Your billing lead drops a stack of eleven denied claims on your desk. All of them are video visits from the same two-week stretch, all from the same payer, and the denial reason on every one is a place-of-service or modifier mismatch. That is what a broken aetna telehealth workflow looks like from the administrative side — not a dramatic breach, just eleven encounters that got documented one way and submitted another.

This guide is for the person who owns that workflow: the practice administrator, the billing supervisor, the privacy officer who signs the vendor agreements. It covers how to verify coverage before the visit, how staff should document the basis for code selection, which vendors in your telehealth stack are business associates, and what to hand over when a patient asks for the record of a video visit.

Does Aetna Cover Telehealth Visits? The Short Operational Answer

Coverage for a telehealth encounter depends on four variables your staff can check before the patient logs on: the member's specific plan and product line, whether the rendering clinician is in network for that plan, whether the service being delivered appears on the payer's covered telehealth service list, and whether the modality used (two-way audio-video versus audio-only) is acceptable for that service under the plan's current policy.

Practices verify all four through the payer's provider portal or eligibility line before the appointment, then record the reference number for the verification in the encounter or the practice management system. Benefits differ across commercial, self-funded employer, exchange, and Medicare product lines, and self-funded plans may carve out telehealth entirely. Never assume a policy you confirmed for one member applies to the next.

Building the Pre-Visit Verification Step Your Front Desk Can Actually Follow

Verification fails when it lives in someone's head. Write it as a five-item checklist inside your scheduling template so the person booking the visit completes it at booking, not the morning of.

  1. Plan identification. Capture the full plan name and product line from the card image or portal, not just "Aetna."
  2. Network status of the rendering clinician for that specific plan, including licensure in the state where the patient is physically located at the time of the visit.
  3. Telehealth benefit confirmation with reference number and date, stored in the practice management system.
  4. Cost-share disclosure to the patient — copay, coinsurance, or deductible application for a virtual visit, documented as delivered.
  5. Modality confirmation — whether the visit is scheduled as audio-video or audio-only, and whether the patient has confirmed working equipment.

That fifth item prevents the most common downstream mess: a visit scheduled as video, converted to a phone call when the patient's camera fails, and then submitted with documentation that describes a video encounter. If the modality changes mid-visit, your staff need a documented way to record it in real time.

State-of-Patient-Location Is an Operational Field, Not a Clinical Detail

Ask for and record the patient's physical location at the start of every virtual encounter. It drives licensure, and it drives place-of-service selection. Make it a required field in your intake form so the encounter cannot be closed without it.

How Your Practice Documents Code Selection for Aetna Telehealth Claims

Coding decisions belong to the rendering clinician and your certified coding staff. Your job as administrator is to build the record that supports whatever they select, and to make sure the claim matches the note.

The elements that typically drive telehealth claim construction are the service code, the place-of-service code distinguishing a telehealth visit delivered while the patient is at home from one delivered while the patient is at another originating site, and any modifier the payer requires to flag synchronous audio-video or audio-only delivery. Payers update these requirements, sometimes mid-year. Your coding lead should hold a dated copy of the current payer policy on file and re-pull it at least quarterly.

Build a simple internal reference that answers, for each payer you bill: which place-of-service values that payer accepts for virtual care, which modifiers it requires, and whether audio-only encounters are separately identified. Do not build it as a "use this code for this situation" cheat sheet. Build it as a policy citation index — payer, policy name, effective date, link, and who verified it.

What the Encounter Record Needs to Contain

Regardless of what code is ultimately selected, the encounter documentation should independently support it. Practices commonly require:

  • Patient's physical location and clinician's location at the time of service
  • Modality actually used, and any mid-visit change
  • Documented patient consent to receive care by telehealth, per state requirement
  • Start and stop times, or total time, when the code family is time-based
  • Identity verification method for the patient
  • Names of all participants on the call, including interpreters and family members

That last item matters twice — once for billing integrity and once for privacy, because a third party on the line is a disclosure your record should reflect.

