Prior Authorization Workflows for Telehealth-Delivered Services
Telehealth prior authorizations fail on structural flaws no clinical documentation can fix.

Prior authorization for telehealth-delivered care does not simply take longer or demand more paperwork than the in-person version. It runs on three separate approval questions that all have to clear before a visit can happen: whether the service itself qualifies for coverage, whether the specific modality (video, audio-only, or asynchronous messaging) is covered under that plan, and whether the patient's location at the time of care, the originating site, meets the payer's rules. Standard PA logic was never built to ask the second or third question. It was built to answer one thing: does this service meet medical necessity. Everything else, modality and site, sits outside that logic entirely, bolted on after the fact rather than designed in.
That gap creates a problem no amount of careful documentation can solve on its own. The three dimensions often get evaluated by different departments inside the same payer, on different timelines, against different criteria, so a provider can satisfy the medical necessity standard perfectly and still get denied because nobody checked whether audio-only was covered for that code, or whether the patient's home qualified as an originating site under that plan. The clinical file can be flawless. The denial still comes back.
What results is a whole additional layer of slower turnaround. It is an entire category of denial that providers cannot see coming and cannot fix with the usual PA playbook, because the rejection has nothing to do with missing clinical information. It reflects missing modality or site documentation that the workflow never asked for in the first place. Understanding that distinction, between a documentation failure and a structural one, is the starting point for fixing anything downstream.
Service eligibility as the first approval layer breaking down for telehealth
Service eligibility asks whether a service meets medical necessity, a question most providers already know how to work. It asks whether a service meets medical necessity, the same question payers ask for an in-person visit. But for telehealth, that question gets stacked on top of a second one that doesn't exist in brick-and-mortar care: does the payer's benefit design even include telehealth as a covered way to deliver that service category. A plan can cover a psychiatric evaluation delivered in the office and exclude or cap the same evaluation delivered by video under a completely separate benefit provision. The clinical notes can be airtight, and the claim still fails on a coverage question the provider never saw coming, because nothing in the intake process flagged it.
Coding makes the split concrete. The one code in that series Medicare does pay is 98016, the brief virtual check-in. That single carve-out determines which services can even be submitted for PA under Medicare in the first place. Get the code wrong for the payer in front of you, and the request doesn't fail on clinical grounds. It fails before clinical review ever starts.
Federally qualified health centers carry an extra layer of complexity on top of that. They bill non-behavioral telehealth to Medicare using HCPCS G2025 through September 30, 2026, after which individual CPT and HCPCS codes take over, a shift that interacts with the prospective payment system's rate structure in ways standard PA submission logic wasn't built to handle. None of this is really a clinical problem. Incomplete documentation drives roughly a third of first-pass denials industry-wide, according to AMA data, but for telehealth specifically, the gap usually sits somewhere other than clinical. It's structural: no modality flagged, no confirmation that the code is even valid for the payer receiving it.
Modality coverage as a separate gatekeeping layer with its own parity patchwork
Clear service eligibility, and the next gate is modality, which operates on its own separate rules. A payer can decide a service is medically necessary and still restrict or flatly exclude a specific way of delivering it, audio-only being the modality that runs into this most often, and that restriction carries its own authorization criteria separate from anything applied to video.
The state-by-state picture explains why this feels so unpredictable. According to the CCHP report, the large majority of states have some law addressing private payer telehealth reimbursement, but only a portion of those states, plus Puerto Rico, actually require payment parity. That means in roughly half the states with any telehealth reimbursement law on the books, a payer can cover a service without paying the same rate for it as an in-person visit. Coverage without parity is the default, not the exception. Practically, that turns into a payer in a non-parity state covering audio-only as a benefit on paper while reimbursing it at a rate that makes offering it a losing proposition, or layering on PA criteria that video visits never have to clear.
The stakes are highest for the patients least equipped to absorb them. Rural patients lean on audio-only the most, and they're also the ones most likely to hit a connectivity wall: the FCC reported that tens of millions of Americans still lack access to a quality rural internet option. For that population, audio-only is a lifeline. It's the only way care happens at all, so whatever a payer decides about authorizing it becomes, in effect, a decision about whether that patient gets care.
