Difference Between Telehealth and Telemedicine: Ops Guide
Your billing manager forwards a takeback notice. The payer says a batch of remote visits was submitted with the wrong place-of-service indicator, and it wants the money back. Meanwhile your privacy officer is asking whether the remote monitoring dashboard your cardiology group turned on last fall counts as "telehealth" for purposes of your policy manual — because if it does, nobody signed a BAA with the device vendor.
Both problems trace back to the same confusion: the difference between telehealth and telemedicine is real, it is operational, and treating the two words as synonyms creates gaps in your billing documentation, your vendor inventory, and your records-release workflow. This guide is for the administrator, billing lead, and privacy officer who have to reconcile all three.
The Difference Between Telehealth and Telemedicine, Stated Plainly
Telemedicine refers to remote clinical services — a licensed clinician evaluating, diagnosing, or treating a patient at a distance using audio-video or, in some circumstances, audio-only technology.
Telehealth is the broader umbrella. It includes telemedicine, and it also includes non-clinical remote activities: patient education, remote patient monitoring data collection, clinician-to-clinician consultation, continuing education, care coordination calls, and administrative meetings that touch patient information.
Practical translation for your operation:
- Every telemedicine encounter is telehealth. Not every telehealth activity is telemedicine.
- Telemedicine generally generates a billable encounter and a chart note. Telehealth may generate neither — and still generate ePHI.
- Payer policies, state licensure statutes, and grant programs each pick their own term. Read the definition in the document in front of you, not the definition you remember.
HHS maintains the federal-facing distinction on its telehealth policy resource for providers, and ONC covers the same ground from a health IT angle on healthit.gov.
Why the Distinction Bites in Billing Before It Bites in Compliance
Billing feels it first because payer edits are automated. Compliance feels it second, usually when someone asks a question nobody can answer from the vendor list.
Place of service, modifiers, and the origination site
Claims for remote clinical services generally require the practice to indicate where the patient was and how the service was delivered. Medicare distinguishes between telehealth furnished in the patient's home and telehealth furnished at another originating site, and it uses distinct place-of-service values for each. Modifier use layers on top of that, and commercial payers do not always mirror CMS.
Your job as an administrator is not to decide which value is clinically correct for a given encounter. Your job is to build a process that makes the correct value determinable and defensible:
- The scheduler or intake staffer records the patient's physical location at the start of the encounter, in a structured field — not free text buried in a note.
- The platform logs the modality actually used: two-way audio-video, audio-only, or store-and-forward.
- The rendering clinician attests to the modality in the note.
- The coder selects codes and place-of-service values from that documented record, applying the payer's current published policy.
- Your compliance file retains the payer policy version in effect on the date of service.
That fifth step is the one practices skip, and it is the one that resolves a retroactive audit. Payer telehealth policies have changed repeatedly since 2020. If you cannot show which policy you relied on, you are arguing from memory.
Not everything remote is "telehealth" to a payer
Medicare treats "telehealth services" as a statutorily defined category. Several other remote service families — brief virtual check-ins, patient-initiated digital communications, remote physiologic monitoring — sit outside that statutory definition and carry their own coverage rules, frequency limits, and documentation expectations. A clinician who says "I did a telehealth visit" may have furnished something the statute treats differently.
Build a crosswalk. One column for the internal service name your staff uses, one column for the payer's category, one column for the documentation elements required. Keep it current against CMS telehealth coverage guidance, and re-verify at least quarterly. Medicare telehealth flexibilities have been extended in short legislative increments since the public health emergency ended, and your billing team should confirm current status rather than rely on last quarter's memo.
HIPAA Doesn't Care Which Word You Use — It Cares About the ePHI
Here is the part that surprises people. The HIPAA rules do not define "telehealth" or "telemedicine." Nothing in the Privacy, Security, or Breach Notification Rules turns on which label your practice applies.
What matters is whether protected health information is created, received, maintained, or transmitted — and by whom. That is why the difference between telehealth and telemedicine matters more to your scope than to your obligations. Defining telehealth narrowly, as "video visits only," causes practices to leave whole categories of ePHI-handling technology outside their risk analysis.
The OCR Notification of Enforcement Discretion that permitted good-faith use of non-public-facing consumer video apps during COVID-19 ended in 2023, following the expiration of the public health emergency and a short transition period. Since then, ordinary Security Rule expectations apply to remote care technology with no telehealth-specific carve-out. OCR's telehealth guidance page is the reference to keep bookmarked, including its material on audio-only encounters.
