How to Build a Compliant Telehealth Workflow in 2026
·17 min read
Key Takeaways
A telehealth workflow is the full sequence of a virtual visit, from eligibility screening through documentation and follow-up, with a compliance requirement built into each stage.
The HIPAA enforcement discretion for telehealth ended at 11:59 pm on August 9, 2023. Consumer video apps without a signed agreement are no longer covered.
Most Medicare telehealth flexibilities now run through December 31, 2027, but a few are permanent, and a few expire sooner.
DEA flexibilities for prescribing controlled substances by telemedicine were extended through December 31, 2026.
The patient's physical location at the moment of the visit is what drives licensure, which makes it a scheduling question rather than a legal footnote.
OCR enforcement in this space overwhelmingly targets one failure: no accurate, thorough risk analysis.
Aug 9, 2023
Date the HIPAA telehealth enforcement discretion expired
Dec 31, 2027
Current expiration for most Medicare telehealth flexibilities
13
OCR Risk Analysis Initiative investigations completed as of April 2026
A clinic can run video visits every day for two years and still be out of compliance without knowing it. The federal waiver that let practices use consumer apps like FaceTime and Skype did not quietly fade out. It ended on a specific date, and a lot of clinics never updated their process.
Building a telehealth workflow that is both safe for patients and defensible under federal rules is an operations problem, not a technology purchase. This guide walks through the seven stages of a virtual visit, the compliance gate that sits at each one, and exactly which federal rules are live right now with their expiration dates attached.
Disclaimer: This article is general information for US clinics, not legal or medical advice. Federal telehealth rules change often, and state requirements vary. Confirm current obligations with your own counsel, compliance officer, and state licensing board before acting.
What Is a Telehealth Workflow?
A telehealth workflow is the documented, repeatable sequence your clinic follows for a virtual visit. It covers who qualifies for one, how the visit gets booked, how consent is captured, which platform is used, what happens during the encounter, how it gets documented and coded, and what triggers follow-up or escalation.
Two things separate a real workflow from an informal habit. It is written down, and every stage has an owner. If your answer to "who confirms the patient's state before the visit" is "whoever picks up the phone," you have a habit, not a workflow.
The compliance angle matters because the requirements are not bolted on at the end. Consent belongs at intake. Licensure belongs at scheduling. A business associate agreement belongs to procurement. Treating compliance as a final review step is how clinics end up rebuilding the whole process twice.
The Rules That Actually Apply Right Now (2026)
Federal telehealth rules sit on several different clocks. Mixing them up is the most common source of bad internal policy, so here is the current status of each with its date.
Rule area
Status
Key date
HIPAA telehealth enforcement discretion
Ended
Expired 11:59 pm, August 9, 2023
Medicare geographic restrictions, non-behavioral
Waived
Through December 31, 2027
Medicare geographic restrictions, behavioral health
Permanent
No expiration
Patient's home as originating site, non-behavioral
Allowed
Through December 31, 2027
Audio-only for non-behavioral Medicare telehealth
Allowed
Through December 31, 2027
Behavioral health in-person visit requirement
Waived
Through December 31, 2027
RHC and FQHC as distant site
Allowed
Until January 1, 2028
DEA controlled substance tele-prescribing
Extended
Through December 31, 2026
Updated HIPAA Security Rule
Proposed only
No final rule issued
Last verified: September 2, 2026. Medicare telehealth authority has been extended repeatedly by short-term legislation. Re-check these dates before relying on them.
HIPAA After the COVID Waiver Ended
During the public health emergency, the HHS Office for Civil Rights said it would not penalize providers for using everyday video apps in good faith. That grace period is over.
OCR announced in April 2023 that the enforcement discretion would expire at 11:59 pm on May 11, 2023, then gave providers a 90-day transition window running from May 12 through 11:59 pm on August 9, 2023. Since August 10, 2023, telehealth has been held to the ordinary HIPAA Privacy and Security Rules with no special allowance. Source: HHS, HIPAA and Telehealth.
What that means in practice:
Your video platform must be capable of HIPAA compliance, and you need a business associate agreement signed with the vendor.
Consumer apps used without a BAA are not acceptable for routine care.
Protected health information moving through the session needs the same safeguards as any other electronic record.
Federal telehealth rules run on separate clocks, which is why a single undated policy goes stale fast.
Medicare Telehealth Flexibilities and Their Dates
For Medicare billing, most of the pandemic-era flexibilities have been extended rather than made permanent. Patients can receive non-behavioral telehealth at home, geographic restrictions are lifted, and audio-only is permitted, all through December 31, 2027.
Behavioral and mental health telehealth is the exception worth memorizing. The removal of geographic restrictions there is permanent, and the requirement for an in-person visit within six months of an initial behavioral telehealth service is waived through the end of 2027. Rural health clinics and federally qualified health centers can serve as a distant site until January 1, 2028, under the Consolidated Appropriations Act of 2026. Source: telehealth.HHS.gov, Telehealth policy updates.
