A digital health company raises $12 million to build a psychiatric care platform. The product is good: intake, matching, video visits, medication management, and messaging between visits. The clinical team is excellent. The engineering is excellent.
Eleven months after launch, three things happen in the same quarter. A state medical board opens an investigation because two of its residents received care from a physician licensed elsewhere. The DEA sends a letter about stimulant prescriptions issued without an in-person examination and without qualifying for any telemedicine exception. And the company's largest commercial payer recoups eighteen months of payments on the ground that the clinical entity was owned by a management company in a state where non-physicians may not own a medical practice — meaning, in the payer's view, that the claims were submitted by an entity not authorized to practice.
Each problem is independent of the others. Each was foreseeable. And each attached at the level of the individual encounter, not the company — which is why "we operate nationally" is not a legal strategy but a description of fifty separate compliance postures.
The right mental model for telehealth is that there is no such thing as telehealth law. There is medical practice law, applied to encounters where the patient and the practitioner are in different places, and the location of the patient usually decides which state's law governs.
Licensure
The governing rule in nearly every state: a practitioner must be licensed in the state where the patient is located at the time of the encounter. The practitioner's own location is generally irrelevant, and so is where the company is incorporated, where the server sits, and where the patient normally lives.
This is the single largest operational constraint on a telehealth business. A national platform requires either practitioners licensed in every state served, or geographic routing that matches each patient to a practitioner licensed where that patient is sitting.
Compacts and expedited pathways:
The Interstate Medical Licensure Compact — an expedited licensure process, not a single license. A physician who qualifies (through a state of principal license, board certification or completion of an ACGME/AOA-accredited residency, and a clean disciplinary and criminal record) can obtain full licenses in participating states through a streamlined application, in weeks rather than months. The physician still holds a separate license in each state, pays each state's fees, and answers to each state's board.
The Nurse Licensure Compact — a genuine multistate license, permitting practice in all participating states on a single license, for RNs and LPN/LVNs. The APRN Compact is a separate and much less widely adopted instrument.
Other compacts cover psychology (PSYPACT, which is a true practice authority for telepsychology), physical therapy, occupational therapy, audiology and speech-language pathology, counseling, social work, EMS, and dentistry, each with a different adoption footprint and a different mechanism.
State-specific telehealth registrations. A number of states offer a limited registration or special-purpose telemedicine license for out-of-state practitioners, typically restricted to telehealth-only practice and sometimes conditioned on a referral from an in-state practitioner.
Exceptions that exist but rarely solve the problem: consultation exceptions permitting an out-of-state specialist to advise a treating in-state practitioner (usually episodic and non-continuous); border-state reciprocity in a handful of jurisdictions; emergency exceptions; continuity-of-care exceptions for an established patient temporarily out of state, which a growing number of states have adopted and which are worth mapping precisely; and federal preemption for VA practitioners, military and Public Health Service providers, and practitioners covered by federal disaster declarations.
Practical implementation. Build state-of-patient verification into the scheduling flow, not the clinical note. Verify at the time of each encounter — a patient traveling on business changes the answer. Maintain a live matrix of which practitioner holds which license with which expiration, and prevent booking outside it at the system level, because a policy that depends on a clinician remembering is a policy that fails.
The practitioner-patient relationship and the standard of care
The standard of care does not change. A telehealth encounter is judged against the same standard as an in-person encounter for the same condition. That principle, stated in nearly every state's telehealth statute and in Federation of State Medical Boards policy, has a hard corollary: if the condition cannot be adequately evaluated by the available modality, the practitioner must escalate — to an in-person visit, to imaging or laboratory work, or to an emergency department. The failure to escalate is the central malpractice theory in telehealth litigation.
Establishing the relationship. Most states now permit a relationship to be established by telehealth, without a prior in-person visit. But states impose conditions, and the conditions vary in ways that matter:
- Modality requirements. Many states require real-time audio-video to establish a new relationship. Some permit audio-only, particularly after coverage expansions for behavioral health and for patients without broadband. A minority permit asynchronous or store-and-forward evaluation for defined conditions.
- Prohibited modalities. A recurring rule is that a questionnaire alone is not sufficient to establish a relationship or to support a prescription — the direct regulatory response to online prescribing platforms.
