A telehealth visit that lacks a documented patient consent record carries more than a technical billing gap. When a payor audit or a Unified Program Integrity Contractor (UPIC) review reaches a telehealth claim, a missing consent entry in the medical record is one of the fastest paths to a recoupment demand, because it undermines the auditor's ability to confirm the encounter happened the way the claim describes. Telehealth providers who treat consent as a one-time intake formality, rather than a record tied to the specific visit, are building an audit exposure into every claim they submit.

State Consent Requirements Vary by Jurisdiction

There is no single national telehealth consent rule. The majority of states impose some telehealth-specific informed consent requirement in statute, administrative code, or Medicaid policy, and the specifics differ from state to state, according to the Center for Connected Health Policy's state consent tracker. Colorado requires a signed written statement before a patient's first telemedicine treatment, and Idaho requires a periodic special informed consent addressing the security of the technology and the risk of data loss. California and Maine, by contrast, accept verbal consent, provided the encounter note documents that the conversation happened. A telehealth provider licensed in multiple states does not get to choose the easiest standard; the applicable rule is the one in the state where the patient is located at the time of the visit.

What Medicare Requires for Consent Documentation

Medicare's consent requirement is narrower than most state telehealth statutes. A standard telehealth evaluation and management visit carries no separate Medicare consent mandate. Communication technology-based services, virtual check-ins billed under HCPCS G2010 and G2012, remote physiologic monitoring, and chronic care management, require patient consent, and CMS permits that consent to be verbal as long as the practitioner documents it in the medical record. One documented consent can cover a full year of those services, but the documentation still has to be present for the period being billed rather than assumed from an earlier encounter.

How Missing Consent Documentation Surfaces in Audits

Telehealth is one of the claim categories UPIC and other program integrity contractors have prioritized since the pandemic-era expansion of telehealth billing. A 2023 Office of Inspector General report examined Medicare psychotherapy payments, including telehealth sessions, made from March 2020 through February 2021, and found an estimated $580 million in improper payments across the sample, $348 million of it tied to telehealth encounters, driven largely by documentation that did not meet Medicare's requirements. When a consent entry is missing, auditors treat it as one more element the documentation failed to establish, and a finding on a small claim sample is routinely extrapolated across the full lookback period into a far larger recoupment demand.

The exposure escalates when investigators conclude that the missing documentation reflects the underlying service, not just the paperwork. DOJ's telehealth fraud enforcement actions have charged healthcare fraud counts against platforms and marketers that billed for visits patients never meaningfully consented to or received, often paired with Anti-Kickback Statute counts tied to per-lead payments to marketing networks. Civil recovery for the same conduct typically proceeds under the False Claims Act. A single missing consent entry will not create that exposure by itself, but a pattern of encounters without documented consent is the pattern these actions target.

Building a Defensible Consent Record

A defensible consent record documents the specific encounter. Each note should capture the date, the communication method (video or audio-only, since several states and CMS treat the two differently), the patient's agreement to proceed, and confirmation that the patient understood telehealth's limits and could request an in-person visit instead. Practices that route intake through a third-party telehealth platform should not assume the platform's intake workflow satisfies the standard that governs the billing provider; platform contracts frequently place that burden on the clinician regardless of what the platform's own consent screen collects. Providers prescribing controlled substances via telehealth face an added layer of state-specific requirements on top of the general consent standard.

A consent form signed once at intake does not document the specific visit an auditor is reviewing. The record has to show consent for that encounter and that technology, not for the relationship in general.

Why Early Legal Counsel Is Critical

It is critical that telehealth providers promptly retain experienced healthcare defense counsel upon receiving a payor audit notice, a UPIC document request, or any other government inquiry touching telehealth billing. Early legal intervention can protect the provider's rights, ensure documentation gaps are addressed before a response is submitted, avoid inadvertent admissions, and allow counsel to communicate with investigators or auditors on the provider's behalf. Delaying legal representation can significantly affect the outcome of a matter.

How Health Law Alliance Can Help

Health Law Alliance has overseen 2,000+ audits and represented 2,500+ clients across telehealth and healthcare-audit matters nationwide. If your practice is facing a telehealth audit that turns on consent documentation, contact our telehealth law and telemedicine attorneys for a free, confidential consultation before the next deadline runs.