The Compliance Crucible: Navigating Intensified Enforcement in Telehealth and Digital Health

By Shannon Smith, DNP, APRN, FNP-C, PMHNP-BC, PMHNP-C · 2026-03-06

The regulatory landscape for telehealth and digital health is rapidly maturing, marked by a significant uptick in enforcement actions from federal agencies like the DOJ, DEA, and OIG, alongside stringent state-level oversight. This digest cuts through the noise, revealing critical trends in self-referral, prescribing, and operational compliance that demand immediate attention from healthcare businesses.

The rapid evolution of telehealth and digital health has ushered in an era of unprecedented innovation, expanding access to care and transforming traditional healthcare delivery models. Yet, with this growth comes a commensurate increase in regulatory scrutiny. Recent intelligence from federal agencies and state boards paints a clear picture: the grace period for digital health is over. Regulators are no longer observing; they are actively enforcing, demanding that virtual care models adhere to the same, if not more stringent, compliance standards as their brick-and-mortar counterparts. For telehealth founders, multi-state practice owners, compliance officers, and investors, understanding these shifts is not merely advisable—it is foundational to sustainable growth and risk mitigation.

> For more on this topic, see our analysis: [Navigating the Minefield: CPOM Compliance for Multi-State Telehealth and Medspa Operations in 2025-2026](/blog/cpom-compliance-multi-state-telehealth-medspa).

This digest synthesizes the most critical regulatory trends emerging from recent enforcement actions and guidance, offering a strategic roadmap for navigating the increasingly complex compliance crucible.

> For more on this topic, see our analysis: [Navigating the Minefield: CPOM Compliance for Multi-State Telehealth and Medspa Operations in 2025-2026](/blog/cpom-compliance-multi-state-telehealth-medspa).

Trend 1: Intensified Federal Scrutiny on Financial Relationships and Prescribing Practices

Federal enforcement agencies, particularly the Department of Justice (DOJ) and the Drug Enforcement Administration (DEA), are sharpening their focus on telehealth practices, signaling a zero-tolerance stance for fraud, waste, and abuse. This is not a subtle shift; it's a direct challenge to business models that prioritize rapid scaling over meticulous compliance.

Stark Law and Anti-Kickback Statute in the Digital Age

Recent DOJ actions (Article 1) underscore a heightened scrutiny of Stark Law violations within telehealth physician self-referral arrangements. Historically, Stark enforcement primarily targeted traditional, in-person networks. However, the DOJ is now actively examining financial relationships that could improperly influence referrals for Designated Health Services (DHS) in the digital realm. This includes arrangements where a physician has a financial relationship with an entity providing DHS (e.g., lab testing, imaging, DME) and refers patients to that entity. The intent behind the referral is often less critical than the existence of a prohibited financial relationship and a referral for DHS.

For example, volume-based compensation for telehealth providers who refer to an affiliated lab, or ownership stakes in a diagnostic facility receiving referrals from the practice's employed or contracted physicians, are now squarely in the DOJ's crosshairs. Penalties are severe, including civil monetary penalties, repayment of claims, and exclusion from federal healthcare programs. This applies to telehealth brands, medspas with ancillary services, dental practices referring for imaging, and chiropractic offices leveraging diagnostic services.

Controlled Substances: The DEA's Unwavering Focus

The DEA's enforcement against telehealth companies for controlled substance violations (Articles 5, 11, 15, 16) has reached critical levels. The expiration of COVID-19 Public Health Emergency (PHE) flexibilities on May 11, 2023, largely reinstated the Ryan Haight Act's in-person examination requirement for prescribing Schedule II-V controlled medications. While the DEA has proposed new rules, the current environment demands extreme caution.

Companies relying on asynchronous or minimal interaction models for controlled substance prescribing are at extreme risk. The DEA is actively pursuing 'pill mill' operations disguised as telehealth, scrutinizing everything from identity verification and patient evaluation protocols to prescription monitoring systems. This extends beyond opioids to stimulants and benzodiazepines. For mental health and pain management specialties, and any practice prescribing controlled substances (e.g., medspas for weight loss, dental practices for anxiety), robust compliance programs, comprehensive prescriber training, and clear documentation are non-negotiable. Failure can lead to loss of DEA registration, license sanctions, and criminal charges.

