← All resources

Telehealth spin up: your first 12 weeks

What to do in weeks 0-12 of a multi-state telehealth launch: an MSO and a PC per CPOM state, a bank account per entity, licensing that runs 30-120 days a state, credentialing 60-150 days a payer, then payer EFT enrollment.

The bank account you open in week two is the hardest thing to change later. Payer EFT enrollment names one account per payer, per entity, so switching banks after you enroll means re-filing all of it and taking reimbursement as paper checks until every form clears. Most founders pick that account in an afternoon, somewhere between incorporating and hiring.

The entity structure is the other one. Unwinding a non-compliant structure means re-papering every clinician contract and every payer enrollment you have. Almost everything else in the first year is reversible: pricing, EHR, brand, the care model itself can all be rebuilt in a quarter. These two cannot, and both get decided in the first three weeks.

Telehealth makes both of those harder than a single-site clinic does, for one reason: you go multi-state on day one. A brick-and-mortar practice adds its second state in year three. A telehealth company launches in eight and discovers that licensure, CPOM, supervision rules, and payer contracting are all per-state, all on different clocks, and all gating each other.

So sequence the work. Three systems have to be right before your first visit: structure, clinical coverage, and money rails. All three start in the first 12 weeks. Payer contracting is the one that keeps running after them, which is why you start it early instead of last. Below is the order the work has to happen in, and what holds up each piece.

This is general information for founders, not legal advice. Rules differ by state and change often. Confirm specifics with healthcare counsel.

The order of operations

ElapsedDo thisBlocked by
Week 0–2Form the entities: an MSO, a friendly PC per CPOM state, and the agreement setFinding a PC owner licensed in your states
Week 1–3Open the bank accounts: one per entity, with lockbox and cards, ready for EFTBanks that cannot take checks or hold per-entity accounts
Week 2–12License and credential: state licenses, DEA, verification, collaborative agreementsState board queues, 30 to 120 days per state. Sequence the slow states, like a New York PC, first
Week 4–24Enroll with payers: contracts, roster loading, then EFT and ERA enrollmentClosed panels and 90 to 180 day contracting
Week 6–12Bind cover and go live: malpractice, E&O, BAAs, LegitScript, protocols signed offCarriers want the structure before they quote

If you launch cash-pay, the first patient can be week three. If you bill insurance, the first payer dollar lands 60 to 90 days after your first claim. Size the runway on that number, not on the go-live date. The two paths split earlier than founders expect either way: a direct-to-consumer company needs card processing and LegitScript certification on roughly the timeline an insurance-billing company needs payer contracts.

Structure: a PC in every state that requires one

Corporate practice of medicine (CPOM) doctrine exists to protect patients. Clinical judgment belongs to licensed physicians, not to business owners. The compliant way to honor that is the MSO-PC model: a physician-owned professional corporation delivers the care, and your company provides everything else the practice needs to run.

For telehealth that is not one PC. It is a friendly PC in each strict-CPOM state you serve, each owned by a physician licensed in that state, each with its own EIN, payer contracts, and bank account, all tied to a single MSO. Everything downstream scales off that. Entity count grows with your state map, and so does the number of accounts, enrollments, and reconciliations to keep straight. Our MSO-PC Wiki (opens in a new tab) covers the model itself: formation, agreements, and the state-by-state detail. Read it alongside this. If the model is new to you, start with what the MSO-PC structure is and how it works (opens in a new tab).

The MSO holds the brand and IP, the technology, billing and admin, and the cap table. Each PC holds clinical judgment, clinician employment, medical records, and payer contracts. Three agreements hold them together:

What to do:

What not to do:

The enforcement wave changed what "good enough" means

For decades the friendly-PC model went largely unenforced. That era ended between 2024 and 2026. The model still works. The lazy version of it is dead, and telehealth companies are the most exposed because they operate in the strict states whether or not they are headquartered there.

Build for the strict states now, even if your first launch map skips them. If you plan to go national you will end up in Oregon and California eventually, and by then the structure is expensive to change.

Regulators and investor counsel check the same four things:

  1. Fees at fair market value. Documented, not asserted.
  2. An owner who governs. A physician with real authority, not a signature.
  3. PC-approved clinical policy. Protocols owned by the practice.
  4. Money that matches the paper. Dollars moving the way the MSA says they do.

The first three are legal work. The fourth is a banking problem, and it is the one founders tend to find out about late. The banking red flags that surface in an MSO-PC audit (opens in a new tab) are almost all failures of the fourth.

Clinical coverage: the clocks that set your launch calendar

Do not conflate the three physician roles. They are different people doing different jobs, and diligence asks about each separately.

One rule sets the shape of the whole business: the clinician has to be licensed where the patient is, not where the clinician is. That makes licensing your growth constraint. Three clocks run at once.

Four things to avoid: announcing a state launch before the licenses are in hand, tracking collaboration rules in a spreadsheet instead of a system with per-state alerts, treating the collaborating physician as a signature, and letting the MSO sign clinician employment agreements.

Two more that are specific to remote care:

On insurance: the PC holds professional liability, and the MSO needs its own E&O and cyber. Claims-made policies need tail coverage when a clinician leaves, so budget for it. Telehealth exclusions are common. Confirm states, modality, and prescribing are all covered before you bind. A policy written for in-person care can exclude the only way you deliver it.

Getting paid: enrollment binds revenue to one account

Payer enrollment is six steps, each gating the next. The last one is why your bank choice in week two constrains you for years.

