Telehealth CPT Codes 2026: A Practice Admin's Playbook
Your biller queues 43 telehealth claims on a Thursday afternoon. Eleven go to Medicare, nine to a national commercial plan, six to a Medicaid managed care plan, and the rest to four smaller payers. Every one of those claims needs a code, a modifier, and a place of service that match that payer's current policy — and the choices are not the same across the four groups. That is the practical problem with telehealth CPT codes 2026: the code set stopped being one set.
This guide is for the person who owns that queue — the administrator, billing lead, or compliance officer who gets the denial report and the records request. It covers how practices build and document code-selection logic, then makes the privacy and vendor consequences explicit, because telehealth billing generates PHI in places your risk analysis probably does not mention.
Telehealth CPT Codes 2026: Two Code Families, One Claim Line
Since CPT 2025, the AMA has maintained a dedicated telemedicine evaluation and management family: synchronous audio-video E/M codes in the 98000–98007 range, synchronous audio-only E/M codes in the 98008–98015 range, and 98016 for a brief communication technology-based check-in. Those codes exist, they are current, and many commercial payers accept them.
Medicare took a different road. Rather than adopting the telemedicine E/M family for the Physician Fee Schedule, CMS has continued to direct billing of telehealth office visits through the standard office/outpatient E/M codes with telehealth modifiers and place-of-service reporting, while recognizing 98016 for brief virtual check-ins. Your Medicare Administrative Contractor's article on telehealth billing is the controlling operational document, not the CPT book alone.
Medicaid adds a third pattern. State Medicaid programs and their managed care plans set their own telehealth code lists, modifier requirements, and originating-site rules, and several diverge from both AMA and Medicare conventions.
What this means operationally: nobody on your staff should be selecting a telehealth code from memory. Code selection in 2026 is a lookup against a payer policy table, applied to documentation that already exists in the note. Your job as an administrator is to build the table and the documentation prompts — not to tell a clinician which code fits a patient.
Which Modifier and Place of Service Go on a 2026 Telehealth Claim?
Here is the short answer practices reference at the desk, subject to each payer's published policy:
- Modifier 95 — synchronous telemedicine service rendered via real-time interactive audio and video.
- Modifier 93 — synchronous telemedicine service rendered via telephone or other real-time interactive audio-only technology.
- Modifier FQ — service furnished using audio-only communications, used by some payers for behavioral health encounters.
- Modifier FR — a supervising practitioner was present through real-time two-way audio/video.
- POS 02 — telehealth provided somewhere other than the patient's home.
- POS 10 — telehealth provided in the patient's home.
Payers differ on whether they want the telehealth POS with the office E/M code, or the office POS plus modifier 95, or the AMA telemedicine E/M codes with no modifier at all. Confirm each payer in writing and store the citation. CMS maintains its current list of covered services and billing instructions on its Medicare telehealth coverage page.
The Payer Policy Matrix Your Billing Lead Should Own
Build one spreadsheet. One row per payer, one column per decision. Assign it to a named person and review it quarterly, with an out-of-cycle review whenever a payer bulletin lands.
Columns that earn their keep:
- Accepted telehealth E/M code family (telemedicine E/M series vs. office/outpatient E/M).
- Required modifier for audio-video and for audio-only.
- Required place of service.
- Whether audio-only is payable at all, and for which service categories.
- Whether the originating site may be the patient's home, and any geographic condition.
- Any prior in-person visit requirement, and the lookback window.
- Consent documentation the payer expects in the record.
- Policy effective date, expiration date, and the URL or bulletin number you pulled it from.
That last column is the one auditors care about. When a payer recoups two years of telehealth claims, the defensible position is "here is the policy version we relied on, dated, retrieved on this date." Undocumented reliance is not a position.
Documentation Elements That Must Exist Before the Coder Opens the Note
Telehealth denials cluster around four missing facts, and all four are workflow problems, not coding problems.
Patient physical location at the time of service
Your intake script captures it, your template records it. This drives place of service, licensure exposure, and in some states consent requirements. "Patient at home" is not enough if the patient was in a hotel three states away.
Practitioner location at the time of service
Home office, satellite clinic, main site. Enrollment and reassignment records need to support wherever you say the service was furnished.
Modality actually used, and why
If the encounter started on video and dropped to phone, the note should say so. Audio-only reimbursement frequently turns on a documented reason the patient could not or would not use video. That sentence has to be written by the clinician during the visit, not reconstructed by a coder in week three.
Time and the basis for level selection
Telemedicine E/M families are time-defined in ways that differ from the office E/M structure. Your template should capture the elements the applicable code family requires, so that whoever assigns the code is reading facts rather than inferring them. Practices document code selection; they do not reverse-engineer it.
The Patient-Location Field Is Now PHI Your Claims Broadcast
This is where telehealth CPT codes 2026 stop being a billing topic. Place of service 10 tells every downstream recipient of that claim that the encounter happened in the patient's residence. Modifier FQ, in the contexts where payers use it, effectively flags a behavioral health encounter conducted by phone.
Claims data is a permitted disclosure for payment. It is still subject to minimum necessary when you send it anywhere other than the payer — and practices send it plenty of other places. Clearinghouse portals, analytics dashboards, revenue cycle outsourcers, denial management contractors, patient statements printed by a mail vendor.