Every Piece of Your Telehealth Stack Is a Vendor Decision

Here is where the operational and the privacy sides collide. A single virtual visit may touch a video platform, a scheduling and reminder service, an e-signature tool for consent, a payment processor for the copay, a transcription or documentation assistant, and a clearinghouse. Most of those create, receive, maintain, or transmit protected health information on your behalf. Most of them are business associates.

OCR's telehealth enforcement discretion from the public health emergency ended in 2023. There is no longer any grace period for using a consumer video product without a business associate agreement in place. HHS maintains guidance on HIPAA and telehealth that practices should read alongside their own vendor inventory.

Pull your telehealth vendor list this week and mark each entry with three fields: does it touch PHI, do we have an executed BAA, and when was that BAA last reviewed. The entries that fail the second question are your immediate work. HHS publishes sample business associate agreement provisions, but sample language is a starting point, not a finished contract — you still need breach notification timelines, subcontractor flow-down, and termination and return-of-data terms that match how you actually operate.

If a vendor comes back with "we don't sign BAAs," that is your answer about whether they belong in a clinical workflow. When you need an executed agreement quickly for a new platform or a transcription tool, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription — rather than waiting three weeks on outside counsel for a routine vendor.

Ask Vendors Where the Recording Lives

Video platforms often retain session recordings, chat transcripts, waiting-room logs, and connection metadata by default. Get the retention setting in writing, set it deliberately, and make sure it aligns with your own record retention policy. A platform quietly holding two years of recordings you never intended to keep is both a records-request problem and a breach-scope problem.

The Records Request That Arrives After a Video Visit

A patient who had an aetna telehealth visit in November emails in January asking for "everything from my video appointment." Your 30-day clock under the HIPAA right of access starts when you receive that request, with one 30-day extension available if you notify the patient in writing of the reason and the expected date.

The operational question is scope. If your practice retains a session recording or chat transcript and uses it to make decisions about the patient, it likely sits inside the designated record set. Decide that question as policy — before a request arrives — and write it down. Staff should not be improvising scope determinations on a deadline.

Also decide how you will deliver it. Patients may request an unencrypted email copy, and you may honor that after warning them of the risk and documenting that you did. What you cannot do is refuse the format outright because it is inconvenient, or charge more than a reasonable cost-based fee.

Denials, Appeals, and the PHI You Attach to Them

Telehealth denials generate appeals, and appeals generate outbound PHI. Minimum necessary applies to every one of them. Your billing team should send the documentation that supports the disputed line, not the entire chart, and should transmit it through the payer's secure portal rather than fax or email whenever the portal accepts attachments.

Log every appeal submission: date, payer, member, documents sent, transmission method. That log is your evidence of reasonable safeguards if a mis-sent packet ever becomes an incident, and it is genuinely useful for tracking which denial reasons keep recurring across your aetna telehealth claim volume.

Assign These Roles by Name

  • Payer policy monitor — pulls and dates current telehealth policy for each payer quarterly
  • Vendor inventory owner — maintains the BAA status field and renewal dates
  • Records request handler — owns the 30-day clock and the scope determination
  • Denial trend reviewer — reports telehealth denial reasons monthly to the administrator

Tie the Whole Thing to Your Risk Analysis

Adding a virtual care line changes your risk profile: new endpoints, new vendors, home network usage by clinicians, new categories of retained media. Your security risk analysis should reflect that, and it should be updated when the stack changes rather than once a year out of habit. Breaches involving business associates show up consistently in the entries on the OCR breach portal, and telehealth expands the number of business associates you depend on.

CMS maintains current information on Medicare telehealth coverage, which is a useful baseline reference even for commercial work — but it is not a substitute for the specific payer policy governing the claim in front of you.

Your Next 30 Days

Inventory the vendors. Close the BAA gaps. Date-stamp your payer policy copies. Write down your designated record set scope for video encounters. Assign the four roles above to actual people.

If a vendor in your telehealth stack is operating without a signed agreement right now, build and export the BAA today and get it in front of them this week. If your broader documentation set — risk analysis, policies, workforce training records — has drifted since you added virtual visits, automating the full compliance document set is a faster path back to current than rebuilding it in a word processor.