  1. Identifiers. NPI Type 1 per clinician, Type 2 per billing entity, which means one per PC rather than one per company.
  2. CAQH and credentialing. Complete and re-attested quarterly. Payers pull from it.
  3. Group contracting. A participating agreement and fee schedule, per payer, per state. Panels close.
  4. Roster loading. Care delivered before a clinician is linked to the contract is usually not payable.
  5. EFT and ERA enrollment. Filed per payer, per entity, naming one bank account: the PC's, never the MSO's. Until it clears, reimbursement arrives as paper checks, even for a company with no office to receive them.
  6. Clearinghouse and claims. Claims out, 835s back, and someone matches every 835 to its deposit.

Telehealth adds its own billing rules on top: place-of-service coding for where the patient is, the telehealth modifiers each payer expects, and state parity rules that differ on whether a virtual visit pays the same as an in-person one. Confirm those per payer per state before you model revenue, because a coding assumption that is wrong in four states shows up as denials, not as a smaller check.

Each payer takes 30 to 90 days. Now the part nobody prices in: change banks after enrollment and you re-file with every payer, in every state, for every entity. For a 10-state group with 12 payers that is not one form, it is over a hundred, and reimbursements arrive as paper checks or fail outright until each one clears. That is the real cost of the account you opened in week two, and it is why switching a healthcare practice's bank (opens in a new tab) is a project rather than an afternoon.

Pick the account you want to still be using in year three, and open it before the first enrollment locks the account number in place.

Money rails: auditors trace dollars, not just documents

Your structure is only as compliant as your money movement. Payer revenue landing in the MSO's account, or fees moving as untitled transfers, dissolves corporate separateness no matter what the documents say. Telehealth makes that easy to get wrong. The MSO has the engineers, the app and the brand, so it looks like the natural place for money to sit, and money sitting there is what a regulator reads as de facto control.

The usual workaround is one bank for the MSO, another for the PCs, several logins, sweeps a CFO runs by hand, and a spreadsheet trail. Operators spend 8 to 12 hours a month on that reconciliation, and they still cannot tell an auditor what each transfer was for. Multiply it by a PC per state and it stops being a workaround.

Three rules make the money side hold up:

  1. Separate accounts per entity, day one. Commingling hands regulators a de facto control argument and makes your financials un-auditable. Whether one bank account can serve multiple PCs (opens in a new tab) has a short answer, and it is no.
  2. Payer money lands at the PC. EFT and ERA enrolled entity by entity, with a lockbox for the paper checks that arrive regardless of how digital the rest of the company is.
  3. Management fees move on rails. Invoiced, PC-approved, paid on the MSA's cadence, and ledgered. Twelve months of intercompany activity should be an export, not archaeology. How to document intercompany transfers between MSO and PC (opens in a new tab) covers what that record needs to contain.

Cash-pay telehealth runs into the same problem from the other side. Card processors and ad platforms underwrite telehealth against LegitScript certification and the shape of your entity structure, and consumer revenue still has to land at the entity that delivered the care. A structure that fails CPOM tends to surface first as a declined merchant application, not as a letter from a regulator.

Buy the compliance layers, build the product

Specialists exist for every layer of the setup. This is a map of the market, not a set of endorsements.

WhoWhat they solveBest at
Zivian HealthCompliance infrastructure for NP/PA workforces: a 50-state rules engine, collaboration management, audit logsScaling an APP workforce
Collaborating DocsPhysician matching for NPs and PAs, state-compliant agreements, collaboration malpractice includedProvider-level coverage
Licensing platforms (Medallion, Verifiable, CertifyOS)Multi-state licensing, credentialing, and payer enrollment paperwork run as software instead of a filing cabinetPaperwork at scale
Leased clinical layers (SteadyMD, OpenLoop, Wheel)A rented 50-state clinician network and PC structure. Speed now, migrate to your own PC laterLaunching before your PC exists
Healthcare counsel (boutique and large firm)MSO-PC formation, MSAs, CPOM and telehealth regulatory workFormation through Series A
LemmaBanking and payments for MSO-PC structures: per-entity accounts, payer EFT and ERA, lockbox, intercompany railsThe money rails

The most common founding mistake is a generalist lawyer forming "an LLC that does telehealth." It breaks CPOM, and it flags you with LegitScript, payment processors, and ad platforms, which is usually how the founders find out.

The readiness checklist

The same list serves a state audit, a payer review, or a fundraise. A week to assemble if you built correctly. A quarter if you did not.

Where the banking layer fits

Lemma is the money rails in that map. It does not write your MSA or structure your entities. That is counsel's work and it comes first. What it does is make the fourth item on the regulators' list true by default: money that matches the paper, at the entity count a telehealth company actually runs.

Every entity sits behind one login, with rule-based sweeps between the MSO and each PC and every transfer auto-labelled as fee, loan, or interest. Opening the next state's PC account takes five minutes online, so the bank never gates a launch. Cash posts itself: sub-accounts per payer, ERA 835s matched to deposit and claim at 96% accuracy, posted to your billing system. Intercompany fees are invoiced, approval-gated with a real PC veto, and fully ledgered for diligence. Payer EFT and ERA enrollment is concierge, and the AI lockbox is live from day one for the checks that arrive before enrollment clears.

The economics: $0 ACH, RTP, and FedNow for clinician payouts and patient refunds, up to 1.75% APY, FDIC insurance up to $10M through a sweep network, $2.50 a lockbox envelope with no minimums, and under a week to go live across the whole entity set. See banking built for telehealth (opens in a new tab) for how it fits a remote-first practice, MSO-PC banking (opens in a new tab) for the per-entity structure, and the MSO-PC Wiki (opens in a new tab) for the model underneath both.

Open the accounts in week two, before your first enrollment locks the account number in place. Everything else is fixable.