Telehealth CPT Codes: A Practice Admin's Billing Guide
A three-provider behavioral health practice ran 412 virtual visits in January and got 61 of them denied. The clinical documentation was fine. The problem was mechanical: audio-only encounters submitted with the audio-video modifier, place-of-service 02 on visits the patient took from their kitchen table, and one payer that had quietly stopped recognizing a code set the billing lead had been using since 2023. Telehealth CPT codes are where your revenue cycle and your privacy program collide, and most practices staff only one side of that collision.
This guide is for the administrator who owns the claim scrubber, the compliance lead who owns the vendor list, and the billing supervisor caught between them. It covers how practices structure and document telehealth code selection, then makes the records-handling and business associate implications explicit — because the platform generating those encounters is a business associate whether or not anyone has papered it.
What Every Telehealth Claim Carries Beyond the Code
A telehealth claim is not a standard office visit claim with a checkbox. Four data elements travel together, and if any one of them contradicts the others, the claim fails or — worse — pays and then gets clawed back on audit.
- The service code. Either an office/outpatient E/M code (the 99202–99215 range), a telemedicine-specific CPT code, or an HCPCS G-code, depending on payer policy and the modality used.
- The place of service. POS 02 for telehealth furnished somewhere other than the patient's home; POS 10 for telehealth furnished in the patient's home. These are distinct, they reimburse differently under some contracts, and staff reverse them constantly.
- The modality modifier. Modifier 95 signals synchronous audio-video. Modifier 93 signals synchronous audio-only. Behavioral health carries additional modifiers under Medicare, and critical access hospitals have their own conventions.
- The originating and distant site facts. Where the patient physically was, where the rendering provider physically was, and whether the provider was licensed in the patient's state at that moment.
That last element is the one your billing system almost never captures and your malpractice carrier cares about most. It is also protected health information the second it lands in a note.
The Snippet Answer: What Do You Need on a Telehealth Claim?
A compliant telehealth claim generally requires: (1) a service code your payer recognizes for the modality delivered, (2) the correct place-of-service code distinguishing home from non-home, (3) a modality modifier identifying audio-video versus audio-only, (4) documentation of the patient's physical location and the provider's location at the time of service, and (5) evidence the patient consented to virtual care. Payer policies differ on all five. Verify each element against the specific payer's current telehealth policy before the claim goes out.
Who Owns Code Selection, and Who Owns Proving It
Code selection belongs to the rendering provider. That is not a formality — it is the line that keeps your practice out of a false claims problem. Your billing staff do not choose codes based on what pays; they validate that the documentation supports what the provider selected, and they route mismatches back for clarification.
Write that division down. In a practice-operations manual, it looks like this:
- Provider: selects the service code and attests to modality, patient location, and total time or medical decision-making in the note.
- Billing specialist: maps the selected code to the payer's current telehealth policy, applies POS and modifier per that policy, and flags any code the payer has not published as telehealth-eligible.
- Billing supervisor: maintains a payer-by-payer telehealth policy grid, reviewed quarterly, with a date stamp on each row.
- Compliance officer: samples 10 telehealth claims per provider per quarter, checks documentation-to-code alignment, and logs the results.
The quarterly grid is the unglamorous part that saves you. Payers change telehealth policy mid-year with little fanfare. If your grid says "Payer X, audio-only behavioral health, verified 2026-01-15," you have a defensible process. If your grid is a shared spreadsheet nobody has touched since 2024, you have exposure.
Telehealth CPT Codes: The 2025 Telemedicine E/M Set and the Payer Split
CPT 2025 introduced a dedicated telemedicine evaluation and management family — the 98000-series — covering synchronous audio-video and synchronous audio-only encounters for new and established patients, plus a brief communication technology-based service code. At the same time, the legacy telephone E/M codes in the 99441–99443 range were deleted from CPT.
Commercial payers and Medicare did not move in lockstep. Medicare's physician fee schedule rulemaking took a different approach to the new telemedicine E/M family than the CPT editorial changes implied, continuing to rely on the office/outpatient E/M codes for most distant-site services. The practical result: your billers cannot assume a single code set works across your payer mix.
This is exactly why the grid matters more than memorization. Build it with these columns: payer, product line, code set accepted, POS required, modifier required, audio-only permitted, consent documentation required, date verified, verified by. Nine columns, one row per payer product. Your billing supervisor updates it; your compliance officer spot-checks it.
Do Not Let a Denial Trend Become a Coding Policy
When denials cluster, the instinct is to change what you submit until claims pay. That instinct produces upcoding investigations. The correct response is to obtain the payer's written telehealth policy, compare it to your submissions, and document the discrepancy. If a payer's policy is genuinely ambiguous, request clarification in writing and keep the response. Written payer guidance is the single most useful artifact in a post-payment audit.
