See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.
See the 60-second demo →Telehealth was already growing before COVID-19. Then the pandemic arrived and CMS temporarily waived geographic restrictions, originating site requirements, in-person visit prerequisites, and dozens of other guardrails. Utilization exploded. And so did fraud.
The Department of Justice has spent the last two years converting COVID-era telehealth enforcement referrals into criminal indictments, civil settlements, and qui tam payouts. The pipeline is still full. For attorneys handling False Claims Act cases, Medicare fraud, and healthcare whistleblower matters, understanding how telehealth billing fraud works is no longer optional.
This guide covers the eight primary telehealth billing fraud schemes, the documentation patterns that signal fraud, how to evaluate a potential qui tam case, and how AI-assisted billing analysis is changing the discovery landscape.
Before spotting fraud, you need to understand the baseline. Medicare telehealth billing requires:
When any of these elements are fabricated, inflated, or missing, you potentially have a fraud case.
DOJ enforcement actions over the past three years reveal recurring patterns. Here are the eight schemes attorneys encounter most often:
The most basic fraud: billing Medicare for a telehealth visit that never occurred. This is common in durable medical equipment (DME) and prescription telehealth schemes where recruiters cold-call Medicare beneficiaries, obtain their insurance information, and submit claims for telehealth evaluations the patients never actually received.
Legitimate telehealth visits get billed at the highest complexity level (99215) regardless of actual complexity. A five-minute refill check billed as a 99215 high-complexity visit (requiring medically appropriate history and exam with high MDM) is a classic audit trigger. CMS data shows certain providers billing 99215 for 90%+ of their telehealth encounters — a statistical impossibility in legitimate practice.
Among the largest enforcement categories. The scheme: telemarketers recruit beneficiaries, brief telehealth “visits” are conducted (or fabricated), physicians sign orders for unnecessary DME (back braces, knee braces, CGMs) or controlled substances, and massive DME claims are filed. The physician often signs hundreds of orders per day without meaningful review.
Billing place-of-service 11 (office) instead of 02/10 (telehealth) for remote visits. CMS reimburses office visits at a higher rate than telehealth visits. When a provider conducts remote visits but bills them as in-person office visits, the difference is fraudulent overpayment. This is particularly common among providers who transitioned to telehealth during COVID but never updated their billing systems or chose not to.
“Incident-to” billing allows non-physician practitioners (NPPs) to bill under a supervising physician's NPI at the physician's higher reimbursement rate, when specific conditions are met. During telehealth, those supervision requirements are difficult or impossible to satisfy. Billing NPP-provided telehealth visits as physician services under incident-to rules — when the physician was not actually supervising — is a growing enforcement focus.
An emerging 2025–2026 enforcement trend: providers using AI scribing tools to auto-generate clinical notes that don't reflect actual clinical encounters. OIG and CMS have flagged patterns of identical or near-identical notes across large volumes of telehealth visits — a statistical signature that the notes were generated rather than documenting real encounters. If the note says the same thing for 200 different patients, it probably wasn't written by a physician reviewing 200 different patients.
Mental health telehealth expanded dramatically under COVID waivers and permanent policy changes. Fraud patterns include: billing 60-minute sessions (90837) for 20-minute encounters, billing individual therapy when group therapy was provided, credential misrepresentation (billing as PhD when delivered by unlicensed counselors), and fabricated session notes. Mental health records are also harder for opposing parties to audit because of additional confidentiality protections, making fraud easier to sustain.
Chronic Care Management (CCM) codes allow monthly billing for care coordination for patients with two or more chronic conditions. During telehealth expansion, some providers billed CCM codes for every Medicare patient with any chronic condition — without providing the required 20 minutes of non-face-to-face care management services. When stacked on top of telehealth E&M codes for the same month and same patient, this creates substantial fraudulent overpayment.
Not every telehealth billing irregularity supports a qui tam case. Use this framework to evaluate viability:
| Factor | Strong Case Signal | Weak Case Signal |
|---|---|---|
| Materiality | Systematic, high-volume overbilling; scheme specifically designed to exploit Medicare billing rules | Isolated billing errors; provider corrected upon audit notice |
| Knowledge | Provider received compliance warnings, OIG advisory, or prior RAC audit before continuing conduct | Billing office error that provider was unaware of |
| Damages | $500K+ overpayment; trebled = $1.5M+ exposure; sufficient to attract DOJ intervention | Under $250K total exposure after trebling |
| Original Source | Whistleblower has direct, independent knowledge not available from public sources | Whistleblower only knows what was in public OIG reports or news |
Before investing in a telehealth fraud case, verify the case is not already pending. The FCA’s first-to-file bar prevents a second relator from filing a complaint based on the same underlying fraud as a pending qui tam action. Search PACER for sealed qui tam filings (you won't see them, but DOJ may decline to intervene if the scheme is already in litigation). The public disclosure bar can also knock out cases where the fraud was substantially similar to what appeared in government audits, OIG work plans, news reports, or congressional hearings.
