California requires telehealth providers to obtain and document a patient’s verbal or written consent before the first virtual visit, hold an active California license (there is no separate telehealth license), and apply the same standard of care they would in person. Providers billing Medi-Cal must also follow specific billing modifiers and disclose the patient’s right to in-person care. Get these three pieces wrong and everything else, from reimbursement to liability, falls apart.
TL;DR:
- Providers must obtain and document verbal or written consent specifically for telehealth before the first virtual visit, covering modality and patient rights.
- Active California licensure, not a separate telehealth license, suffices, and the standard of care used in in-person visits applies to telehealth.
- Billing Medi-Cal requires correct application of specific modifiers for video, audio-only, or asynchronous services, along with proper enrollment and documentation of the patient’s location.
- Offering audio-only services for new patients is limited and requires patient attestation explaining why video isn’t feasible; all modalities need separate consent.
- Telehealth tools must meet security standards similar to physical records, including signed BAAs, encryption, and secure communication channels to ensure privacy compliance.
Table of Contents
- Understanding California Telehealth Laws: Consent, Licensure, and Standard of Care
- Medi-Cal Telehealth Billing Rules and Compliance Requirements
- Which Telehealth Modalities Are Permitted for California Providers?
- Privacy and Security Rules Under California Telehealth Laws
- Can Out-of-State Providers Treat California Patients via Telehealth?
- Building a Compliance Checklist for California Telehealth Practices
- What California’s Telehealth Rules Look Like From Inside a Practice
- Getting Compliant Telehealth Therapy in California
- Where to Verify California Telehealth Requirements Directly
- Sources
Understanding California Telehealth Laws: Consent, Licensure, and Standard of Care
The statute that anchors nearly every telehealth compliance question in California is Business and Professions Code §2290.5. It defines telehealth broadly as the delivery of health care services through electronic information and communication technologies, and it puts the consent burden squarely on the provider who initiates the telehealth relationship. Before that first virtual encounter, you have to tell the patient they’re receiving care via telehealth, confirm they understand what that means, and document their agreement, either verbally or in writing.
This isn’t a formality you can skip because a patient seems comfortable with video calls. The law treats telehealth consent as distinct from general treatment consent, which is why practices that fold it into intake paperwork need to make sure the required statutory elements (the fact that telehealth is being used, the patient’s right to decline, and their right to in-person care) actually appear in that document rather than being implied.
A common misconception trips up new telehealth providers: California does not issue a “telehealth license.” If you’re already licensed to practice medicine, psychology, marriage and family therapy, or clinical social work in California, that license covers telehealth delivery of those same services. The Medical Board of California frames telehealth as a tool within the scope of an existing license, not a separate practice area, and that framing matters because it means the standard of care doesn’t shift just because the visit happens over a screen. A missed diagnosis or inadequate documentation carries the same liability exposure on telehealth as it would in an exam room.
Group practices catch a break here. Rather than requiring every clinician in a group to individually re-collect telehealth consent, California allows the group to document consent once at the practice level, provided the documentation meets the statutory bar. That reduces paperwork duplication significantly for multi-provider clinics, though each provider still needs to confirm the consent on file actually covers the modality being used.
Speaking of modality: if your practice offers video visits but also uses audio-only calls for some patients, you need separate consent for that audio-only modality. A patient who agreed to video sessions hasn’t automatically agreed to phone-only care, because the clinical risks and limitations differ between the two.
Key statutory obligations under California telehealth laws include:
- Document consent (verbal or written) before the first telehealth encounter, and note the modality it covers.
- Confirm your existing California professional license authorizes the services you’re delivering; no additional telehealth credential is needed.
- Apply identical documentation and diagnostic standards you’d use in an in-person visit.
- Disclose the patient’s right to request in-person care instead of telehealth.
- Obtain modality-specific consent separately if you add audio-only services alongside video.
- For group practices, confirm the practice-level consent record actually names the provider and modality involved.
