The Ultimate Guide to Behavioral Health Billing Compliance

Practical steps for accurate coding, eligibility checks, authorization tracking and denial management to cut behavioral health claim denials.
SHARE

Behavioral health billing compliance is a complex but essential process for providers offering mental health and substance use disorder services. 

It involves navigating federal regulations, state laws, and payer-specific requirements to ensure accurate claims and avoid costly penalties. 

Here’s what you need to know:

  • Key Challenges: Providers face hurdles like time-based CPT codes, prior authorization demands, payer carve-outs, and evolving regulations (e.g., telehealth rules, MHPAEA enforcement).

  • Common Risks: Documentation errors, credentialing issues, and authorization failures lead to high denial rates – behavioral health claims are denied 85% more often than general medical claims.

  • Regulatory Highlights: Medicare and Medicaid rules, HIPAA privacy standards, and payer-specific policies require precise adherence to avoid audits, recoupments, or exclusion from programs.

  • Solutions: Implement real-time eligibility checks, use automated claim scrubbing tools, and conduct regular compliance audits. Track key metrics like denial rates (<5%) and clean claim rates (≥95%) to refine workflows.

Proper documentation, coding accuracy, and proactive denial management are crucial for financial stability and audit readiness.

This guide outlines actionable steps to build a compliant billing process that minimizes risks and maximizes revenue.

Key Regulations and Payer Requirements

Behavioral health billing involves navigating a maze of federal rules, state Medicaid policies, and individual payer requirements. Below, we break down the key regulatory layers and what they mean for providers.

Medicaid and Medicare Billing Rules

Medicaid and Medicare each have unique submission and payment processes. One important point to note is Medicaid’s role as the payer of last resort:

“Medicaid is called the payer of last resort because Federal regulations require that all available health insurance benefits be used before Medicaid considers payment.” [2]

For patients covered by both Medicare and Medicaid, Medicare must be billed first. Starting in 2024, mid-level clinicians – such as Licensed Professional Counselors (LPCs), Licensed Marriage and Family Therapists (LMFTs), and Licensed Addiction Counselors (LACs) – must enroll as Medicare providers to treat patients with dual eligibility [2].

When it comes to substance use disorder (SUD) services, Medicaid programs often rely on ASAM criteria to determine the appropriate level of care. Providers submitting authorizations should reference specific ASAM dimensions (e.g., Dimension 1: Intoxication/Withdrawal) to meet payer expectations [1]. For Medicare, Opioid Treatment Programs (OTPs) bill using bundled weekly payment G-codes (G2067–G2074). These programs must hold SAMHSA certification and Medicare enrollment [1].

Medicare has extended its telehealth flexibilities for behavioral health through 2026. This includes allowing patients to receive services from home (using POS 10) and permitting audio-only visits when appropriate. To bill for these, providers must use the FQ modifier and include specific documentation [1][2].

HIPAA and Privacy Compliance

Billing processes must also comply with strict privacy and data protection laws like HIPAA. The Privacy Rule’s “minimum necessary” standard (45 CFR §164.502(b)) limits billing staff access to only the information needed for their tasks – such as patient demographics and relevant billing codes. Full clinical charts and psychotherapy notes are off-limits without explicit patient consent [5]. Psychotherapy notes, in particular, are highly protected under 45 CFR §164.501 and require patient authorization even for billing purposes [5].

For substance use disorder records, 42 CFR Part 2 adds another layer of protection. Providers must obtain written patient consent for treatment, payment, and operations (TPO). Additionally, a Qualified Service Organization Agreement (QSOA) is required alongside standard Business Associate Agreements (BAAs) [5].

The financial risks for non-compliance are steep. As of 2026, HIPAA penalties for willful neglect can reach $2,190,000 per violation. A single investigation by the Office for Civil Rights (OCR) could cost a practice between $15,000 and $100,000 in legal fees [5]. For example, the February 2024 Change Healthcare breach – caused by a lack of multi-factor authentication – exposed over 100 million records, resulting in a $22 million ransom payment and six weeks of disrupted claim submissions for behavioral health providers [5].

Any billing vendor, whether a clearinghouse, billing company, or offshore coder, must sign an Omnibus-compliant BAA. If a breach occurs, the 60-day notification period begins as soon as the organization or its vendor becomes aware of the incident [5].

Payer-Specific Policies and Supervision Requirements

Payer-specific rules are another critical aspect of behavioral health billing. Many insurers “carve out” behavioral health benefits to specialized managed behavioral health organizations (MBHOs) like Optum, Magellan, or Carelon (formerly Beacon Health Options) [1]. This means claims for mental health or SUD services often need to be sent to a separate entity, not the one listed on the patient’s insurance card.

