Skip to main content
Telehealth

Audio-Only Telehealth Is Legit—Your EHR Might Not Be Ready

CMS now pays for audio-only telehealth. But if your EHR treats it like a phone call, you're in for a world of hurt—and a potential HIPAA breach.

For years, telehealth meant video. But that's a costly misconception. Video is just one option, and often the least accessible. In the CY 2025 Physician Fee Schedule final rule, CMS made a quiet but crucial change: it permanently revised the definition of an 'interactive telecommunications system' to include two-way, real-time audio-only communication for any Medicare telehealth service furnished to a beneficiary in their home. The catch? The distant-site practitioner must be technically capable of audio-video, and the patient must not be capable of or must not consent to video. That's a win for access. But it's also a compliance landmine if your health IT stack isn't built for it.

Can audio-only be both legal and clinically sound? Absolutely. But only if you treat it as a data problem, not a phone call. The moment a clinician documents an audio-only visit, that encounter becomes electronic protected health information. The HIPAA Security Rule's technical safeguards (45 CFR 164.312) require access controls, and the Access Control standard specifically includes unique user identification, emergency access procedure, automatic logoff, and encryption and decryption—with encryption listed as an addressable specification. Addressable does not mean optional. It means you have to assess whether it's reasonable and appropriate, and if you skip it, you document why. Most small practices I've seen skip the documentation. That's a risk they don't need to take.

Here's a scenario I've seen far too often: a physician takes an audio-only call on a personal cell phone. No unique user ID. No automatic logoff. No encryption tied to the EHR. That's not a telehealth visit; that's an unsecured disclosure waiting for a breach notification letter. Under the HIPAA Breach Notification Rule, you have 60 calendar days from discovery to notify each affected individual (45 CFR 164.404). And with the 2026 civil monetary penalty adjustment, the maximum penalty per violation is $73,011 for Tiers 1 through 3, and the Tier 4 cap for willful neglect not corrected within 30 days is $2,190,294. A single sloppy audio visit can cost more than the practice earns in a year.

Why audio-only is not a lesser form of care

The clinical argument for audio-only is straightforward: many patients cannot use video. They lack broadband. They lack smartphones. They are elderly, rural, or both. CMS recognized this by requiring that the practitioner be capable of audio-video—so the clinician isn't off the hook—but the patient can decline or be unable. That's a reasonable accommodation, not a loophole.

But the documentation burden shifts. With video, you can observe gait, tremor, skin color, respiratory effort. With audio-only, you must rely on history and patient report. That means your EHR must capture the same discrete data elements you'd capture in person. This is where health informatics matters. The US Core Implementation Guide (v9.0.0, STU 9) defines the minimum constraints on FHIR resources for patient data access, and it's built on FHIR R4. If your telehealth module doesn't map to those profiles, you're creating unstructured notes that won't flow to other systems. That's information blocking, or close to it.

The 21st Century Cures Act made sharing electronic health information the expected norm. Information blocking is a practice that interferes with access, exchange, or use of EHI unless required by law or covered by an exception. The applicability date moved to April 5, 2021, and before October 6, 2022, EHI was limited to USCDI data elements. As of January 1, 2026, USCDI v3 is the baseline data standard required in the ONC Health IT Certification Program. USCDI v3 has 94 data elements in 19 data classes. If your audio-only visit doesn't capture those elements in a codified way, you're not interoperable. You're just talking on the phone.

The interoperability reality check

Most EHRs were built for in-person encounters. Telehealth was bolted on. Audio-only was bolted on last. That's why so many systems store audio-only visits as free-text notes rather than structured FHIR resources. FHIR R4 was published on December 27, 2018, and it was the first release with Normative content. FHIR R5 came in March 2023 with 157 resources. The tooling exists. The problem is implementation.

A concrete example: a 72-year-old Medicare patient in a rural county has congestive heart failure. She has a landline, no smartphone. Her cardiologist bills an audio-only follow-up. The visit is legal under the CY 2025 PFS rule. But the cardiologist's EHR doesn't have a discrete field for 'audio-only' as a modality. The note goes in as a telephone encounter. The patient's primary care physician never sees it in the longitudinal record. Three weeks later, she's admitted with fluid overload. The information existed. It just didn't move. That's the informatics failure—not the audio-only policy.

To fix it, you need three things. First, a modality code in your EHR that distinguishes audio-only from audio-video and in-person. Second, FHIR-based exchange that maps to US Core profiles so the encounter travels. Third, a security wrapper that meets the HIPAA Security Rule's technical safeguards. None of that is exotic. It's just work.

What the rule actually requires—and what it doesn't

The CY 2025 PFS rule does not mandate audio-only. It permits it. That distinction matters. You can still require video for your practice if you want. But if you do, you're limiting access for the patients who need it most. I think that's a mistake. The evidence base for audio-only is strong enough for common chronic disease follow-ups, medication management, and behavioral health. It's weaker for acute presentations where physical exam matters. So use judgment.

The rule also doesn't relieve you of the HIPAA Privacy Rule's minimum necessary standard (45 CFR 164.502(b)). When you disclose PHI during an audio-only visit—say, to a specialist on a consult—you must limit the information to what's needed for that purpose. That's harder on a phone call because there's no screen to share. You have to be deliberate.

And you still need a business associate agreement if you use a third-party telehealth platform. A business associate is anyone who creates, receives, maintains, or transmits PHI on behalf of a covered entity for a regulated function. That includes the vendor hosting your audio bridge. If you're using a consumer app with no BAA, you're out of compliance. Period.

What I'd actually do

If I ran a practice, I'd stop treating audio-only as a temporary COVID accommodation and build it into the permanent workflow. Specifically: I'd configure my EHR to capture a discrete 'audio-only' modality flag on every encounter. I'd require clinicians to document why video wasn't used—patient incapable or patient declined—because that's what the CMS rule hinges on. I'd turn on automatic logoff and unique user identification for any device used for telehealth, and I'd encrypt the audio stream end-to-end. I'd map the encounter data to US Core profiles so it flows to the patient's longitudinal record. And I'd train front desk staff to ask patients about their technology capacity at scheduling, not at visit time.

The alternative—pretending audio-only is second-class care—is worse. It pushes patients back into emergency departments for problems that could be managed with a phone call and a good informatics backbone. The technology is here. The rules allow it. The only missing piece is the discipline to implement it correctly.

Sources

  • Federal Register (CY 2025 Physician Fee Schedule) - https://www.federalregister.gov/documents/2024/12/09/2024-25382
  • eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  • eCFR 45 CFR Part 164 Subpart D (Breach Notification) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
  • ONC / HHS (HTI-1 Final Rule) - https://healthit.gov/regulations/hti-rules/hti-1-final-rule/
  • US Core Implementation Guide - https://hl7.org/fhir/us/core/
  • Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment

Share this article:

Comments (0)

No comments yet. Be the first to comment!