← Back to blog

Telehealth Coding Compliance: 2026 Rules and Checklist

August 15, 2026
Telehealth Coding Compliance: 2026 Rules and Checklist

Telehealth coding compliance in 2026 means applying the right CPT code, POS code, and modifier for each payer before every claim leaves your practice. CMS, HHS, the AMA, and the OIG are four governing bodies whose guidance determines whether your telehealth claims pay or deny. Before you submit any telehealth claim, run this quick check:

  • Confirm payer track. Medicare, Medicaid, and commercial payers each follow different rules. Never apply a single universal rule across all three.
  • Verify POS code. Use POS 10 when the patient is at home, POS 02 for other telehealth originating sites, and confirm your payer accepts the distinction.
  • Attach the correct modifier. Modifier 95 (synchronous audio/video), 93 (audio-only), GT, GQ, or FQ each serve specific payer and service scenarios.
  • Document consent. Missing telehealth-specific informed consent can make an encounter non-billable regardless of clinical quality.
  • Record patient and provider locations. Both physical addresses at the time of service must appear in the note.

Key Takeaways

Telehealth coding compliance in 2026 requires payer-specific POS codes, correct modifiers, complete documentation of patient and provider locations, and annual verification against the CMS Medicare telehealth services list.

PointDetails
Payer rules differ materiallyMedicare, commercial, and Medicaid payers require different POS codes, modifiers, and code sets; one universal rule causes denials.
Numerous Medicare codesNumerous codes appear on the Medicare telehealth services list; verify annually after the January 1 Physician Fee Schedule update.
Documentation has nine required elementsConsent, modality, locations, participant names, start/end times, and time vs MDM basis are the elements auditors check first.
Flexibilities expire after 2027Many Medicare telehealth flexibilities run through December 31, 2027; build workflows now for the rules that follow.
Himshield automates the gapHimshield scans EHR data pre-submission, flags payer-specific mismatches, and generates audit-ready response packets for independent practices.

Table of Contents

How do current CMS and HHS rules affect your telehealth coding?

CMS maintains a Medicare telehealth services list and updates it annually through the Physician Fee Schedule rulemaking process. Additions and deletions take effect January 1 each year, so a service payable in December may not be payable in January under a new rule cycle. The public may submit requests for additions on an ongoing basis, which means the list genuinely shifts year to year.

HHS documents key policy updates including which flexibilities are temporary and which are permanent. Many Medicare telehealth flexibilities introduced during the public health emergency are now extended through December 31, 2027. Those include expanded coverage for behavioral health services, audio-only visits under specific conditions, and the waiver of geographic and originating site restrictions for most services. After 2027, absent further Congressional action, several of those flexibilities will revert to pre-pandemic rules.

Statistic: Numerous codes appear on the Medicare telehealth services list under current guidance, covering services from standard office visits to behavioral health and remote monitoring.

Key CMS/HHS items your billing team must track:

  • Annual Physician Fee Schedule final rule (published each November, effective January 1)
  • Behavioral health telehealth expansions, which carry their own consent and documentation requirements
  • Audio-only allowances, which require modifier 93 and specific documentation of why video was not used
  • Geographic and originating site waivers, currently active through 2027 but not guaranteed beyond that date

Pro Tip: Subscribe to the CMS Physician Fee Schedule listserv and the HHS telehealth.hhs.gov update feed. Both are free and push rule changes directly to your inbox before the January 1 effective date.


Which CPT codes, POS codes, and modifiers apply to telehealth?

The single biggest source of telehealth denials is treating Medicare, commercial, and Medicaid billing as interchangeable. They are not. Payer-by-payer variation is the primary operational risk: applying one universal rule across all payers causes preventable denials.

The two coding tracks to keep separate

Medicare track: Bill standard E/M codes (99202–99215 for new and established office visits) with the appropriate POS code and modifier. Medicare does not broadly accept the AMA 98000 series for telehealth, with the narrow exception of CPT 98016 (patient-initiated digital evaluation). Billing a 98000-series code to Medicare outside that exception will deny.

Commercial and Medicaid track: Many commercial payers and some Medicaid programs accept the 98000 series (98000–98015 for online digital evaluation and management services). Acceptance varies by plan and state. Always verify each payer's current telehealth policy before billing.

POS codes and modifiers

  • POS 10: Patient located at home. This is the standard for most post-pandemic telehealth visits and is increasingly required by Medicare for home-based encounters.
  • POS 02: Telehealth provided other than in patient's home. Still used for facility-based originating sites.
  • Modifier 95: Synchronous audio/video telehealth. Required by Medicare and most commercial payers for real-time video visits.
  • Modifier 93: Audio-only telehealth. Required when video is not used; must be paired with documentation explaining why video was unavailable or not appropriate.
  • Modifier GT / GQ: Legacy modifiers still accepted by some commercial payers and certain Medicaid programs. Check payer policy before using.
  • Modifier FQ: Audio-only behavioral health services under specific Medicare rules.

