A date of service from March 2025 can still be filed with Medicare until March 2026. Corrected claims, appeals, and payer audit requests run longer than that. So even though the calendar says 2026, the telehealth CPT codes 2025 introduced are still sitting in your work queues — in denials you haven't resolved, in an appeal your biller is drafting today, and in the sample a payer will pull eighteen months from now.

This guide is for the administrator who owns that queue. It covers what the 2025 telemedicine code set changed operationally, how practices document code selection defensibly, and — the part that gets skipped — which vendor agreements and records-handling obligations every telehealth encounter drags behind it.

Which Telehealth CPT Codes 2025 Introduced

The AMA's CPT 2025 code set added a dedicated telemedicine evaluation and management family, retiring the practice of describing every virtual visit with an office visit code plus a modifier:

  • 98000–98003 — synchronous audio-video telemedicine E/M, new patient
  • 98004–98007 — synchronous audio-video telemedicine E/M, established patient
  • 98008–98011 — synchronous audio-only telemedicine E/M, new patient
  • 98012–98015 — synchronous audio-only telemedicine E/M, established patient
  • 98016 — brief synchronous communication technology-based service (the "virtual check-in" successor to HCPCS G2012)

The operational catch: Medicare did not adopt the 98000–98015 range for the CY2025 Physician Fee Schedule. CMS treated those codes as non-payable and directed practices to continue reporting office/outpatient E/M codes with the appropriate place of service and modifier for Medicare telehealth. CMS did accept 98016 as the replacement for G2012. Commercial payers and Medicaid programs split — some adopted the new family immediately, some lagged a full year, some published nothing and simply denied.

That split is why your 2025 aging report probably still has telehealth lines on it.

Your Payer Matrix Is a Compliance Document, Not a Cheat Sheet

Practices that came through 2025 cleanly did one thing: they maintained a written, dated, per-payer matrix showing which telehealth code family that payer accepted, effective when, with a link or PDF of the payer bulletin that established it.

Keep that matrix even now. When a payer audits a 2025 date of service, the question is never "was this the right code?" in the abstract. It's "what instruction were you following on that date, and can you produce it?" A matrix with source citations answers that in one screen. Institutional memory does not.

Who owns the matrix

Assign it by name, not by department. One person — usually the billing lead — owns quarterly review. The compliance officer countersigns. Store versions, don't overwrite them; an overwritten spreadsheet destroys exactly the evidence you'll need.

Code Selection Is a Documentation Workflow, Not a Lookup

Nothing in this article tells you which code fits a given encounter. That determination belongs to the rendering clinician working from the CPT descriptors, payer policy, and the documented content of the visit. Your job as administrator is to make sure the determination is traceable.

Three operational controls do most of the work:

  1. Modality captured at the encounter, not reconstructed later. Audio-video versus audio-only drives code family selection and modifier use. If your documentation template doesn't force a modality field, your coders are guessing, and a guess is an audit finding.
  2. Patient physical location documented. Telehealth billing depends on where the patient was, and licensure depends on it too. "Patient at home in [state]" is a one-line habit that prevents a licensure inquiry.
  3. Time or medical decision making recorded consistently. The 2025 telemedicine E/M codes are structured around the same selection logic clinicians already use. Whichever basis the clinician relies on, the note has to show it.

Run a monthly ten-chart telehealth sample against those three fields. Report the pass rate to your compliance committee. That single metric surfaces template problems months before a payer does.

Place of Service 10 Is a Privacy Disclosure You Make on Every Claim

Here is the implication almost no coding webinar covers. POS 02 means telehealth somewhere other than the patient's home. POS 10 means the patient was in their home.

When you submit POS 10, you are transmitting, to a payer and through a clearinghouse, an assertion about where a specific person physically was during a specific health service. That is protected health information, and it is more sensitive than it looks. For a patient in a domestic violence situation, a custody dispute, or a substance use treatment program, home-location data attached to a behavioral health code is exactly the combination that causes harm when it leaks.

Practical consequences for your operation:

  • Restriction requests get harder. A patient who pays out of pocket and requests that you not disclose to their health plan has a right to that restriction under the HIPAA right-to-request-restrictions provision. Your telehealth workflow needs a hold-the-claim path, not just a sticky note.
  • Minimum necessary applies to your own reports. Telehealth utilization dashboards that include POS and patient identifiers get circulated to practice managers who don't need them. Strip or aggregate.
  • Clearinghouse and RCM vendors are business associates. They are handling home-location data at volume. Their agreements and their breach notification timelines matter more than they did when everything was POS 11.

