New Telehealth Codes for 2025: Ops and Privacy Guide
Your billing lead drops a stack of denials on your desk: forty-one virtual visits from a single provider, all rejected, all with the same remark about an invalid procedure code. The provider is not wrong about what they did. The coder is not wrong about what the code descriptor says. The problem is that the new telehealth codes for 2025 split the payer world in two, and nobody updated the practice's charge master or the front-desk scheduling script to match. If you administer a practice that bills virtual visits, this guide covers what the 2025 CPT telemedicine family changed operationally, how Medicare diverged from commercial payers, and — the part most coding articles skip — the privacy, records, and vendor obligations that came along with it.
What Are the New Telehealth Codes for 2025?
For CY2025, CPT introduced a dedicated family of telemedicine evaluation and management codes in the 98000–98016 range. Before that, practices reported virtual visits using the standard office and outpatient E/M codes with a telehealth modifier. The 2025 set gave telemedicine its own descriptors.
The family breaks down along three axes:
- Modality — synchronous audio-video versus synchronous audio-only.
- Patient status — new patient versus established patient.
- Level — tiered the way office E/M is tiered, built around medical decision making or total time on the date of the encounter.
Code 98016 sits apart from the rest. It describes a brief communication technology-based service — the short virtual check-in with an established patient that does not rise to an E/M visit. Medicare adopted 98016 as the successor to the older HCPCS virtual check-in code.
That last point is the crux of the operational problem. Medicare adopted 98016 and did not adopt the rest of the family for the Physician Fee Schedule. CMS instead directed practitioners to continue reporting the standard office and outpatient E/M codes for Medicare telehealth, with the appropriate telehealth modifier and place of service. Many commercial and Medicaid managed care plans went the other direction and began accepting or requiring the 98000-series.
Two Rulebooks, One Encounter: The Payer Matrix Your Billing Team Needs
You cannot run virtual visits on a single coding convention anymore. Build a payer matrix and treat it as a living document owned by a named person.
At minimum, the matrix needs a row per payer and columns for: accepted telemedicine code family, required modifier, required place of service, audio-only policy, whether an established-patient relationship is required, and the date you last verified the policy. Verification dates matter more than you think — plans revised these policies mid-year through 2025 and into 2026, often through provider bulletins rather than contract amendments.
Assign matrix ownership to your billing manager, with a quarterly review calendared. If your practice contracts with a billing company, the matrix is still yours. The vendor executes; you own the accuracy of what gets submitted under your NPI.
Where the Denials Actually Come From
In practice, four failure patterns account for most rejected virtual claims:
- 98000-series submitted to Medicare. The code is valid CPT; it is simply not payable under the fee schedule for those services. The fix is a payer-driven code mapping in your billing system, not provider re-education.
- Place of service mismatch. POS 10 for telehealth in the patient's home versus POS 02 for telehealth at a location other than the home. Front-desk registration often defaults to whatever was used last, and nobody asks where the patient physically was.
- Missing or wrong modality modifier. Modifier 95 for synchronous audio-video, modifier 93 for audio-only, and the behavioral-health-specific audio-only modifier where a payer requires it. The 98000-series descriptors already encode modality, which is exactly why some payers reject a modifier that other payers demand.
- Documentation that does not support the modality billed. A note that says "telehealth visit" and nothing else cannot substantiate audio-video versus audio-only if the claim is reviewed.
None of these are coding judgment calls. They are configuration and intake-workflow problems, which means an administrator can fix them without touching clinical decision making.
How Your Practice Documents Code Selection — Not Which Code Is Right
Your job is to build the documentation scaffolding, then let the clinician or certified coder select the code. That scaffolding should capture, in the note or a structured field:
- The patient's physical location during the encounter and the practitioner's location.
- The modality actually used, including any mid-visit downgrade from video to audio-only and the reason.
- Confirmation that the patient consented to a virtual encounter, and how that consent was obtained.
- Start and stop times, or total practitioner time on the date of service, so a time-based selection can be substantiated.
- Who else participated — interpreter, family member, supervising physician, resident.
- The platform used, by name.
Add these as required fields in your telehealth note template rather than relying on free text. When a payer audits a sample of virtual claims, the presence or absence of a structured modality field decides how long the audit takes.
One note on internal policy language: describe how your practice determines and documents code selection. Do not publish an internal cheat sheet that tells providers which code to use for which presenting problem. That is the fastest way to turn an administrative document into evidence of upcoding pressure.
The Privacy Consequences of the New Telehealth Codes for 2025
Here is what nobody tells practice administrators: a code-set expansion changes behavior, and changed behavior changes your risk surface. When audio-only telemedicine got its own recognized descriptors, practices that had been reluctant to bill phone visits started billing them at volume. When commercial payers accepted the new family, service lines that had stayed in-person went hybrid.