Common denial scenarios include billing POS 02 when the patient was at home (should be POS 10), omitting modifier 95 on a video visit, or billing 98000-series codes to Medicare without confirming the 98016 exception applies.

Pro Tip: Build a payer-specific grid in your practice management system that maps each payer to its accepted POS code, modifier, and code set. Update it every January and whenever a payer issues a policy bulletin.


What documentation do auditors expect for telehealth visits?

Auditors expect specific documentation elements that go beyond a standard office visit note. Missing even one element can turn a paid claim into a recovery demand. The table below maps each required item to the auditor's reason for wanting it.

Documentation ElementWhy Auditors Require It
Telehealth-specific informed consentConfirms patient agreed to telehealth limitations; missing consent can void the encounter
Modality used (video, audio-only, asynchronous)Determines which code and modifier are appropriate
Patient's physical location at time of serviceGoverns licensure, originating site rules, and POS code selection
Provider's physical location at time of serviceRequired for distant site billing and state licensure verification
Names and roles of all participantsConfirms supervising provider identity and any auxiliary staff present
Visit start and end timesSupports time-based E/M level selection and audit of billed duration
Basis for E/M level: time or MDMAuditors verify the documented basis matches the billed code level
Technology platform usedConfirms HIPAA-compliant platform; supports BAA documentation
Any technology failures or interruptionsExplains gaps in service and whether the visit met minimum requirements

Beyond the note itself, auditors reviewing telehealth claims typically request:

  • Originating and distant site documentation
  • Business Associate Agreement (BAA) for the telehealth platform
  • Provider licensure verification for the patient's state
  • Credentialing records
  • Preauthorization artifacts where required by the payer

Pro Tip: Add mandatory EHR template fields for patient location, provider location, modality, and consent status. Set hard-stops that prevent note finalization without those fields completed. This single workflow change eliminates the most common documentation gaps before the claim is ever generated.

For a deeper look at medical necessity documentation that supports E/M level selection in telehealth encounters, the Himshield blog covers specific examples tied to 2026 coding standards.


What are the most common telehealth billing mistakes?

Most telehealth denials trace back to a short list of repeatable errors. Each one has a straightforward prevention step.

  • Wrong POS code. Billing POS 02 when the patient was at home. Prevention: add a patient-location field to your intake workflow and map it automatically to POS 10 or 02 at claim generation.
  • Missing or wrong modifier. Omitting modifier 95 on a video visit or using GT when the payer requires 95. Prevention: payer-specific modifier rules in your claim scrubber.
  • Billing 98000-series codes to Medicare. These deny except for CPT 98016. Prevention: a hard edit in your billing system that flags 98000-series claims destined for Medicare.
  • Treating RPM and CCM as telehealth. Remote patient monitoring and chronic care management codes use separate billing rules and should never carry telehealth POS/modifier combinations. Prevention: separate RPM/CCM workflows from your telehealth billing queue entirely.
  • Missing telehealth consent. Some states require per-visit verbal consent; others allow annual consent. Prevention: track state-specific consent requirements and document consent in every note.
  • Incorrect time calculation. Billing a higher E/M level based on total encounter time without documenting that time was the basis for level selection. Prevention: EHR template field that requires the provider to select "time" or "MDM" as the basis and enter total time when time is chosen.

Run a targeted coding audit on your last 90 days of telehealth claims to identify which of these errors appear most frequently in your practice. Fix the highest-volume error first.


How do state licensure and patient location affect telehealth billing?

The patient's physical location at the time of service generally governs which state's licensure requirements apply to the treating provider. A physician licensed only in Texas who conducts a telehealth visit with a patient physically located in New Mexico is practicing medicine in New Mexico, regardless of where the physician sits.

Practical steps to capture at intake and during the visit:

  • Record the patient's state and full address at scheduling, not just at registration.
  • Confirm the patient's location again at the start of the visit and document it in the note.
  • Verify the treating provider holds an active license in the patient's state before the visit occurs.
  • Track Interstate Medical Licensure Compact (IMLC) participation: the Compact currently covers most U.S. states and territories and allows eligible physicians to obtain expedited licenses in member states, but not all states participate and some specialties carry additional restrictions.
  • Document consenting language that specifically addresses telehealth limitations, privacy risks, and the right to discontinue.

State rules on consent frequency also vary. The AAFP notes that some states require per-visit verbal consent at minimum, while others accept annual written consent. California is one example of a state with specific per-visit requirements. Track your patient population's states and maintain a reference sheet for each.

Pro Tip: Add three fields to your scheduling intake form: patient state at time of service, consent obtained (yes/no/type), and interpreter needed. These three data points prevent the most common licensure and consent documentation failures.

