California CPOM Compliance for Telehealth Practices: What You Must Know

Telehealth has made it easier for medical practices, wellness platforms, specialty providers, and health care startups to reach patients across California. A patient can now meet with a physician from home, receive follow-up care through a secure video platform, and access specialized support without sitting in a waiting room. But the convenience of virtual care does not remove California’s strict rules about who may own, control, and operate a medical practice.

For telehealth practices, one of the most important legal issues is California CPOM compliance. CPOM stands for the corporate practice of medicine. In simple terms, California generally does not allow a non-physician, general corporation, investor group, management company, or tech platform to control the medical side of a practice. Even when the business is virtual, the law still focuses on one core principle: medical decisions must remain under the control of properly licensed medical professionals.

This matters for telehealth companies because many virtual care models involve several moving parts. There may be physicians, nurse practitioners, medical assistants, marketing vendors, software platforms, call centers, payment processors, investors, and management service organizations. If those relationships are not structured properly, a business that looks modern and efficient on the surface may create serious legal risk underneath.

What CPOM means in California

California’s corporate practice of medicine doctrine is designed to prevent unlicensed individuals or business entities from interfering with a physician’s professional judgment. The rule is not just about who signs paperwork. It is about who actually controls the practice.

A compliant structure should preserve physician control over clinical decisions, patient care, treatment plans, medical records, referrals, diagnostic testing, supervision of clinical staff, and the overall medical direction of the practice. A non-physician business owner may be able to provide administrative support, technology, marketing, staffing assistance, billing support, office space, or back-end operations, but that support cannot cross the line into controlling medicine.

For telehealth companies, that line can become blurry. A software dashboard might determine which provider sees a patient. A marketing team might promise a specific treatment before the physician has evaluated the patient. A business executive might pressure clinicians to prescribe a particular medication because it increases revenue. A call center might direct patients toward certain services without proper clinical review. Each of these examples can raise CPOM concerns if non-physicians are influencing medical judgment.

Why telehealth does not get a CPOM exception

Telehealth is a method of delivering care. It is not a separate category of medicine with relaxed ownership or control rules. A California patient receiving care through a screen is still receiving health care. That means the practice must still evaluate licensing, scope of practice, informed consent, patient privacy, prescribing rules, recordkeeping, supervision, advertising, and CPOM compliance.

This is especially important for practices serving patients across multiple cities or counties. Whether the business is helping patients in Los Angeles, Orange County, the Bay Area, or san diego, California compliance should be built into the business model before the platform scales.

The same principle applies when the company is based outside California but treats California patients. If the patient is in California, the business should carefully evaluate whether California licensure and California practice rules apply. A physician may not be physically located in California, but the physician generally needs the proper California license to provide medical care to California patients.

Common CPOM risk areas for telehealth practices

CPOM problems often happen when a company grows quickly and treats legal structure as an afterthought. The business may start with one physician and a small admin team, then add subscription billing, paid ads, outside investors, non-physician managers, remote contractors, and automated intake workflows. Without proper legal review, control can gradually shift away from the licensed medical professionals.

Some of the most common risk areas include:

  • Non-physician ownership of the medical practice: A general business entity should not directly own or operate the medical practice if it is providing physician services.
  • Improper use of a “medical director”: Simply naming a physician as medical director does not fix CPOM problems if the physician does not truly control the clinical side of the practice.
  • Management company overreach: An MSO may support the business, but it should not make clinical decisions or control physician judgment.
  • Revenue arrangements tied to clinical services: Compensation models should be reviewed carefully to avoid improper fee splitting, kickback concerns, or control issues.
  • Marketing promises before medical review: Ads and landing pages should not guarantee prescriptions, outcomes, or treatments before a licensed provider evaluates the patient.
  • Control over patient records: Medical records should remain under proper clinical ownership and control, even if a software vendor stores or manages the system.
  • Automated protocols without physician oversight: Intake tools and algorithms may support efficiency, but licensed professionals must retain appropriate clinical judgment.

The MSO-PC model and why details matter

Many California telehealth businesses use some version of an MSO-PC structure. MSO stands for management services organization. PC stands for professional corporation. In a simplified version, the physician-owned professional corporation provides medical services, while the MSO provides non-clinical administrative support.

This structure can be useful, but it is not automatically compliant. The documents must match the reality of how the business operates. Regulators and opposing parties may look beyond the agreement and ask practical questions: Who hires and fires clinical staff? Who controls the patient relationship? Who sets clinical protocols? Who decides what services are offered? Who owns the medical records? Who controls coding and billing? Who has the final say when business goals conflict with medical judgment?