- Identity verification of both the patient and the practitioner.
- Disclosure of the practitioner's name, credentials, licensure, and location, and a means of contacting them.
- Emergency protocols — the practitioner must know the patient's physical location and have a plan for local emergency services.
Informed consent. Many states require specific consent to telehealth in addition to ordinary treatment consent, some in writing, some documented in the record. Content typically includes the modality's limitations, privacy and security risks, the possibility of technology failure, the right to an in-person visit, and how records will be maintained.
Documentation must meet the same standard as in-person care, and should additionally record: the modality used, the patient's location, the practitioner's location, who else was present, the identity verification performed, the consent obtained, and — importantly — the practitioner's assessment of whether the modality was adequate for the presenting problem.
Follow-up and continuity. Several states require that the telehealth practitioner either provide or arrange for follow-up care and make records available to the patient's primary practitioner. A platform designed around one-off transactional encounters should read its states' continuity requirements carefully.
Scope of practice for nurse practitioners, physician assistants, and other practitioners follows the state where the patient is located, including collaborative practice or supervision agreements. A model built on independent NP practice does not port to a supervision state without a supervising physician licensed there.
Prescribing
Non-controlled substances. Generally permitted following a telehealth encounter that establishes a valid practitioner-patient relationship, subject to the modality rules above and to the federal requirement of a valid prescription issued for a legitimate medical purpose by a practitioner acting in the usual course of professional practice. State rules restricting specific drug classes — and a handful of states with additional requirements for particular categories — must be checked individually.
Controlled substances are the hardest question in telehealth, and the one that generates the most enforcement.
The Ryan Haight Online Pharmacy Consumer Protection Act, codified principally at 21 U.S.C. § 829(e), prohibits dispensing a controlled substance by means of the internet without a valid prescription, and defines a valid prescription as one issued by a practitioner who has conducted at least one in-person medical evaluation of the patient, or who is a covering practitioner — unless the practice constitutes the practice of telemedicine as defined in 21 U.S.C. § 802(54).
The § 802(54) telemedicine exceptions are narrow and mostly institutional:
- The patient is treated by, and physically located in, a DEA-registered hospital or clinic.
- The patient is being treated by, and in the physical presence of, a DEA-registered practitioner.
- The practitioner is a Department of Veterans Affairs practitioner acting within the scope of employment.
- The practitioner has obtained a special registration for telemedicine — an authority Congress created and which DEA had not implemented for many years, with proposed frameworks under consideration.
- A public health emergency declaration is in effect with an accompanying designation.
- Other circumstances the Attorney General and Secretary jointly determine by regulation.
The pandemic flexibilities, which permitted prescribing controlled substances via telemedicine without a prior in-person evaluation, have been extended repeatedly by temporary rule rather than made permanent. Verify the current status before building a business on them. Proposed rules have contemplated a tiered framework — permitting some Schedule III–V prescribing via telemedicine with a special registration, imposing stricter conditions or in-person requirements for Schedule II, and creating separate pathways for buprenorphine for opioid use disorder and for VA practitioners.
Layered on top: state controlled substance rules, which in several states are stricter than federal law; prescription drug monitoring program check requirements, which are mandatory in most states and which apply to telehealth prescriptions; and electronic prescribing of controlled substances requirements, mandatory under Medicare Part D and under most state laws, with identity-proofing and two-factor authentication requirements for the prescriber.
Practical posture. A telehealth business that prescribes controlled substances should assume the rules will tighten, should build in-person evaluation capacity or referral relationships before it needs them, should implement PDMP checks and documentation of them as a hard gate, and should not design a business model whose viability depends on a temporary rule remaining in effect.
Reimbursement
Medicare. Governed principally by 42 U.S.C. § 1395m(m) and 42 C.F.R. § 410.78. The traditional structure imposed:
- A geographic restriction — the patient had to be in a rural health professional shortage area or non-metropolitan county.
- An originating site restriction — the patient had to be at a qualifying facility, not at home.
- A limited list of eligible practitioners and covered services.
- A requirement of interactive audio-video.
