January 24, 2025
Telehealth providers at a crossroads: Navigating insurance, compliance and cash-only models amid state regulations

Telehealth providers at a crossroads: Navigating insurance, compliance and cash-only models amid state regulations

This audio is auto-generated. Please let us know if you have feedback.

Editor’s note: Paul Schmeltzer is a member of commercial law firm Clark Hill and counsels clients on healthcare issues like telehealth and regulatory matters.

As patient care via telehealth continues to grow, providers face critical decisions on whether to align with insurance plans, and therefore meet the stringent requirements under HIPAA, or to operate on a cash-only basis and navigate complex state-by-state data privacy laws.

Each choice comes with distinct advantages and challenges that shape the operations and sustainability of telehealth practices. 

Telehealth providers who opt to align with insurance plans can tap into a wider patient base, thereby potentially increasing their patient volume. Accepting insurance also ensures a steady flow of reimbursements which can be a crucial lifeline for the financial stability of a telehealth practice. 

However, accepting insurance means that the provider must adhere to the requirements under HIPAA’s Privacy and Security Rules that mandate, among other things, robust standards for safeguarding patient information, necessitating substantial investments in secure communication platforms, advanced data encryption and compliance measures, including risk analyses and comprehensive staff training.

Although HIPAA’s obligations can be onerous, it’s a law that has been refined over nearly 30 years, and its established requirements make it easier for telehealth providers to achieve compliance. Non-compliance with HIPAA can result in the HHS’ Office for Civil Rights issuing severe penalties, including hefty fines and corrective action plans. 

Conversely, some telehealth providers prefer to avoid the rigorous requirements under HIPAA and instead choose to adopt a cash-only model. This option offers greater operational flexibility as providers can set their own rates, potentially leading to higher earnings per telehealth encounter. The cash-only model also provides a simplified billing process that can mitigate administrative costs by cutting the complexities associated with insurance claims.

But the cash-only model also presents significant challenges. It may limit access for some patients, particularly those who depend on insurance to afford healthcare services.

And until federal privacy legislation — such as the recently proposed American Privacy Rights Act of 2024 — is passed to establish a federal standard for data privacy and security regulation, telehealth providers adopting the cash-only model will need to navigate a complex labyrinth of state-by-state data privacy regulations. This is in addition to the challenge of understanding how each state enforces their unique rules regarding licensure, reimbursement rates and telehealth practice standards. 

Over the past few years, there has been a proliferation of state comprehensive data privacy laws that were created in part to fill gaps in federal privacy laws.

However, most have full or partial exemptions for businesses and data regulated by HIPAA or certain other federal laws that protect the confidentiality of personal data, like the Gramm–Leach–Bliley Act. This is clearly an advantage for telehealth providers who have already achieved compliance with HIPAA. 

Several states have enacted health data privacy laws or amended their existing privacy laws to protect consumer health data that is not covered by HIPAA. These state health data privacy laws create new compliance obligations for telehealth providers and grant consumers new rights regarding their health data.

While Washington and Nevada do not have comprehensive consumer privacy laws, they have enacted new health data privacy laws which include many of the same privacy-related rights and obligations created by the comprehensive consumer laws in other states.

Leave a Reply

Your email address will not be published. Required fields are marked *