More virtual encounters mean more platforms, more recordings, more transcripts, and more staff working from places you have never inspected.
Platform Sprawl and the BAA Gap
Count your telehealth-adjacent vendors honestly. The video platform. The scheduling and reminder tool that sends the visit link. The e-consent tool. The interpreter service that joins the call. The AI scribe or transcription service your providers started using on their own. The cloud fax that receives outside records. The billing company. The clearinghouse.
Every one of those that creates, receives, maintains, or transmits protected health information on your behalf is a business associate and needs an executed agreement before it touches PHI. HHS publishes sample business associate agreement provisions that show the required elements, but sample provisions are a starting point, not a signature-ready contract.
The pattern I see most often in growing virtual programs: a provider adopts a transcription tool in March, the practice discovers it in October during a security risk analysis, and there is no agreement in place for the intervening seven months. If you are staring at that gap right now, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription — and close it this week rather than next quarter.
Also confirm the vendor is willing to sign. A consumer-grade video product with no BAA offering is not a telehealth platform, regardless of how well it works. The OCR telehealth enforcement discretion from the public health emergency ended in 2023; there is no longer a grace period for non-compliant remote communication technology. HHS maintains current guidance on HIPAA and telehealth for covered entities.
Recordings, Chat Logs, and the Designated Record Set
Decide, in writing, whether your practice records virtual encounters. Then enforce it.
If you record, those recordings are PHI. They likely fall within the designated record set if they are used to make decisions about the patient, which means a patient access request can reach them. Set a retention period, document where recordings live, confirm the vendor's deletion behavior actually deletes, and check whether the vendor retains copies in backups after you purge.
The same applies to in-visit chat, waiting-room messages, and AI-generated transcripts and summaries. A transcript that a provider reviewed and used to draft the note is not scratch paper. Your records custodian needs a documented answer to "where do telehealth artifacts live" before someone asks under a records request or a subpoena.
Remote Staff and the Locations You Have Never Inspected
Audio-only visits are easy to conduct from a kitchen table. Your workforce policy needs to address household members overhearing, screen visibility, use of personal devices, and what happens to a printed schedule at a home office. Add a remote-work attestation to onboarding and re-collect it annually.
Then verify technically: full-disk encryption, automatic session lock, MFA on the EHR and the telehealth platform, and no local downloads of patient lists. Your security risk analysis should treat each remote work location as part of the environment, not as an exception.
Records Requests for Virtual Encounters
A patient who had four audio-only visits and one video visit asks for their complete record. The 30-day access clock runs the same as it does for in-person care. What differs is where the material sits.
Build a telehealth records-request checklist for whoever handles ROI:
- Encounter notes in the EHR.
- Recordings or transcripts held in the telehealth platform, if your policy retains them.
- Consent documents held in an e-signature tool.
- Secure messages exchanged around the visit.
- Any remote monitoring data pulled into the chart.
If any of those live only in a vendor system, your BAA needs to obligate the vendor to make the data available to you within a timeframe that lets you meet the 30 days. Ask for that in writing during contracting, when you still have leverage.
Federal Coverage Rules Keep Moving — Build for That
Medicare's statutory telehealth flexibilities — the geographic and originating-site provisions in particular — have been extended through a series of short-term legislative actions, with at least one lapse and retroactive correction along the way. Certain behavioral health telehealth provisions sit on firmer, permanent footing. The practical consequence for administrators: do not hard-code coverage assumptions into your scheduling logic, and check the current status on the CMS telehealth coverage page before each quarter opens.
Keep a dated log of what the rules were when you billed. If a lapse happens and claims are later reprocessed, that log is how you reconstruct what you did and why.
A 30-Day Cleanup Plan
Week 1 — Inventory. Billing manager pulls every virtual visit billed in the last six months by payer, code, modifier, and POS. Privacy officer lists every vendor that touched a virtual encounter. Compare the vendor list against your executed BAAs.
Week 2 — Configure. Build the payer matrix. Set payer-specific code mapping and modifier edits in the billing system. Add required modality and location fields to the telehealth note template.
Week 3 — Contract. Execute missing BAAs. Request written confirmation of recording retention and deletion behavior from your video vendor. Add records-availability language to any agreement up for renewal.
Week 4 — Train and document. Twenty minutes with the front desk on asking and recording patient location. Twenty minutes with providers on the modality documentation fields. Update your telehealth policy, your remote-work attestation, and your risk analysis to reflect the current environment. If your policy set has not been touched since your program was three providers, an automated HIPAA risk analysis and policy build is faster than editing a five-year-old Word file.
The new telehealth codes for 2025 were a coding change on paper and an operations change in practice. The denials get your attention first; the vendor and records gaps are what actually cost you later.
If your virtual program grew faster than your paperwork, start with the agreements. Build the Business Associate Agreements your telehealth vendors are missing and get them signed before your next records request or audit forces the question.