Scheduling Software for Multi-State Telehealth Practices
Real-time license verification at booking prevents the compliance gap that grows with scale.

Multi-state telehealth practice has grown alongside the broader market expansion, and scheduling software is where compliance with that reality either gets caught or gets ignored. FAIR Health's inaugural Quarterly Telehealth Regional Tracker found that 18.4% of commercially insured patients filed at least one telehealth claim in Q1 2026, up from 17.3% the quarter before. Behavioral health drives most of that volume: 52.1% of patients with a telehealth claim in Q1 2026 got a mental health diagnosis, and Grand View Research puts psychiatry at 12.7% market share in 2025, the largest single segment. The global telehealth market was valued at $77.4 billion in 2025 and is headed toward $187.5 billion by 2033, an 11.5% compound annual growth rate. At that scale, treating multi-state compliance as a side concern in a scheduling tool isn't a small oversight, it's a mistake with a paper trail, and most vendors are still building as if it isn't a problem worth solving.
The licensure rule that determines whether a scheduled appointment is legal
The rule is simple to state and easy to break by accident: a provider has to be licensed in the state where the patient is physically sitting during the session, not where the practice is based and not where the patient's home address happens to be on file.
Picture a patient who normally lives in one state but is spending a week in another for a family visit. She logs into her regular therapy session from a hotel room in the state she's visiting. Her provider is licensed in her home state only. Unless that provider also holds a license in the state she's currently in, or qualifies under some narrow exception, the session may not be legally covered. Nothing about the clinical content of the visit changed. What changed was where her phone happened to be standing, and that's a scheduling fact, not a clinical one. A calendar tool that only tracks home addresses will never catch it.
There's no such thing as a national telehealth license. Every appointment requires answering the same three-part question: where is the patient right now, what licensing pathway does that state allow for this provider's profession, and has that pathway actually been confirmed for today, not last month.
Interstate compacts help, but they don't close the gap, and treating them as a fix is the first mistake most practices make. Various compacts expand portability for different types of healthcare and mental health professionals, but participation is uneven and shifts constantly. As of early 2025, only four states had fully enacted the APRN Compact and were active in it, which tells you how far compact coverage still has to go even for a single profession.
Some of the largest patient populations sit in states that make this hardest. California has historically stayed outside the IMLC, the NLC, and PSYPACT, meaning a provider treating a California-located patient generally needs a California license, full stop. New York has similarly limited compact participation and typically requires its own license too. Massachusetts has partial compact participation requiring verification, so scheduling staff need to verify by profession rather than assume coverage. Hawaii has compact legislation pending but nothing enacted, so a Hawaii license is typically still required. Washington became a full NLC member in January 2024, though other professions practicing there still need separate verification.
Controlled substances add another layer. Holding a valid license in a state doesn't automatically clear a provider to prescribe controlled substances to a patient located there. That requires separate DEA authority and compliance with the Ryan Haight Act, and a scheduling system that treats "licensed" as the same thing as "cleared to prescribe" is building in a blind spot.
HIPAA sets a floor, not a ceiling. Some states layer additional privacy rules on top of federal law, and any scheduling system expanding into those states has to account for the difference instead of assuming HIPAA compliance covers everything by default.
The scheduling system is the first place a non-compliant booking can be stopped before it happens. It's also, in most practices today, the exact place where it slips through, because nobody ever asked the software to check.
How credentialing fragmentation turns a licensing gap into a scheduling failure
The information needed to catch a licensing gap already exists somewhere inside most practices. It's just scattered. HR holds one piece, compliance holds another, the credentialing team holds a third, and scheduling staff work off whatever was last handed to them, often by email or a shared spreadsheet nobody actually owns.
As a practice grows from two states to a dozen, the gap between "this provider is licensed" and "this provider is confirmed licensed for this specific patient in this specific state today" widens fast. Verisys has described how a small administrative oversight in credentialing tracking can escalate into a real operational disruption, or a compliance violation, once an organization's scale outpaces its manual tracking systems.
That's why monthly or automated license monitoring has become close to standard practice for organizations operating across many states. Rivon Health has noted that credentialing for telehealth across many states becomes difficult to manage in-house, because keeping it accurate at that scale stops being realistic with spreadsheets and calendar reminders.
Scheduling sits downstream of all this, and blaming the scheduling tool alone misses where the actual break happens. If the platform can't read live licensure status, it has no way to enforce the rule described above. It just fills open slots on a calendar and hopes the humans caught the problem earlier in the process. That's the real failure mode: not a missing feature so much as a missing connection, the scheduling layer and the credentialing data never talking to each other in real time.
