To use this for telehealth, a US-based healthcare provider would need to sign a BAA (Business Associates Agreement) with Cal. Realistically, the security features you mentioned would only be relevant in determining the punitive outcome of a HIPAA violation.