Key takeaways
- Telehealth is card-not-present and often recurring, so processors look closely at consent, cancellation, and what services are being billed.
- Keep card data out of your clinical systems with tokenization and hosted fields; keep PHI out of your payment processor.
- California's Automatic Renewal Law and CCPA/CPRA apply to membership-style telehealth models.
Telehealth providers payment processing in San Francisco covers everything from a solo therapist in the Inner Sunset seeing clients by video, to a direct-primary-care membership practice in the Financial District, to venture-backed virtual clinics in SoMa and Mission Bay offering weight management, mental health, dermatology, or men's and women's health across multiple states. The payments layer for all of them shares three traits: card-not-present, frequently recurring, and sitting next to protected health information. Processors treat that combination carefully.
How processors classify telehealth
Underwriting looks at what you actually bill for. A licensed provider billing consults and follow-ups is a medical services merchant with card-not-present exposure. A subscription model with medications, supplements, or devices bundled in raises additional questions: pharmacy licensing, what is being shipped, whether any products fall into supplement or nutraceutical categories that get their own scrutiny, and how renewals are consented. A platform that also sells peptides, compounded products, or aggressive weight-loss protocols can find itself in high-risk underwriting regardless of its clinical legitimacy. Be precise about what you sell and how.
Keeping card data and health data separate
Your EHR and scheduling stack should never touch raw card numbers, and your payment processor should never see clinical detail. Use hosted payment fields on your patient portal so card entry happens in the processor's environment, and store cards as tokens through tokenization for future visits. On the health-data side, keep line-item descriptions in payment records generic ("visit", "membership") so PHI does not leak into a payment system that is not built for it. Confirm your HIPAA obligations and any business associate agreements with counsel; the payments side can be structured to stay outside PHI scope, but only if you design it that way.
Subscriptions, memberships, and the Automatic Renewal Law
Membership-based care is common in San Francisco, and it is a subscription in the eyes of California law. The Automatic Renewal Law requires clear disclosure of renewal terms before consent, affirmative acceptance, a written acknowledgment, and cancellation at least as easy as signup, including online for online enrollment. A patient who cannot find the cancel button disputes the charge, and the issuer sides with them. Build recurring billing with pre-renewal notices, account updater for reissued cards, and a one-click cancel. Keep the consent log; it is your representment evidence.
Chargebacks in virtual care
Telehealth disputes cluster in a few reason codes: "services not rendered" for missed or cancelled visits, "cancelled recurring" on memberships, and "not as described" when outcomes disappoint. Evidence that wins: appointment logs with join timestamps, the signed financial policy including no-show terms, the consent record for the membership, and correspondence. Because networks measure disputes against monthly transaction counts and monitoring begins around 0.9%-1%, a small practice with a few hundred transactions a month has little margin. Enroll in alert programs so you can refund a contested charge before it posts, and use fraud screening on new-patient signups to keep stolen-card disputes off the account.
Settlement and cash flow
Card payments settle in 1-2 business days. For larger self-pay procedures or corporate wellness contracts, ACH settles in 1-3 business days at a flat fee. Employer clients paying for a group program can settle instantly to the merchant wallet with stablecoins if they are set up for it. If you use QuickBooks, the sync is one-way: transaction data is pushed into QuickBooks, and your practice management software remains the clinical system of record.
Privacy beyond HIPAA
California's CCPA/CPRA applies to consumer data once a business crosses the applicable thresholds, and health-adjacent data can fall into sensitive categories with extra obligations. A San Francisco telehealth company marketing to consumers is squarely in scope. Confirm your notices, opt-outs, and data handling with counsel and make sure your payment vendor's data practices fit.
Category pitfalls
If your model includes supplements or nutraceuticals, read Why Nutraceutical Brands Get Declined by Stripe and PayPal before you apply, because the product side will drive underwriting more than the clinical side. Be candid in the application about every revenue line.
San Francisco telehealth providers who separate card data from clinical data, treat cancellation as a product feature, and keep consent records tidy get stable processing. The ones who bolt payments onto a clinical stack without thinking about scope tend to discover the problem during a dispute or an audit.
Ready to get set up with Flux?
Cards, ACH, and stablecoins in one platform, with volume-based pricing. No setup fees or contracts.
Get Started