logo
Telehealth and Advanced Practitioner Coding Considerations

Coding

Telehealth and Advanced Practitioner Coding Considerations

With the increased utilization of both advanced practitioners (i.e., physician assistants [PAs] and nurse practitioners [NPs]) and telehealth, Health Insurance Portability and Accountability Act (HIPAA) covered entities need to stay abreast of the recent changes and the continued implementation of best practices.

 

On November 1, 2024, the Centers for Medicare and Medicaid (CMS) announced the Calendar Year (CY) 2025 Medicare Physician Fee Schedule Final Rule, which finalized changes to the Physician Fee Schedule (PFS). Telehealth was one of the items that received a lot of attention because of its adoption during COVID-19 and the changes that are occurring during 2025.

 

On the non-surgical PA front, there are also several updates regarding the American Medical Association (AMA) and CMS updates for telehealth services and coding requirements. Importantly, covered entities need to distinguish between what is permissible when treating and coding for a Medicare or Medicaid beneficiary and those individuals covered by a private payor. 

 

A prudent practice is to update policies and procedures, as well as implement training and evaluate the current settings in electronic health records. 

 

Analysis

 

Given the focus on telehealth, let’s begin with the November 1, 2024, CMS interpretation of the PFS and CMS’s “Telehealth FAQ Calendar Year 2025.” While the full PFS telehealth portion appears below, there are three key take-aways from both CMS published items: (1) Through March 31, 2025, Medicare beneficiaries can receive telehealth services in their home and do not need to be in a rural area or a medical facility; (2) Through March 31, 2025, any licensed practitioner who can independently bill Medicare may furnish telehealth services; and (3) “Incident to” codes are updated. 

 

Importantly, the CMS website links to https://telehealth.hhs.gov/providers/telehealth-policy/telehealth-policy-updates, which indicates that “Medicare patients can receive telehealth services for non-behavioral/mental healthcare in the home through September 30, 2025.” 

 

The November 1, 2024 excerpt follows:

 

“Absent Congressional action, beginning January 1, 2025, the statutory limitations that were in place for Medicare telehealth services prior to the COVID-19 PHE will retake effect for most telehealth services. These include geographic and location restrictions on where the services are provided, and limitations on the scope of practitioners who can provide Medicare telehealth services. However, the final rule reflects CMS’s goal to preserve some important, but limited, flexibilities in our authority, and expand the scope of and access to telehealth services where appropriate. 

 

For CY 2025, we are finalizing our proposal to add several services to the Medicare Telehealth Services List, including caregiver training services on a provisional basis and PrEP counseling and safety planning interventions on a permanent basis. We are finalizing to continue the suspension of frequency limitations for subsequent inpatient visits, subsequent nursing facility visits, and critical care consultations for CY 2025. 

 

We are finalizing that beginning January 1, 2025, an interactive telecommunications system may include two-way, real-time, audio-only communication technology for any Medicare telehealth service furnished to a beneficiary in their home, if the distant site physician or practitioner is technically capable of using an interactive telecommunications system, but the patient is not capable of, or does not consent to, the use of video technology.

 

We are finalizing that, through CY 2025, we will continue to permit distant site practitioners to use their currently enrolled practice locations instead of their home addresses when providing telehealth services from their home.

 

We are finalizing, for a certain subset of services that are required to be furnished under the direct supervision of a physician or other supervising practitioner, to permanently adopt a definition of direct supervision that allows the supervising physician or practitioner to provide such supervision via a virtual presence through real-time audio and visual interactive telecommunications. We are specifically finalizing to make permanent that the supervising physician or practitioner may provide such virtual direct supervision (1) for services furnished incident to a physician or other practitioner’s professional service, when provided by auxiliary personnel employed by the billing physician or supervising practitioner and working under his or her direct supervision, and for which the underlying HCPCS code has been assigned a PC/TC indicator of ‘5’ and services described by CPT code 99211, and (2) for office or other outpatient visits for the evaluation and management of an established patient who may not require the presence of a physician or other qualified healthcare professional. For all other services furnished incident that require the direct supervision of the physician or other supervising practitioner, we are finalizing to continue to permit direct supervision be provided through real-time audio and visual interactive telecommunications technology only through December 31, 2025.