Two habits to adopt now:
- Statement suppression review. If a patient has requested confidential communications, or paid out of pocket and restricted disclosure to their plan, make sure your telehealth encounter does not surface on a household statement or an EOB path the patient asked you to avoid.
- Reporting field discipline. Ad hoc telehealth utilization reports pulled for a board meeting or a payer negotiation should not carry patient identifiers alongside modality and diagnosis. De-identify or aggregate before the file leaves your building.
Your Telehealth Vendor Stack Is Longer Than Your BAA List
OCR's pandemic-era enforcement discretion for telehealth platforms ended in August 2023. There is no remaining allowance for a non-compliant consumer video tool, and HHS keeps its current expectations on the HIPAA and telehealth topic page.
Walk your actual telehealth encounter and count the vendors that touch PHI:
- The video platform.
- The SMS or email service that sends the visit link.
- The waiting-room or check-in module, if it is a separate product.
- The interpreter service that joins the call.
- Any ambient documentation or transcription tool the clinician turned on.
- The e-prescribing gateway.
- The clearinghouse.
- The card-present or card-not-present payment processor collecting the telehealth copay.
- Whoever hosts the recording, if you record.
Most practices have signed BAAs for one, seven, and eight. Numbers four, five, and nine are where I find gaps during vendor reviews — especially transcription tools that a clinician enabled independently because the free tier was convenient.
Three questions per telehealth vendor
Ask them in writing, and file the answers with the contract: Do you have a signed BAA with us covering the current product configuration? Where is PHI stored and for how long? Do you use encounter content for model training, product improvement, or any secondary purpose?
If the answer to the third question is anything other than a clean no, escalate before the next telehealth session. If you are missing paperwork for a vendor already in production, you can produce a signature-ready Business Associate Agreement the same afternoon rather than waiting on a vendor's legal queue.
The Recording, the Transcript, and the 30-Day Access Clock
If your telehealth platform records visits or your ambient tool retains a transcript, and clinicians use that material in care or billing decisions, treat it as part of the designated record set. That triggers the right of access — generally 30 days, with one 30-day extension on written notice.
Decide the following before a patient asks, not after:
- Do you record at all? If yes, who authorizes it and how is patient notice given?
- What is the retention period, and does the vendor actually enforce deletion?
- Can your records staff retrieve a recording without a support ticket to the vendor? If not, you cannot meet 30 days reliably.
- Does the transcript feed the note, or sit outside the chart? Outside-the-chart artifacts still get requested and still get subpoenaed.
The cleanest posture for most small and mid-size practices is: do not record, retain transcripts only as incorporated into the signed note, and configure the vendor to purge raw audio on a short fixed schedule. Write that down as policy so a new clinician cannot quietly change it.
Claims Hold-and-Release When Telehealth Authority Is in Doubt
Medicare's broader telehealth flexibilities have run on short-term legislative extensions tied to federal funding deadlines, and they briefly lapsed during the fall 2025 shutdown before being restored retroactively. Behavioral health telehealth sits on firmer statutory ground; general medical telehealth has repeatedly depended on a date on a calendar.
Do not let your billing team improvise through the next gap. Write a two-page procedure:
- Trigger. Named person checks the CMS telehealth page and the MAC bulletin list on the first business day of each month, and within 48 hours of any expiration date.
- Hold. If authority is uncertain, telehealth claims for affected service categories go into a hold bucket in your practice management system with a documented reason code.
- Communicate. Front desk gets a scripted message about potential patient responsibility. Do not tell patients a claim will be paid when you do not know.
- Release. When authority is confirmed, release in date order and reconcile against timely-filing windows.
- Document. One log entry per hold cycle: date, source consulted, decision, who approved.
That log is also your answer when a patient complains that they were billed differently in January than in March.
Fold Telehealth Into the Risk Analysis, Not a Side Memo
The Security Rule requires an accurate, thorough assessment of risks to ePHI across your whole environment. A telehealth program adds clinician home workstations, personal mobile devices, a new class of business associate, and recorded encounter content. If none of that appears in your current risk analysis, the analysis is out of date — and HHS has proposed tightening documentation expectations in its January 2025 Security Rule rulemaking, which remains a proposal.
Practices that keep this current tend to do three things: they re-run the risk analysis when a material vendor or modality changes, they map each finding to a policy that names a responsible role, and they keep dated evidence of both. If assembling that package by hand is what keeps getting deferred, tools that generate your HIPAA risk analysis and the supporting policy set will get you to a reviewable document faster than another quarter of good intentions.
Your Next 30 Days
Four assignments, four owners, four due dates:
- Billing lead: complete the payer policy matrix for your top eight payers, with source citations and effective dates.
- Clinical informatics or template owner: confirm the telehealth note template captures patient location, practitioner location, modality, reason for audio-only, and time.
- Privacy officer: walk one live telehealth encounter end to end, list every vendor that touches PHI, and reconcile against the signed BAA file.
- Records custodian: test retrieval of one recording or transcript and time it. If it takes more than five business days, fix the access path or stop retaining the artifact.
Getting telehealth CPT codes 2026 right is mostly a documentation and vendor-governance exercise wearing a billing costume. The practices that handle it well treat the code question and the privacy question as one project with one owner. If your compliance documentation has not caught up with the telehealth program you actually run, build the current risk analysis and policy set first — everything on the punch list above depends on it.