Key takeaways
- Telehealth is card-not-present healthcare, which is underwritten more carefully than an in-person clinic.
- Some telehealth niches (weight loss, hormone therapy, hair loss, certain prescriptions) are treated as high-risk by acquiring banks.
- Keep the payment system free of protected health information; PCI and HIPAA are separate obligations.
Telehealth providers payment processing in Los Angeles has become its own category because LA has become a telehealth capital. There are virtual primary care and urgent care groups headquartered in Century City and Playa Vista, direct-to-consumer brands in Santa Monica and Culver City selling dermatology, hair loss and weight management visits, therapy and psychiatry platforms in Pasadena and Burbank, and a large number of solo practitioners across the county who moved a portion of their practice online. Every one of them is running a card-not-present healthcare business, and that combination gets a careful look from acquiring banks.
Why telehealth is underwritten differently from a clinic
A physical clinic in Glendale with a chip terminal is a low-risk file. The same doctor charging cards over the internet for video visits is card-not-present, which carries higher interchange and more fraud exposure. Add a subscription model, a prescription component, or a consumer-marketed condition, and the bank starts asking questions. Certain niches are flagged almost automatically: weight loss and GLP-1 programs, hormone and testosterone therapy, hair loss, sexual health, and anything marketed with before-and-after imagery. Those are not prohibited, but they are placed with banks that accept the category, usually with a reserve and closer monitoring. This comparison of high-risk and low-risk processing explains what changes when you land in that bucket.
The underwriting file for an LA telehealth practice
- Medical Board of California licenses for prescribing clinicians, and for out-of-state patients, the licenses or compacts that cover them.
- A description of the patient flow: intake, consult, prescription, fulfillment, follow-up.
- Your pharmacy relationships if you dispense or partner with a compounding pharmacy.
- Your refund and cancellation policy for visits and memberships.
- Marketing samples; banks check whether claims match what you deliver.
- Corporate documents, including any professional corporation and MSO structure, since California's corporate practice of medicine doctrine shapes who can own what.
Subscriptions, memberships and the Automatic Renewal Law
Many LA telehealth brands bill monthly. Under California's Automatic Renewal Law, that requires clear and conspicuous disclosure of the recurring terms, affirmative consent, a written acknowledgment, and a cancellation path as easy as signup, online included. Confirm the specifics with counsel, because the law has been amended and enforcement is active. Use a recurring billing platform with tokenization and an account updater, send pre-billing reminders, and log consent. The consent record is what wins a "did not authorize" dispute, and telehealth subscriptions can approach the network dispute thresholds around 0.9 percent to 1 percent surprisingly quickly when patients forget a monthly plan.
HSA/FSA and healthcare MCCs
Telehealth practices coded under a healthcare MCC can generally accept HSA and FSA cards for eligible services, and patients increasingly expect it. Confirm the MCC and the IIAS or healthcare-merchant configuration with your processor. Practices that mix eligible medical visits with ineligible wellness products should think about how those are separated at checkout, since a mismatch creates problems for the patient at tax time.
PCI and HIPAA: keep them apart
Card data belongs in the payment system; protected health information belongs in the EHR. Never put a diagnosis, medication or visit reason in a transaction memo. Use hosted payment fields in your patient portal so card numbers go straight to the processor, and tokenize cards for repeat billing. This keeps your PCI compliance scope small and keeps the processor out of the HIPAA chain of custody. If a vendor touches PHI, you need a business associate agreement; the cleaner design is one where the payment vendor never does.
Fraud patterns specific to telehealth
Stolen cards are used to obtain prescriptions and products for resale, particularly in the GLP-1 and hormone categories. Card testing hits any public-facing form. A fraud detection layer with AVS, CVV, device signals and velocity rules is not optional here. Identity verification at intake, which you likely already do for clinical reasons, doubles as fraud control; keep the two workflows connected.
Settlement and cash flow
Card settlements arrive in 1-2 business days. Employer contracts and health-plan payments belong on ACH, which settles in 1-3 business days and avoids card fees on large checks. A one-way push into QuickBooks keeps your finance team from reconciling thousands of visit charges by hand. For a practice in a high-risk niche, a rolling reserve will reduce day-to-day settlement for a period; model it before you commit to ad spend.
LA telehealth can get stable, sensible processing. The providers who manage it describe their model honestly, document consent, keep clinical data out of the payment stack, and treat fraud screening as part of patient safety rather than a cost to be minimized.
Ready to get set up with Flux?
Cards, ACH, and stablecoins in one platform, with volume-based pricing. No setup fees or contracts.
Get Started