically covered?
No. A platform's own marketing claim doesn't satisfy your obligations. You still need a signed BAA with that vendor (if it's acting as a business associate), a documented risk analysis specific to how you use the platform, and documented identity-verification and consent processes.

Q: Can I prescribe controlled substances to a patient in another state via telehealth if I'm licensed in my own state?
Generally, no. You need to be licensed in the state where the patient is physically located at the time of the visit, and you need to comply with that state's PDMP and prescribing requirements, not just your home state's rules.

Q: Is the Medicare in-person mental health visit requirement the same as the DEA prescribing rule?
No, they're separate rules from different agencies. The DEA rule governs whether you can legally prescribe a controlled substance via telemedicine. The Medicare rule (currently delayed until January 1, 2028) governs whether Medicare will pay for certain mental health telehealth services without a preceding in-person visit.

Q: What's the single most common telehealth compliance gap you see?
Missing or outdated BAAs with telehealth vendors, and PDMP checks that aren't documented consistently across every state where a practice sees patients.

This is a fast-moving regulatory area. Confirm the current status of DEA, HHS, and CMS telehealth rules directly with those agencies before making prescribing, licensure, or platform decisions for your practice.