Every Telehealth Code Implies at Least Three Vendors

Bill a synchronous telemedicine service and you have, at minimum: a video platform, a scheduling and reminder pathway, and a claims transmission chain. Most practices have more — an interpreter service dialed into the call, an AI scribe drafting the note, a patient-payment processor, a cloud backup of session artifacts.

Every one of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. OCR's COVID-era enforcement discretion for telehealth platforms ended in 2023, and the transition period with it. There is no remaining grace period for a consumer video tool with no agreement behind it. HHS keeps its telehealth-specific HIPAA guidance current, including its guidance on audio-only encounters.

The vendors practices forget

  • The AI scribe or ambient documentation tool. It hears the entire encounter. Ask where audio is stored, for how long, whether it trains models on your data, and get that in writing as a restriction in the agreement.
  • The interpreter contractor. A per-call vendor is still a business associate.
  • The waiting-room SMS notifier. Appointment reminders that name the modality and the clinician disclose more than "you have an appointment."
  • The recording archive. If your platform records by default and you haven't turned it off, you have created a designated record set component with a retention obligation and a discovery exposure.
  • The billing consultant with remote read-only access. Read-only is still access.

Pull your telehealth vendor list against your signed agreement file this week. When you find the gap — and there is almost always a gap in the scribe, interpreter, or archive row — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription, which matters when the gap is a single small vendor and you don't want a platform contract to close one row on a spreadsheet.

When Flexibilities Lapse: The Claim-Hold Playbook

Medicare's statutory telehealth flexibilities — the geographic and originating-site waivers that let non-behavioral-health telehealth reach a patient's home — have been extended in short increments by a series of appropriations measures rather than made permanent. During the fall 2025 funding lapse, those flexibilities briefly expired, and practices that kept billing normally generated denials they then had to rework by hand.

Do not build your workflow around a specific expiration date, and do not trust a webinar slide from last quarter. Check the CMS Medicare telehealth page and the policy tracker at telehealth.hhs.gov before each expiration window, and write down a standing procedure:

  1. Two weeks out: billing lead confirms current authority status and notifies scheduling.
  2. Lapse day: hold affected Medicare telehealth claims rather than submitting into a denial. Behavioral health telehealth to the home has separate, permanent authority — segment it out so you don't hold claims you could have paid.
  3. During a hold: front desk uses one approved script about potential coverage changes. Do not let staff improvise financial statements at the point of scheduling.
  4. On restoration: release held claims, then reconcile against the hold list. Anything that didn't move gets escalated within five business days.

Records Requests for Telehealth Encounters

A patient's right of access covers the telehealth note, the associated billing record, and any recording you retained that you use to make decisions about them. Your 30-day clock does not pause because the material lives in a video platform your EHR doesn't index.

Two failure modes to fix now. First, requests that require pulling from a second system routinely blow the deadline because nobody assigned the pull. Name the person. Second, staff sometimes send a session recording when the request was for the chart — an over-disclosure that is itself a HIPAA problem. Your access procedure needs an explicit scope-confirmation step before anything leaves the building.

Retention deserves a decision on paper. If you don't need session recordings, configure the platform not to make them. A recording you never created cannot be breached, subpoenaed, or mishandled by a temp.

A 30-Day Cleanup Plan

Week 1 — Billing lead: reconcile open 2025 telehealth denials against the payer matrix. Flag any denial where the matrix has no dated source citation.

Week 2 — Compliance officer: inventory every system touched by a telehealth encounter. Match against signed agreements. Close gaps.

Week 3 — Clinical documentation owner: confirm the encounter template forces modality and patient location. Sample ten charts.

Week 4 — Administrator: update the risk analysis to reflect telehealth systems, remote workstations, and recording retention. If your last analysis predates your current platform, it is out of date — and the Security Rule requires it to be accurate and current. Teams that would rather not rebuild it from a blank template can automate the risk analysis and supporting policy set and spend the saved hours on the vendor gaps instead.

The 2025 telemedicine code family will keep showing up in your appeals and audit samples through 2027. Treat the telehealth CPT codes 2025 brought in as an operations problem with a documentation trail and a vendor list — not as a lookup table — and both halves of the exposure shrink at once.

Start with the vendor list, because it is the shortest task with the largest downside. Pull it today, and put a signed BAA behind every telehealth vendor before your next records request arrives.