The last two weeks of December delivered two federal actions that will shape the first quarter for every practice we work with. Neither is what the industry hoped for, and both are manageable if the practice knows what they say.

On December 21, 2024, the President signed the American Relief Act, 2025, the continuing resolution that funds the government through March 14, 2025. It extends the Medicare telehealth flexibilities that were due to expire on December 31, but only through March 31, 2025. On December 27, the HHS Office for Civil Rights announced a notice of proposed rulemaking to update the HIPAA Security Rule, the first substantial revision since 2013. Here is what each does, who it affects, and what to do in January.

Key takeaways

  • Medicare telehealth flexibilities now run through March 31, 2025. January and February visits proceed as in 2024; the cliff moved to April 1, and the next funding deadline of March 14 is when Congress will look at it again.
  • The physician payment relief that was in the December 17 draft was dropped. The 2.83% conversion factor cut takes effect January 1.
  • The HIPAA Security Rule proposal would make every implementation specification required, mandate MFA and encryption, and set a 72-hour restoration target. It is a proposal with a 60-day comment period; nothing is required today.
  • Most of what the proposal asks for is what a competent IT provider already recommends; a practice that starts in January will have less to do whatever the final rule says.

Telehealth: three months, not two years

The bipartisan funding draft released on December 17 would have extended the telehealth flexibilities for two years and included a partial offset to the 2025 physician payment cut. That draft collapsed within 48 hours. The bill that passed the House on December 20 and the Senate in the early hours of December 21, and was signed the same day, kept a three-month telehealth extension and dropped the physician payment relief entirely. The 2.83% conversion factor reduction takes effect on January 1 as finalized in the CY2025 Physician Fee Schedule final rule.

What is extended through March 31, 2025:

  • Removal of the geographic restriction and the patient's home as an eligible originating site, so Medicare patients anywhere can receive telehealth at home.
  • The expanded list of eligible distant site practitioners, including physical therapists, occupational therapists, speech-language pathologists and audiologists.
  • Federally qualified health centers and rural health clinics as distant sites.
  • The delay of the in-person visit requirement for mental health telehealth.
  • Audio-only telehealth where permitted.
  • The Acute Hospital Care at Home program.

What this means operationally is that January and February telehealth visits for Medicare patients at home can proceed as they did in 2024, and that the same cliff now sits at April 1. The funding deadline of March 14 is the next moment Congress must act on something, and telehealth will be in that conversation. We think practices should plan for a further extension as the likely outcome and prepare for the alternative anyway, because a plan that depends on Congress meeting a deadline is not a plan.

Running Medicare telehealth in the first quarter

The coding does not change. Medicare telehealth visits continue to use the office visit codes 99202 to 99215 with place of service 02 (patient not at home) or 10 (patient at home), and modifier 93 for audio-only where required. Medicare is not paying the new CPT telemedicine codes 98000 to 98015; 98016 replaces G2012 for the virtual check-in. Commercial payers that adopted the 98000 series have their own rules, and a payer grid is the way to keep them straight.

ScenarioMedicare coding through March 31If flexibilities lapse April 1
Established patient, video, at home, non-rural99212 to 99215, POS 10, modifier 95 where the MAC requires itNot a covered telehealth service; convert to in-person
Established patient, audio-only, at home99212 to 99215, POS 10, modifier 93; patient unable or unwilling to use video documentedNot covered except limited mental health scenarios
Mental health, video, at home, establishedCovered; in-person requirement delayedCovered only if the in-person visit requirement is met
Brief patient-initiated check-in, 5 to 10 minutes98016 (replaces G2012)Still covered; communication technology-based services are not telehealth under the statute
Physical therapy via videoCovered through March 31 as a distant site practitionerNot covered

The right-hand column is the conversion list. Build it now by tagging every Medicare patient with a recurring telehealth visit in the scheduling system, so that if April 1 arrives without an extension, the front desk has a list rather than a search. Check each Medicare Advantage plan's telehealth policy separately; MA plans may cover telehealth as a supplemental benefit regardless of the statutory rules, and many do. And confirm state law and licensure for any patient located in another state during the visit, because the federal extension changes nothing there.

The HIPAA Security Rule proposal

OCR's proposal, announced December 27 and scheduled for Federal Register publication in early January with a 60-day comment period, would rewrite much of the Security Rule. It is a proposal. Nothing is required today, the current rule remains in force, and a new administration arrives on January 20 with its own view of pending rules. But the content tells a practice where regulators believe the floor should be, and most of it is what a competent IT provider would recommend anyway.

