A billing manager at a three-provider behavioral health practice recently pulled a report and found 214 telehealth claims from a single quarter submitted with the wrong telehealth place of service code. Nobody had done anything malicious. A new scheduler had been trained to pick the first telehealth option in the dropdown, and the dropdown was alphabetical. The practice had been paid at a facility rate for visits delivered to patients sitting in their kitchens.

If you run a practice that bills any virtual visits, this is your problem to solve — and it is not only a revenue problem. The place of service code you transmit tells every payer, clearinghouse, and downstream vendor something specific about where your patient was physically sitting. That makes it a billing decision and a disclosure decision at the same time. This guide covers the operational mechanics, the role assignments, and the privacy exposure your compliance file needs to account for.

What the Telehealth Place of Service Code Actually Tells a Payer

Place of service (POS) codes are two-digit values on the professional claim that identify the setting where a service was furnished. For virtual care, two codes carry the load:

  • POS 02 — Telehealth Provided Other than in Patient's Home. The patient was at an originating site that is not their residence: a clinic, a school-based site, a partner facility.
  • POS 10 — Telehealth Provided in Patient's Home. The patient was in their residence, including temporary lodging.

CMS added POS 10 to the code set in 2022 specifically to separate home-based virtual care from facility-originated virtual care. The practical consequence is that the two codes generally map to different payment rates — POS 02 to the facility rate, POS 10 to the non-facility rate — so selecting the wrong one distorts reimbursement in one direction or the other. The current definitions live in the CMS Place of Service code set, which is the authoritative source your billing team should be checking against, not a vendor cheat sheet from 2023.

Modifiers Are a Separate Decision from POS

Modifier 95 flags a synchronous service delivered via interactive audio and video. Modifier 93 flags a synchronous audio-only service. These describe how the encounter was conducted; the POS code describes where the patient was. Your staff need to understand that as two independent fields, because payers reject claims where the two contradict each other.

Medicare has, at various points, instructed practitioners to report the POS that would have applied had the service been furnished in person and append modifier 95, rather than using 02 or 10 — an approach designed to preserve payment parity. That instruction has changed more than once alongside successive short-term extensions of Medicare telehealth flexibilities. Do not carry forward a rule you learned two years ago. Check the current guidance on the CMS telehealth page and your Medicare Administrative Contractor's bulletins each January, and treat commercial and Medicaid payers as separate rulebooks entirely.

The Short Answer for Your Cheat Sheet

Which telehealth place of service code do you use? Use POS 10 when the patient was in their home or temporary residence during the encounter. Use POS 02 when the patient was at any other originating site. Add modifier 95 for audio-video encounters or modifier 93 for audio-only. Then verify the specific payer's published instruction, because some payers direct providers to report the in-person POS with a telehealth modifier instead. Document the patient's location in the encounter note regardless of which code the payer wants.

The Intake Question Your Front Desk Has to Ask Every Time

Code selection depends on a fact that only the patient can supply: where they are, right now. That means the determination starts at intake, not in billing.

Build a single scripted question into the virtual check-in: "For your record and your insurance, can you confirm the address where you're located for today's visit?" Not "are you home?" — patients answer that question loosely from a parked car outside a grocery store. Ask for the location, capture the state, and capture whether it is a residence.

The state matters independently of the POS code. Licensure and payer network rules turn on the patient's state at the time of service, and a patient who has driven across a state line to visit family has changed the compliance picture even though the POS code stays at 10.

Have your staff record the answer in a structured field the coder can see. Free-text notes buried in a chat log do not survive an audit and do not scale past a dozen visits a day.

Who Owns the Decision: Role Assignments That Prevent the 214-Claim Problem

Assign these four roles by name in writing. Ambiguity here is how the alphabetical-dropdown failure happens.

  1. Scheduler or intake staff — captures and records the patient's stated location and encounter modality at check-in. Does not select codes.
  2. Rendering provider — documents patient location, provider location, modality, and consent to virtual care in the encounter note. Attests that the note reflects the visit.
  3. Coder or biller — determines POS and modifier from the documented facts and the payer's current published rule. Escalates any encounter where the documentation is silent on location.
  4. Compliance lead or practice administrator — maintains the payer-rule matrix, updates it at least quarterly, and runs the monthly POS distribution report.

That monthly report is the cheapest control you will ever implement. Pull telehealth claims by POS code and modifier, grouped by provider and by payer. A provider whose panel is entirely home-based patients should not be generating POS 02 claims. A sudden shift in the ratio means someone changed a template or a default setting.

Why POS 10 Turns a Claim Into a Location Disclosure

Here is where the billing conversation becomes a privacy conversation, and where most practices have never thought it through.

