Your billing manager pulls the March report: 63 telehealth encounters, 11 denials, and every one of the denials traces back to a place-of-service mismatch. Nobody miscoded on purpose. The front desk simply never recorded where the patient physically sat during the visit, so the coder guessed, and the guess didn't match the payer's policy.

That is what telehealth billing failure looks like in practice — not a coding argument, but a missing field on an intake screen. This guide walks through the operational mechanics your administrative staff control, then makes the privacy, records-handling, and vendor-contract consequences explicit. It is written for administrators, billing leads, and privacy officers, not for clinicians and not for patients. Coding decisions belong to your providers and certified coders; your job is to make sure the facts they need are captured, documented, and defensible.

The Four Facts a Telehealth Claim Depends On

Every remote encounter your practice bills rests on four pieces of information. Miss any one and you get a denial, a refund request, or a records production you can't complete.

1. Where the patient physically was

Patient location at the time of service drives place-of-service selection, state licensure questions, and sometimes payer eligibility entirely. "Home" and "not home" are different codes. A patient in a car in a parking lot is neither, and your staff need a script for asking.

Build the question into scheduling and into the visit opener: "Where are you located right now?" Record the answer as structured data in the encounter, not as free text buried in a note. Free text is invisible to your coders and invisible to an auditor's sampling logic.

2. Where the rendering provider was

Distant-site location affects licensure, payer enrollment, and — increasingly — your Security Rule risk analysis. A provider taking visits from a home office is a workstation your practice is responsible for. Log it. If a clinician relocates temporarily, your credentialing coordinator and your privacy officer both need to know, for different reasons.

3. Which modality was used

Real-time audio-video, audio-only, store-and-forward, and asynchronous messaging are separate billing categories with separate modifier conventions and separate payer rules. Your platform should stamp the modality automatically. If it doesn't, your staff record it manually at the close of the visit — before the encounter is released to coding, not after.

Audio-only matters twice over. It changes the claim, and it changes your vendor analysis, because a VoIP or app-based calling service handling protected health information is a business associate while a traditional landline call is not.

Many payers and most states require the patient to consent to a telehealth encounter, and many require that consent be documented in the record. Some require it once; some require it per episode. Your practice needs a consent artifact with a date, a method, and a name attached — not a verbal acknowledgment that lives only in a clinician's memory.

What Information Does a Telehealth Claim Need?

A clean telehealth claim generally requires: the patient's physical location at the time of service, the rendering provider's location, the modality used (audio-video versus audio-only versus asynchronous), the appropriate place-of-service code, any payer-required modifier indicating the service was delivered remotely, documented patient consent where required by payer or state law, and standard encounter documentation supporting the level of service billed. Your coders select the specific codes and modifiers from the documented facts and the payer's current policy — your administrative workflow's job is to make sure every one of those facts exists in the record before the encounter is released for coding.

Place-of-Service and Modifier Selection Is a Documentation Problem

Two place-of-service codes exist for telehealth: one for services delivered to a patient in the home, one for services delivered to a patient elsewhere. Modifiers exist to flag synchronous audio-video delivery and audio-only delivery. Payers apply these differently, and commercial payer policy frequently diverges from Medicare policy.

Do not let your billing staff apply a default. Defaults are how eleven claims come back at once. Instead:

  • Maintain a payer grid — one row per contracted payer, columns for accepted place-of-service codes, required modifiers, audio-only policy, and consent requirements.
  • Assign one named owner to review that grid quarterly against published payer policy bulletins.
  • Date-stamp every row. When a payer recoups eighteen months later, you want to show what the policy said on the date of service.
  • Route any encounter missing location or modality data to a hold queue rather than to coding.

CMS publishes its current telehealth service list and billing guidance at cms.gov/medicare/coverage/telehealth, and the federal telehealth resource center maintains plain-language billing and reimbursement guidance for providers. Both change. Check them on a calendar, not on a rumor.

Medicare Authority Has Moved in Short Increments — Build for That

Since the public health emergency ended, Medicare's telehealth flexibilities have been extended through a series of short-term legislative vehicles rather than permanent statute. Extensions have run in increments of months, and authority has lapsed at least once before being restored retroactively. In past lapses, CMS directed Medicare contractors to hold affected claims temporarily rather than process them immediately.

