Points of interest…
- Licensure follows the client's physical location, not yours, every session.
- HIPAA compliance requires a signed Business Associate Agreement, not vendor marketing claims.
- Confirm client identity, location, and local emergency contacts before starting each session.
An in-office session and a video session covering identical clinical ground carry different liability exposure, and licensing boards have caught up to that fact faster than most practices have. The 2018 NASW Standards for Technology and Social Work Practice set the baseline, but the bulletin most agencies still keep on hand was written for pandemic-era emergency waivers that have since expired.
Those waivers are gone. Interstate compacts, state telehealth statutes, and platform-specific HIPAA rules have replaced improvised 2020 workarounds with enforceable 2026 standards, and boards are issuing sanctions accordingly.
The practical tension is straightforward: clinicians who learned distance practice during an emergency exemption period are now operating under permanent rules they never formally reviewed.
How Ethical Frameworks Apply to Telehealth Practice
An ethical framework for telehealth is simply the set of written professional standards that tell you what you owe a client when the session happens over video, phone, chat, or a client portal instead of across a desk. Three layers govern that work: the NASW Code of Ethics (including its technology standards), the global ethical principles issued jointly by the International Federation of Social Workers and the International Association of Schools of Social Work, and whatever telehealth rules your state licensing board has adopted. You are accountable to all three at once.
The NASW Code as Your Baseline
The technology provisions in the social work code of ethics are not a separate rulebook. They restate core duties for an electronic environment: practice only within your competence, protect confidentiality across every device and platform you touch, and obtain informed consent specific to technology-mediated services before the first session. That last point trips up new practitioners. Consent to treatment is not consent to treatment by video. Clients need to understand the format, its limits, what happens when the connection drops, and how their information travels.
The Code also addresses electronic search of client information, social media conduct, and record storage. Read those sections directly rather than relying on summary, because board complaints frequently hinge on the exact wording.
Global Principles: Dignity, Access, Non-Discrimination
The IFSW/IASSW global statement of ethical principles centers human dignity, self-determination, and the right to participate. Applied to remote delivery, those commitments become concrete questions about access. Does a client on a phone-only data plan get an inferior version of your service? Are you screening out people with limited digital literacy, disabilities that affect screen use, or unstable housing without private space? Non-discrimination in a virtual practice means actively accommodating the digital divide, not assuming everyone arrives with broadband and a closed door.
Competence Now Includes the Technology
The substance of your ethical obligations does not change online. What changes is the scope of competence. Digital competencies for social work practice now include vetting the platform itself: encryption standards, signed business associate agreements, data residency, breach notification terms, and whether the vendor trains its models on session content.
State boards frequently add requirements on top of the national code, such as telehealth-specific consent language, mandatory training hours, or limits on audio-only service. When a board rule is stricter than the Code, the board rule controls your license.
Building a Risk Management Plan for Remote Practice
A risk management plan is not a document you write once and file. Treat it as a repeating loop you run before, during, and after every distance engagement. The five steps below map the minimum workflow most licensing boards and malpractice carriers expect you to be able to describe if asked.

