Guide

Telehealth Enforcement: What the Takedowns Have in Common

Summary

Telehealth fraud cases target the same handful of patterns: billing for encounters that never happened, signing orders for patients a provider never actually evaluated, kickbacks from marketing companies that pay per order for equipment or lab tests, billing codes that were never payable by telehealth, and volume so high it could not be real. The common thread is a claim disconnected from a genuine, documented, medically necessary encounter. Guard the encounter and you guard yourself.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What telehealth fraud cases actually target

Telehealth enforcement is not random; it clusters around a few recurring patterns, and knowing them is the best defense a solo practice has. Federal fraud cases run on the False Claims Act, which imposes treble damages and per-claim penalties for knowingly submitting false claims — and "knowingly" reaches reckless disregard, not just deliberate intent 1. Almost every telehealth takedown reduces to one idea: a claim not backed by a real, documented, medically necessary encounter.

The patterns repeat across cases:

  • Billing for services never rendered — phantom visits.
  • Signing orders for patients the clinician never actually evaluated.
  • Kickbacks routed through telehealth marketing companies.
  • Billing codes that were never payable as telehealth.
  • Volume so high it could not correspond to real care.

Pattern one: services not rendered

The first and most common pattern is billing for services that were never rendered — phantom visits, or orders signed for patients the clinician never actually evaluated. Marketing operations recruit providers to sign off on equipment or test orders for patients they meet for seconds or not at all; the government treats each resulting claim as a false claim 1.

For a solo practice the lesson is narrow and concrete: if you did not conduct and document the encounter, do not let a claim go out under your number for it. That discipline includes no-shows — a canceled or missed visit is never a billable encounter on a claim form. Bill the patient a missed-visit fee under your policy if you have one, but keep it off the insurance claim entirely, because a claim for a visit that did not happen is a false claim by definition.

Pattern two: billing the wrong code as telehealth

A second pattern is billing a code as telehealth when it was not payable that way. CMS publishes the definitive list of services payable as Medicare telehealth each year, including which are permanent, which are temporary, and which qualify for audio-only delivery 2. Billing a code that is not on the list as though it were telehealth-eligible produces claims that were never payable — a false-claim exposure even without bad intent.

For behavioral health specifically, Medicare's coverage booklet lays out the eligible provider types, the covered codes, and the telehealth rules, including the incident-to constraints 3. Check the code against the current list before the claim goes out. The list changes year to year, and last year's answer is not automatically this year's — a lapsed flexibility that quietly moved a code off the list is exactly the kind of thing that surfaces in an audit.

Pattern three: kickbacks from marketing companies

A third pattern — the one behind the largest dollar figures — is kickbacks routed through telehealth marketing companies. A platform offers to pay a provider per order or per consult for durable medical equipment, genetic tests, or braces; that per-order payment is the classic anti-kickback problem. The anti-kickback safe harbors define which arrangements are protected — bona fide employment, personal services with compensation set in advance, and others, each with required elements 4. A pay-per-referral deal fits none of them.

When you cannot tell whether a telehealth arrangement is a problem, the OIG's published advisory opinions on specific arrangements show how the agency reasons 5. This is also where professional courtesy waivers get misread — a courtesy discount is not automatically a lawful arrangement, and the details decide whether it stays inside the law. The safe test for any platform offer: is it paying fair value for defined work, or a bounty tied to how many orders you generate?

Pattern four: volume that could not be real

A fourth pattern is volume that could not be real — a provider "seeing" hundreds of patients in a day, or signing orders faster than any evaluation could support. Data analytics flag impossible-day patterns first, and once flagged, the False Claims Act's reckless-disregard standard means you cannot defend the claims by saying you never looked at what was billed under your name 1.

A related risk is NPI fraud: someone using your national provider identifier to submit orders you never made, which surfaces as volume you cannot account for. Watch your own remittance data for services you did not perform, and treat unexplained claims as a problem to run down, not ignore. The consequence at the far end is exclusion — the OIG can bar an individual from federal programs, after which no federal payment may be made for their services 6.

What every takedown has in common

What every telehealth takedown has in common is a broken link between the claim and a genuine encounter. The defenses are unglamorous and effective: document the encounter, its medical necessity, and its real duration; keep the billing paper that proves the service happened; and never sign for something you did not personally do.

Two adjacent enforcement magnets deserve the same discipline. UDT billing draws scrutiny because drug-test claims must show medical necessity per test, per patient, per date — the same real-encounter logic applied to a lab order. And any service ordered through a marketing pipeline carries the kickback question on top of the necessity question. For a solo, the strongest single protection is that your records can reconstruct exactly what happened for every claim you submitted.

