Telehealth Codes: A Practice Admin's Billing Playbook
A payer sends your billing lead a records request for 42 telehealth visits from the previous quarter. They want the note, the modality, the patient's physical location at the time of service, and proof the visit was synchronous. Your platform retains connection logs for 90 days. Eleven of those visits are older than that.
That is the real operational problem with telehealth codes: the code on the claim is a claim about facts, and the facts live in four different systems owned by three different companies. This guide is for the administrator, biller, or privacy officer who has to make those systems agree — how place of service and modifier assignment actually gets decided, what documentation has to exist before the visit ends, and which vendors need a Business Associate Agreement because they can see the encounter.
The Four Fields That Make a Telehealth Claim
Staff talk about "the telehealth code" as if it were one field. It is at least four, and a denial can come from any of them.
The procedure code itself
Practices generally bill the service that was performed — an office or outpatient E/M, a behavioral health service, a specific screening — and then flag the modality. CPT 2025 introduced a dedicated telemedicine E/M family in the 98000 series, including audio-video codes, audio-only codes, and a brief communication technology-based service code. Medicare did not adopt most of that family when it appeared, instructing practices to continue reporting standard E/M codes with a telehealth place of service and modifier instead.
That split is the point. Commercial payers, Medicaid programs, and Medicare have moved at different speeds, so your fee schedule crosswalk has to be payer-specific and dated. Your billing lead determines code selection by reading the current CPT guidance alongside each payer's published telehealth policy, then documents the basis for that mapping in a written internal reference. Nobody on your staff should be selecting a code from memory or from a printout that predates the current plan year.
Place of service
POS 02 and POS 10 distinguish telehealth furnished somewhere other than the patient's home from telehealth furnished in the patient's home. That is a factual determination about where the patient physically sat, not a default. It also affects the facility versus non-facility payment rate on many schedules, which is why an unexamined default in your practice management system quietly changes your revenue.
Modifiers
Modifier 95 signals a synchronous audio-video encounter. Modifier 93 signals synchronous audio-only. Modifier GQ covers asynchronous store-and-forward. Behavioral health carries its own layer — FQ for audio-only delivery in certain mental health and substance use contexts, FR where a supervising practitioner participated through real-time two-way audio-video. Institutional claims may still require GT under some payer rules.
Consent and location attestation
Not a code, but the field auditors ask for. Many state Medicaid programs and commercial policies require documented patient consent to the telehealth modality and documentation of patient location. If that lives in a free-text note instead of a structured field, you cannot report on it, and you cannot produce it in bulk when a payer asks for 42 visits.
Which Telehealth Codes and Modifiers Belong on a Claim?
Short answer, for the person building the workflow:
- One procedure code for the service actually performed, selected under the payer's current telehealth policy and the current CPT guidance.
- One place of service code reflecting where the patient physically was — POS 10 for the home, POS 02 for any other originating site.
- One modality modifier — 95 for audio-video, 93 for audio-only, GQ for asynchronous — plus any specialty modifier the payer requires, such as FQ or FR for behavioral health.
- Documentation in the record of modality, patient location, provider location, consent, and start and stop times.
Payers disagree on the details, and the details change with each plan year. Treat every element as payer-specific until your billing lead has confirmed otherwise in writing. CMS maintains the Medicare telehealth service list and current billing instructions on its Medicare telehealth page, and HHS publishes plain-language billing guidance for providers at telehealth.hhs.gov.
What Your Front Desk Captures Before the Visit Connects
Nearly every telehealth denial and every audit failure traces back to something that should have been captured in the first ninety seconds of the encounter. Build it into the check-in script and make the fields required.
- Patient's physical address at the time of service. Not the address on file. Ask. This drives POS selection and can determine whether the rendering clinician is licensed to provide the service at all.
- Modality actually used. If video failed and the visit finished by phone, that is an audio-only encounter and the coding follows the facts, not the appointment type.
- Consent to telehealth, recorded with date and the name of the person who obtained it.
- Identity verification method. How your staff confirmed they were talking to the right patient — and, if applicable, who else was in the room.
- Provider's location, including whether the clinician was working from a home office. Several payers require it and your risk analysis needs it.
Assign one owner. In most practices the scheduler captures fields one through four, the clinician confirms modality in the note, and the biller reconciles before the claim drops. Write down who does what. Unassigned steps do not happen.