The medical record and billing file tell very different stories. You need both.
A telehealth fraud case involving a high-volume practice can generate tens of thousands of claims and hundreds of thousands of pages of billing records and clinical documentation. Human review at this scale is prohibitively expensive and slow. AI changes this equation.
AI billing analysis tools can flag statistical anomalies across an entire claims history in minutes: the provider billing 99215 for 94% of visits, the 15 patients in a single afternoon all receiving identical CGM orders, the clinical notes with cosine similarity above 0.97 suggesting template generation rather than individual documentation.
Cross-referencing billed service dates against EHR login timestamps, video platform logs, and provider location data is tedious for humans but straightforward for AI. Phantom visits leave gaps: no EHR login, no video session, no phone record. AI can surface these gaps across thousands of claims in seconds.
AI can identify impossible code combinations (billing both an E&M and a TCM code for the same date when the rules prohibit it), inappropriate modifier use, and diagnosis codes that don't clinically support the billed complexity level — all high-value fraud signals that human reviewers miss under time pressure.
Upload billing files, CMS claims data, or clinical records. MedLegal AI identifies upcoding patterns, phantom billing gaps, and CPT anomalies — the same analysis that takes human consultants weeks, done in minutes.
Try MedLegal AI Free →Understanding current DOJ priorities helps you identify which telehealth fraud schemes are most likely to attract intervention:
The FCA statute of limitations is 6 years from the date of the violation, or 3 years from when the government knew or should have known (whichever is later), but never more than 10 years. For telehealth fraud that occurred during the COVID public health emergency (2020–2023), the clock is running. COVID-era telehealth claims from 2020 hit the 6-year mark starting in 2026.
Yes — if the patient has direct, independent knowledge of the fraud not derived solely from publicly available information, they can serve as a relator. Patient whistleblowers are often the strongest original source witnesses in phantom billing cases.
Frequently yes. Most states have their own False Claims Acts (with varying relator share percentages), and Medicaid was subject to the same telehealth billing expansion as Medicare. Many large telehealth fraud schemes billed both Medicare and Medicaid, doubling your damages base and opening multiple state-level claims alongside the federal FCA case.
DOJ intervenes in roughly 25-30% of all FCA cases filed. Telehealth cases with strong documentary evidence, clear scienter, large damages, and a cooperative whistleblower with direct knowledge have historically attracted intervention at higher rates. Cases against organized fraud networks (rather than individual providers) are especially attractive to DOJ because a single intervention can yield a large settlement across multiple defendants.
If DOJ intervenes: 15-25% of the government's recovery. If the relator litigates without intervention: 25-30%. In a $10M settlement with DOJ intervention, the relator typically receives $1.5M-$2.5M. In the large DME telehealth fraud cases, relator shares have exceeded $10M.
Telehealth billing fraud is the most active healthcare enforcement category in 2026, with billions in recoveries already secured and hundreds of cases still working through the pipeline. For attorneys handling FCA qui tam cases, the combination of large dollar amounts, clear documentary proof in billing records, and DOJ's stated enforcement priorities makes telehealth fraud cases highly attractive.
The challenge is the scale of documentation. A single high-volume telehealth provider can generate years of claims data that would take a human billing consultant months to analyze. AI-assisted review — flagging statistical anomalies, reconciling dates, and surfacing CPT pattern irregularities across thousands of claims — compresses that timeline dramatically and often surfaces fraud patterns that manual review would miss.
If you have a potential telehealth fraud whistleblower client, the window on COVID-era claims is closing. Move quickly, document your relator's original source basis carefully, and use every available tool to build your damages analysis before filing.
MedLegal AI uploads medical billing files and CMS claims data, then surfaces upcoding anomalies, phantom billing gaps, and statistical fraud signals. Built for attorneys and legal teams — no medical billing expertise required.
Analyze Records Free →© 2026 MedLegal AI — medicalai.law — AI-powered medical records analysis for attorneys and legal nurse consultants. This article is for informational purposes only and does not constitute legal advice.