 

We are finalizing a policy to continue to allow teaching physicians to have a virtual presence for purposes of billing for services furnished involving residents in all teaching settings, but only in clinical instances when the service is furnished virtually (for example, a three-way telehealth visit, with the patient, resident, and teaching physician in separate locations) through December 31, 2025. This virtual presence will continue to meet the requirement that the teaching physician be present for the key portion of the service.”

 

Patient access to and the clinical provision of telehealth services by medical professionals are not the only areas of change. The American Medical Association (AMA) Current Procedural Terminology (CPT) codes also changed. Telemedicine codes experienced an overhaul with 17 new codes being released, which include both audio-visual and audio-only services. 

 

The breakdown of the new codes follows:

  • New CPT Codes: The 2025 CPT Manual includes 17 new codes for telemedicine visits, encompassing both audio-visual and audio-only services for new and established patients. For instance, codes 98000–98003 pertain to new patient visits, while codes 98008–98011 address established patient visits. 

  • Virtual Check-Ins: CPT code 98016 has been introduced to replace the previous virtual check-in code G2012. This service is designed for established patients and must be patient-initiated, involving a 5-10 minute medical discussion unrelated to any evaluation and management (E/M) service in the prior seven days or leading to an E/M service within 24 hours.

  • CMS Policies: Through calendar year 2025, CMS will continue to permit distant-site practitioners to use their currently enrolled practice locations instead of their home addresses when providing services from their home. Additionally, teaching physicians are allowed to have a virtual presence for billing purposes when supervising residents in all teaching settings.  

Where PAs are utilized, the following codes should be considered:

  • Modifier 25 Usage: For most non-surgical procedures, if a physician performs a significant and separately identifiable E/M service beyond the usual pre and post-operative work on the same date, it may be reported by appending modifier 25 to the E/M code. This ensures that the additional E/M service is recognized separately from the procedure performed.  

  • Add-On Code G0559: CMS has introduced HCPCS code G0559 for post-operative care services provided by a practitioner other than the one who performed the surgical procedure (or another practitioner in the same group practice). This code reflects the time and resources involved in post-op visits by practitioners not involved in the original surgery.  

These updates strive to enhance the flexibility and accuracy of coding for telehealth services and non-surgical situations. Ensuring documentation and coding accuracy is going to be critical for avoiding downstream liability. 

 

For example, on August 19, 2024, the U.S. Department of Justice announced a False Claims Act settlement with a practice for submitting claims for payment where services were rendered by NPs or PAs not enrolled with Medicare and Medicaid and the physicians had no personal involvement in the supervision of the advanced practitioners (see United States and State of New York ex rel. Nikki Patel v. Orange Medical Care, P.C., et al., 16 Civ. 8589 [PGG] [SDNY Aug. 13, 2024]). 

 

In sum, providers and facilities are encouraged to review the new requirements, have a third party assess billing and coding practices, identify what should be included in a medical record, and revise policies and procedures to reflect these updates. 

 

Conclusion

 

As it is said, “An ounce of prevention is worth a pound of cure.” Distilling private payors’ permitted practices from Medicare permitted practices is going to be critical to avoiding potential False Claims Act liability and the return of overpayments. A proactive approach of having a third-party auditor explain the coding changes and advise on language to include in the medical record, and implementing new policies and procedures while training professionals, especially when advanced practitioners are involved, is crucial to avoiding adverse actions. 

 

Rachel V. Rose, JD, MBA, advises clients on compliance, transactions, government administrative actions, and litigation involving healthcare, cybersecurity, corporate, and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases. She also teaches bioethics at Baylor College of Medicine in Houston. Rachel can be reached through her website: www.rvrose.com

 

 

 

HIPAA Trends to Watch in 2025

Security

HIPAA Trends to Watch in 2025 :New Year, new HIPAA considerations. As of December 9, 2024, there were more than 168 million individuals affected by healthcare data breaches reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). This number is record breaking.
Coming Soon to a Federal Register Near You: Changes to the FTC’s Health Breach Notification Rule

Practice Management

Coming Soon to a Federal Register Near You: Changes to the FTC’s Health Breach Notification Rule:On April 26, 2024, the Federal Trade Commission (FTC) announced changes to its Health Breach Notification Rule, 16 CFR Part 318 (HBNR). The effective date is 60 days after its publication in the Federal Register
Considerations for Whistleblowers and Companies

