CPT 98014: Audio-Only Visit Billing and Privacy Rules
A physician takes a 22-minute phone call with a patient she saw four months ago. No video — the patient was in a parking lot with two bars of signal. The note says "telephone visit, medication adjustment discussed." Your biller opens the encounter, sees no start and stop time, no documented patient location, no note about why video wasn't used, and no record that the patient agreed to an audio-only visit. She now has to decide whether this encounter belongs in the CPT 98014 family at all, or whether it goes out as an office visit with a modifier, or whether it goes back to the clinician unbilled.
That decision costs you money either way. It also touches four HIPAA obligations most practices never updated when the phone became an exam room. This guide covers the operational mechanics of the audio-only telemedicine codes, then makes the records-handling and vendor implications explicit.
What CPT 98014 Is, in One Paragraph
CPT 98014 is one of the telemedicine evaluation and management codes that entered the CPT code set for 2025. It sits in the block for synchronous audio-only encounters with an established patient — a four-code ladder distinguished by the level of medical decision making or the total time the clinician spends on the date of the encounter. Parallel blocks cover audio-video visits (new and established) and audio-only visits with new patients. A separate code covers brief technology-based check-ins. Which specific code applies to a given encounter is a clinical documentation determination made by the rendering clinician, not something your billing staff can back into. Your job is to make sure the record supports whatever they select, and that the payer on the claim actually recognizes the code family.
Verify the descriptor in your own code set
Do not build a cheat sheet from a blog post — including this one. Pull the current-year CPT descriptors and the associated guidelines into your internal coding reference, note the time ranges and decision-making levels exactly as published, and date-stamp the version. When a payer denies a claim in the 98000 series, the first question in the appeal is which code-set year you were working from.
Why Your Medicare Claims May Not Use CPT 98014 at All
Here is the operational trap. The AMA created these codes; that does not obligate every payer to pay them. When the 98000-series codes took effect, CMS did not adopt the full set for separate payment under the Physician Fee Schedule and directed practitioners to continue reporting office and outpatient E/M codes with the appropriate telehealth modifier and place of service for Medicare telehealth encounters. Commercial payers split — some adopted the new family quickly, some kept requiring the old office-visit-plus-modifier construction, and some published nothing and denied both.
So your billing rules cannot say "use CPT 98014 for phone visits." They have to say "for payer X, audio-only established-patient encounters are reported this way; for payer Y, this way." Build that as a payer matrix your billing lead owns and reviews quarterly. Check the current status of Medicare telehealth policy directly at CMS's telehealth page rather than relying on a vendor newsletter, because the statutory flexibilities governing Medicare telehealth have been extended in short increments and the rules for audio-only differ by service type.
Modifiers and place of service still matter
Whichever code family a payer wants, the claim usually needs a modifier indicating audio-only versus audio-video, plus a place-of-service code reflecting where the patient was — home versus a facility. Those two fields are where clean documentation pays for itself. If your intake staff never captured the patient's physical location during the call, your biller is guessing, and a guess on place of service is a claim you will eventually be asked to substantiate.
The Seven Fields Your Note Needs Before Anyone Codes It
Turn this into a template block in your documentation system, required and visible, not buried in a smart phrase nobody expands.
- Modality actually used — audio-only, or audio-video. If video dropped mid-visit, say so and say when.
- Why audio-only — patient declined video, lacked a device, lacked bandwidth, or requested telephone. One sentence.
- Patient consent to the modality, captured verbally and documented, including consent to any recording.
- Patient's physical location at the time of the call, at least to the level of state and setting type.
- Clinician's location, because licensure and some payer rules turn on it.
- Start and stop times, or total time on the date of the encounter, per the code-set guidelines.
- Who initiated the contact and whether it relates to a service already billed in the prior seven days.
Assign owners. Front desk captures items 3 and 4 during the pre-call verification. The clinician owns 1, 2, 5, 6, and 7. Your biller does not fill in any of them after the fact — that is chart alteration, and it will be characterized that way in an audit.
Identity Verification on a Phone Line You Can't See
An audio-only visit removes your two easiest identity checks: the face and the photo ID. What replaces them has to be written down as a procedure, not improvised by whoever answers.
Most practices settle on two static identifiers plus one dynamic one — full name and date of birth, plus something only the patient would know from the record, such as the last provider seen or the pharmacy on file. Do not use the last four digits of a Social Security number as a verifier; it is a poor secret and it puts an identifier into your call notes for no reason.
Also decide, in writing, what happens when a spouse or adult child answers and says the patient is unavailable. That is a disclosure decision, and it should not be made by a medical assistant under time pressure. Your minimum-necessary policy needs a phone-specific paragraph.
The Vendors You Just Added Without Noticing
The moment your practice started billing audio-only encounters at volume, your vendor inventory changed. Walk the call path and name every party that touches it:
- Your VoIP or cloud telephony provider. It carries the content of the visit and generates call detail records tied to patient identity. Business associate.