Medicare's Moving Expiration Dates Are an Operational Problem, Not a Policy Debate
Since the end of the public health emergency, Congress has extended Medicare's expanded telehealth authority in short increments — sometimes a year, sometimes a quarter, sometimes attached to a continuing resolution. There have been lapses. During a lapse, claims for services that were reimbursable the week before can be rejected or held.
Do not let a single person carry this in their head. Assign it as a standing calendar item: your billing supervisor checks the current status of Medicare telehealth authority on the CMS telehealth coverage page at the start of every month and before any known expiration date, and documents what they found. When authority is uncertain, your front desk needs a script and your schedulers need to know whether to convert appointments to in-person.
Build the fallback now, while nothing is on fire. Which visit types can convert to in-person on 48 hours' notice? Which providers have in-person capacity? Which patients have travel barriers that make conversion impossible? That is a one-page document, and it is worth more than any coding webinar.
Where Telehealth Codes Create HIPAA Exposure Your Billing Team Never Sees
Every telehealth CPT code on a claim implies a technology stack behind it. That stack creates disclosures your privacy officer is accountable for.
The Platform Is a Business Associate. Full Stop.
OCR's pandemic-era enforcement discretion for telehealth communication technologies ended in 2023. There is no remaining allowance for consumer-grade video tools without a business associate agreement. If a provider in your practice is running visits on a personal video account because the sanctioned platform was glitchy, you have an unpapered disclosure of PHI and a documentation problem on the same encounter.
Audit this the boring way: pull a month of telehealth claims, sample twenty, and ask each rendering provider which platform they used. Compare against your executed BAA list. Any platform without a current signed agreement goes on a remediation list with a date. If you find a gap and need an agreement in hand quickly, you can generate a signature-ready business associate agreement rather than waiting on legal calendar time.
Audio-Only Visits Have Their Own Records Trail
Audio-only encounters get billed through a different code path, and they often get delivered through a different technology path — a softphone, a call-forwarding service, a mobile app. Each of those is a vendor. Each may retain call metadata, voicemail, or recordings. Ask your telephony vendor directly: what do you retain, for how long, and where? Put the answer in your vendor inventory.
If any part of your practice records telehealth sessions — for supervision, training, or documentation — that recording is part of the designated record set when it is used to make decisions about the patient. It falls under the same access, amendment, and retention obligations as the chart, and it must be addressed in your retention schedule.
Location Data Is PHI
Documenting the patient's physical location is a billing requirement. It is also a piece of information many patients would consider sensitive — a home address, a workplace, a shelter, a car in a parking lot. Apply minimum necessary. Your billing staff need to know the location qualifies as home or not-home; they do not need the street address in a claim note. Train to that distinction.
The Risk Analysis Gap Telehealth Opens
The Security Rule requires an accurate and thorough assessment of risks to electronic PHI across your environment. Most practices completed one before they added telehealth, then added three vendors, two integrations, and a scheduling widget without touching the document. HHS's Security Rule guidance is clear that this is an ongoing obligation, not a one-time artifact, and proposed updates to the rule have signaled tighter expectations around asset inventories and documentation.
Your telehealth stack belongs in scope: the video platform, the waiting-room application, the e-consent tool, the payment collection integration, the interpreter service, the clearinghouse that touches the claim. Each one gets a row, a data-flow description, a safeguard, and a residual risk rating.
If that inventory does not exist in writing, building it by hand takes weeks. Practices that would rather spend those weeks on denials management can automate the risk analysis and policy document set and get a current, dated deliverable covering the telehealth systems they actually run. What matters to an investigator is that the analysis is current, specific to your environment, and reflects the systems in use — not who typed it.
A 30-Day Cleanup Sequence
- Days 1–5. Pull 90 days of telehealth claims. Sort by payer, code, POS, and modifier. Identify every combination in use.
- Days 6–12. Retrieve current written telehealth policy from your top five payers by volume. Build the nine-column grid.
- Days 13–18. Reconcile the claim data against the grid. Log every mismatch. Determine whether any require corrected claims or a refund analysis — involve counsel if the pattern is systemic.
- Days 19–24. Inventory every technology touching a telehealth encounter. Match against executed BAAs. Remediate gaps.
- Days 25–30. Update your risk analysis to include the telehealth stack. Update your retention schedule to address recordings and call metadata. Brief providers on the documentation elements their code selection depends on.
HHS maintains practical provider-facing telehealth resources worth circulating to clinical staff alongside your internal grid.
Start With the Vendor List
Telehealth CPT codes will keep shifting — CPT revises annually, Medicare authority moves on a legislative clock, and commercial payers publish policy changes with thirty days' notice or less. The coding grid is a living document and always will be.
The privacy foundation underneath it should not be. Pin down the vendor inventory, the executed agreements, and a risk analysis that names your actual telehealth systems. Then let the coding grid change quarterly without the compliance file changing with it. If your risk analysis predates your telehealth program, build a current one against the systems you run today and give your next auditor something dated this year.