If a telehealth arrangement or order worries you

If a telehealth arrangement or a past order worries you, there is a path short of waiting for an audit. Read the OIG's advisory opinions for the closest arrangement to yours before you sign anything new 5. If you discover you have already submitted claims that a real encounter does not support — a code that was not payable, orders you should not have signed — the OIG maintains a Self-Disclosure Protocol for conduct that implicates federal fraud laws, a route that mitigates exposure when you come forward 7.

Bring in counsel when:

  • A telehealth platform offers per-order or per-consult pay tied to volume.
  • Your remittance data shows services you cannot account for.
  • You cannot rule out that a fraud statute is in play, not just a coding error.

The telehealth enforcement record is a map of exactly which shortcuts turn into cases. The FCA and the solo practice meet on the same terms as the FCA and any large operator — one knowingly unsupported claim is enough — so use the record to route around the patterns rather than testing them.

Common questions

Letting a claim go out that a real, documented encounter does not support. Whether it's a phantom visit, an order signed for a patient you barely saw, or a code that was never telehealth-payable, the pattern is the same: the claim outruns the care. Keep every claim tied to a documented, medically necessary encounter and you sidestep the most common exposure.

Paying a provider per order or per consult is the classic anti-kickback pattern, and it fits none of the safe harbors. A legitimate arrangement pays fair-market value for defined work, not a bounty per referral. Before signing with any telehealth platform, look closely at how it pays: per-order compensation tied to volume is the warning sign the enforcement cases keep returning to.

Check CMS's list of services payable as Medicare telehealth, which it publishes each year and updates as codes move on and off. The list also flags audio-only eligibility. Billing a code as telehealth when it isn't on the current list produces claims that were never payable — a false-claim exposure even without intent. Verify against this year's list, not last year's.

Stop signing, quantify what happened, and get the facts to counsel. If claims went out that a real encounter doesn't support, the OIG's Self-Disclosure Protocol is the route for conduct implicating fraud laws, and coming forward mitigates exposure. Don't wait for an audit — the reckless-disregard standard means sitting on a known problem makes it worse, not better.

It is the core protection. Enforcement cases target the gap between the claim and the encounter, so a record that reconstructs the real, medically necessary visit — its content, its necessity, its duration — closes that gap. Contemporaneous documentation, retained with the billing record, is what lets you answer an audit with facts instead of memory. It is the cheapest insurance a solo has.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Justice (2026). The False Claims Act. U.S. Department of Justice. linkThat the FCA imposes treble damages and per-claim penalties for knowingly submitting false claims, that 'knowingly' includes reckless disregard, and that relators can sue — the enforcement engine behind telehealth fraud cases.
  2. 2.Centers for Medicare & Medicaid Services (2026). List of Telehealth Services. Centers for Medicare & Medicaid Services (CMS). linkThat CMS publishes the definitive annual list of codes payable as Medicare telehealth, including permanent vs temporary status and audio-only eligibility.
  3. 3.Centers for Medicare & Medicaid Services (2025). Medicare and Mental Health Coverage. CMS Medicare Learning Network (MLN1986542). linkThat Medicare's mental health booklet lists eligible provider types, covered codes, telehealth rules, and incident-to constraints for behavioral health.
  4. 4.Office of the Federal Register (2026). 42 CFR 1001.952 — Exceptions (Anti-Kickback Safe Harbors). eCFR. linkThat the anti-kickback safe harbors protect defined arrangements — employment, personal services with set compensation, and others — each with required elements a pay-per-order deal cannot meet.
  5. 5.HHS Office of Inspector General (2026). Advisory Opinions. HHS Office of Inspector General (OIG). linkThat the OIG issues and publishes advisory opinions on whether specific arrangements implicate the anti-kickback statute.
  6. 6.HHS Office of Inspector General (2026). Exclusions Program. HHS Office of Inspector General (OIG). linkThat the OIG can exclude an individual from federal health programs, after which no federal program payment may be made for their services.
  7. 7.HHS Office of Inspector General (2026). Health Care Fraud Self-Disclosure Protocol. HHS Office of Inspector General (OIG). linkThat the OIG maintains a Self-Disclosure Protocol for conduct implicating federal fraud laws, and that coming forward through it mitigates exposure.

https://www.gale.care/for-providers/fa-telehealth-enforcement-patterns · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)