Skip to content

How to Start a Telehealth Company: Licensing, HIPAA & Compliance in 2026

How to Start a Telehealth Company: Licensing, HIPAA & Compliance in 2026

Telehealth is no longer a pandemic-era workaround — it’s a permanent, fast-growing segment of American healthcare. But the legal foundation underneath a telehealth business is more complicated than most founders expect. Licensing, HIPAA, controlled-substance prescribing, and payer reimbursement rules all vary by state, and getting any one of them wrong can shut down your business before it scales.

This guide breaks down what a telehealth company — whether a solo physician expanding into virtual care or a venture-backed digital health startup — needs to have in place in 2026. If you’re structuring the business itself, our healthcare business transactions page covers entity structure and ownership considerations that pair with the compliance issues below.

1. Provider Licensing: The Foundation You Can’t Skip

The single biggest misconception about telehealth is that a provider only needs to be licensed where they sit. In reality, a telehealth visit is legally considered to occur where the patient is physically located at the time of the appointment. That means a provider treating patients in 10 states generally needs to be licensed — or otherwise authorized to practice — in all 10.

Licensure compacts help, but they aren’t a national license. The Interstate Medical Licensure Compact (IMLC) is the most relevant pathway for physicians, and it has grown quickly: as of early 2026 it includes over 40 member states plus Washington, D.C. and Guam, and issued thousands of new licenses in a single recent month alone. The Compact lets a physician with a full, unrestricted license in their “State of Principal License” apply for expedited licenses in other member states rather than starting each state’s application from scratch.

A few things founders consistently get wrong about the IMLC:

  • It’s not automatic. Physicians still need a Letter of Qualification from their home state, and each state license issued through the Compact must be separately obtained and maintained.
  • Membership changes. States can join — or, in rare cases, exit or restrict participation — so a compliance matrix built once and never revisited becomes stale fast.
  • Non-physician providers have separate compacts. Nurses, PAs, psychologists, physical therapists, and several other license types each have their own interstate compact, with different member states and different rules. If your platform uses NPs, PAs, or therapists, you need to track their compacts independently of your physicians’. (If you’re structuring provider agreements across multiple states, see our guide on physician employment contracts.)

Some states also offer telehealth-specific registrations rather than full licensure — Florida, for example, allows a limited registration for out-of-state physicians to treat Florida residents remotely, which is narrower in scope than a full license but faster and less expensive to obtain.

Practical takeaway: Before you expand into a new state, confirm (1) whether your provider type has a compact covering that state, (2) whether the state has a telehealth-specific registration option, and (3) what the fallback full-licensure timeline looks like if neither applies.

Quick Reference: Licensing Pathways at a Glance

PathwayBest ForTypical TimelineKey Limitation
Interstate compact (e.g., IMLC)Providers treating patients in multiple member states regularlyWeeks, once qualifiedOnly covers member states; separate license still required per state
Full state licensureSolo/short-term expansion into one new stateWeeks to monthsSlowest option; required wherever no compact or registration applies
Telehealth-specific registrationProviders who need limited, faster authorization (e.g., Florida’s out-of-state registration)Faster and cheaper than full licensureNarrower scope of practice than a full license
Locum/temporary permitsShort-term coverage needsVaries by stateNot a long-term compliance solution

2. HIPAA Compliance for a Virtual-First Business

HIPAA doesn’t bend for telehealth — if anything, remote care creates more places for a breach to happen: video platforms, scheduling tools, patient portals, chat features, and payment processors all touch protected health information.

A compliant telehealth company needs, at minimum:

  • A HIPAA-compliant video and communications platform, backed by a signed Business Associate Agreement (BAA) with every vendor that touches patient data.
  • Encrypted intake, scheduling, and payment systems — not just the video call itself. A common (and costly) mistake is compliant video paired with a non-compliant intake form or SMS reminder tool.
  • Documented patient-location verification at the start of every visit. Since practice location follows the patient, your platform should log and retain where the patient was located when care was delivered — this is both a licensing safeguard and a HIPAA documentation issue.
  • State-specific informed consent for telehealth. A number of states require a separate telehealth consent form, distinct from general treatment consent.
  • Breach response and OCR investigation protocols in place before you need them. If a breach or complaint does occur, having outside counsel and a response plan ready significantly changes the outcome. (See our related guide on HIPAA compliance for healthcare providers.)