One statistic worth internalizing: the consent requirement under BPC §2290.5 applies before the initial delivery of service, not before every visit. Once documented, that consent generally covers the ongoing relationship unless the modality changes, according to DHCS guidance. That single detail saves administrative staff from redundant consent collection at every follow-up appointment.
Medi-Cal Telehealth Billing Rules and Compliance Requirements
If you bill Medi-Cal for telehealth services, the statute only gets you halfway there. The operational rules live in the Medi-Cal telehealth policy manual, and getting the modifiers wrong is one of the fastest ways to see a claim denied.
Medi-Cal recognizes three primary telehealth modifiers, each tied to a specific delivery method:
- Modifier 95 applies to interactive audio and video, the standard synchronous video visit most behavioral health providers use.
- Modifier 93 applies to audio-only synchronous services, relevant for phone-based sessions when video isn’t available or appropriate.
- Modifier GQ applies to asynchronous store-and-forward services, where clinical information is transmitted and reviewed at a later time rather than in real time.
Providers also need to know when originating site and transmission fees come into play. Codes like Q3014 and T1014 cover the facility fee for the site where the patient is physically located during a telehealth encounter, but reimbursement eligibility depends on the setting and provider type, so it’s worth confirming current fee schedules before assuming a claim qualifies.
Enrollment matters just as much as coding. To bill Medi-Cal for telehealth, you need active enrollment as a Medi-Cal provider, and if you practice within a group, your group affiliation has to be correctly reflected in the billing record. A therapist who’s individually licensed but billing under a group NPI without proper affiliation documentation risks claim rejection even when the clinical service was appropriate and the modifier was correct.
Here’s how the core requirements break down by category:
DHCS guidance is explicit on one point that trips up administrators: Medi-Cal beneficiaries have to be told telehealth is voluntary and that they can request in-person services instead. If your practice can’t provide in-person care directly, you need a documented process for connecting patients to it within a reasonable timeframe. This isn’t optional paperwork. It’s a coverage condition, and DHCS has signaled it’s phasing in stricter video-option requirements over time, meaning audio-only reliance will face more scrutiny going forward.
Documentation should tie each visit to the modality used, the modifier billed, and, when applicable, the TAR number. Loose or inconsistent charting here is one of the most common reasons behavioral health claims get flagged during Medi-Cal audits.
Which Telehealth Modalities Are Permitted for California Providers?
California telehealth laws don’t treat every delivery method the same way, and knowing where the lines sit protects both your reimbursement and your patients.
-
Synchronous video is the default modality for establishing new patient relationships and delivering ongoing care. It satisfies the “same standard of care” expectation most directly because it lets the clinician observe affect, body language, and environment, which matters enormously in behavioral health assessment.
-
Audio-only services face real limits. Medi-Cal generally restricts audio-only from being used to establish a brand-new patient relationship unless specific exceptions apply, such as sensitive services where video access creates a barrier, or documented technology or connectivity limitations on the patient’s side. Providers need patient attestation on file explaining why audio-only was used instead of video.
-
Store-and-forward transmission, where clinical data or recordings are sent for later review rather than reviewed live, comes with narrower eligibility. Federally Qualified Health Centers and Rural Health Clinics may use store-and-forward to establish care under specific DHCS-defined conditions, but the documentation trail needs to show what was transmitted, when, and how the reviewing clinician acted on it.
-
Remote patient monitoring (RPM) covers devices that transmit physiological data, blood pressure readings or glucose levels, for instance, though its behavioral health applications are narrower than in primary care. Medi-Cal coverage for RPM requires documentation showing the monitoring is clinically appropriate for the diagnosis and that a clinician is actually reviewing the data on a defined schedule, not just collecting it passively.
Pro Tip: Build a one-line modality note into your visit template (“Video, full session,” “Audio-only, patient declined video due to bandwidth”) so your billing team never has to guess which modifier applies after the fact.
For behavioral health specifically, most California practices lean heavily on synchronous video because it best supports risk assessment and the therapeutic alliance, while audio-only tends to serve as a documented exception rather than a default option.