Confidentiality, Privacy & Data Security Online
In telehealth social work, a platform is HIPAA-compliant only when the vendor signs a Business Associate Agreement and the practice actually configures the technical, administrative, and physical safeguards the HIPAA Security Rule requires.1 Marketing labels like "secure" or "encrypted" are not proof of compliance, and consumer video and messaging apps almost never qualify for clinical use.2
What Compliant Platforms Actually Look Like
Current 2026 standards for behavioral health telehealth converge on a specific technical baseline:
- Encryption in transit: TLS 1.2 or higher for all data moving between client, clinician, and server, with DTLS-SRTP protecting video and audio streams.2
- Encryption at rest: AES-256 for stored notes, recordings, transcripts, AI-generated summaries, and shared documents.2
- Authentication: Multi-factor authentication for clinicians, with access-restricted meeting links rather than open URLs shared over email.1
- Access controls: Role-based permissions so administrative staff, supervisors, and clinicians see only what their role requires.2
- Audit logging: A record of who accessed which record, when, and from where, retained and reviewable.2
- Signed BAA: Not just with the video vendor, but with every third party that touches protected health information, cloud storage, EHR, transcription services, AI scribes, analytics tools, and email providers.4
If a vendor will not sign a BAA, the tool cannot legally hold or transmit client information, regardless of how strong its encryption claims are.4
Practical Safeguards Before and During Sessions
Technology is only half the picture. Before each session, confirm the client is in a private space and using headphones, and do the same on your end: closed door, no smart speakers listening, screen positioned away from windows or shared household sightlines.4 Disable session recording by default, and if you record for supervision or clinical reasons, document the purpose, get explicit consent, and restrict access to the file.1
For stored records, apply the minimum necessary principle: limit which staff can open session notes, recordings, and messaging threads.5 Keep endpoints hardened with device encryption, automatic screen lock, current patches, and endpoint detection where the practice can support it. Document your backup and recovery process2 and run a HIPAA security risk analysis on a regular schedule, updating it whenever you add a new tool or workflow.1
Common Pitfalls to Avoid
- Using SMS, iMessage, WhatsApp, or standard Zoom accounts for clinical content or scheduling that references diagnoses.
- Sending records, intake forms, or treatment summaries over unencrypted email.
- Conducting sessions over public or unsecured Wi-Fi without a VPN.
- Storing session notes or recordings on personal devices, USB drives, or consumer cloud accounts that fall outside a BAA.
- Sharing meeting links publicly or reusing the same open link across clients.
Cross-State Licensing and Jurisdiction Rules
Cross-state practice is where telehealth trips up even experienced social workers. The controlling principle is straightforward: you generally must be licensed or otherwise authorized in the state where your client is physically located during the session, and you must also satisfy the licensing requirements of the state where you are located. Legal residence is not the deciding factor. If your client is on vacation, traveling for work, or has temporarily relocated, their physical location at the time of the session drives which state's rules apply.
Verify Location, Not Just Residence
Before each cross-state encounter, confirm where the client actually is. New York guidance, for example, directs providers to verify the client's state of residence before telepractice because it may determine which licenses are required. But residence alone is not a safe substitute for physical location. Build a habit of asking, at the start of every session, where the client is sitting. That single question protects you when a client's location shifts between appointments.
The Social Work Licensure Compact
The Social Work Licensure Compact is designed to eventually let qualifying practitioners hold a multistate license and practice in other member states, including via telehealth, without applying for a separate license in each one. As of July 2026, 35 states have enacted the compact through legislation. That number reflects enacted laws only, not that the system is running.
Here is the critical distinction: the compact has activated, but multistate licenses were not yet being issued as of 2026. Implementation was expected to take roughly 18 to 24 months, and one source projected full operation around spring 2027, though that date is not established. In practical terms, you cannot rely on the compact alone right now to serve a client in another enacted state.
What to Do Until Licenses Are Issued
Until multistate privileges are actually available, use whatever authorization the client's state permits. Depending on the state, that may mean:
- A full license in the client's state
- A temporary or provisional authorization for time-limited practice
- A telehealth registration where the state offers one
- A statutory exception for occasional or continuity-of-care contact
No single nationwide exception exists, so check each state individually rather than assuming one workaround covers all.
Also remember that the compact, once operational, will not erase local rules. Even with a qualifying multistate license, you must still follow the client's state law on scope of practice, supervision, consent, telehealth, and professional conduct. Compact eligibility itself typically requires a current, unencumbered license in a member state plus primary residence there, with separate pathways for master's-level and clinical social workers. Treat licensing as an ongoing compliance task, not a one-time box to check.
Related Articles
Informed Consent and Documentation for Online Services
Informed consent is where most distance-practice complaints begin or end. Build a telehealth-specific consent packet rather than bolting a paragraph onto your in-person form, and document that the client received, understood, and agreed to it before the first session. Use this checklist to audit your paperwork, then verify the exact language your licensing board requires, content varies state to state.