Behavioral health gets somewhat better federal footing. CMS has confirmed audio-only is permanently allowed for behavioral health, with no requirement to first prove video was infeasible, and behavioral health keeps additional protections, including a patient's right to receive care from home regardless of where they live. None of that guarantees a commercial plan will actually cover it the same way. States are starting to close that distance on their own terms. Colorado's HB 25-1002, effective January 1, 2026, requires insurers to apply nationally accepted criteria for authorization and concurrent review of behavioral health care and bars limiting treatment to short-term symptom relief. It's a real constraint on modality-level gatekeeping, worth watching, but it only reaches as far as Colorado's borders.
Originating site requirements as the third layer under shifting 2026 rules
The third gate asks where the patient physically is during the visit, and it behaves differently depending on the payer, the service, and the modality involved.
Medicare has bought some breathing room here. Under the Consolidated Appropriations Act, 2026, a Medicare patient can receive telehealth from anywhere in the United States, with geographic restrictions lifted through December 31, 2027, and the patient's home now counts as a qualifying originating site. That's real relief, but it has an expiration date attached and doesn't apply evenly across every service type once 2027 ends. Treating it as permanent is a planning mistake.
The billing mechanics show exactly how much originating site still drives the money and the approval. Place of service code 10, patient at home, triggers the non-facility payment rate. Code 02, patient somewhere else, triggers the facility rate. That difference means originating site functions as a reimbursement lever. It's a reimbursement decision baked into the same field.
Tele-mental health has its own timeline running in parallel, and it deserves attention now rather than later. The in-person visit requirement for new behavioral health patients stays paused through December 31, 2027, so a new patient can start treatment entirely by video or phone with no prior in-office visit required, though established patients still need an annual in-person visit. That pause ends January 1, 2028, when in-person visit requirements for tele-mental health kick back in. That's a hard deadline, over a year out, but close enough that practices building patient panels now need to plan around it before it arrives.
FQHCs and rural health clinics run under yet another version of the rules. FQHCs bill non-behavioral telehealth using the specific CPT or HCPCS code for the service once G2025 sunsets on October 1, 2026, and the patient's home stays a qualifying originating site through the extension period, while behavioral visits get paid under the all-inclusive rate or the prospective payment system, an entirely different authorization and billing track than standard Medicare uses.
None of this reaches commercial or Medicaid managed care. Originating site rules for those plans sit completely outside the Medicare extension, so any provider working across payer types needs a separate originating site logic for each one. There's no single national standard to fall back on here, only a set of parallel rulebooks that happen to overlap in places.
CMS-0057-F changes to telehealth PA workflows in 2026
CMS-0057-F took effect in January 2026, and it's a real intervention, but it changes how fast and how clearly payers have to respond. It does nothing to collapse the three-dimension structure underneath. The rule makes each layer more visible and puts a clock on it. It does not make any of the three layers go away.
The timeline changes are the most immediately felt. Standard PA requests now have to be decided within 7 calendar days, down from 14, and expedited or urgent requests move from a matter of days to a matter of hours. Denials also have to say something specific now: a payer can no longer reject a request with a generic "does not meet medical necessity" and call it done. The denial has to state the actual clinical reason. That single change finally gives provider teams something concrete to correct, resubmit against, or appeal, whichever of the three dimensions actually caused the denial.
Payers also now have to publish annual PA performance data, approval rates, denial rates, average decision times, with the first reports due March 31, 2026. That's the first real chance to benchmark how payers actually behave, rather than relying on anecdote. And starting January 1, 2027, payers covered by the rule have to support FHIR-based APIs for electronic PA submission, including Coverage Requirements Discovery, Documentation Templates and Rules, and Prior Authorization Support. That's the beginning of machine-to-machine PA rails that could let a system check requirements in real time at the point an order is placed, rather than after submission.
Two gaps undercut how much relief this rule actually delivers to telehealth specifically. CMS-0057-F does not currently touch drug prior authorizations at all, which is a serious hole given how much telehealth volume runs through medication management, OUD treatment and psychiatric prescribing chief among it. And separately, the DEA's allowance for prescribing controlled substances by telehealth expires December 31, 2026 unless a permanent rule replaces it. Providers doing medication management by telehealth are staring down a prescribing cliff that nothing in this PA reform addresses.
The rule's reach also has a hard edge. It applies to Medicare Advantage, Medicaid, CHIP, and ACA exchange plans, not to self-funded employer plans, which make up the majority of commercial coverage in a lot of markets. Texas's gold-carding law shows the same pattern at the state level: it covers only state-regulated commercial plans, roughly a fifth of the state's insured population, and doesn't touch Medicaid, CHIP, or self-funded plans. There's a bill in motion that could extend similar standards further into Medicare Advantage, the Improving Seniors' Timely Access to Care Act of 2025, S.1816 and H.R.3514, bipartisan and still moving, but it's legislation, not law, and worth tracking rather than counting on.