Documentation That Survives an Audit — and Answers a Records Request
Telehealth records create a retention problem that in-person visits do not. Your note lives in the chart for years. The evidence that the visit was synchronous audio-video may live only in a platform log that your vendor purges on a schedule you did not choose.
Two questions for your platform vendor, in writing, this week: how long are session logs retained, and can you export them yourself? If the answer to the first is shorter than your payer look-back window, your practice needs a monthly export routine and a defined storage location inside your own environment.
Recordings raise the stakes further. If your practice records telehealth visits and uses those recordings to make decisions about the patient, they sit in the designated record set — which means a patient can request them and the HIPAA right of access clock applies: 30 days, with one 30-day extension on written notice. Decide deliberately whether you record at all. "We record by default because the platform offers it" is how practices end up producing video to attorneys.
Where Telehealth Codes Turn Into a Privacy Problem
Codes are disclosures. A claim carrying a behavioral-health-specific audio-only modifier tells the plan something about the encounter beyond the diagnosis line. POS 10 tells the plan the patient was at home. That is ordinarily a permitted payment disclosure, but it interacts with rights your staff must be trained to honor.
The one that catches practices: a patient who pays out of pocket in full has the right to restrict disclosure of that service to their health plan. Your front desk needs a script for it and your billing system needs a way to flag the encounter so no claim goes out. Telehealth behavioral health is where this request most often arrives, and it usually arrives at the desk, not at the privacy officer.
Minimum necessary also applies to your own internal routing. If your billing contractor gets a full chart export to code a virtual check-in, that is more PHI than the task requires. Scope access by role and review it quarterly. NIST's SP 800-66r2 maps Security Rule requirements to concrete controls if you need a framework for that review.
One more: the enforcement discretion that let practices use consumer video apps during the public health emergency ended years ago. Full HIPAA rules apply to your telehealth stack today. OCR's telehealth guidance page is the current reference.
Every Vendor That Touched the Visit Needs a BAA
Walk one telehealth encounter end to end and list who could see PHI. A typical list runs longer than administrators expect:
- The video platform, and any separate telephony provider used for audio-only visits
- The scheduling or patient-intake tool that collected the location and consent fields
- The interpreter service that joined the call
- Any ambient documentation or transcription tool used during the encounter
- The clearinghouse that transmits claims carrying your telehealth codes
- Your outsourced coding or billing contractor
- The cloud storage where you park exported session logs
- Any remote IT support vendor with access to workstations
Each of those is a business associate. Each needs an executed agreement on file, with a named owner and a renewal date. If your telehealth program grew during the emergency years and nobody went back to paper the vendor list, that gap is the first thing an OCR investigator will find after an incident. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is usually faster than waiting on a vendor's legal department to send their template.
Do not stop at signature. Ask each vendor where PHI is stored, whether subcontractors are involved, what their breach notification timeline to you is, and what happens to your data at termination. Record the answers next to the agreement.
When Coverage Flexibilities Lapse: Your Claim-Hold Policy
Medicare's statutory telehealth flexibilities have been extended in short increments tied to appropriations legislation, and there have been lapses. DEA's tele-prescribing flexibilities for controlled substances have followed a similar pattern of temporary extensions. Neither is something you can set and forget.
Assign a named person to check the current expiration date monthly and to own a written claim-hold policy: which service categories pause, which get held for retroactive processing, how patients get told before the visit rather than after the bill, and who signs off on releasing held claims. Practices that improvised through the last lapse spent weeks on rework. A one-page policy prevents that.
Your 30-Day Assignment Sheet
- Week 1 — Billing lead builds a dated, payer-specific telehealth code and modifier crosswalk. Privacy officer pulls the vendor inventory for the telehealth stack.
- Week 2 — Confirm platform log retention in writing. Stand up a monthly export to storage you control.
- Week 3 — Make location, modality, consent, and identity-verification fields required at check-in. Train the desk on the self-pay restriction request script.
- Week 4 — Close BAA gaps. Publish the claim-hold policy. Run a 20-claim internal audit comparing POS and modifier on the claim against the note.
If that internal audit turns up disagreement between the claim and the record in more than a claim or two, the problem is workflow design, not staff carelessness. Fix the required fields before you retrain anyone.
Start with the vendor list, because it is the gap with the longest tail. Inventory every party that touches a telehealth encounter, then put an executed BAA behind each one. If your broader documentation set — risk analysis, policies, procedures — also dates to the emergency years, bringing the full compliance document set current is the natural next project once your telehealth codes and vendor files are clean.