- Written consent covering technology, confidentiality limits, and the platform in useName the specific platform you use, explain how sessions are secured, and describe the privacy risks that come with transmitting clinical information electronically. Kentucky's telehealth statute for behavioral health practitioners, KRS 335.158, requires informed consent before services begin and disclosure of technology-related privacy risks; the implementing regulation calls for written consent addressing specified elements, including the client's right to in-person services and the limitations of the technology. Also disclose your license type and credentials, which Kentucky requires explicitly.
- Emergency contact and physical location collected before the first sessionObtain the client's precise physical address for each session and at least one local emergency contact, and document both. Kentucky requires emergency contact disclosure as part of telehealth consent. Maine's rules require that consent inform clients of crisis resources and what happens if technology fails mid-session, so record the backup phone number and the agreed fallback plan alongside the contact information.
- Session format, fees, and cancellation terms written for telehealthDocument whether services are delivered by video, phone, or asynchronous message; how each format is billed; and how no-shows and technology-related disruptions are handled. Maine requires that consent address the effect of telehealth on billing. Spell out whether a dropped connection counts as a missed session and who initiates reconnection.
- State-specific disclosures required by statute or regulationCheck both your licensing state and the client's state. Ohio requires consent at the initial session that defines teletherapy and addresses risks, security, and confidentiality, and permits documentation through verbal acknowledgement, an online signature, or a hard-copy form. Michigan requires documented consent before services begin. Maine additionally requires written permission before recording any session, with disclosure of how recordings are stored and disposed of.
- Record-retention practices for electronic notes and consent formsStore signed consents, session notes, and any recordings in the same secure clinical record system, not in email threads or platform chat logs. Follow the retention period set by your licensing board and employer policy, document how electronic records are backed up and eventually destroyed, and re-execute consent when you change platforms, add a service format, or the client relocates to another state.
Maintaining Boundaries in Digital Communication
Digital tools have collapsed the distance clinicians used to rely on to keep personal and professional life separate, and that collapse is now the most common source of boundary complaints in remote practice. A client who once might never have crossed paths with a therapist outside the office can now find them in seconds through a shared friend list or a public profile.
Social Media Separation
Maintain two distinct online identities: a private profile locked down for family and friends, and, if desired, a professional page used only for practice-related content. Never friend, follow, or accept connection requests from current clients on personal accounts, and set a clear intake-stage policy about what happens if a former client reaches out later. Search privacy settings should be reviewed quarterly, since platforms change defaults without notice; therapist education on digital abuse and cyber control should include these reviews.
Texting and Response-Time Norms
Text messaging invites a casualness that does not belong in clinical work. Define, in writing, when texting is appropriate (scheduling, brief logistics) and when it is not (any clinical content, crisis disclosures, or emotionally loaded material). Standard SMS is not encrypted and should never carry treatment details. Set explicit response-time expectations, such as replies within one business day, so clients are not left guessing whether a message reached a real emergency response or simply landed in an inbox overnight.
Preventing Dual Relationships
Online life makes dual relationships easier to fall into and harder to notice. Shared social circles, public group memberships, community forums, and even algorithm-driven "people you may know" suggestions can surface overlapping connections a clinician never anticipated. Watch for signs early: a client commenting on a public post, mutual friends appearing in suggested connections, or overlapping membership in the same online support group. Address any overlap directly and document how it was handled.
Put It in Writing
All of this should live in a single written digital communication policy, reviewed and signed at intake alongside informed consent, following telehealth social work best practices. Spell out acceptable platforms, response windows, social media rules, and what happens if a boundary is unintentionally crossed. A clear policy protects clients from confusion and protects clinicians from the ambiguity that fuels most online boundary violations.
Verifying Client Identity, Location, and Access Before Sessions
Verifying who is on the screen and where they are physically located creates a direct tension between clinical convenience and ethical safety. Remote practice removes the waiting room cues that once confirmed who was present. A telehealth session should never begin with an unverified person in an unknown place.