Your operational response is not to predict Congress. It is to build a hold-and-verify step:

  1. Put the current expiration date of Medicare telehealth authority on your billing calendar with a 30-day advance reminder.
  2. Two weeks before expiration, confirm status with your MAC and your clearinghouse.
  3. If authority lapses, hold affected Medicare telehealth claims rather than submitting and absorbing denials — but keep billing commercial and Medicaid lines normally, since those follow separate rules.
  4. Tell patients nothing about coverage you can't confirm. Front-desk staff should say "we're verifying coverage for this visit type," not guess.

Why Telehealth Billing Expands Your Business Associate List

Count the vendors that touch a single remote visit. The video platform. The scheduling tool that sent the link. The e-signature service that captured consent. The interpreter service. The payment processor collecting the copay. The clearinghouse. The transcription or ambient documentation tool if you use one. The analytics script running on the page where the patient clicked "join visit."

Every one of those that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and every one requires a signed agreement before it touches data. The HIPAA enforcement discretion that let practices use consumer video apps during the emergency ended in August 2023. There is no remaining grace period. HHS maintains current guidance on telehealth and HIPAA obligations, including its position on audio-only encounters.

Most practices discover the gap the same way: a records request or a security questionnaire forces someone to actually list the vendors, and three of them have no agreement on file. If that's where you are, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than waiting on outside counsel to redline a template you already have.

The three questions to ask each telehealth vendor

  • Do you retain any content from the session? Recordings, transcripts, chat logs, and waiting-room metadata are all PHI if they identify the patient. Get retention periods in writing.
  • Where does the data physically live, and who has administrative access? Subcontractor chains matter. Your BAA should require downstream agreements.
  • What is your breach notification timeline to us? You have 60 days from discovery to notify affected individuals. If your vendor takes 55 of those days to tell you, you have a problem you created at contract signing.

Where Telehealth Billing Quietly Leaks PHI

The billing side of a remote visit creates exposure the clinical side doesn't.

Payment pages and tracking scripts. If your "pay your telehealth bill" page carries third-party analytics or advertising pixels, and the URL or form fields reveal anything about the patient's care, you have a disclosure to evaluate. OCR's guidance on online tracking technologies has been litigated and partially narrowed, but the underlying principle survives: disclosure of identifiable health information to a third party needs a legal basis. Have your privacy officer inventory every script on every patient-facing page in the payment and scheduling path.

Recordings and transcripts. A recorded telehealth session is part of the designated record set if it's used to make decisions about the patient. That means it's subject to the 30-day access right, and your staff need to be able to produce it. If you can't produce it, don't record it.

Remote billing staff. Coders and billers working from home handle full claim detail. Their home network, their screen visibility, and their printer are all in scope for your risk analysis. NIST's Cybersecurity Resource Guide for implementing the HIPAA Security Rule is the practical reference for scoping those controls.

Screenshots and workarounds. When a system doesn't capture patient location, staff invent a place to put it — a sticky note, a personal phone photo, a spreadsheet on a desktop. Every workaround you don't know about is an unmanaged PHI repository. Ask about them directly during training; nobody volunteers them.

A 30-Day Cleanup You Can Actually Run

Week 1 — Inventory. List every vendor involved in a telehealth encounter from scheduling through payment posting. Mark which have executed BAAs on file and where those documents live. Name a single owner for the list.

Week 2 — Close the contract gaps. Execute agreements for anything unmarked. For anything that refuses to sign, decide whether to replace it and set a date.

Week 3 — Fix intake. Add structured fields for patient location, provider location, modality, and consent. Route incomplete encounters to a hold queue. Retrain front-desk and intake staff on the location script and document that the training happened.

Week 4 — Audit backward. Pull a sample of 25 telehealth claims from the prior quarter. For each, confirm you can locate patient location, modality, consent, and the payer policy in effect on the date of service. Whatever you can't find is your remediation list, and it's also your overpayment exposure.

Repeat the Week 4 sample quarterly. Ten minutes per claim, four hours a quarter, and you will never again learn about a systemic telehealth billing problem from a recoupment letter.

Next Step

Start with the vendor list — it is the fastest gap to find and the most expensive to ignore. If the inventory turns up agreements you never executed, you can produce a signature-ready BAA in a single sitting and clear the backlog this week. If the inventory turns up something larger — no current risk analysis, stale policies, no documented training — the broader HIPAA risk analysis and policy document set covers the rest of the file an auditor will ask for.