Insights/Healthcare Cybersecurity

Virtual Patient Observation Has a Privacy Problem If the Infrastructure Is an Afterthought.

Published August 2, 2026Updated August 2, 2026

A hospital rolls out virtual observation the efficient way. Carts and cameras arrive, the vendor confirms the product is HIPAA compliant and the video is encrypted, and the program goes live. What no one examined is that the cameras were dropped onto the same flat network as the guest Wi-Fi, that the whole monitoring team shares a single login, and that nobody actually decided whether the feeds are recorded or simply watched. On paper, the box marked "HIPAA compliant" is checked. In practice, some of the most sensitive video a hospital will ever capture is riding on infrastructure no one designed for it.

That scene is a composite, an illustration rather than a specific incident — but the pattern behind it is common, and it is worth taking seriously. As health systems expand programs like the VA Maryland Health Care System's dedicated virtual sitter room, a quiet assumption travels along with the technology: that privacy is a feature the vendor already handled. It is not. A camera pointed at a patient — sometimes during their most vulnerable moments — is among the most sensitive data sources in the building. Whether it is handled safely is decided far less by a product label than by the infrastructure and the choices underneath it.

"HIPAA compliant" is about the product, not your program

The phrase is doing a lot of quiet work. A vendor can build a product with genuine security capabilities, but compliance is not a property of a device — it is a property of how your organization deploys, configures, governs, and monitors the whole system. HHS is explicit that the foundation is a documented risk analysis: an assessment of where protected health information lives and moves and what threatens it, which then drives nearly every other safeguard. A program that skips that step and leans on a product's marketing has not become compliant; it has only assumed it is.

Encryption is necessary, not sufficient

Encryption matters, and it belongs in any serious deployment. But under the HIPAA Security Rule, encryption is an addressable implementation specification — one an organization applies based on its own risk analysis rather than a universal switch that, once flipped, ends the conversation. An encrypted video stream still travels a network someone has to segment, is reached through accounts someone has to control, and is governed by policies someone has to write. Encryption protects data in one dimension. It does nothing about who can log in and watch, and that is often where the real exposure lives.

Who can see the feed

Access control is where privacy becomes concrete. It means unique accounts rather than a shared password taped to a monitor, role-based permissions built on least privilege so each person sees only what their job requires, strong authentication, and sensible session handling so an unattended workstation does not sit logged in all night. It also means audit logging — a durable record of who viewed which patient and when — because you cannot investigate, or even notice, misuse you never recorded. Those same logs are what make a meaningful response possible if something does go wrong.

Where the feed lives on the network

A camera in a patient room should not share a network with the cafeteria's guest Wi-Fi, yet that is a surprisingly common default. Network segmentation — isolating observation devices and traffic on their own controlled segment, firewalled from everything else — is a privacy control as much as a technical one. Good segmentation limits who and what can reach those feeds, contains the blast radius if another part of the network is compromised, and turns "the cameras are on the network somewhere" into a deliberate, defensible design. The network architecture is not a backdrop to privacy. It is part of the mechanism.

Recording, live-only, and retention

One decision quietly shapes much of a program's risk profile: is the video recorded, or only viewed live? The answer is neither obviously right nor purely technical. Recording may serve legitimate purposes, but it also creates a store of extraordinarily sensitive footage that then has to be protected, retained, and eventually disposed of — with clear answers to where it lives, how long it is kept, who can export it, and who can ever replay it. Live-only viewing carries less of that long-tail exposure but forecloses later review. Either path can be defensible; what is not defensible is arriving there by accident because no one made the call.

The vendor is inside your trust boundary

The moment a vendor's platform touches protected health information — processing it, transmitting it, or storing it in the cloud — that vendor is inside your trust boundary, and the relationship needs a business associate agreement that puts safeguard obligations in writing. It also warrants real diligence: where does the data actually flow, where is it stored, how is it protected in transit and at rest, and what is the vendor's own security posture. Outsourcing the technology does not outsource the responsibility, and a weak link in a vendor's environment is a weak link in yours.

Dignity is a design requirement

Not every privacy question is a data question. Some are about the person in the bed. Thoughtful camera placement, privacy modes that can be engaged during bathing, toileting, or examinations, clear notification to patients and visitors that observation is in use, and workforce training on respectful conduct all protect something the network cannot: a patient's dignity. A program can be technically airtight and still feel like surveillance if these are ignored. Designing for the human being on camera is part of doing this well.

A privacy-and-security readiness checklist

Before pointing a camera at a patient, work through the decisions that determine whether the program protects them:

  • Complete a documented risk analysis covering where observation data lives, moves, and is exposed.
  • Apply encryption in transit and at rest, informed by that risk analysis.
  • Require unique accounts, role-based least privilege, strong authentication, and session controls.
  • Turn on audit logging, and monitor it for inappropriate access.
  • Segment observation devices and traffic onto their own controlled, firewalled network.
  • Decide recording versus live-only, and set retention, storage, export, and replay rules.
  • Put business associate agreements in place, and review vendor data flows and security posture.
  • Define camera placement, privacy modes during personal care, and patient and visitor notification.
  • Train the workforce on respectful, compliant conduct, and prepare an incident and breach-response plan.
  • Review the whole design with your privacy, compliance, and legal leadership before launch.

Where the infrastructure conversation starts

None of this is legal advice, and the determinations that matter — what your risk analysis concludes, what your policies require, what your obligations are — belong to your privacy, compliance, and legal leadership. But those decisions only hold if the infrastructure can enforce them. Segmentation, identity and access, encryption, audit logging, and hardened devices are what turn a privacy policy from an intention into a control.

That is where Metro Relay works. As a Dallas–Fort Worth technology infrastructure advisor and implementation partner, Metro Relay helps with network segmentation and isolation for observation systems, identity and access design, encryption in transit and at rest, firewall and switching architecture, audit-logging and monitoring infrastructure, device hardening, vendor and integration coordination, and security validation. What stays with the healthcare organization is everything that is properly yours — the risk analysis and its conclusions, policy and retention decisions, patient notification, and every legal determination. Metro Relay builds and secures the technical foundation your privacy program depends on; it does not make legal or compliance judgments on your behalf.

If your organization is deploying or expanding virtual patient observation, the time to design privacy and security into the infrastructure is before the first camera goes live — not after a review finds the gaps.

Deploying virtual patient observation? Ask Metro Relay for a Technology and Infrastructure Readiness Review covering network segmentation, identity, encryption, and audit.

We help DFW healthcare organizations build the segmentation, access controls, and monitoring that make a privacy program enforceable — the technical foundation beneath your compliance decisions.