3. Controlled Substance Prescribing: The DEA Piece Founders Underestimate

If your telehealth model involves prescribing controlled substances — including behavioral health, addiction treatment, or pain management — the DEA rules are a separate, evolving compliance track from state licensing.

As of early 2026, DEA-registered providers can prescribe certain Schedule III–V medications for opioid use disorder via telemedicine without a prior in-person visit, provided the prescriber checks the state’s prescription drug monitoring program first. However, broader flexibility for remote prescribing of other controlled substances without an in-person evaluation remains a temporary measure, extended repeatedly while the DEA finalizes a permanent framework. Founders building a prescribing-heavy telehealth model should treat this as a moving target requiring ongoing legal monitoring, not a one-time setup task.

4. State-by-State Reimbursement and Payment Parity

Getting licensed and HIPAA-compliant doesn’t guarantee you’ll get paid. Reimbursement rules vary by payer type and by state:

  • Medicare has extended telehealth payment parity for many services, but coverage details and eligible provider types continue to be updated through CMS rulemaking.
  • Medicaid coverage for telehealth varies significantly by state, with each state setting its own scope and reimbursement rate.
  • Private payers are governed by state parity laws. As of mid-2026, most states plus D.C., Puerto Rico, and the Virgin Islands have some form of private payer telehealth law — but “coverage parity” (the same services must be covered) is not the same as “payment parity” (the same rate must be paid), and a number of states require only one or the other.

Building your reimbursement strategy state by state — rather than assuming Medicare’s rules apply everywhere — is essential before you scale to a new market.

5. Building a Compliance System, Not a Checklist

The organizations that do this well in 2026 aren’t the ones who complete a one-time launch checklist. They build ongoing systems:

  • A live compliance matrix tracking every provider’s license status, compact eligibility, and renewal dates by state.
  • Monthly or automated monitoring as you expand past a handful of states — manual tracking breaks down quickly once you’re operating in 10, 20, or 50 states.
  • Legal review before entering each new state, since telehealth-specific statutes, consent requirements, and prescribing rules change independently of federal policy.

Frequently Asked Questions

Do I need a license in every state where my telehealth patients are located? In most cases, yes. Telehealth visits are treated as occurring where the patient is physically located, not where the provider is based. Licensure compacts and state telehealth registrations can speed this up, but they don’t eliminate the requirement.

Is a licensure compact the same as a national telehealth license? No. Compacts streamline the application process for member states, but a provider must still hold a valid license or authorization for each state where they treat patients.

Can I prescribe controlled substances via telehealth without an in-person visit? For certain Schedule III–V medications used in opioid use disorder treatment, yes, under current DEA rules, subject to state PDMP review. Broader controlled-substance prescribing without an in-person exam remains under temporary, evolving DEA flexibilities.

What’s the biggest compliance mistake new telehealth companies make? Treating licensing, HIPAA, and reimbursement as a one-time setup instead of an ongoing system. Compact membership, state telehealth statutes, and DEA prescribing rules all change regularly, and a compliance matrix built at launch will go stale within months.

A note on currency: IMLC membership, DEA prescribing flexibilities, and state payer parity laws change frequently. This article reflects the regulatory landscape as of July 2026 and will be reviewed periodically — always confirm current status with counsel before relying on specific figures for a compliance decision.

Florida Healthcare Law Firm advises telehealth companies, digital health startups, and multi-state physician groups on licensing strategy, HIPAA compliance, and regulatory structuring. If you’re launching or expanding a telehealth business, schedule a consultation to build a compliance plan around your specific footprint.

Schedule a consultation and get the legal guidance you need to expand into new states with confidence.