Statutory changes and a long series of extensions relaxed each of these, permanently for behavioral and mental health services (where the home is an originating site, geographic restrictions do not apply, and audio-only is permitted for certain services, subject to an in-person visit requirement within a defined period before and periodically after — a requirement that has itself been repeatedly delayed) and, for other services, through temporary extensions that Congress has renewed in short increments.
This is the single most important practical point about Medicare telehealth: the non-behavioral-health flexibilities have been extended, not made permanent, and the extensions have sometimes lapsed briefly before retroactive renewal. A business dependent on them should model the downside and should track the current expiration date as a standing agenda item.
Other Medicare pathways that do not depend on those extensions: remote patient monitoring and remote therapeutic monitoring codes; chronic care management and principal care management; behavioral health integration; virtual check-ins and e-visits; Federally Qualified Health Center and Rural Health Clinic provisions; and the flexibilities available inside ACO and other value-based arrangements, which are frequently broader than fee-for-service rules.
Medicaid is state by state. Nearly all state Medicaid programs cover some telehealth; coverage of audio-only, store-and-forward, and remote monitoring varies widely, as do originating site rules and payment rates.
Commercial insurance is governed by state law. Distinguish carefully:
- Coverage parity — the plan must cover a service delivered by telehealth if it covers the same service in person. Most states have some form of this.
- Payment parity — the plan must pay the same rate. Far fewer states require it, several require it only for certain services, and a number expressly permit lower telehealth rates. Assuming parity is a common and expensive financial modeling error.
- Modality and location conditions embedded in the parity statute itself.
Billing mechanics matter more here than in most fields: place of service codes, telehealth modifiers, and documentation of the modality. Miscoding is the most common source of recoupment, and a recoupment demand for eighteen months of claims is a serious event for a company at any stage.
Cash-pay models avoid the reimbursement analysis entirely but not the licensure, prescribing, corporate practice, or privacy analyses — and they raise their own questions where a patient is a Medicare beneficiary, because a practitioner who has not opted out and who bills a beneficiary privately for a covered service has a problem.
Corporate structure and the corporate practice of medicine
The doctrine. In roughly half the states, a corporation not owned by licensed physicians may not employ physicians to practice medicine or own a medical practice. The rationale is that lay ownership interferes with clinical judgment. Related prohibitions bar fee splitting — sharing professional fees with a non-licensee — and, in some states, reach arrangements where compensation is a percentage of professional revenue.
States vary enormously. Some enforce strictly with statutory prohibitions and active board enforcement; some have judicial doctrine with little enforcement; some exempt certain entity types or have no doctrine at all; and several apply it to some professions and not others.
The standard structure for a multi-state telehealth company is the friendly PC / MSO model:
- A professional corporation or professional LLC in each corporate-practice state, owned by a licensed physician, employing or contracting with the clinicians and holding the clinical relationship and the payer contracts.
- A management services organization — the venture-backed operating company — that provides everything non-clinical: technology, scheduling, billing, marketing, human resources, real estate, and administration.
- An administrative services agreement between them, for a fair market value management fee.
- A succession or stock transfer restriction agreement with the physician owner, giving the MSO the right to designate a successor owner on defined events, so the equity does not become an accident of one person's circumstances.
Where these structures fail:
- A percentage-of-revenue management fee in a state that treats it as fee splitting. A flat fee or a cost-plus fee is safer; document fair market value either way.
- A management fee untethered to services actually delivered, which is both a fee-splitting problem and — where federal program dollars are involved — an anti-kickback problem.
- MSO control over clinical decisions: the agreement, and the practice, must leave clinical judgment, treatment protocols, clinician hiring and credentialing decisions, and utilization decisions with the PC. Prescribing algorithms designed by the MSO and imposed on clinicians are the fact pattern regulators cite most often.
- Nominal physician ownership with no real authority, in a state that looks at substance.
- One PC used across states with different requirements, rather than state-specific entities.