The scope test to run this month
Ask your IT lead and privacy officer to list every technology that touches patient information remotely. Not every technology used for video visits — every technology used remotely. A realistic list at a mid-size practice includes:
- The video encounter platform
- The patient portal and its messaging function
- SMS appointment reminder and recall tools
- Remote physiologic monitoring devices and the vendor dashboard behind them
- E-consult or curbside-consult platforms between clinicians
- Interpretation services joining video calls
- Ambient documentation or transcription tools running during encounters
- Cloud storage or backup holding recorded sessions, if you record
- Analytics or marketing tracking code on the pages where patients schedule remote visits
Items one through three are usually on the vendor list. Items four through nine frequently are not. Every one of them is telehealth under the broad definition, and every one of them may involve a business associate.
Your Telehealth Vendor List Is Longer Than Your Telemedicine Platform
When a practice says "we have a BAA for telehealth," it usually means it has one BAA — with the video vendor. That is the single most common gap I see in remote care programs.
Work through the list above and, for each entry, answer three questions in writing: Does this vendor create, receive, maintain, or transmit PHI on our behalf? Do we have an executed BAA? When was it last reviewed against the vendor's current subprocessors and data locations?
Two traps deserve specific attention.
Remote monitoring device vendors
The device manufacturer, the connectivity provider, and the dashboard operator are sometimes three different companies. Patient-identifiable readings flow through all three. Your BAA with the reseller does not automatically bind the entity that actually stores the data. Ask for the subprocessor list in writing.
Ambient scribes and transcription
If a tool listens to the encounter and produces a draft note, it is processing PHI in the most sensitive form available — the patient's own voice describing symptoms. Confirm the BAA covers model training and secondary use, and confirm in writing whether audio is retained after the note is generated, and for how long.
If any of those vendors are operating on a handshake or a click-through terms page with no BAA in place, close the gap before you expand the program. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is generally faster than waiting for a vendor's legal team to circulate their own template.
Records Requests: Where the Telehealth Chart Lives
A patient submits a right-of-access request for "everything from my video visits." Your 30-day clock starts on receipt. What are you actually producing?
If the encounter note lives in your record system, that part is routine. But telehealth generates artifacts that often sit outside it: chat transcripts from inside the video platform, uploaded photos the patient sent before the visit, remote monitoring trend data on a vendor dashboard, session recordings if your practice records.
Designated record set determinations are yours to make and document. Make them before the request arrives, not during. Then:
- Write down, per system, whether its contents are in your designated record set.
- Confirm you can export from each in-scope system without vendor assistance. If you cannot, that is a contract term to negotiate at renewal.
- Assign a named owner for each export path — not "IT," a person.
- Document retention and deletion timelines for session recordings, and enforce them.
The same inventory answers a harder question later: if that vendor has a breach, whose records were affected and how do you enumerate them for notification?
Consent, Location, and Licensure — the Front Desk's Three Questions
Telemedicine adds jurisdictional complexity that in-person care does not. The patient's physical location at the time of service typically governs which state's licensure and consent rules apply, and several states impose telehealth-specific informed consent requirements that go beyond your standard consent form.
Script it for intake staff. Three questions, asked every time, logged in structured fields:
- What state are you physically located in right now?
- Are you somewhere you can speak privately? (If not, offer to reschedule — this protects the patient and documents your reasonable safeguards.)
- Confirm the telehealth-specific consent on file is current for this state and this modality.
Also decide, in writing, what happens when a clinician is remote. A physician taking calls from a home office is a workforce member accessing ePHI from an unmanaged location. Your Security Rule policies should address device encryption, screen privacy, household members, and prohibited networks — and your workforce training should cover it annually, with sign-off retained.
A 60-Day Sequence for Practices That Already Went Live
Days 1–15. Build the technology inventory. Assign the privacy officer to own it. Flag every system without a BAA.
Days 16–30. Execute missing BAAs. Build the service-name-to-payer-category crosswalk with your billing lead and start archiving payer policy versions by date.
Days 31–45. Update your risk analysis to include the newly inventoried remote systems, and document the risk management decisions that follow from it. If your last risk analysis predates your remote monitoring program, it is out of date by definition — automating the risk analysis and supporting policy set is a reasonable way to close that gap without a six-week consulting engagement.
Days 46–60. Rewrite the intake script, retrain the front desk, and run a tabletop: a telehealth vendor notifies you of a breach at 4 p.m. on a Friday. Who calls whom, and how fast do you produce the affected-patient list?
Get the Paper in Place First
The difference between telehealth and telemedicine is not academic vocabulary. It determines how wide you draw the circle around your remote care program — and every vendor inside that circle needs an executed agreement before the next encounter, not after the next incident.
If your inventory turned up vendors without one, build and export a signature-ready BAA and get them signed this week. It is the shortest path from "we think we're covered" to a document you can hand an auditor.