Clinician interacting with scheduling tablet intake form


Your 30/60/90-day plan to operationalize telehealth compliance

Days 1–30: Fix the highest-risk gaps now

  1. Pull your last 90 days of telehealth claims and identify denial reasons. Categorize by POS error, modifier error, missing documentation, and wrong code set.
  2. Build a payer-specific grid covering Medicare, your top three commercial payers, and Medicaid. Map accepted POS codes, modifiers, and code sets for each.
  3. Add EHR hard-stops for patient location, provider location, modality, and consent status.
  4. Confirm your telehealth platform has a current BAA on file.

Days 31–60: Train staff and build sustainable workflows

  • Conduct a 60-minute coding training session covering POS 10 vs 02, modifier 95 vs 93, and the Medicare 98000-series restriction. Use real denied claims as examples.
  • Update EHR note templates to include all documentation elements from the audit checklist above.
  • Schedule a chart audit of 10–15 telehealth records per provider to measure documentation completeness.

Days 61–90: Automate and monitor

The table below maps roles to specific 90-day tasks.

RoleTaskTarget Deadline
Billing coderBuild and validate payer-specific POS/modifier gridDay 15
Practice administratorConfirm BAA for telehealth platform; verify provider licensure by patient stateDay 30
ClinicianComplete EHR template training; adopt time vs MDM documentation habitDay 60
Billing coderRun chart audit on 10–15 telehealth records per providerDay 60
Practice administratorImplement automated claim edits for POS/modifier/code-set rulesDay 90
All staffReview updated payer grid; subscribe to CMS/HHS update feedsDay 90

For a full audit survival checklist tied to 2026 payer expectations, the Himshield blog provides a step-by-step guide you can adapt to your practice's telehealth volume.


How automation reduces telehealth coding risk in practice

Automated compliance tools address the core problem: no billing team can manually maintain payer-specific POS/modifier/code-set rules across Medicare, dozens of commercial payers, and multiple Medicaid programs simultaneously. The operational use cases where automation delivers the clearest return include:

  • Payer-rule mapping: Automated engines apply the correct POS, modifier, and code set per payer before the claim is generated, catching mismatches that manual review misses.
  • EHR template enforcement: Automated prompts and hard-stops prevent note finalization without required telehealth documentation fields completed.
  • Claim scrubbing: Pre-submission edits flag 98000-series codes destined for Medicare, missing modifiers, and POS mismatches before they reach the clearinghouse.
  • Chart sampling for audits: Automated sampling pulls a statistically representative set of telehealth records for internal review, reducing the manual burden of audit preparation.

A practice running 200+ telehealth visits per month across Medicare and two commercial payers faces hundreds of payer-rule permutations per week. Automated claim-scrubbing rules that apply payer-specific POS/modifier/code logic before submission dramatically reduce denials when practices operate across multiple payer types — catching errors that manual review at that volume simply cannot sustain.

Pro Tip: When evaluating any automated compliance tool, ask specifically whether its payer-rule engine updates automatically when CMS publishes the annual Physician Fee Schedule final rule. A static rule set that requires manual updates defeats the purpose of automation.


The compliance discipline that makes telehealth access sustainable

Telehealth genuinely expands access to care for patients who cannot easily reach a clinic. That access depends entirely on whether practices can sustain telehealth programs financially, and financial sustainability depends on getting paid. The compliance discipline described in this guide is not a bureaucratic obstacle to care. It is the mechanism that keeps telehealth programs funded.

The tension most practices feel is real: clinicians want to focus on the patient, not on documenting modality and participant roles. The answer is not to choose between access and compliance. It is to build the compliance requirements into the workflow so thoroughly that they become invisible to the clinician. EHR hard-stops, pre-populated template fields, and automated claim edits do exactly that. The clinician sees a prompt; the billing team sees a clean claim; the auditor sees a defensible record.

What concerns me most in 2026 is the gap between practices that have updated their workflows for the post-pandemic rule environment and those still operating on pandemic-era assumptions. The flexibilities extended through 2027 are real, but they are not permanent, and the practices that treat them as permanent will face a painful correction when the sunset arrives. Build your workflows for the rules that will exist in 2028, not the rules that exist today.


How Himshield protects your telehealth revenue before claims deny

Independent practices running telehealth programs across Medicare and commercial payers are leaving recoverable revenue on the table every week, not because of clinical errors, but because payer-rule complexity outpaces manual review capacity.

Himshield

Himshield scans your EHR data before submission, identifies POS/modifier/code-set mismatches by payer, flags missing documentation elements, and auto-drafts corrections with one-click physician e-signature. The platform delivers per-provider, per-payer Revenue Leakage Reports so you see exactly where telehealth denials are concentrated and how much is at risk. When an audit arrives, Himshield assembles a submission-ready response packet from your existing records.

The free 30-day audit shows you the dollar value of your current telehealth coding gaps with no commitment required. Start your free audit at Himshield and see your Revenue Leakage Report within 30 days.


Sources

Stay current by tracking these primary sources directly. Rule changes arrive without warning, and billing blogs often lag official publications by weeks.

Subscribe to the CMS Physician Fee Schedule listserv and the HHS telehealth update feed. Both are free and deliver rule changes before they take effect.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.