Federal fraud and abuse. Telehealth has been a major enforcement priority. The OIG has issued a Special Fraud Alert concerning arrangements with telemedicine companies, describing suspect characteristics: patients identified by the company rather than by clinical need; compensation to practitioners based on the volume of items or services ordered; a business model serving only federal beneficiaries or only non-federal patients in a way that suggests structuring; and practitioners with no ability to follow up. The largest telehealth prosecutions have involved arrangements in which a marketing company paid practitioners per order for durable medical equipment, genetic testing, or compounded drugs, with the "telehealth encounter" as a formality. Where a business pays practitioners for orders or receives payment tied to orders, the Anti-Kickback Statute analysis is the first analysis to run, not the last. The Stark Law applies where physicians have financial relationships with entities furnishing designated health services.
Privacy, security, and other obligations
HIPAA applies fully. Telehealth platforms are business associates or covered entities depending on structure, and the pandemic-era enforcement discretion for non-public-facing communication technologies has ended. Requirements to address specifically: end-to-end encryption for video and messaging; business associate agreements with the video vendor, the transcription vendor, the scheduling vendor, and the analytics vendor; access controls and audit logging; and a risk analysis that actually covers the telehealth stack rather than only the electronic health record.
Tracking technologies on patient-facing telehealth pages are a live litigation risk. Pixels and analytics SDKs on intake flows transmit exactly the information that supports a wiretapping or health-privacy claim, and health-related web tracking has generated a substantial volume of class actions.
Recording an encounter implicates state wiretapping and eavesdropping laws, several of which require all-party consent. Build consent into the flow and document it.
Consumer protection. Subscription and auto-renewal statutes reach telehealth memberships; advertising claims about outcomes and about clinician credentials are actionable; and state consumer health data statutes may cover data the platform holds outside HIPAA's reach.
Malpractice insurance. Confirm that the policy covers telehealth, covers every state in which patients are located, and covers the specific modalities used, including asynchronous care. Many policies contain territorial limitations that a national platform violates on its first day. Confirm coverage for the PC entities as well as the MSO, and confirm that a claims-made policy has adequate tail coverage arrangements.
Accessibility. Platforms must be accessible under the ADA and Section 504 where applicable, including interpretation for patients with limited English proficiency and effective communication accommodations for deaf and hard-of-hearing patients — an obligation that survives the move to a video interface and is frequently overlooked in product design.
Clinical protocols and credentialing. Verify licensure and DEA registration at hire and at defined intervals; check the National Practitioner Data Bank and exclusion lists; and maintain a peer review process. Hospital and health system telehealth arrangements can use credentialing by proxy under the Medicare conditions of participation, which avoids duplicative credentialing at each originating site.
A worked example
A company launches a chronic care management platform for hypertension and diabetes, with remote monitoring devices, asynchronous messaging, and periodic video visits.
Structure. Friendly PCs in the twenty-eight states it will serve initially, each owned by a physician licensed there, with a single MSO providing technology and administration under a flat-fee administrative services agreement supported by a valuation. Stock transfer restriction agreements with each PC owner.
Licensure. Physicians and NPs matched to patients by the patient's real-time state. NP scope reviewed state by state, with supervising physicians engaged in supervision states. The scheduling system blocks any booking outside the license matrix.
Modality. Video for the initial visit in every state, because the strictest states require it and a uniform protocol is easier to operate and defend than twenty-eight variations. Asynchronous messaging for interim care where permitted, with a documented escalation protocol.
Prescribing. Non-controlled only, deliberately, to avoid the Ryan Haight problem entirely. PDMP checks nonetheless implemented for the antihypertensives and other agents where a state requires it.
Reimbursement. Built on remote patient monitoring and chronic care management codes, which are permanent Medicare benefits, rather than on the telehealth flexibilities. The business model does not depend on an extension.
Fraud and abuse. Clinician compensation is per unit of time, not per order or per device. Device suppliers are unaffiliated and receive nothing from the company. The arrangement is documented against the OIG's Special Fraud Alert factors.
Privacy. BAAs with every vendor. A risk analysis covering the monitoring devices, the mobile app, the messaging layer, and the data warehouse. Tracking pixels removed from all authenticated pages and audited quarterly on the marketing site.
Insurance. Malpractice coverage confirmed for telehealth, for asynchronous care specifically, and for all twenty-eight states, with the PCs as named insureds.