Practice Management

Considerations for Whistleblowers and Companies:In June 2022, I wrote an article, “The False Claims Act and the Seal: What Whistleblowers Need to Know,” which I encourage everyone reading this article to also read. The United States Supreme Court’s decision in United States ex rel. Polansky v. Executive Health Resources (599 U.S. 419; 2023) confirmed that the United States government has nearly unfettered discretion “to dismiss a [federal False Claims Act] suit over a relator’s objection” (Id. at 423; see also State ex rel. Fox v. Thornley, 2023 IL App [4th]; citing Polansky as instructive when interpreting the Illinois False Claims Act).
Zero Trust and the ONC-SAMHSA Initiative

Security

Zero Trust and the ONC-SAMHSA Initiative:"Cybersecurity is patient safety" is a phrase that should be indoctrinated into everyone's brain in the healthcare and public health sector. The notion is highlighted by a late-January/early-February series of announcements by Lurie Children's Hospital of Chicago that the hospital went "old school," reverting to paper records and establishing a call center as part of its business continuity process in order to "protect the information of our patients, workforce, and organization at large." Subsequently, they announced that the "network was accessed by a known criminal threat actor."
The Uniform Commercial Code and Its Relation to Hardware, Software, and Related Services Used by Healthcare Sector Participants

Practice Management

The Uniform Commercial Code and Its Relation to Hardware, Software, and Related Services Used by Healthcare Sector Participants:As set forth in 45 CFR § 164.502(a)(3), a business associate may not utilize protected health information (PHI) in any way that would violate the Health Information Portability and Accountability Act of 1996 (HIPAA) and the related Privacy Rule.
Data Use Agreements: Utilization and Distinguishing from Business Associate Agreements

Practice Management

Data Use Agreements: Utilization and Distinguishing from Business Associate Agreements:Any person in the healthcare industry knows or should learn that if they are considered a covered entity or business associate (including subcontractor), that creates, receives, maintains, and/or transmits protected health information (PHI), then a business associate agreement (BAA) is required. See 45 CFR §160.103, 45 CFR § 164.504. This is not a new phenomenon; in fact, it has been required for over 20 years.
Whistleblowers and Company Data: To Collect or Not to Collect

Practice Management

Whistleblowers and Company Data: To Collect or Not to Collect:Before the thought, "Oh, I have access to all this information - ‘Come on Barbie, let's go party' 1" crosses a potential whistleblower's mind, there is one question to ask. "Should I collect documents from my employer or a person that I contract with to perform services?" This is critical to avoiding potential liability at both the employment and post-employment stages. What are the potential ramifications? It depends. 
Two HIPAA Enforcement Actions Underscore the Importance of the Confidentiality, Integrity, and Availability of Patient Information and the Consequences

Security

Two HIPAA Enforcement Actions Underscore the Importance of the Confidentiality, Integrity, and Availability of Patient Information and the Consequences:In March 2023, the current Presidential Administration announced its national cybersecurity strategy. Prior to its release, the President issued two Executive Orders, which underscored the importance of privacy of individuals' health information, tracking data without the knowledge or consent of a consumer/patient, and coordination among federal government agencies to implement initiatives or strengthen existing initiatives.
If Conduct Appears to Buck the Legal Norm, Chances Are That It Does

Auditing

If Conduct Appears to Buck the Legal Norm, Chances Are That It Does:It's akin to wearing Doc Martens to a professional cocktail party reception or Uggs to court. In other words, the wardrobe choice jumps out as not being appropriate for the situation. Likewise, certain conduct that violates the Anti-Kickback Statute (AKS) and the False Claims Act (FCA) unequivocally jumps out as being unlawful under the facts and circumstances, yet persons engage in the inappropriate behavior. 
The Significance of Not Obtaining Patient/Consumer Consent Before Poaching Data

Practice Management

The Significance of Not Obtaining Patient/Consumer Consent Before Poaching Data:Now, in 2023, the FTC announced two consent orders related to the prohibited poaching and use of PHI by known third parties and the DOJ announced another settlement under its Civil Cyber-Fraud Initiative. 
Administration for Strategic Preparation and Response Releases Updated Cybersecurity Framework Implementation Guide

