CPT 98008: Audio-Only Telehealth Billing and BAA Risks
Your billing lead drops a denial on your desk: a claim for a phone visit with a brand-new patient, rejected with a code the clearinghouse describes as "procedure not covered by this payer." The provider documented the encounter. The front desk collected demographics. The code on the claim was CPT 98008. Nothing went wrong clinically — the problem is administrative, and it starts with a payer policy nobody checked before the code was switched on in your charge master.
This guide is for practice administrators, billing managers, and privacy officers who need to operationalize audio-only telemedicine visits. It covers what the code represents, how practices document code selection defensibly, and — the part that gets skipped — the vendor and records-handling obligations a phone visit quietly creates.
What Is CPT 98008? A Short Answer for Your Billing Team
CPT 98008 is a synchronous audio-only telemedicine evaluation and management code for a new patient, introduced in the CPT 2025 code set alongside a family of telemedicine E/M codes numbered 98000 through 98016. Within that family, 98000–98007 describe audio-video visits (new and established patients), 98008–98015 describe audio-only visits, and 98016 describes a brief technology-based check-in.
The audio-only codes are stratified the same way office E/M codes are: by level of medical decision making, or alternatively by total time on the date of the encounter. CPT also attaches a threshold requirement that the encounter include more than ten minutes of medical discussion. Code selection within the family is a clinical and documentation determination made by the rendering provider — your job is to make sure the record supports whichever code leaves the building.
The Payer Question You Answer Before You Turn the Code On
A CPT code existing is not the same as a payer paying for it. When the telemedicine E/M family was published, the Centers for Medicare & Medicaid Services did not adopt 98000–98015 for Medicare payment; the agency directed practitioners to continue reporting the office/outpatient E/M codes with the applicable place-of-service and modifier conventions instead. Commercial payers and state Medicaid programs made their own, divergent calls — some recognize the new family, some do not, some recognize the audio-video codes but not the audio-only ones.
That divergence is your operational problem, not your provider's. Before CPT 98008 is available for selection in your system, someone in your practice should have documented, per payer:
- Whether the payer recognizes the 98000–98016 family at all
- Whether audio-only encounters are separately payable or require a different code with a modifier
- What place-of-service value the payer expects for a home-based patient
- Whether the payer imposes an originating-site or established-relationship condition
- The effective date of the policy and the date you last verified it
Keep that grid in a shared file with a named owner and a quarterly review date. Medicare telehealth authorities have been extended in short legislative increments over the past several years, which means a policy you verified two quarters ago may no longer be current. Check the CMS telehealth coverage page before you make a permanent configuration change.
Documenting an Audio-Only Encounter So Code Selection Holds Up
Audio-only visits fail audits for boring reasons. The note reads like an office visit, the modality is never stated, and there is no time capture. Fix that at the template level rather than through provider reminders.
Fields your telehealth note template should force
- Modality. Explicit statement that the encounter was conducted by real-time audio only, and why video was not used (patient declined, no capable device, connection failed).
- Start and stop time, or total time on the date of encounter. If your providers select by time, the number has to be in the note, not in the billing comment field.
- Duration of medical discussion. The audio-only family carries a discussion-length threshold; a template checkbox is cheaper than an appeal.
- Patient location and practitioner location at the time of service.
- Identity verification method. How staff confirmed they were speaking to the right person — date of birth plus one additional identifier is a common practice standard.
- Consent to telehealth and, where applicable, acknowledgment of cost-sharing.
- Medical decision making elements in the provider's own structure.
Do not have your billing staff choose the level. Their role is to confirm that the documented elements support the level the provider selected, and to route the chart back when they do not. Write that division of labor into your coding policy so it survives staff turnover.
The scheduling data problem
Most practices discover mid-audit that they cannot report how many audio-only visits they performed, because the scheduler used the same visit type for video and phone. Create distinct appointment types before volume builds. You will need the count for payer negotiations, for internal utilization review, and for any risk analysis update that touches remote care.
The Phone Is a Vendor Now: BAAs for Audio-Only Telehealth
Here is the part that billing conversations skip. When your practice moved from a landline to a cloud phone system, softphones, or a telehealth platform that dials out, you added business associates.
OCR's guidance on audio-only telehealth draws a practical line. A traditional landline call travels over a network that is not "electronic media" under the HIPAA rules, so the carrier is generally not a business associate for that transmission. Voice over IP, smartphone apps, cloud-hosted PBX systems, call recording services, transcription tools, and platforms that store call data are a different matter — those vendors create, receive, maintain, or transmit protected health information on your behalf, and a business associate agreement is required.
