California CMIA Requirements for a Telehealth Startup: A Practical Compliance Guide
Building a telehealth startup in California means aligning your operations with the Confidentiality of Medical Information Act (CMIA) while also satisfying the federal Health Insurance Portability and Accountability Act (HIPAA). This guide translates those obligations into practical steps across licensure, structure, consent, privacy and security, vendor management, and revenue cycle so you can launch and scale with confidence.
What follows is a founder-friendly, operations-focused roadmap. You will see how CMIA intersects with HIPAA for electronic protected health information (ePHI), how to structure your entity around the Corporate Practice of Medicine doctrine, and how to operationalize patient consent documentation, Business Associate Agreements, and billing rules for synchronous telehealth and other modalities.
Defining Telehealth Services in California
Core modalities you should plan for
- Synchronous telehealth: real-time audio-video visits that mirror in-person care.
- Audio-only visits: telephone encounters when clinically appropriate and allowed by payer policy.
- Asynchronous store-and-forward: secure exchange of clinical data (e.g., images, questionnaires) reviewed later.
- Remote patient monitoring: ongoing collection and review of physiologic or behavioral data.
- Provider-to-provider e-consults: interprofessional advice without the patient present.
Clinical standards and documentation
- Maintain the same standard of care as in-person services; use protocols that identify when to escalate to in-person evaluation.
- Document the modality (audio-video, audio-only, asynchronous), patient location at the time of service, and any technology limitations that affect care.
- Verify and record patient identity, emergency contact/location, and consent before starting each encounter.
Operational design choices
- Define triage criteria and scheduling rules by modality to ensure clinical appropriateness.
- Map data flows for each modality so CMIA/HIPAA controls cover every touchpoint where ePHI is created, stored, or transmitted.
Ensuring Provider Licensure Compliance
Where the patient sits controls licensure
If a patient is physically in California at the time of service, the rendering clinician generally must hold an active California license (physician, nurse practitioner, physician assistant, behavioral health, or other allied professional, as applicable). Build this into scheduling logic and geolocation checks.
Cross-border and scope-of-practice considerations
- Do not rely on out-of-state licensure to treat California patients. Use credentialing workflows that reject bookings when licensure does not match patient location.
- Apply California supervision/collaboration rules for your discipline mix (e.g., NPs, PAs, behavioral health). Your clinical governance policy should spell out who may do what by modality.
- Align prescribing workflows with federal and state telehealth prescribing rules, especially for controlled substances; hard-stop orders that are not permitted via telehealth.
Credentialing, privileging, and payer enrollment
- Implement primary-source verification for licenses, DEA registrations (if applicable), education, and board certifications.
- Build templates for payer enrollment that reflect telehealth locations and modalities to avoid claim denials later.
Navigating the Corporate Practice of Medicine Doctrine
Use a PC–MSO structure to separate clinical from business
California’s Corporate Practice of Medicine doctrine restricts lay entities from practicing medicine or controlling clinical judgment. A common startup approach is a physician-owned professional corporation (PC) that employs or contracts with clinicians, paired with a management services organization (MSO) that your startup operates to provide non-clinical services (technology, staffing, revenue cycle, marketing, facilities, analytics).
Preserve clinical independence
- Reserve to the PC: hiring/firing and supervision of clinicians, clinical policies and standards, setting/approving clinical compensation methods, and quality management.
- MSO services must be administrative only, with fair market value fees not tied to the volume or value of referrals; avoid fee-splitting and improper control provisions.
- Document decision rights in the MSO agreement and create a compliance playbook that operationalizes those boundaries.
Obtaining and Documenting Patient Consent
Content to disclose for telehealth consent
- What telehealth is, how it works, and any modality-specific limitations or risks.
- Alternatives (including in-person care) and the right to withdraw consent at any time without affecting future care or benefits.
- Privacy and security expectations under the CMIA and HIPAA, including potential residual risks from technology use.
- Financial disclosures: possible costs, coverage, and any site or technology fees.
Acceptable methods and recordkeeping
- Written or electronic consent (e-sign), portal click-through with demonstrable attribution, or verbal consent documented in the medical record.
- Time/date, modality, and the staff member capturing consent should be logged. Use a standardized “Patient Consent Documentation” template in your EHR.
- Re-consent when there is a material change in modality, risks, or program terms.
Special populations and language access
- For minors or those with legal representatives, obtain consent from the authorized decision-maker consistent with California law.
- Provide language assistance and accessible formats; document interpreter use and materials provided.
Implementing Privacy and Data Security Measures
CMIA and HIPAA apply together—design for the stricter rule
The CMIA protects “medical information” held by providers, health plans, and certain contractors and businesses; HIPAA protects PHI, including ePHI, held by covered entities and business associates. Many telehealth startups fall under both. Build policies that meet HIPAA’s floor and CMIA’s California-specific protections.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Security program essentials for ePHI
- Security risk analysis and risk management plan covering your full data inventory (applications, devices, integrations, vendors).
- Encryption in transit and at rest, strong authentication (including MFA), device management (MDM), patching, and secure configuration baselines.
- Role-based access control, least-privilege provisioning, periodic access reviews, and audit logging for administrative and clinical actions.
- Data minimization and retention schedules; secure deletion and media sanitization when data is no longer needed.
- Secure-by-design telehealth workflows: no unsecured SMS for clinical content, vetted video platforms, and documented no-recording policies unless clinically necessary.