Identity Confirmation at Intake and Each Session
At intake, request a government-issued ID through a secure upload or video review. Do not store the image longer than necessary. At the start of every session, have the client verbally confirm their full name and date of birth, even when their face is visible. This small step catches unauthorized third parties and cases of mistaken identity. If the client is a minor or has a guardian, confirm that the authorized adult is also present, not just listening off camera.
Location as a Licensing and Safety Trigger
Ask the client to state their current physical address each session, not just once at intake. The location determines whether your clinical social work licensure covers the client's state and tells you which emergency services to call if the session is interrupted by a crisis. If the address differs from what you expected, pause and address the jurisdiction question before proceeding. Use a direct prompt: "Please tell me the address where you are right now." For clients who are unhoused or staying with others, accept a description of the immediate environment if a formal address is unavailable, then document that limitation.
Accommodating Limited Digital Access
Not every client has reliable video or broadband. Offer phone-only sessions or audio-first telehealth when clinically appropriate, and keep low-bandwidth options available, including for telehealth rural social work. If a client cannot show an ID on video, accept verbal confirmation and document the limitation. Access barriers should not become a reason to skip verification altogether.
Documenting What You Verified
Record the identity confirmation method, the confirmed location, and any accessibility accommodation in the session note. Note when a client declined to confirm location or could only provide a partial address. This documentation shows that you met the standard of care even when technology limited the process.
Emergency Protocols and Crisis Response for Distance Clients
There is no single national crisis protocol for telehealth, so your agency or practice has to build one and document it before the first session. The sequence below reflects the components that published telehealth risk-management guidance consistently agrees on.

AI, Emerging Technology, and the Future of Ethical Practice
Using AI to save ten minutes on a note is not the same decision as disclosing that use to the client, and confusing the two is where most ethical exposure starts. AI tools are already embedded in daily practice for the majority of social workers, according to a 2026 NASW survey, but adoption has outpaced clear rules about disclosure, oversight, and accountability.
What NASW Currently Says
NASW updated its clinical practice resources in August 2026 with dedicated guidance on artificial intelligence, and its Code of Ethics Revision Workgroup has recommended developing supplemental guidance specifically on ethical AI use, a signal that formal standards are still catching up to practice. CSWE has not issued a standalone AI policy; the closest joint document is the Standards for Technology in Social Work Practice, published by NASW, ASWB, CSWE, and the Clinical Social Work Association, which NASW cites as the anchor for AI-related expectations. Together, these sources converge on a consistent message: AI can support practice but cannot replace clinical judgment, consistent with established social work practice models, and technological competence is now treated as a baseline expectation, not an optional skill.
Data Risks and Algorithmic Bias
Chatbots, AI transcription services, and generative note-writing tools all process sensitive client information, often through third-party servers the client never agreed to. NASW's guidance flags this as a direct threat to privacy, confidentiality, and the integrity of the medical record itself. A tool that summarizes a session or drafts a treatment plan may also introduce or reinforce systemic bias, making free implicit bias tests and training resources a useful checkpoint, since the underlying models are trained on data that does not necessarily reflect the populations social workers serve. NASW names algorithmic bias explicitly as an ethical issue, not a technical footnote, and expects clinicians to scrutinize AI output for fairness and equitable access before it shapes an assessment or a document.
Practical Guardrails
Until formal supplemental standards arrive, a few practices reduce risk substantially:
- Disclose before use: Tell clients when AI is involved in transcription, note drafting, or risk scoring, and document that consent as part of the informed consent process covered elsewhere in this guide.
- Treat output as a draft: Every AI-generated note, summary, or risk flag needs human review before it becomes part of the record or informs a clinical decision.
- Check for bias: Ask whether an AI risk assessment tool has been validated across diverse populations, and flag discrepancies rather than defaulting to the algorithm's score.
- Verify accuracy: NASW's technology standards require that any information gathered or disseminated through tech tools be accurate and validated, which places the verification burden on the clinician, not the software.
AI will keep changing faster than the ethics literature can track it. The safest posture is to let it assist, never decide.