Compliance

Administration for Strategic Preparation and Response Releases Updated Cybersecurity Framework Implementation Guide:Whenever I present, which is often, I often receive follow-up questions from participants regarding resources to utilize when creating, reviewing, and/or supplementing a compliance program, including relevant policies and procedures. 
Recent False Claims Act Cases Shed Light Upon Compliance Scrutiny

Practice Management

Recent False Claims Act Cases Shed Light Upon Compliance Scrutiny:As touted by the U.S. Department of Justice (DOJ) and Members of Congress alike, including Senator Chuck Grassley (R-IA), the False Claims Act, 31 U.S.C. §§ 3729, et seq. (FCA) is the federal government's primary tool to root out fraud and put money back into the federal fisc.
HIPAA Considerations When Business Associates and Data Are International

Compliance

HIPAA Considerations When Business Associates and Data Are International:Although it is said that "business is global," there are some nuances to this blanket statement to consider when creating, receiving, maintaining, or transmitting electronic protected health information or electronic health information (PHI) internationally. Before delving into items to consider when business associates (including subcontractors) and PHI are international, it's important to appreciate that both the U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR) and the U.S. Department of Justice (DOJ) have the ability to enforce violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as the related Privacy Rule, Security Rule, and Breach Notification Rule.
The U.S. Government and Cooperation Credit in Relation to the False Claims Act and the Federal Anti-Kickback Statute

Practice Management

The U.S. Government and Cooperation Credit in Relation to the False Claims Act and the Federal Anti-Kickback Statute:Those familiar with the healthcare industry have no doubt learned that the U.S. Department of Health and Human Services Office of the Inspector General (HHS-OIG) and the U.S. Department of Justice (DOJ) have identified both the False Claims Act (FCA) and the Anti-Kickback Statute (AKS) as laws critical to thwarting fraud, waste, and abuse. Often, these two laws come together in a FCA case. 
No Surprises Act and Good Faith Estimate Considerations for Behavioral Health Providers

Practice Management

No Surprises Act and Good Faith Estimate Considerations for Behavioral Health Providers:Overview: Enacted as part of the Consolidated Appropriations Act of 2021, Pub. L. 116-260 (Dec. 27, 2020), the No Surprises Act (NSA) and the related regulations, which became effective January 1, 2022, should have a positive impact for patients.
Two Hot Ransomware Items to Watch

Compliance

Two Hot Ransomware Items to Watch:The healthcare sector continues to be a target of cybercriminals. An area that continues to emerge is ransomware as a service (RaaS)-basically the adoption of a Software as a Service model, which is subscription-based and "enables affiliates to use already-developed ransomware tools to execute ransomware attacks." 
Waiving Copays Associated with Medicare - Just as Illegal Now as it Was in 1994

Practice Management

Waiving Copays Associated with Medicare - Just as Illegal Now as it Was in 1994:On December 19, 1994, the U.S. Department of Health and Human Services, Office of Inspector General (HHS-OIG) published a Special Fraud Alert in the Federal Register related to the waiver of copays, with the intention of alerting the public about "its concern about possible widespread and abusive health care industry practices, and seeking wider dissemination of information to the general public." 
The Oft-Overlooked Federal Trade Commission's Health Breach Notification Rule Gets a Nudge

Compliance

The Oft-Overlooked Federal Trade Commission's Health Breach Notification Rule Gets a Nudge:For many, when an individual's Protected Health Information (PHI) is unlawfully accessed, the first law that comes to mind is the Health Insurance Portability and Accountability Act of 1996 (HIPAA). 
The Biggest Threat to Healthcare Cybersecurity: Telehealth

Practice Management

The Biggest Threat to Healthcare Cybersecurity: Telehealth:According to a recent study by SecurityScorecard and Dark Owl, "Telehealth systems have experienced an enormous increase in targeted attacks."
COVID-19 or Not: The Anti-Kickback Statute Remains a Tool of Choice for False Claims Act Violations

Practice Management

COVID-19 or Not: The Anti-Kickback Statute Remains a Tool of Choice for False Claims Act Violations:The COVID-19 pandemic has not diminished the focus of the U.S. Department of Justice ("DOJ") and whistleblowers, who are known as "Relators," from bringing and enforcing claims that violate both the federal Anti-Kickback Statute (AKS)   and the False Claims Act (FCA). 
Sharing of PHI with Large Tech Companies, Confidential Agreements, and HIPAA's Prohibition on the Marketing and Sale of PHI

Compliance

Sharing of PHI with Large Tech Companies, Confidential Agreements, and HIPAA's Prohibition on the Marketing and Sale of PHI:
As stated on Forbes, "The chief worry isn't about thieves getting their hands on lost or stolen devices, but the ease with which companies can gain access to the personal information."