Breach preparedness and response
- Incident response plan with defined severity tiers, forensics, containment, and notification workflows that satisfy both HIPAA and CMIA timelines.
- Workforce training, phishing simulations, and sanctions policy; annual reviews and tabletop exercises.
Managing Business Associate Agreements
Who needs a Business Associate Agreement (BAA)?
Any vendor that creates, receives, maintains, or transmits PHI for you is a business associate under HIPAA and must sign a BAA. Typical examples include your EHR, cloud hosting, teleconferencing/video platforms, messaging, e-fax, claims clearinghouses, analytics, and certain support vendors. Under the CMIA, many of these vendors also act as “contractors,” so your agreements should address both regimes.
What to build into each BAA
- Permitted uses/disclosures, minimum necessary standards, and prohibition on unauthorized secondary uses (e.g., marketing or data sales).
- Administrative, physical, and technical safeguards; subcontractor flow-down obligations; right to receive breach reports promptly.
- Return or secure destruction of PHI at contract end; cooperation with audits and investigations; indemnification and cyber insurance expectations.
Vendor due diligence and oversight
- Risk-rate vendors; collect evidence such as SOC 2 Type II or HITRUST, penetration tests, and security questionnaires.
- Maintain a vendor inventory with BAA status, data elements accessed, and renewal/termination dates; conduct periodic reassessments.
Understanding Billing and Coding Requirements
Build a payer policy matrix
Coverage and documentation rules vary across Medicare, Medi-Cal, and commercial plans. Maintain a living matrix of allowable codes by modality, place of service, required modifiers, and medical necessity notes, and update it as payer bulletins change.
Documentation that supports payment
- Chief complaint, history/exam or time and medical decision-making, and clinical rationale for using telehealth.
- Patient location at the time of service, modality used, identity verification, and that telehealth consent was obtained.
- For asynchronous services and remote patient monitoring, include device data, review time, and care management actions.
Codes, places of service, and modifiers to know
- Use standard E/M and procedure codes when clinically and payer-appropriate; many payers accept the same CPT/HCPCS codes used in-person.
- Place of service: POS 10 (telehealth provided in the patient’s home) or POS 02 (telehealth provided other than the patient’s home), as required by the payer.
- Modifiers: 95 (synchronous, real-time audio-video); 93 or HCPCS FQ (audio-only, where applicable); GT (interactive audio-video) or GQ (asynchronous) if specifically required by a payer. Always confirm payer-specific combinations.
Claims hygiene and denial prevention
- Pre-claim validation that the code, POS, and modifier trio matches payer policy and patient benefit design.
- Clear internal guidance for when to use telephone E/M, e-visits, interprofessional consults, and remote monitoring codes.
- Concurrent audits on a sample of telehealth charts to confirm that documentation supports coding and that consent is on file.
Conclusion
Operational excellence in California telehealth rests on seven pillars: clear modality definitions, rock-solid licensure controls, a compliant PC–MSO structure, robust patient consent practices, CMIA/HIPAA-grade privacy and security, airtight BAAs, and disciplined billing. Treat each pillar as a living program with owners, metrics, and audits, and you will stay compliant as regulations and payer rules evolve.
FAQs
What specific CMIA requirements apply to telehealth startups in California?
Under the CMIA, you must safeguard “medical information,” restrict access to authorized personnel, and prevent unauthorized use or disclosure. Implement policies for minimum necessary use, workforce training, role-based access, audit logs, and secure transmission/storage of ePHI. Establish contractor agreements that bind vendors to CMIA-level confidentiality and security, maintain breach response procedures and timely notifications, and prohibit data sales or marketing uses without valid authorization. When CMIA and HIPAA both apply, design your program to meet the stricter rule.
How must patient consent be obtained and documented for telehealth services?
You may obtain consent in writing, electronically, or verbally, but it must be documented in the medical record before providing telehealth services. Record what was explained (nature of telehealth, risks, alternatives, privacy and cost), how consent was captured (e-signature, portal attestation, or staff-witnessed verbal consent), and the date/time. Re-consent when material program terms or modalities change, and follow California rules for minors and language access needs.
What are the compliance obligations regarding Business Associate Agreements?
Execute a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on your behalf. Your BAA should define permitted uses/disclosures, require administrative/technical safeguards, obligate subcontractors to the same protections, mandate prompt breach reporting, and address PHI return or destruction at term end. Because many vendors are also “contractors” under the CMIA, incorporate California-specific confidentiality and security clauses and perform ongoing vendor risk management.
How do billing modifiers apply to telehealth service claims?
Modifiers signal how a service was delivered. Common patterns include 95 for synchronous audio-video telehealth, 93 or HCPCS FQ for audio-only (when the payer allows it), and GT or GQ only when a payer specifically requires them. Pair the correct modifier with the appropriate place of service—typically POS 10 (patient’s home) or POS 02 (other location)—and ensure your documentation supports the selected modality. Always confirm requirements in each payer’s most current telehealth policy.
Table of Contents
- Defining Telehealth Services in California
- Ensuring Provider Licensure Compliance
- Navigating the Corporate Practice of Medicine Doctrine
- Obtaining and Documenting Patient Consent
- Implementing Privacy and Data Security Measures
- Managing Business Associate Agreements
- Understanding Billing and Coding Requirements
- FAQs
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.