When you submit POS 10, you are asserting on a transmitted claim that this identified patient was in their residence at a specific date and time. Combine that with a diagnosis code and you have disclosed something about a person's location, health condition, and daily pattern in a single 837 transaction. That is protected health information, and it travels through your clearinghouse, your payer, and whatever subcontractors sit behind them.

This is not an argument for miscoding. It is an argument for treating your telehealth claim stream as a named disclosure pathway in your risk analysis, with the same rigor you apply to your patient portal. The minimum necessary standard does not apply to disclosures required for payment in the sense of blocking them — but it does apply to what your internal staff can see, what your reports export, and how much location detail your clinical documentation captures beyond what the code requires.

How Much Location Detail Is Too Much in the Chart

You need enough to support the code and satisfy licensure. You do not need a full street address for a patient in a domestic violence shelter, a residential treatment facility, or a temporary living arrangement they have asked you not to record. Give your providers a documented exception path: record the state and the residence/non-residence determination, note that the specific address was withheld at the patient's request, and move on. Then make sure that exception path is written into your telehealth policy rather than living in one supervisor's head.

The Vendor List Behind a Single Telehealth Claim

Trace one virtual visit end to end and count the business associates. A typical small practice touches five to eight:

  • The video platform hosting the encounter
  • The scheduling or intake tool that captured the location answer
  • The EHR or practice management system storing the note
  • The clearinghouse transmitting the 837
  • The billing service or RCM vendor, if you outsource
  • Any transcription, scribe, or AI documentation tool in the loop
  • Cloud backup and any analytics or reporting overlay

Every one of those needs a signed business associate agreement, and the BAA needs to cover the actual data flow — not the flow that existed when you signed it in 2021. HHS maintains telehealth-specific HIPAA guidance worth re-reading with your current vendor stack in front of you. The notification-of-enforcement-discretion posture that covered non-compliant platforms during the public health emergency ended in 2023; there is no remaining grace period for a consumer video tool with no BAA behind it.

Two vendor questions specific to telehealth coding deserve direct answers in writing:

Does the platform retain recordings, transcripts, or chat logs by default? If yes, that is PHI in a system your retention schedule probably does not mention, and it is discoverable and requestable. Get the retention setting documented and align it with your policy.

Does your billing vendor make POS determinations on your behalf? If a third party is selecting the telehealth place of service code from your documentation, you have delegated a coding decision to a business associate. Your agreement should specify that they follow your payer matrix and escalate rather than guess, and your audit rights should let you sample their work.

If your vendor inventory and BAA set are not current, that is a documentation project, not a mystery. Practices that need to rebuild the whole set — risk analysis, policies, vendor register — often start by generating a complete HIPAA compliance document set and then editing it against their actual workflows, which is faster than drafting from a blank page. For a single missing agreement with a new telehealth platform, a signature-ready business associate agreement closes the gap in an afternoon.

Documentation That Survives a Payer Audit

Payers auditing telehealth claims typically ask for the same short list. Build your note template so it produces all of it without the provider thinking about it:

  • Date, start time, and end time of the encounter
  • Patient's physical location, at minimum state and residence/non-residence
  • Provider's physical location
  • Modality — audio-video or audio-only — and, if audio-only, why
  • Documented patient consent to receive care virtually
  • Identity verification method used at the start of the call
  • The clinical content that supports the service level billed

Audio-only visits deserve extra attention. Practices that serve patients without reliable broadband will bill audio-only encounters at meaningful volume, and payer rules for those are narrower and change more often. Track your audio-only percentage by payer so you know your exposure before someone else calculates it for you.

A 30-Day Cleanup You Can Actually Finish

Week 1. Pull twelve months of telehealth claims. Report POS code and modifier by provider and payer. Flag anything that looks like a default rather than a decision.

Week 2. Rebuild the payer matrix. One row per payer, one column each for POS instruction, accepted modifiers, audio-only policy, and the date you last verified it against a primary source.

Week 3. Fix intake. Script the location question, add the structured field, retrain schedulers, and remove or reorder any dropdown that lets alphabetical order make the choice.

Week 4. Close the privacy loop. Confirm a current BAA for every vendor in the telehealth chain, document platform retention settings, add the claim stream to your risk analysis, and write the location-detail exception path into your telehealth policy.

Then set a recurring calendar item for the second week of every January to re-verify the matrix, because telehealth payment rules have changed on a roughly annual cycle for four straight years and there is no sign of that stopping.

If the cleanup surfaces gaps in your risk analysis or your policy set — and it usually does — automating the risk analysis and policy documentation gets you to a defensible file without spending three months on drafting. Start with the claims report this week; the coding fix and the privacy fix are the same project.