A scheduling platform without a live link to credentialing data is always working from information that's already stale by the time a patient books. That's the architectural gap driving compliance exposure in multi-state telehealth, and it's rarely visible until an audit or a complaint forces someone to go looking for it.
The right question to ask when evaluating a platform is how well it handles the underlying complexity that time zones represent. It's whether the system knows, at the moment of booking, which providers are cleared to see which patients in which states, today, not last quarter.
The feature checklist multi-state telehealth practices should use to evaluate scheduling platforms
A handful of features separate a scheduling tool that merely fills a calendar from one built to hold up under multi-state scrutiny.
HIPAA compliance with a signed data protection agreement comes first, and it isn't negotiable. Some vendors bundle the BAA into the base plan; others sell it as an add-on or restrict it to higher tiers. Confirm which one applies, and check that the BAA actually covers every data flow, booking, reminders, video, and intake forms, not just the video call itself.
Licensure-aware scheduling logic is the feature most platforms skip entirely, and it's the single biggest tell of whether a vendor understands this market or is just guessing. Can the system flag or block a booking when a provider isn't licensed in the patient's current state? Can staff pull up a provider's full state coverage map before confirming a slot, rather than finding out about the gap after the appointment is already sitting on the calendar?
Per-visit location documentation matters just as much as the booking itself. The system needs to record where the patient was physically located at the time of the session, not just the home address stored in their profile, because that's the record an auditor will ask for.
Multi-timezone handling sounds basic, but it has to work correctly on both sides of the appointment, provider time zone and patient time zone, reflected accurately in every confirmation and reminder sent out.
Patient self-scheduling with location capture is where a lot of practices unknowingly recreate the exact gap described above. Research cited by Koalendar puts patient preference for online booking at 67%, and that preference isn't going away. But self-scheduling that doesn't ask the patient where they'll physically be during the visit reopens the same compliance hole a licensing check was supposed to close.
EHR integration and appointment write-back need to happen without a staff member re-typing anything into a second system. Integration with the major platforms, Epic, athenahealth, NextGen, eClinicalWorks, is the baseline expectation, not a premium feature.
Automated reminders cut no-shows, and the money at stake is real: Koalendar has noted that a 12% no-show rate can cost a lab close to $90,000 a year. Reminders are table stakes at this point, but in a multi-state context they should also reconfirm where the patient will be joining from, not just when.
Audit trail and compliance reporting round out the list. A multi-state practice needs to produce, on demand, an exportable record showing who saw whom, from where, under which license, on which date. Without that, an audit turns into a scramble through old calendar entries and email threads.
Pricing that scales sensibly with provider count deserves real scrutiny too. A full multi-provider, multi-location EHR suite can run into the hundreds of dollars per provider per month. A focused scheduling tool with compliance features built in often costs a fraction of that and fits more easily alongside whatever EHR the practice already runs.
Last, BAA coverage across the entire vendor stack is baseline infrastructure, not an optional extra. Every vendor touching protected health information, video, EHR, scheduling, billing, third-party data processors, needs a signed BAA on file. Missing even one is a gap, no matter how good the rest of the stack looks.
How the leading scheduling platforms perform against these criteria
No platform on the market today fully automates multi-state licensure enforcement end to end. That's worth saying plainly before going through the list, because it changes how each one should be judged: not as a finished compliance solution, but as a piece of infrastructure that still needs pairing with credentialing data and, in most cases, human review.
Cal.com offers HIPAA-compliant scheduling with a BAA included at no extra charge on its Organizations plan (15 or more users) and its Enterprise plan. It covers the core telehealth scheduling loop: patient self-scheduling, EHR integration, automated reminders, and built-in video. Within Health switched to Cal.com after finding its previous scheduling tool wasn't HIPAA-compliant, and Plume moved off the scheduling layer built into its Healow EMR, cutting annual scheduling costs from roughly $60,000 to $25,000. What Cal.com doesn't do natively is check a provider's licensure state against a patient's location; that logic has to be layered on through EHR integration or a separate credentialing system. It fits practices that want compliant scheduling without buying an entire clinical suite.
SimplePractice bundles scheduling, billing, documentation, and HIPAA-compliant video into one system, with automated reminders, intake forms, and a secure client portal. It's built specifically for mental health and behavioral health providers, which lines up directly with the fact that 52.1% of Q1 2026 telehealth claims involved a mental health diagnosis. Scheduling and core workflows can go live the same day, and pricing runs higher than a lightweight scheduler if booking is all a practice actually needs. Multi-state licensure enforcement isn't native here either; it needs outside credentialing support. Solo and small-group therapists running hybrid practices are the clearest fit.