2019 HIPAA Settlements and Take-Aways

Compliance

2019 HIPAA Settlements and Take-Aways:
The Health Insurance Portability and Accountability Act of 1996 ("HIPAA")  and the Health Information Technology for Economic and Clinical Health Act ("HITECH Act")  are two of the pillars that form the foundation of a patient's privacy rights in relation to his/her protected health information ("PHI"), as well as the obligations of covered entities, business associates, and subcontractors to ensure the confidentiality, integrity, and availability of the data.
This is also a good time to remind providers that a deceased individual's PHI is subject to HIPAA for 50 years. 
HIPAA and Health Apps and APIs   Oh My

Compliance

HIPAA and Health Apps and APIs Oh My :All this to say that technology is complex
The Importance of Being Earnest   Why HIPAA and HITECH Compliance Matters

Auditing

The Importance of Being Earnest Why HIPAA and HITECH Compliance Matters:What's significant is the underlying violations of the Security Rule
Recent HHS Guidance Underscores the Importance of HIPAA Compliance

Practice Management

Recent HHS Guidance Underscores the Importance of HIPAA Compliance:Everyone who participates in the United States healthcare system either as a patient
The False Claims Act, Knowledge  and the 60 Day Rule

Coding

The False Claims Act, Knowledge and the 60 Day Rule:Three important terms of the FCA
A Prescription for Start Ups Relationships with Physicians

Practice Management

A Prescription for Start Ups Relationships with Physicians:The purpose of the note is to provide an overview that educates readers
What is a Legal Hold and e Discovery Anyway

Practice Management

What is a Legal Hold and e Discovery Anyway:The transition from paper to electronic records
Update Medicare Quality Reporting Programs

Practice Management

Update Medicare Quality Reporting Programs:By now, the healthcare industry should be aware of the fundamental shift in reimbursement
Learning from Vanderbilt: Dealing with HIPAA Breaches

Compliance

Learning from Vanderbilt: Dealing with HIPAA Breaches:What did Vanderbilt announce?
HIPAA, Legal Holds, and PHI: Rachel Rose, J.D., M.B.A. With Sean McKenna, J.D., B.A.

Compliance

HIPAA, Legal Holds, and PHI: Rachel Rose, J.D., M.B.A. With Sean McKenna, J.D., B.A.:I spent almost 16 years with the federal government handling healthcare fraud matters
CMS Emergency Preparedness Rule Released - Do You Have a Plan?

Compliance

CMS Emergency Preparedness Rule Released - Do You Have a Plan?:a breach or a ransomware attack, which potentially impacts the confidentiality, integrity, or availability of the protected health information
Working From Home - Make a Security Checklist

Compliance

Working From Home - Make a Security Checklist:Regardless of the industry, the number of individuals who telecommute, at least once a week, is increasing.
What Healthcare Entities and Business Associates Can Learn From Other Government Agencies and Related Laws About Handling and Disposing of PII and PHI.

Practice Management

What Healthcare Entities and Business Associates Can Learn From Other Government Agencies and Related Laws About Handling and Disposing of PII and PHI.:One just needs to turn on the television, listen to Bloomberg, or read the U.S. Department of Health and Human Services' (HHS) Wall of Shame to hear about data breaches involving personally identifiable information (PII) and protected health information (PHI). 
Relative Value Units Important Now More Than Ever

Coding

Relative Value Units Important Now More Than Ever:In light of The Patient Protection and Affordable Care Act, the of physician groups and practices, and reimbursement issues, physicians need to appreciate what Relative Value Units (RVUs) are and how they can impact compensation.

Rachel V. Rose, JD, MBA

Rachel V. Rose, JD, MBA


Principal at Rachel V. Rose - Attorney at Law, PLLC

Email me

Houston, TX

 

Total articles published on BC Advantage 36

Editorial Ad

Ad pdf ad here