Payers also use varying criteria to determine medical necessity. While Medicaid often relies on ASAM guidelines, commercial payers may use tools like MCG (Milliman Care Guidelines) or InterQual. Knowing which criteria a payer uses is essential for proper documentation. The 2024 MHPAEA final rule has increased oversight on Non-Quantitative Treatment Limitations (NQTLs), giving providers more leverage to appeal restrictive policies [1].

Supervision billing adds another layer of complexity. When non-credentialed clinicians provide services under a licensed supervisor’s NPI, the rendering provider’s details go in Box 24J, while the supervisor’s information is entered in Box 17 on the CMS-1500 form [3]. Rules about which provider types can be supervised and for how long differ by payer, so verifying each payer’s policies is crucial.

 

Finally, prior authorization issues are a common cause of denials, accounting for 20–30% of behavioral health claims being rejected. Setting automated reminders 5–7 days before an authorization expires can help avoid coverage gaps [4].

Common Compliance Risks in Behavioral Health Billing

Building a Compliant Billing Workflow

Billing operations in behavioral health are full of potential pitfalls. Behavioral health claims face denial rates 85% higher than general medical claims [6][11], with facilities losing 10–20% of collectible revenue due to preventable errors [6]. Identifying where these risks occur is the first step in addressing them.

Documentation Errors and Medical Necessity

Documentation issues are the leading cause of claim denials and audits in behavioral health. In 2023, 30% of mental health claims were denied, compared to 19% for other healthcare services [7]. A significant factor is poorly written or incomplete notes that fail to meet payer requirements.

Common documentation mistakes include:

  • Vague language without measurable observations

  • Missing session start and stop times

  • Duplicate notes

For time-based CPT codes like 90832, 90834, and 90837, payers expect precise, minute-level documentation – not rounded estimates.

To avoid denials, clinical records must demonstrate a clear connection between diagnosis, treatment goals, and interventions – often referred to as the “golden thread.” Without this, medical necessity becomes difficult to defend. For example, when billing a psychotherapy add-on with an E/M code, the documentation must clearly separate the two activities and show non-overlapping times. Blurring these distinctions is a common audit trigger.

Another overlooked area is the underuse of CPT 90785 for interactive complexity. An estimated 50–70% of qualifying sessions fail to bill for this code despite meeting the criteria [4]. While this doesn’t directly cause compliance issues, it highlights how documentation gaps can lead to both underbilling and overbilling.

These challenges often overlap with credentialing problems, further complicating billing accuracy.

Credentialing and Provider Enrollment Issues

Errors in credentialing and provider enrollment can have serious consequences, including recoupment demands and fraud investigations [10]. Billing for services provided by a clinician who isn’t credentialed or enrolled with a payer is a major compliance risk.

Credentialing can take anywhere from 60 to 180 days depending on the payer [8], and delays can cost $5,000–$15,000 per provider each month [8][10]. Behavioral health adds complexity due to its variety of license types – like LPCs, LCSWs, LMFTs, and PMHNPs – each with unique state scopes of practice and NPI taxonomy codes. A mismatch between a provider’s taxonomy code and the services billed is a common reason for claim rejections.

Supervision arrangements also carry risks. Clinicians billing under a supervisor’s NPI must comply with payer-specific “incident-to” rules, and not all payers permit this. Assuming one payer’s policy applies universally can lead to denials. Additionally, failing to screen staff monthly against the OIG LEIE and SAM.gov exclusion lists is a frequent oversight that can escalate into significant compliance issues [9][10].

Eligibility and Authorization Failures

Eligibility and authorization errors are the largest controllable source of revenue loss in behavioral health billing. Eligibility mistakes account for 24% of denials, while prior authorization failures add another 20–30% [4][12].

The main challenge lies in timing and verification. Coverage verified days before an appointment may no longer be valid by the service date, especially for patients with Medicaid or fluctuating employment. Behavioral health often involves layered benefits across different care levels (residential, PHP, IOP, outpatient), each requiring separate verification and authorization. Missing a carve-out – where behavioral health benefits are managed by a separate MBHO – results in hard denials that are rarely recoverable.

Authorization management is equally demanding. Behavioral health often requires re-authorization every 3–14 days during a single treatment episode [13]. Services provided during a lapse between expired and renewed authorizations are almost never recoverable through appeals [13]. Practices that fail to track session counts or set reminders for renewals often discover coverage lapses only after receiving denied claims. Alarmingly, up to 60% of denied claims are simply written off instead of appealed [11][12].