Tebra, built from the former Kareo and PatientPop, offers a modern self-scheduling front end tied directly to the EHR calendar, along with integrated intake and multi-location support. It holds a 4.1 out of 5 rating on G2, and a demo is available though there's no public free trial. Multi-state licensure logic isn't a documented feature; compliance tracking here leans on EHR data plus whatever credentialing system runs alongside it. It suits independent, multi-location practices that want an EHR-native scheduling layer with a strong patient-facing front end.
Athenahealth runs as an all-in-one platform with automation, analytics, and telehealth built in, priced on a percentage-of-collections model. Its athenaOne product holds a 3.4 out of 5 on G2, with demos only and no public free trial as of August 2025. Go-live can take around 11 weeks, a real problem for any practice trying to expand into new states quickly. It's built for large health systems that want one EHR suite to run everything, less so for practices that just want a standalone scheduling layer.
NextGen delivers strong multi-location scheduling, billing integration, and a patient portal, with solid scalability and compliance reporting. NextGen Practice Management holds a 4.6 out of 5 on G2, with pricing available on request. It fits medium to large multi-location practices that need deep EHR interoperability and serious compliance reporting, though the learning curve is steeper and the interface can overwhelm smaller teams.
PracticeQ, from IntakeQ, combines online booking, intake forms, payments, and EHR/PM-embedded scheduling in one system. It handles family appointments, time-zone conversion, card-on-file payments, and multi-provider, multi-location calendars, with a Scheduling Helper feature that surfaces the next available openings automatically. Pricing runs on a flat per-provider subscription, which gives growing practices a predictable cost structure. It's a good fit for outpatient specialty and behavioral health clinics that want a fast rollout on top of an existing EHR.
Solutionreach leans into patient communication: two-way texting, automated reminders, and telehealth support, integrated with EHR and CRM platforms. It holds a 4.3 out of 5 on G2, with quote-based pricing, plus custom Enterprise packages. It's a communications tool first, not a compliance tool, so multi-state licensure logic still needs a separate system layered in. Practices that care most about patient outreach and engagement, on top of a scheduling system they already trust, get the most out of it.
Prosper AI automates booking, rescheduling, cancellations, and call routing through AI voice, handling after-hours volume without needing staff on the line. It also reaches into payer-side calls like prior authorization and benefits verification, one of the few tools on this list that goes beyond patient-facing scheduling entirely. Pricing is quoted on a usage or collections basis. It fits multi-location specialty groups and health systems where phone volume and call abandonment are the main headache, best paired with an EHR-native or compliance-aware scheduling layer for the multi-state piece.
DrChrono offers a mobile-first EHR and scheduling system with strong iPad and iPhone apps, tying EHR, billing, telehealth, and payments together in one place. It holds a 3.5 out of 5 on G2, the lowest among the platforms named here, with quote-based pricing across its Prometheus, Hippocrates, Apollo, and Apollo Plus tiers, and a 30-day free trial available. Multi-state compliance features aren't documented as native capabilities. It's built for practices that want to manage care on the go through a single mobile ecosystem.
UKG, formerly Kronos, handles workforce and staff scheduling at scale: shift optimization, credential tracking, time and attendance, audit trails, and labor compliance. Pricing is enterprise-level and quote-based. This isn't a patient booking tool, it's a staff scheduling tool, and it matters here for internal provider scheduling and credential tracking rather than anything patient-facing. Hospital groups managing complex shift rotations and credential compliance at scale are the intended audience.
Patients join via a browser-based link with no download required; the platform is HIPAA and GDPR compliant. It's video-first, not scheduling-first, so it needs pairing with a separate scheduling tool to get any real booking automation. Any clinic offering virtual visits that wants a simple, low-friction video experience fits well here.
IntakeQ focuses on customizable intake and booking forms, consent documents, e-signatures, and workflows built around a specific practice's needs, with several compliance-adjacent features included. It works best as a complement to a scheduling platform rather than a replacement for one, suited to clinics that need tailored intake processes while keeping compliance intact.
Across all of them, the pattern holds: strong scheduling, strong video, strong communication, but licensure enforcement by state still depends on pairing the platform with a live, well-maintained credentialing system. None of them treats it as a first-class problem to solve on its own, and that's the gap worth naming plainly rather than papering over with a features list. The closest fit for any given practice is the platform built around the assumption, from day one, that where the patient is sitting matters just as much as when the appointment starts. Right now that assumption still lives mostly outside the scheduling software, in a separate credentialing system someone has to remember to check.