Controlled Substances and the DEA Extension
Prescribing controlled substances by telemedicine without a prior in-person exam remains possible, but only under a temporary extension. The DEA and HHS issued a fourth temporary extension covering January 1, 2026 through December 31, 2026, allowing DEA-registered practitioners to prescribe Schedule II through V medications via telemedicine when conditions are met, and permitting audio-only for certain FDA-approved medications used in opioid use disorder treatment. Source: Federal Register, Fourth Temporary Extension.
Build your prescribing policy so it can survive that date changing. A workflow that hard-codes "telemedicine prescribing is allowed" will be wrong the moment the extension lapses or a permanent rule replaces it.
The Proposed HIPAA Security Rule Update
OCR issued a notice of proposed rulemaking on December 27, 2024, published in the Federal Register on January 6, 2025. The comment period closed March 7, 2025, and drew more than 4,000 comments. No final rule has been issued.
It matters anyway, because it signals direction. The proposal would remove the long-standing split between "required" and "addressable" safeguards and would mandate multi-factor authentication across access points to electronic protected health information. Source: Federal Register, HIPAA Security Rule NPRM.
Clinics turning on MFA now are not gold-plating. They are getting ahead of a change that is clearly coming.
The Telehealth Workflow in 7 Stages
Here is the sequence, with the compliance gate that belongs at each step:
1. Eligibility and triage decides whether the complaint is safe to handle virtually.
2. Scheduling and licensure check confirms the patient's physical location and your provider's license there.
3. Consent and intake captures and documents telehealth-specific informed consent.
4. Technology check and the BAA confirms the platform is covered by a signed agreement and the patient can connect.
5. The visit itself verifies identity and location, then conducts and documents the encounter privately.
6. Documentation and coding records modality, locations, times, consent, and clinical content.
7. Follow-up and escalation closes the loop on orders, referrals, and anything that needs in-person care.
Each stage of a virtual visit carries its own compliance gate, which is why compliance cannot be a final review step.
Stage 1: Eligibility and Triage
Not every complaint belongs on video. Build a short screening list that routes patients correctly before a slot is ever booked.
Practical approach: keep a written list of complaint types your clinic handles virtually, a list it never handles virtually, and a middle category requiring clinician review. Chest pain, severe shortness of breath, suspected stroke, and acute abdominal pain belong in the never category with an instruction to call 911.
If you want a patient-facing framework for the same judgment call, our guide on when a virtual visit is the right call covers the scenarios in more detail.
Stage 2: Scheduling and Licensure Check
Licensure follows the patient, not the provider. A physician sitting in Ohio treating a patient who is physically in Kentucky that morning generally needs to be authorized to practice in Kentucky. The patient's location at the time of the visit is what controls.
That makes it a scheduling question. Add one required field to your booking process: what state will you physically be in during this appointment? Snowbirds, college students, and traveling workers break assumptions constantly.
The Interstate Medical Licensure Compact offers physicians an expedited path to licenses in participating states, which now covers more than 40 states plus the District of Columbia and Guam. Source: Interstate Medical Licensure Compact. Note that the compact speeds up getting licenses; it does not replace the need to hold one.
Stage 3: Consent and Intake
Telehealth consent is its own document, separate from your general consent to treat. Capture it before the first virtual visit and document that you did.
A workable consent covers:
What telehealth services are being offered and how they are delivered
The limits of a remote exam and the technology risks involved
How privacy is protected and how records are stored
The patient's right to refuse or withdraw at any time and switch to in-person care
What to do in an emergency, including calling 911 rather than the clinic
Any limits on prescribing through a virtual visit
Record consent in the chart with a date and the method used. Verbal consent counts in many contexts, but only if the note proves it happened.
Stage 4: Technology Check and the BAA
Two separate checks live here, and clinics routinely do only the second.
The compliance check: Does your organization have a signed business associate agreement with the platform vendor? A vendor claiming to be "HIPAA compliant" in its marketing is not the same as a vendor that has executed a BAA with you. Ask for the countersigned document and file it.
The patient check: send a test link, connection instructions, and a fallback plan ahead of the appointment. A five-minute pre-visit tech check by a staff member converts a large share of failed visits into completed ones, and it costs far less than a no-show slot.
Stage 5: The Visit Itself
Three things happen at the top of every encounter before clinical work begins:
Verify identity. Confirm the patient's full name and date of birth, the same as you would at a front desk.
Confirm location. Ask where the patient physically is right now and note the address or at least the state. This drives both licensure and any emergency response.
Confirm privacy on both ends. The provider needs a closed door. The patient should be told they can reschedule if they are somewhere they cannot speak freely.
Then conduct the visit, naming clearly what the remote format cannot assess. A note that says "no abdominal exam possible by video" is a clinical safeguard and a legal one.