Run this vendor inventory this week
- Cloud telephony / VoIP provider. BAA required if PHI is transmitted or stored. Confirm whether call detail records, voicemail, and recordings sit in their cloud.
- Voicemail-to-email or voicemail transcription. Frequently a separate vendor from the phone system. Frequently missing from the BAA binder.
- Call recording and quality-monitoring tools. Recordings of a clinical encounter are PHI. Know the retention period and who can replay them.
- AI scribe or ambient documentation tools used on phone visits. Ask where audio is processed, whether it is retained for model training, and whether the contract prohibits secondary use.
- SMS/appointment reminder platform that sends the dial-in link or callback notice.
- Interpreter services conferenced into the call.
If that inventory turns up vendors you cannot produce a signed agreement for, close the gap in writing rather than by email assurance. A six-step business associate agreement generator that exports signature-ready PDF and DOCX gets a compliant document in front of a telephony vendor the same afternoon, on a one-time purchase rather than another subscription line item. Get the agreement executed before the next audio-only visit, not after the next incident.
One more contract term to insist on: breach notification timing. Your obligations run on statutory clocks, and a vendor who reports to you on day 55 has effectively consumed your investigation window.
The enforcement discretion is long gone
During the public health emergency, OCR exercised enforcement discretion for telehealth conducted over non-public-facing consumer apps. That discretion ended in 2023, with a short transition period that also closed in 2023. Any workflow still running on a personal consumer video or messaging account because "it was allowed during COVID" is out of policy today. Verify with your own eyes what your providers actually dial from — a surprising number of after-hours callbacks still come from personal cell phones with caller ID blocked and no BAA anywhere in sight. Review OCR's telehealth and HIPAA materials with your clinical leads.
An Audio-Only Visit Is Still a Designated Record Set
When a patient asks for records of a phone visit billed under CPT 98008, your right-of-access obligation is identical to an in-person visit: respond within 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
Two wrinkles specific to audio-only care:
Recordings. If your practice records telehealth calls and retains them, that recording may fall inside the designated record set if it is used to make decisions about the individual. Decide your position deliberately, write it into your records policy, and make sure the release-of-information staff know the answer before a request arrives — not while a patient is on hold.
Transcripts. AI-generated transcripts and draft notes raise the same question. If a draft is corrected and the final note is what informs care, document that the draft is transient and set an automatic deletion interval with the vendor. Undefined retention is how a single vendor incident becomes a five-year archive of clinical conversations.
Where Audio-Only Visits Show Up in Your Risk Analysis
Your security risk analysis has to reflect the systems you actually run. Adding a cloud phone system, a recording tool, and a transcription service is a material change. Update the analysis, note the new data flows, and document the safeguards you selected — encryption in transit, access controls on recording playback, workforce training on identity verification by phone.
NIST Special Publication 800-66 Revision 2 remains the most usable free framework for mapping Security Rule requirements to concrete controls, and it is written in language a non-engineer administrator can follow. If you would rather generate the risk analysis and supporting policy set than build it from a blank document, automated HIPAA risk analysis and policy generation will move you further in an afternoon than another spreadsheet template will.
Note also that HHS proposed significant Security Rule amendments in early 2025 that would tighten expectations around asset inventories, encryption, and vendor verification. Track the rulemaking rather than assume your 2023 documentation ages well.
Your 30-Day Action List
- Days 1–5. Pull every telehealth claim from the last two quarters. Separate audio-only from audio-video. Identify which codes were reported and to which payers.
- Days 6–12. Build the payer policy grid. Assign an owner and a review cadence. Do not enable any code in the charge master without a documented payer position.
- Days 13–18. Update the telehealth note template with modality, time, discussion duration, location, identity verification, and consent fields. Test it with two providers before deployment.
- Days 19–24. Complete the telephony vendor inventory. Match each vendor to a signed BAA. Execute the missing ones.
- Days 25–30. Update the risk analysis, set retention rules for recordings and transcripts, and brief release-of-information staff on how phone-visit records are produced.
Check the OCR breach portal once a quarter and read the entries involving business associates. The pattern is consistent: the vendor holding the data was not the vendor anyone in the practice was watching.
Close the Contract Gap Before the Next Phone Visit
Billing a phone encounter correctly is a fee-schedule and documentation exercise. Handling it lawfully is a vendor exercise. If your audio-only workflow depends on a cloud phone system, a transcription tool, or a recording service without a signed agreement in the file, generate the business associate agreement now and get it countersigned this week. It is the cheapest control on the list and the first one an investigator asks to see.