Trend 2: The Intricacies of Multi-State Operations: CPOM, Licensure, and Supervision

Expanding across state lines, a common strategy for telehealth and digital health companies, introduces a labyrinth of state-specific regulations. The notion of a 'national' telehealth practice is a regulatory fiction; rather, it's a collection of state-specific practices, each with its own unique requirements.

Corporate Practice of Medicine (CPOM) and MSO Structures

States like Nebraska (Article 3) maintain a Corporate Practice of Medicine (CPOM) doctrine, generally prohibiting corporations from employing physicians or controlling medical practice. While Nebraska's enforcement might be less explicit than some states, the principle remains: clinical decision-making must reside with licensed professionals. This necessitates carefully structured Management Services Organization (MSO) models, where the professional entity (owned by licensed professionals) delivers clinical services, and the MSO provides administrative support. The key is ensuring the MSO does not exert control over clinical decisions or engage in prohibited fee-splitting.

This is particularly relevant for medspas, where medical procedures must be performed under the supervision and direction of a licensed physician, and the entity providing these services must comply with CPOM. Any telehealth brand building a national provider network must meticulously craft its MSO agreements to avoid CPOM violations in every state of operation.

Physician Licensure, Supervision, and Valid Patient-Provider Relationships

Multi-state medical practice laws (Article 2) dictate that providers must be licensed in every state where their patient is located at the time of service. This is a fundamental principle, especially for services like hormone optimization where prescribing is involved. Robust systems for patient location verification and provider licensure are essential. Beyond licensure, each state defines a 'valid patient-provider relationship' differently, often requiring synchronous audio-visual encounters or specific documentation. For instance, Missouri (Article 8) has specific requirements for establishing this relationship as a prerequisite for prescribing.

For medspas leveraging telehealth for oversight (Article 7), the complexity multiplies. State-specific delegation of authority rules and direct supervision mandates vary significantly. Some states may require direct, on-site supervision for aesthetic procedures, while others permit indirect oversight. Vermont's evolving rules for PAs and NPs (Article 12) highlight this variability: NPs may have full practice authority, while PAs still require collaborative agreements. Medspas must ensure their medical director is licensed in every state where services are rendered and is actively engaged in oversight, often necessitating multiple medical directors or a single medical director with multi-state licensure.

Trend 3: FDA Oversight of Digital Tools and Products

The FDA's regulatory reach extends deeply into the digital health space, impacting everything from diagnostic kits to AI-powered clinical decision support tools and pharmaceutical advertising.

At-Home Diagnostics and AI/ML Software

The FDA maintains strict authority over at-home diagnostic testing kits (Article 4), regulating them as medical devices. Practices utilizing these kits must ensure they are FDA-authorized, properly labeled, and used within their intended scope. Utilizing unauthorized or misbranded kits, even inadvertently, exposes practices to enforcement actions.

Similarly, the FDA is actively refining its approach to AI-powered Clinical Decision Support (CDS) software (Articles 9, 13). The distinction between a regulated 'medical device' and unregulated 'health software' is crucial. If an AI algorithm provides a definitive diagnosis without substantial human clinician review, or dictates a treatment protocol that could cause harm, it is more likely to be considered a regulated medical device. For telehealth platforms, medspas using AI for skin analysis, dental practices for radiographic interpretation, and chiropractors for posture analysis, vendor due diligence and understanding the regulatory status of AI tools are paramount. The emphasis is on AI augmenting, not superseding, licensed practitioner expertise, with liability ultimately resting with the human provider.

Pharmaceutical Advertising and Pharmacy Board Regulations

The FDA has clarified its expectations for direct-to-consumer (DTC) advertising of prescription drugs (Article 6), particularly for telehealth platforms. This guidance emphasizes fair balance, risk disclosure, and substantiation of claims. Telehealth brands promoting prescription medications (e.g., weight-loss, hormone therapy) must ensure their marketing materials prominently display risks alongside benefits, and that all claims are truthful and substantiated. Off-label promotion is strictly prohibited.

Furthermore, state pharmacy boards, such as those in Missouri (Article 14) and Vermont (Article 20), regulate the dispensing, compounding, and fulfillment of medications, including those prescribed via telehealth. This means ensuring that telehealth prescriptions meet all state requirements for a valid prescription and that any partner pharmacies are properly licensed and adhere to state-specific compounding and patient counseling standards. This is critical for medspas and functional medicine practices utilizing compounded medications.