Stage 6: Documentation and Coding
Telehealth notes carry everything a regular note carries, plus several elements specific to the modality:
The patient's location and the provider's location during the visit
The modality used, meaning audio-video or audio-only
Start and stop times when billing is time-based
Confirmation that telehealth consent was obtained
Who else was present, including family members or interpreters
Any limitations of the remote examination
Provider identification and signature
Keep telehealth notes in the same chart as in-person visits rather than a separate system. Splitting the record creates gaps that hurt both continuity of care and audit defense. For teams evaluating documentation support tools, our overview of AI documentation tools in US healthcare covers what those systems do and where they still need human review.
Stage 7: Follow-Up and Escalation
Every virtual visit ends with an explicit disposition. Not "we'll see how it goes."
Define in advance what triggers an in-person visit, who calls the patient if results come back abnormal, how referrals get tracked to completion, and what the after-hours pathway is. Then write down the specific symptoms that should prompt the patient to seek immediate care, and put them in the visit summary.
Patient Safety Guardrails You Cannot Skip
Compliance protects the clinic. These two protect the patient, and they are where thin workflows fail hardest.
Verifying Patient Identity and Location
Remote care removes the visual and procedural cues a front desk provides. Verify identity at every visit, not just the first. For controlled substance prescribing or any high-risk care, tighten it further with a photo ID check on camera.
Location verification is the one people skip, and it carries the most weight. It determines which state's rules apply, which emergency services you would call, and whether your provider is licensed to be in that encounter at all.
The Emergency Escalation Plan
If a patient deteriorates mid-visit, or discloses something that requires immediate intervention, your clinician needs a script rather than improvisation.
Minimum viable plan:
The patient's current physical address, captured at the start of every visit
An emergency contact on file
A written protocol for calling 911 to the patient's location, including who dials while the clinician stays on the call
Documented handoff instructions if the patient is directed to an emergency department
Practices that skip this usually discover the gap during the one visit where it mattered.
What OCR Actually Penalizes
Clinics tend to imagine the enforcement risk is an intercepted video call. The record says otherwise.
OCR's Risk Analysis Initiative targets a specific and unglamorous failure: organizations that never conducted an accurate, thorough assessment of risks to electronic protected health information. As of April 2026, the initiative had completed 13 investigations.
Two documented examples show the pattern. Comprehensive Neurology, PC settled in April 2025 for $25,000 with a two-year corrective action plan, in what was the eighth action under the initiative. BST & Co. CPAs, LLP settled in August 2025 for $175,000, also with a two-year corrective action plan, as the tenth. In both cases, the finding was the same: no adequate risk analysis.
The practical takeaway is blunt. A documented, current risk analysis covering your telehealth platform, your devices, and your data flows is the single highest-value compliance artifact your clinic can produce. It is also the one most likely to be missing.
Review the whole workflow on a set schedule, at least annually, and immediately whenever a federal date shifts. Given how much of the current framework runs on temporary extensions, a calendar reminder tied to those expiration dates is worth more than a thicker policy binder. Wider context on where US care delivery is heading appears in our roundup of broader US healthcare trends, and the clinical practice side is covered in how telemedicine is reshaping clinical practice.
FAQ
Not on its own. The OCR enforcement discretion that permitted consumer apps ended August 9, 2023. Standard consumer FaceTime carries no business associate agreement, so it is not appropriate for routine clinical telehealth.
Yes. Any vendor handling protected health information on your behalf is a business associate and needs a signed agreement. Marketing language claiming HIPAA compliance does not replace an executed BAA.
Yes, and it should be telehealth-specific rather than folded into general consent to treat. Document what was explained, when consent was given, and how it was captured.
Generally, only if licensed or otherwise authorized in the state where the patient is physically located during the visit. The Interstate Medical Licensure Compact speeds up obtaining those licenses but does not remove the requirement.
Under the current DEA and HHS extension, yes, through December 31, 2026, when conditions are met. That authority is temporary, so confirm the current rule before relying on it.
Putting It Into Practice
A compliant telehealth workflow is not a binder you write once. It is a sequence with an owner at every stage, a set of dated federal rules you re-check on a schedule, and a risk analysis you keep current.
Start with the two items that carry the most weight for the least effort: get the signed BAA in your file, and get a real risk analysis done. Those close the two gaps that federal enforcement actually targets. The rest of the workflow is easier to build once those are handled.
Which stage is weakest in your clinic right now, the licensure check or the escalation plan? Share your experience in the comments, and pass this along to whoever owns compliance at your practice.
Published by Certify Me USA
Certify Me USA Editorial Team
Published by Certify Me USA, a resource covering healthcare, workplace safety, and certification topics for US professionals. Guides are built from federal regulator publications and primary government sources, with rules dated so readers can verify what is current.
Keep Your Telehealth Workflow Current
Get plain English breakdowns of US healthcare rules and compliance changes, sourced from federal regulators and dated so you know what is live.
A plain beginner guide to ISO 9001, 14001, and 45001 for US healthcare and service organizations, covering what they mean, costs, timelines, and if you need them.