Time from decision to launch: about nine months, most of it entity formation and licensure. Time saved by not having to unwind a controlled substance program or a fee-splitting management fee: considerably more.
Conclusion
Telehealth's legal complexity is not conceptual. It is combinatorial: a modest number of rules, multiplied by fifty states, multiplied by the number of professions on the platform.
Three points do most of the work.
Location of the patient decides the law — licensure, scope of practice, modality requirements, consent, prescribing, and parity all follow the patient. Build that into the product, not into a policy manual.
Do not build a business on a temporary rule. The controlled substance telemedicine flexibilities and most of the Medicare telehealth flexibilities exist by extension. Businesses built on the permanent authorities — behavioral health, remote monitoring, chronic care management — have been dramatically more stable than businesses built on the temporary ones.
The corporate structure is a clinical compliance question, not a tax question. The friendly PC / MSO model works when the PC genuinely controls clinical decisions and the management fee is fair market value and untethered from professional revenue. Where it fails, the consequences reach the claims themselves — and a payer that concludes the billing entity was not authorized to practice will ask for everything back.
Frequently asked questions
Where does the practitioner need to be licensed? In the state where the patient is physically located at the time of the visit. Not where the patient lives, not where the practitioner sits, and not where the company is incorporated. A patient who takes a scheduled appointment from a hotel in another state has changed the governing law for that encounter, which is why location verification belongs in the scheduling flow rather than in the chart note.
Does the Interstate Medical Licensure Compact give a physician one license for many states? No. It is an expedited pathway to obtaining separate full licenses in participating states. Each license carries its own fees, renewal cycle, continuing education requirements, and board jurisdiction. The Nurse Licensure Compact, by contrast, is a genuine multistate privilege.
Can a first visit be conducted by telehealth? In most states, yes, and most require real-time audio-video for a new patient relationship. A completed questionnaire alone is not sufficient anywhere, and platforms built on that model have been the direct target of both board discipline and federal enforcement.
Can we prescribe controlled substances after a video visit? Only if a Ryan Haight exception applies, or under whatever temporary rule is currently in effect. Because those rules have been extended in short increments rather than made permanent, a business whose economics depend on them is carrying a real and recurring risk. Build in-person evaluation capacity or a referral relationship before you need it.
Does insurance have to pay the same rate for a telehealth visit? Coverage parity is common; payment parity is not. Many states permit lower telehealth rates, and several require parity only for defined services. Confirm the answer for each state and each payer before building it into a financial model.
Do we need a separate professional corporation in every state? In corporate practice of medicine states, effectively yes — with a licensed owner in each. A single PC used across states with different ownership rules is the most common structural defect in early-stage telehealth companies, and it is far cheaper to fix before payer contracts and claims history accumulate.
Can the management company set clinical protocols? It can build tools that support clinical decisions. It cannot direct them. The distinction is real, and regulators evaluate the practice rather than the recital in the agreement. Protocols authored by the MSO and imposed on clinicians without a clinical governance process are the fact pattern most often cited in enforcement.
Is a percentage-of-collections management fee acceptable? In some states, yes; in several, it is fee splitting; and where federal program dollars are involved it also invites an anti-kickback analysis. A flat or cost-plus fee supported by a written valuation avoids the question entirely, at modest cost.
Are we allowed to record visits? Only with the consent the applicable state requires, which in several states means all-party consent. Build the consent into the encounter flow and preserve the record of it.
Does our malpractice policy cover this? Read the territorial and modality provisions specifically. Many policies limit coverage to named states or exclude asynchronous care, and a national platform can be outside coverage from its first week without anyone noticing until a claim arrives.
What to build, in order
Before the first patient:
- A state matrix — for every state served: licensure requirements and compact availability, modality rules for establishing a relationship, consent requirements, prescribing restrictions, scope of practice and supervision rules for each profession on the platform, corporate practice status, parity rules, and PDMP obligations. This document is the company's core compliance asset and it must be maintained, not written once.
- Entity structure — PCs where required, an MSO, administrative services agreements at documented fair market value, and stock transfer restriction agreements.
- Credentialing — primary source verification of licensure and DEA registration, National Practitioner Data Bank query, exclusion screening against LEIE and SAM, and a re-verification schedule.