- Softphone and mobile app vendors if clinicians dial from laptops or personal devices.
- Call recording and storage, if you record. Recordings are PHI in a durable, highly reidentifiable format.
- Ambient documentation or transcription services, including AI scribes listening to the call audio. These are business associates, and their retention and model-training terms need reading line by line.
- Appointment reminder and SMS platforms that send the call-in number or link.
- Answering services and after-hours nurse lines that route calls that later become billable encounters.
Each one needs an executed business associate agreement on file, with the vendor's actual legal entity name, a date, and a signature you can produce in under ten minutes. OCR's telehealth guidance for covered entities is explicit that the enforcement discretion that existed during the public health emergency ended, and that remote communication vendors handling PHI on your behalf are business associates. If you find a gap while reading this, you can produce a signature-ready business associate agreement the same afternoon rather than waiting on a vendor's legal queue.
Call recordings are part of the record — decide that on purpose
If you record audio-only visits and use those recordings to make care or billing decisions, you have created something that lives inside your designated record set. That means it is subject to the right of access, it is subject to your retention schedule, and it is discoverable. Many practices decide the operational cost outweighs the benefit and stop recording entirely, keeping only the clinician's note. That is a defensible choice. What is not defensible is recording by default because the phone system offers it, storing recordings for years in a vendor's cloud, and having no idea how many exist.
State Call-Recording Consent Is a Separate Body of Law
HIPAA does not govern wiretapping. Roughly a dozen states require all parties to consent before a call is recorded, and some of them apply that rule based on the location of either party. Your patient in a two-party-consent state, called by a clinician in a one-party state, creates a question your telephony vendor will not answer for you.
Practical rule: script an all-party consent announcement at the start of every recorded call, document the patient's verbal agreement in the note, and honor a refusal by turning recording off without penalizing the patient. Have counsel review the script once. It is a fifteen-minute review that prevents a bad year.
When a Patient Asks for the Phone Visit Record
The right of access clock does not change because the encounter happened by phone. A request for records from an audio-only visit is due within 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
What trips practices up is scope. If the patient asks for "everything from my March phone appointment" and you hold a recording, a transcript generated by an AI scribe, and the clinician's signed note, all three may be in scope. Your records custodian needs a written answer to that question before the request arrives, and your release-of-information workflow needs a step that checks the telephony and transcription systems — not just the chart. Practices that only search the chart produce incomplete responses and then get a second, angrier request.
Update Your Risk Analysis for the Phone Exam Room
Most practices' security risk analyses describe an office with workstations and a server closet. If a meaningful share of your encounters now happen over a phone line, from clinicians' homes, through a telephony vendor and possibly an AI listener, the analysis is stale — and a stale risk analysis is one of the most commonly cited findings in OCR resolution agreements. HHS's Security Rule guidance library is the reference point for what an adequate analysis covers.
New items to enumerate: home network security for remote clinicians, personal device use for softphones, recording storage locations and encryption, transcription vendor retention, call detail record access, and who at your telephony vendor can listen to stored audio. Then map each risk to a control and a named owner. If maintaining that documentation by hand is why it hasn't happened, automated HIPAA risk analysis and policy generation will produce the report and the supporting document set in a form you can hand to an auditor, which is faster than another quarter of good intentions.
One note on direction of travel: the Security Rule amendments proposed in early 2025 would tighten expectations around asset inventories and risk analysis documentation. They remain a proposal. Don't build workflows around unfinalized text, but do notice that nothing in it would make a vague, undated risk analysis more acceptable than it is today.
A 30-Day Cleanup Sequence
Week 1. Pull the current-year CPT descriptors for the audio-only and audio-video telemedicine E/M families into your internal coding reference. Build the payer matrix showing, per payer, whether CPT 98014 and its siblings are accepted or whether office-visit codes with modifiers are required.
Week 2. Add the seven required documentation fields to your telephone-visit template. Brief clinicians in one ten-minute huddle, not an email.
Week 3. Inventory the call path. List every vendor, confirm the BAA, and note the recording retention setting for each. Decide whether you record at all, and write the decision down with a date and a signature.
Week 4. Update the risk analysis, the release-of-information checklist, and the minimum-necessary policy's phone section. Run one test records request that includes a phone visit and time how long the response takes.
For the consumer-facing side of any health app or portal you point patients toward, the FTC's health privacy guidance is worth a read — some of those tools sit outside HIPAA and inside the FTC's Health Breach Notification Rule, and patients don't distinguish.
Start With the Document You'd Be Asked for First
If OCR called your practice tomorrow about a phone-visit complaint, the first three things requested would be your risk analysis, your policies, and the BAA for the vendor involved. Billing CPT 98014 correctly protects revenue; having those three documents current protects the practice. Generate your risk analysis and compliance document set and get the paperwork ahead of the phone call instead of behind it.