Home / Blog / Industry Guides
Industry Guides

Telemedicine Payment Processing and HIPAA: What Telehealth Providers Need to Know

7 min read·Karma Card Payments·Published ·Updated
Telemedicine Payment Processing and HIPAA: What Telehealth Providers Need to Know

You run a telehealth practice, and your processor just asked questions you weren't expecting, or stopped answering yours. Maybe you added a weight-management program, moved to monthly memberships, or simply started growing fast. Here's how payments, HIPAA, and underwriting fit together, so you can get back to caring for patients.

Why telehealth payments feel harder than they should

Patients pay online for a consult, a prescription, or a monthly program, and they never set foot in an office. To a card processor, that adds up to card-not-present sales of regulated healthcare, often billed on a recurring schedule. Each piece adds scrutiny on its own.

None of that means your practice is doing anything wrong. It means generic processors weren't built to tell a licensed telehealth provider apart from a questionable online pharmacy, so their algorithms often treat both the same way. That's why payment processing set up specifically for telehealth starts with understanding how your care model actually works.

When HIPAA applies to payment processing, and when it doesn't

This is usually the first question telehealth founders ask, and the answer is more reassuring than most expect.

Section 1179 of the Social Security Act, added by HIPAA, sets aside a specific category of activity. When an entity is authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments for a financial institution, HIPAA's rules don't apply to it with respect to those activities. The exemption covers payments for health care made by card, check, account, or electronic funds transfer.

In plain terms, a card processor that only moves the payment is generally not your business associate, and you don't need a business associate agreement just to run a patient's card.

HIPAA doesn't follow the payment. It follows the patient's health information, so the real work is keeping that information out of places a payment never needed it.

Where a BAA does come in

The exemption covers payment activities, not everything a vendor might do for you. Legal commentary on Section 1179 points out that a financial institution can become a business associate when it performs functions beyond payment processing on a provider's behalf, such as managing accounts receivable.

The same logic applies across your tech stack. If a billing platform, patient portal, or gateway add-on stores visit notes, diagnoses, or treatment details next to payment data, that vendor is handling protected health information and likely needs a BAA. Ask every vendor directly what data they store and whether they'll sign one.

It also helps to separate two compliance jobs that often get blurred. PCI DSS governs how cardholder data is protected. HIPAA governs patient health information. A telehealth practice usually deals with both, but for different data in different systems. Keeping card data inside the payment gateway and clinical data inside your health record system makes each job far easier to manage and to explain to an auditor.

Our overview of HIPAA-conscious payment setups goes deeper on structuring this for a practice.

Keep PHI out of descriptors, receipts, and invoices

The most common privacy slip in telehealth payments isn't a breach. It's a billing descriptor or receipt that says more than it needs to.

Discreet descriptors also cut chargebacks. A patient who doesn't recognize a charge often disputes it, and one who recognizes it but feels exposed by the wording may dispute it too. Neutral, recognizable wording with a customer-service phone number solves both problems.

Why underwriters label telehealth high-risk

Telehealth isn't high-risk because medicine is risky. It's high-risk because a few patterns common in the category produce chargebacks, regulatory exposure, or both. Knowing which ones apply to you lets you answer them before an underwriter asks.

Compounded GLP-1 medications

FDA declared the tirzepatide shortage resolved in December 2024 and the semaglutide injection shortage resolved in February 2025, which narrowed the room for large-scale compounding of those drugs. FDA then sent waves of warning letters to telehealth companies about compounded GLP-1 marketing, including roughly 80 warning letters in September 2025 and further rounds in 2026.

The letters targeted claims that implied FDA approval, called compounded products "generic" versions of approved drugs, or suggested they were the same as brand-name medications. Acquiring banks read those letters too. If you offer compounded medications, expect detailed questions about your pharmacy partners, your marketing language, and your prescribing workflow.

Prescriptions and pharmacy

Card networks place pharmacies in their highest-scrutiny tier. Visa's Integrity Risk Program lists pharmacy merchant category codes in Tier 1, which brings extra obligations for any acquirer that boards them. Telehealth models that dispense or ship medication often get underwritten through that lens, and some acquirers expect third-party healthcare certification before approval.

Subscriptions and memberships

Monthly programs support continuity of care, and they're hard on dispute ratios. Patients forget, lose portal access, or stop a medication without cancelling. The FTC's click-to-cancel rule was vacated by the Eighth Circuit in July 2025, but the agency restarted that rulemaking in early 2026 and keeps enforcing the Restore Online Shoppers' Confidence Act against hard-to-cancel subscriptions. Make cancellation simple and confirmations clear.