- Product controls — patient location capture at booking and at encounter start, a hard block on booking outside the license matrix, consent capture, identity verification, and emergency location data.
- Clinical governance — protocols authored and approved by clinicians, an escalation policy that names the conditions requiring in-person evaluation, and a peer review process.
- Privacy and security — a risk analysis covering the full telehealth stack, BAAs with every vendor, encryption, audit logging, and a tracking-technology audit of every patient-facing page.
- Insurance — malpractice with confirmed telehealth, modality, and multistate coverage; cyber; and D&O.
Continuously:
- Track the expirations — license renewals, DEA registrations, the current end date of any temporary federal flexibility the business relies on, and state legislative sessions in the states that matter most.
- Audit encounters for documentation of modality, location, consent, and escalation decisions.
- Review compensation for any drift toward volume-of-orders incentives.
- Re-run the parity and coverage analysis annually, because state telehealth statutes change every session.
A note on where the risk actually falls
It is worth stating plainly which of these failures are survivable and which are not.
Documentation gaps and modality mismatches produce board inquiries and, at worst, corrective action. They are unpleasant and fixable.
Reimbursement errors produce recoupment, which is a cash event that can be existential for an early-stage company but is rarely a legal catastrophe.
Corporate practice defects produce recoupment plus, in some states, a challenge to the practice's authority to bill at all — which converts a structural problem into a claims problem retroactively.
Controlled substance prescribing outside an exception and compensation tied to the volume of orders are the two that produce criminal exposure. Both are avoidable by design decisions made at the outset, and both have been the subject of the largest telehealth prosecutions brought to date. A company that gets everything else approximately right and these two exactly right is in a materially better position than the reverse.
Two adjacent models worth distinguishing
Employer-sponsored virtual care. A company offering virtual primary care to its own workforce sits inside a different set of rules than a direct-to-consumer platform. The benefit is very likely an ERISA group health plan, which brings plan document, summary plan description, Form 5500, COBRA, and nondiscrimination obligations that companies routinely overlook when they describe the program as a perquisite rather than a benefit. It may also be a HIPAA-covered health plan in its own right, separate from the vendor's status. And it raises an employment law problem the clinical team will not see: the employer must not receive individually identifiable health information about participants, which requires a firewall between the vendor and human resources that is designed rather than assumed.
International telehealth. Treating a patient physically located in another country is governed by that country's licensure and practice rules, not by U.S. law, and most jurisdictions require local registration. Data transfer adds a second layer — the GDPR treats health data as a special category requiring an Article 9 condition, and cross-border transfer requires an adequacy decision or an appropriate safeguard. A U.S. platform that lets a traveling patient take a visit from abroad has, on that encounter, potentially practiced without a license in that country and exported health data without a transfer mechanism. Most companies address this by blocking non-U.S. IP addresses at the encounter layer, which is blunt, imperfect, and considerably better than nothing.
Related articles
- HIPAA Privacy and Security Compliance for Covered Entities and Business Associates — the privacy layer in detail.
- Healthcare Fraud and Abuse: The Anti-Kickback Statute, the Stark Law, and the False Claims Act — the telefraud analysis.
- Healthcare Regulatory Compliance Toolkit — the full roadmap.
- Anti-Kickback and Stark Law Compliance Checklist — the arrangement review.
- HIPAA Security Rule Risk Analysis Checklist — covering the telehealth stack.
- Professional Malpractice: Standards of Care, Expert Proof, and Defenses — the failure-to-escalate theory.
- Cloud and SaaS Agreements: Service Levels, Data Rights, Security, and Exit — the vendor stack.
- Managing a Multistate Remote Workforce — the employment analogue of the fifty-state problem.
- Business Insurance and Coverage Disputes: CGL, E&O, Cyber, and D&O — confirming the policy actually covers the practice.
- Vendor Cybersecurity Diligence Checklist — diligence on the video and messaging vendors.
This article is provided for general informational purposes and does not constitute legal advice. Telehealth rules are state-specific and several federal authorities described here operate under temporary extensions subject to change. Consult qualified healthcare regulatory counsel before launching or expanding a telehealth service.