Trend 4: Billing, Coding, and Payer Compliance Under the Microscope

As telehealth becomes mainstream, so too does the scrutiny on its financial mechanisms. Commercial payers and government programs are demanding meticulous adherence to billing and coding rules, with the OIG leading the charge.

OIG Guidance and Program Integrity

The Office of Inspector General (OIG) has reinforced the importance of robust compliance programs for telehealth and digital health companies (Article 10). This guidance highlights key risk areas such as fraud, waste, and abuse, emphasizing the expectation that providers proactively implement measures to ensure billing accuracy, medical necessity, and patient safety in virtual care settings. The OIG's focus on the seven elements of an effective compliance program is not merely suggestive; it is foundational to demonstrating a good faith effort to prevent fraud and abuse. This includes written policies, designated compliance personnel, training, auditing, and enforcement.

Payer-Specific Policies and Parity Laws

Telehealth billing and coding compliance (Article 17) remains a complex area. Commercial payer policies vary significantly by plan and state. Practices must proactively verify patient eligibility, benefits, and specific telehealth coverage policies. Inadequate documentation, upcoding, or unbundling are primary drivers of audit findings and recoupments. Self-pay models, while seemingly simpler, require transparency in pricing and adherence to consumer protection laws.

Moreover, state telehealth parity laws (Article 18) mandate that health plans cover services delivered via telehealth at the same rate and to the same extent as in-person services. However, these laws vary significantly by state regarding payment parity, coverage parity, covered modalities, and eligible providers. For multi-state operators, this necessitates a robust compliance framework that can adapt to a patchwork of regulations, potentially requiring different operational policies and billing strategies for each jurisdiction.

What This Means For Your Practice

The current regulatory environment is a compliance crucible, testing the resilience and integrity of every healthcare business operating in the digital space. The days of 'move fast and break things' are unequivocally over. Instead, a strategic, proactive, and deeply informed approach to compliance is the only path to sustainable growth.

  • Re-evaluate All Financial Relationships: Conduct immediate, thorough legal reviews of all physician compensation models, joint ventures, and referral agreements, particularly those involving DHS. Ensure strict adherence to Stark Law and AKS exceptions.
  • Fortify Controlled Substance Protocols: Assume the strictest interpretation of DEA rules. Implement robust patient identity verification, comprehensive evaluations, and meticulous documentation. If prescribing controlled substances via telehealth, ensure you meet the narrow exceptions to the in-person rule or integrate compliant in-person components.
  • Master Multi-State Nuances: Abandon the 'one-size-fits-all' mentality. Develop state-specific compliance protocols for licensure, CPOM structures (e.g., MSOs), supervision requirements, and valid patient-provider relationships. This includes understanding the specific practice acts for PAs and NPs in each state.
  • Vet Your Digital Tools: Conduct rigorous due diligence on all at-home diagnostic kits and AI-powered CDS software. Understand their FDA regulatory status, intended use, and limitations. Ensure AI augments, rather than replaces, clinical judgment, and that data privacy is paramount.
  • Strengthen Your Compliance Program: The OIG's guidance is a blueprint. Implement all seven elements of an effective compliance program, including regular training, internal audits, and a culture that encourages reporting. This is your first line of defense against enforcement actions.
  • Optimize Billing and Payer Compliance: Stay abreast of evolving commercial payer policies and state telehealth parity laws. Ensure accurate coding, meticulous documentation, and transparent financial practices for both insured and self-pay patients.

The regulatory landscape is not static; it is a dynamic ecosystem requiring continuous monitoring and adaptation. TrueEval remains committed to providing the insights and infrastructure necessary to navigate these complexities, transforming compliance from a burden into a strategic advantage. Your proactive engagement with these critical trends will define your practice's future in the evolving digital health economy.


Further Reading

  • [Navigating the Minefield: CPOM Compliance for Multi-State Telehealth and Medspa Operations in 2025-2026](/blog/cpom-compliance-multi-state-telehealth-medspa)
  • [The Compliance Crucible: Navigating Intensified Enforcement in Telehealth's Next Chapter](/blog/compliance-crucible-intensified-enforcement-telehealth)
  • [Telehealth Tensions: Navigating DEA Scrutiny, CPOM Landmines, and State Board Enforcement in a Post-PHE World](/blog/telehealth-tensions-dea-cpom-state-board-enforcement)
  • [Telehealth's Tightening Grip: DEA, DOJ, and State Boards Signal a New Era of Scrutiny](/blog/telehealth-tightening-grip-dea-doj-state-boards-scrutiny)