Privacy and Security Rules Under California Telehealth Laws
HIPAA doesn’t disappear because a session happens over video, and neither does California’s Confidentiality of Medical Information Act (CMIA). Both frameworks apply fully to telehealth, which means the platform you use has to meet the same security bar as your physical records room, not a lighter one because it’s “just video.”
In practice, that means:
- Any third-party platform handling protected health information needs a signed Business Associate Agreement (BAA) before you use it clinically.
- Video and messaging traffic should run through end-to-end encryption, not a consumer-grade app that happens to have a video feature.
- Authentication has to confirm both provider and patient identity, and access logging should create an audit trail showing who accessed a record and when.
- Session recordings, if you make them, need explicit patient consent separate from the general telehealth consent, and stored recordings fall under the same retention and security rules as written records.
- Text and messaging communications containing clinical content need to live in a secure, logged system rather than personal SMS or unencrypted email.
E-prescribing through telehealth carries its own layer of federal controls, particularly for controlled substances, so behavioral health providers managing medication alongside therapy need a prescribing workflow that satisfies DEA telehealth prescribing rules on top of the state privacy framework.
Pro Tip: Document your platform’s security compliance once, in a standing office policy, rather than re-verifying it per patient. Something like: “Sessions conducted via [platform name], BAA executed [date], encrypted end-to-end, session data retained per practice HIPAA policy” covers you across your entire caseload.
A practice offering secure telehealth sessions statewide has to treat platform selection as a compliance decision, not just a convenience one. The wrong video tool, however easy it is to use, can undo every other piece of consent and documentation work you’ve done correctly.
Can Out-of-State Providers Treat California Patients via Telehealth?
The general rule is unambiguous: to bill Medi-Cal for telehealth services delivered to a California patient, you need an active California license. Physical location of the provider doesn’t override where the patient is sitting when care is delivered, and California treats the patient’s location as the jurisdiction that governs the encounter.
That rule has narrow exceptions. Federal emergency flexibilities have, at times, loosened cross-state restrictions temporarily, and some interstate licensure compacts create faster pathways to California licensure for certain professions, though California’s participation and the specifics vary by license type and shouldn’t be assumed without checking current status. Employer-sponsored arrangements, where a national telehealth company employs providers across multiple states, still require that the individual clinician treating a California resident hold California licensure for that encounter.
Hospital credentialing under federal telehealth regulations does allow distant-site provider credentials to be accepted by an originating-site hospital under certain conditions, which matters for larger health systems coordinating specialty telehealth consults, but this pathway is distinct from outpatient behavioral health practice and shouldn’t be relied on as a general licensure workaround.
For documentation purposes, note the patient’s physical location at the time of each telehealth encounter, and if you’re treating patients who split time between states, confirm licensure covers wherever they’re located during the actual session. A few practical safeguards:
- Verify and document the patient’s state of physical location before each session, not just at intake.
- Confirm your license status covers the modality and jurisdiction before scheduling any out-of-state patient.
- Treat interstate compact eligibility as license-specific; don’t assume parity across professions.
- Flag any patient who travels frequently for a location check-in at the start of each session.
Building a Compliance Checklist for California Telehealth Practices
Turning statute into daily practice comes down to templates your staff actually uses, not policy binders nobody opens.
Consent scripting should separate video and audio-only clearly. A synchronous video script might read: “Before we begin, I want to confirm you understand this session is being delivered via telehealth video, that you have the right to request in-person services instead, and that your consent will be documented in your record.” If audio-only is used for any session, a distinct line should confirm the patient understands the limitations of a phone-only format compared to video, per the consent language DHCS and county behavioral health plans have modeled.
- Confirm consent documentation exists before the first session and specifies the modality it covers.
- Verify Medi-Cal enrollment and group affiliation are current before submitting any telehealth claim.
- Match the billing modifier to the actual modality delivered, not the modality originally scheduled if it changed.