The provisions that matter most for an independent practice or a billing company, as we read the announcement and fact sheet:

Proposed requirementWhat it would mean for a small practice
All implementation specifications become required; the "addressable" category is removedNo more documenting why a control was not reasonable; the control is expected
Encryption of ePHI at rest and in transit, with limited exceptionsEncrypted laptops, phones, backups and email; a documented exception for legacy systems
Multi-factor authenticationMFA on the EHR, practice management system, email and remote access
Technology asset inventory and network map, reviewed annuallyA written list of every device and system touching ePHI and how data moves between them
Vulnerability scanning at least every six months and penetration testing annuallyTwo scans a year and one test, usually through the IT vendor
Restore critical systems and data within 72 hoursTested backups and a written restoration plan with a time target
Annual compliance auditA yearly review of every Security Rule requirement, documented
Business associates verify their safeguards in writing annuallyPractices collect an annual written verification from each vendor; vendors produce one
Business associates notify covered entities within 24 hours of activating a contingency planA named contact and a notification clause in the BAA

OCR cited the scale of recent breaches, including the Change Healthcare incident that reached about 100 million notifications this fall, as the reason the rule needs updating. We agree with the direction and we expect the final version, if there is one, to differ in the details and the timeline. Comments are due 60 days after publication, and practice associations will file them; a practice that wants to be heard on the cost of penetration testing for a three-physician office should send its comment through its specialty society.

What the proposal would actually take in a small practice

We have walked several practices through the table above against what they have today, and the pattern is consistent. MFA and encryption are usually partly done: on the EHR because the vendor forced it, not on email or the remote access tool. The asset inventory does not exist, but it takes an afternoon with a spreadsheet and a walk around the building. Backups exist and have never been restore-tested. The risk analysis is two to four years old. Vulnerability scanning and penetration testing are the items with a real cost, and the ones where the IT vendor's quote matters. Nothing on the list is exotic, and the practices that treated the February clearinghouse outage as a warning have done most of it already.

What we think

The telehealth extension is too short and the physician payment relief should have stayed in the bill; a three-month horizon makes planning harder for practices and patients without saving anyone money. The Security Rule proposal is overdue. A practice that is HIPAA compliant under the 2013 rule and running without MFA is compliant on paper and exposed in practice, and the proposal says so plainly. Neither action changes what a well-run practice should do in January: keep the telehealth workflow, keep the patient list, switch on the controls, and document the work.

Questions we hear

If the flexibilities lapse on April 1, what happens to a telehealth visit already scheduled for April 3?

For a Medicare patient at home outside a rural area, it would not be a covered telehealth service under the pre-2020 rules, with exceptions for mental health services that meet the in-person requirement and a few others. The visit would need to be in person or rescheduled. That is why the tagged list matters, and why the conversion should be planned for the week of March 17, after the funding deadline, not the week of March 31.

Do we need to comply with the proposed Security Rule now?

No. Proposed rules have no compliance date. If finalized, the proposal contemplates compliance within 180 days after the final rule's effective date, which would be well into 2025 at the earliest and could be much later. Treat the controls as good practice, not as a deadline.

Does this change our compliance wording?

No. A practice or vendor describes itself as HIPAA compliant against the rule in force. There is no government HIPAA certification, and any vendor claiming one should be asked what they mean. Revelrex operates as HIPAA compliant and SOC 2 compliant, and our HIPAA training course is being updated to cover the proposal as it moves. Practices that want the January telehealth and eligibility work handled can read about the billing service, and any practice can book a call to talk through the first-quarter plan.

What to do this month

  1. Keep the Medicare telehealth workflow exactly as it was in 2024: office visit codes, place of service 02 or 10, modifier 93 for audio-only, 98016 in place of G2012.
  2. Tag every Medicare patient with a recurring telehealth visit in the scheduling system and name the person who owns the April conversion if it is needed.
  3. Check each Medicare Advantage plan's telehealth policy and record it on the payer grid.
  4. Put March 14 and March 31 on the practice calendar with owners.
  5. Turn on MFA everywhere it is available and not yet on, starting with email and remote access.
  6. Confirm full-disk encryption on every laptop and phone that touches patient data, and that backups are encrypted and have been restore-tested this year.
  7. Write the asset inventory; a spreadsheet is fine, and it should include the systems vendors run for you.
  8. Update the security risk analysis if it is older than a year, and ask each business associate in writing whether they support MFA and encryption today and how they would meet a 72-hour restoration target.