For recurring billing specifically, our guide to reducing chargebacks on subscriptions covers reminders, retries, and cancellation flows.

Controlled substances and the DEA telemedicine flexibilities

If your practice prescribes controlled substances through telemedicine, your processor will ask how. The DEA and HHS extended the pandemic-era telemedicine flexibilities, which allow prescribing Schedule II through V medications without a prior in-person evaluation, through December 31, 2026. It was the fourth temporary extension.

Two final rules also took effect on December 31, 2025. One creates a permanent telemedicine pathway for prescribing buprenorphine to treat opioid use disorder. The other covers certain VA practitioners treating veterans. For other controlled substances, what happens after 2026 is still unsettled, so plan around the rules currently in effect and watch closely for DEA announcements this fall.

Prescribing rules also vary by state, and some states set their own requirements for establishing a patient relationship through telehealth. Your clinicians' licensing map and your prescribing protocols are worth having on paper before an underwriter asks.

Underwriters will want to know whether controlled substances are part of your model and how you'd adapt if the flexibilities lapse. This is general information, not legal advice.

Tell your processor before you add a new service line

Many telehealth freezes trace back to one moment: the practice added a new program, such as weight management, hormone therapy, or a new prescription category, without telling its processor. From the bank's side, an account approved for routine virtual consults suddenly started charging for something nobody reviewed.

Send a short note before launch. Describe the service, pricing, billing frequency, pharmacy partner if there is one, and expected volume. It's a five-minute email that can spare you months of held funds.

The same applies to big pricing changes. Moving from single visits to higher-priced monthly programs changes your average ticket, and average ticket is one of the first numbers a risk team watches.

What helps a telehealth application get approved, and stay approved

  1. Licensed clinicians in every state where you treat patients, with documentation you can share.
  2. Named pharmacy partners and their licensing, especially for compounded products.
  3. Marketing that avoids cure claims, approval implications for compounded drugs, and guaranteed results.
  4. Clear subscription terms, a simple cancellation path, and reminder emails before each renewal.
  5. Neutral billing descriptors with a reachable support number.
  6. A refund policy that reflects clinical reality, such as refunds for consults that never took place.

Pair that with PCI compliance support and a habit of answering patient billing questions quickly, and you give an acquirer every reason to keep your account open. Most telehealth chargebacks start as a confused patient who couldn't reach anyone.

A note on patient trust

Patients choosing telehealth are often trusting you with something sensitive, whether that's weight, mental health, sexual health, or a chronic condition. A billing experience that feels careless can undo the trust your clinicians built in the visit itself.

A few practical touches go a long way:

Clear pricing before the appointment, discreet statements, and fast answers when something looks wrong all protect that relationship. They also happen to be exactly what keeps a merchant account healthy.

Find a payment partner who understands care, not only transactions

You built a telehealth practice to make care easier to reach. Your payments should support that, not interrupt it. We work with providers to build telemedicine payment processing that fits clinical workflows, with patient privacy considered from the first conversation.

When you're ready to talk through your model, start a conversation with Karma Card Payments.

Frequently asked questions

Does my credit card processor need to sign a BAA?

Usually not. Section 1179 of the Social Security Act exempts entities from HIPAA when they are only authorizing, processing, settling, or collecting payments for health care. A business associate agreement becomes relevant when a vendor stores or handles protected health information beyond the payment, such as visit notes or diagnoses in a billing platform. This is general information, not legal advice.

What should a telehealth billing descriptor say?

Use your practice's name and a reachable customer-service number, and leave out conditions, medications, or treatment types. Statements are often seen by family members or employers, so neutral wording protects patient privacy. Recognizable, discreet descriptors also reduce chargebacks from patients who don't remember a charge or feel uncomfortable with how it appears.

Why is telehealth considered high-risk by payment processors?

Telehealth combines card-not-present payments, regulated healthcare, and often recurring billing. Prescriptions and pharmacy activity fall into Visa's highest-scrutiny tier, compounded GLP-1 marketing has drawn waves of FDA warning letters, and subscriptions raise dispute ratios. None of that disqualifies a practice, but it means underwriters ask detailed questions before approving.

Are the DEA telemedicine prescribing flexibilities still in effect in 2026?

Yes. The DEA and HHS extended the telemedicine flexibilities for prescribing Schedule II through V controlled substances without a prior in-person visit through December 31, 2026. Separate final rules for buprenorphine treatment and certain VA practitioners took effect December 31, 2025. Watch for DEA updates on what follows the current extension.

Ready to get approved?

Most high-risk merchants are approved in 24–48 hours. No application fee, no long-term contract.