- Check whether a TAR applies to the service category before treatment, not after the claim bounces.
- Confirm the platform BAA is current and encryption/authentication settings are active.
- Log the patient’s physical location for each session in the clinical note.
- Store consent records in the same system as clinical documentation, tagged by modality, so an audit request doesn’t require reconstruction from memory.
| Checklist Area | What to Verify | Where It Lives |
|---|---|---|
| Consent | Modality-specific, documented before first session | Intake record |
| Licensure | Active CA license, matches service scope | Credentialing file |
| Billing | Correct modifier (95/93/GQ), enrollment current | Billing system |
| Platform security | BAA signed, encryption active, audit logs on | IT/compliance file |
| Patient access rights | In-person option disclosed and documented | Clinical note |
Pro Tip: Run a quarterly self-audit pulling five random telehealth charts and checking each against this table. Most compliance gaps surface in the gap between what a policy says and what’s actually in the chart, and five charts is usually enough to catch a pattern.
Insurers using third-party corporate telehealth vendors also owe patients specific disclosures under Insurance Code §10123.856, including in-network status and continuity-of-care options. If your practice partners with or bills through such a vendor, confirm those disclosures are reaching patients, since the obligation sits with the insurer but affects how your patients understand their coverage.
What California’s Telehealth Rules Look Like From Inside a Practice
Reading the statutes is one thing. Running a caseload of thirty telehealth clients a week under them is another, and the gap between the two is where most compliance headaches actually live.
At Revivehealththerapy, consent isn’t a form clients sign once and forget. It’s built into intake as a specific conversation: which modality they’ll use, what happens if the connection drops, and that they can always ask for an in-person session at our Oakland or Walnut Creek offices instead. That last point matters more than people expect. Clients who know they can come in person often choose to stay virtual anyway, but having the option documented protects everyone.
Billing is where the real friction shows up. Sliding-scale clients paying out of pocket skip the modifier conversation entirely, but insurance and superbill clients need every session coded correctly the first time, because resubmitting a denied claim costs more staff time than getting it right upfront. The lesson after years of statewide telehealth delivery: build your modality notation into the session template itself, not as a separate billing step. It’s the single habit that prevents the most claim denials.
— Amy
Getting Compliant Telehealth Therapy in California
If you’re a patient rather than a provider trying to parse all this, here’s the practical takeaway: Revivehealththerapy offers secure, licensed telehealth therapy across California, built on exactly the consent, privacy, and documentation standards outlined above, so you’re not the one who has to verify compliance before booking a session.
Sessions run on income-based sliding-scale pricing, and the practice accepts insurance along with HSA and FSA funds, so cost doesn’t have to be the barrier that keeps someone out of care. If you’d rather sit across from a therapist in person, in-person sessions remain available at the Oakland location alongside the Walnut Creek office, with telehealth as a flexible option rather than the only one. Therapists like Sasha Levine, LMFT work specifically within this telehealth framework, handling consent and modality questions as part of intake rather than leaving clients to figure it out. If you’re weighing whether telehealth or in-person care fits your situation, or you have questions about how insurance coverage applies to virtual sessions, reach out to start the conversation and get scheduled.
Where to Verify California Telehealth Requirements Directly
For the legal text itself, go to BPC §2290.5, the source for consent and standard-of-care requirements. For Medi-Cal billing specifics, modifiers, TARs, and enrollment rules, the Medi-Cal telehealth policy manual and DHCS Telehealth FAQ are the operative documents. Licensure and standard-of-care questions belong with the Medical Board of California, while insurer disclosure obligations sit in Insurance Code §10123.856. The CCHP California page tracks policy changes across all of these sources in one place, worth bookmarking since telehealth rules shift more often than most other areas of health law.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- California Business and Professions Code §2290.5
- Telehealth Frequently Asked Questions – DHCS
- Medi‑Cal telehealth policy (mednetele.pdf)
- Telehealth | Medical Board of California
- California State Telehealth Laws – CCHP