If the MSO controls the medical practice in substance, the structure may be challenged even if the paperwork appears organized. A strong MSO agreement should clearly separate administrative services from clinical control. It should also use compensation terms that are commercially reasonable and not simply a disguised way for a non-physician entity to receive medical practice profits.

Telehealth consent, privacy, and patient communication

CPOM compliance is only one part of a legally sound telehealth operation. California telehealth practices should also pay close attention to patient consent. Before delivering health care through telehealth, the provider initiating telehealth should inform the patient about the use of telehealth and obtain verbal or written consent where required.

Privacy is another major concern. Telehealth platforms handle sensitive health information, payment information, intake forms, chat messages, images, prescription data, and sometimes recordings. HIPAA, California privacy rules, vendor contracts, cybersecurity practices, and business associate agreements may all matter. A practice should know exactly what information is collected, where it is stored, who can access it, and how vendors are allowed to use it.

Patient-facing communication should also be clear. If the practice uses remote monitoring, asynchronous messaging, text reminders, patient portals, AI-supported intake, or third-party scheduling tools, the business should evaluate whether the disclosures, consents, privacy policies, and vendor agreements actually match the workflow.

Advertising and lead generation concerns

Telehealth practices often depend heavily on digital marketing. Paid ads, SEO pages, social media campaigns, influencer partnerships, affiliate programs, and landing pages can generate leads quickly. But health care marketing has legal limits.

Marketing should not imply that a patient will automatically receive a prescription. It should not make unsupported claims about outcomes. It should not hide who is actually providing care. It should not allow a marketing vendor to steer clinical decisions based on conversion rates. A campaign that works well from a sales perspective can still create legal exposure if it misrepresents the patient experience or interferes with physician judgment.

Lead generation contracts should be reviewed carefully. Some arrangements may raise issues involving referral fees, fee splitting, patient inducements, data privacy, false advertising, or unfair business practices. Telehealth businesses should be especially careful when using third-party companies that are paid based on booked appointments, completed prescriptions, or revenue generated from medical services.

Questions telehealth founders should ask before scaling

A telehealth practice does not need to wait for a lawsuit, investigation, investor diligence request, payer audit, or board complaint before addressing CPOM compliance. The better approach is to review the structure early and update it as the company grows.

Important questions include:

  • Is the medical practice owned by the proper licensed professional or professional entity?
  • Does the physician retain real control over clinical decisions?
  • Are the MSO’s services limited to non-clinical administrative support?
  • Do the contracts clearly separate business operations from medical judgment?
  • Are providers properly licensed for the patients they treat?
  • Are patient consents, privacy policies, and vendor agreements current?
  • Does the marketing avoid guarantees, misleading claims, or improper referral arrangements?
  • Are medical records controlled and protected appropriately?
  • Do compensation arrangements avoid improper fee splitting or disguised clinical control?
  • Can the business explain its compliance structure during investor, payer, or regulatory review?

Why proactive legal review can protect growth

A telehealth practice may look attractive to investors, partners, and patients because it is scalable. But the same scalability can multiply legal risk. A questionable ownership structure affecting ten patients may become a much larger problem once the platform treats thousands of patients across California.

Proactive legal review can help identify issues before they become expensive. This may include reviewing entity formation, ownership documents, physician agreements, MSO agreements, vendor contracts, patient-facing terms, privacy policies, marketing language, employment relationships, contractor arrangements, billing procedures, and internal compliance policies.

The goal is not to slow the business down. The goal is to build a structure that can withstand growth. A properly designed compliance foundation can make the business stronger, more attractive to serious partners, and better prepared for diligence, audits, disputes, and regulatory questions.

How we can help

California CPOM compliance for telehealth practices requires more than a template contract or a quick entity filing. The legal structure should match the way the business actually operates, how patients are treated, how providers are supervised, how revenue flows, and how clinical decisions are protected.

Law Office of Kris Mukherji, APC provides personalized legal services for business owners, health care entrepreneurs, professionals, and growing companies that need practical guidance. Our firm is based in San Diego and is known as one of the highest locally ranked law firms. We help clients evaluate risk, structure business relationships, review contracts, and make informed decisions before legal problems interfere with growth.

If you are starting, restructuring, investing in, or scaling a telehealth practice in California, a free case consultation can help you understand your next steps. Contact Law Office of Kris Mukherji, APC to discuss your telehealth business, CPOM compliance concerns, and the legal structure needed to support long-term success.