The scaled deployment of AI-assisted PA tools and evaluation criteria for providers adopting them
AI-assisted PA tools have moved well past pilot stage into real production use, but a tool's actual value comes down to one question: does it address all three approval dimensions, or does it just speed up submission on the service eligibility layer while leaving modality and site checks to chance.
Cohere Health said, in an interview, that it processes millions of PA requests annually, with AI issuing a real-time approval in a large majority of cases and clinical staff signing off on the rest; the company says no request is ever denied by AI alone. Those numbers come from the company itself and haven't been independently verified. Optum rolled out its own AI-powered digital PA tool in February 2026, describing it as automation meant to cut delays and widen access, and named Allina Health, the nonprofit system that owns and runs several hospitals around Minneapolis, as one of the first health systems to adopt it.
Scale alone doesn't prove the underlying problem is solved, though. Research published in Health Affairs Scholar found that electronic prior authorization by itself hasn't delivered the reduction in provider burden or form-completion cost that everyone expected. The reason tracks directly back to the three-dimension framework: ePA speeds up the act of submitting a request, but it doesn't touch the underlying logic problem of checking service, modality, and site together. A faster form is still the wrong form if nobody built in the modality or site check.
FQHCs face a version of this that's sharper than most. A center working across several managed Medicaid MCOs, often four to eight distinct plans in a single service area, needs a tool that checks PA requirements against the specific plan a patient is enrolled in, in real time, at the point of order. A tool that just standardizes submission into one portal doesn't solve that. It just makes the wrong answer arrive faster.
The FHIR API mandate landing January 1, 2027 changes the calculus here, because once payers actually support Coverage Requirements Discovery and Prior Authorization Support APIs, a tool that queries those APIs at the moment an order is entered can surface modality and site requirements before anything gets submitted. That's the mechanism that could finally close the documentation gap responsible for so many first-pass denials.
Providers evaluating these tools should be asking a specific set of questions before signing anything, not accepting a vendor's general pitch about efficiency:
- Does the tool check all three dimensions, service eligibility, modality coverage, and originating site, or does it only check service eligibility?
- Does it plug directly into the EHR and payer portal combination already in use, or does it require re-keying data by hand?
- Can it handle Medicaid MCO fragmentation, or is it really built for commercial and Medicare Advantage payers only?
- Does it surface denial reasons in a form clinical staff can act on, matching what CMS-0057-F now requires payers to disclose?
- For practices with multilingual patient panels, FQHCs especially, does the post-authorization outreach include multilingual communication, since an approved PA that never turns into a completed appointment is still a gap in care?
Building a telehealth PA workflow that holds across all three approval dimensions
None of this points toward a checklist. It points toward a workflow architecture, and the architecture has to be built around the three-dimension structure from day one, not layered on top of an existing service-eligibility process after the fact. Retrofitting modality and site checks onto a workflow that was only ever designed to answer the medical necessity question just reproduces the same fragmentation at a smaller scale, one denial category at a time.
That means the intake step has to ask three questions before a request ever leaves the building: is the service covered, is the modality covered for that service under that specific plan, and does the originating site meet that payer's rule for that service category. Skipping any one of them at intake doesn't save time. It just moves the failure downstream, to a denial that looks like a documentation problem but is actually a design problem.
The regulatory environment gives practices a real opening to build this correctly, not just faster. CMS-0057-F's denial specificity requirement means a workflow can now route a rejection straight to whichever dimension caused it, rather than treating every denial as a generic clinical appeal. The FHIR API mandate arriving in 2027 gives that same workflow a machine-readable way to check modality and site requirements before submission instead of after a rejection comes back. Neither one replaces the underlying architecture. Both make it possible to build one that actually holds.
Sources
- Telehealth Billing Updates Clinics Must Know in 2026
- What Is the CMS 2026 Prior Authorization Rule & How Will It Affect Providers? | Elion
- How 2026 E/M and Telehealth Rules are Changing | Medwave
- Prior Authorization in 2026: IRA, CMS Reform & AI Automation
- Prior Authorization Automation for FQHCs: 2026 Practical Guide | Linear Health
- Telehealth policy updates | Telehealth.HHS.gov
- Latest Trends in Insurance Prior Authorization in Telehealth