Denial Code

Common Cause

Prevention Strategy

CO-16

Missing claim information

Use EHR prompts to complete all required fields before submission

CO-50

Medical necessity not established

Document functional impairment using tools like PHQ-9 or GAD-7

CO-151

Authorization expired

Set alerts 5–7 days before authorization expiration

CO-4

Inconsistent modifier

Maintain a payer-specific modifier matrix (e.g., 95 vs. GT for telehealth)

Understanding these risks is key to creating a billing workflow that minimizes compliance issues and maximizes revenue potential.

Creating a billing workflow that prioritizes compliance means addressing potential issues before they arise. Every step of the revenue cycle – from scheduling an appointment to posting the final payment – carries risks that need to be managed. Success hinges on clear processes, consistent execution, and effective tools. These adjustments align with the regulatory and risk management strategies discussed earlier.

Eligibility Verification and Benefit Review

Eligibility verification is a critical point where many avoidable denials occur. It’s essential to confirm insurance eligibility at each admission, not just for new patients.

Behavioral health billing introduces added complexity because benefits are often “carved out” and managed by separate administrators. For example, payers like Optum and Magellan frequently handle behavioral health benefits independently from the primary medical plan. Submitting a claim to the wrong payer can result in hard denials, so it’s important to confirm the carve-out payer’s name, payer ID, and contact details during verification.

A detailed benefit review should gather key information, including the remaining deductible, coinsurance percentage, copay tiers for specialists, session limits, sessions used so far, and prior authorization requirements. For telehealth visits – which account for about 40% of all behavioral health visits in 2026 [4] – make sure to confirm the correct Place of Service (POS) code (POS 10 for home, POS 02 for other sites) and required modifiers (95 or GT). These details ensure claims move smoothly through the process without unnecessary delays.

Always document the insurance representative’s name, the date of the call, and a reference number during verifications. This paper trail can be invaluable for future appeals if coverage disputes arise.

Once eligibility and benefits are confirmed, the focus shifts to ensuring that coding practices align precisely with clinical documentation.

Coding Accuracy and Claim Scrubbing

Even with verified eligibility and thorough documentation, coding errors can derail claims. For instance, billing for a 60-minute psychotherapy session when only 42 minutes were documented can lead to an automatic denial. The submitted code must match the documented service, not what the provider intended to deliver.

Before claims are sent to payers, they should go through a claim scrubbing process. This automated pre-submission review flags issues like NCCI bundling conflicts, incorrect or missing modifiers, mismatched diagnosis and procedure codes, and incomplete fields. It’s an essential step, especially for high-volume practices, to catch errors that might otherwise slip through. Top-performing behavioral health practices typically maintain a clean claim rate of 95% or higher.

Telehealth coding also requires careful attention. Modifiers 95 and GT aren’t interchangeable across all payers, so it’s critical to use payer-specific coding references for modifiers, POS codes, and bundling rules to minimize errors.

Denial Management and Corrective Action

Accurate coding and claim scrubbing lay the groundwork, but proactive denial management is essential to maintaining compliance. Act quickly, as recovery rates drop for claims older than 60 days [1]. Set clear resolution goals – such as addressing eligibility denials within three days and medical necessity denials within 7–10 days – to improve recovery rates. For medical necessity denials, requesting a peer-to-peer review with the payer’s medical director often yields better results than written appeals alone.

Analyzing denial patterns can highlight workflow weaknesses. For example, repeated denials citing a lack of medical necessity may point to the need for better clinical documentation templates rather than more appeals.

Tracking key metrics can help refine billing workflows:

Metric

Target Benchmark

Common Cause for Failure

Clean Claim Rate

≥ 95%

Coding errors, missing authorizations, eligibility failures

Denial Rate

< 5%

Missing prior authorizations, documentation gaps, coding errors

Days in AR

< 40 days

Slow follow-up, payer delays, timely filing issues

Denial Overturn Rate

≥ 50%

Weak appeal letters, insufficient clinical documentation

AR > 90 Days

< 15% of total AR

Stale denials, unresolved coordination of benefits, credentialing delays

(All metrics based on industry benchmarks [1].)

In early 2026, a multisite behavioral health group discovered that 18% of its denials were due to “benefit exhausted” or “authorization required” errors. By implementing a behavioral benefit verification script at scheduling and setting EHR alerts to notify staff when 75% of authorized visits were used, the group reduced its denial rate to under 6% within one quarter [14]. This example shows how addressing issues early in the process, rather than relying on appeals, can lead to lasting improvements in billing compliance. Insights from tracking these patterns also contribute to broader compliance monitoring efforts.

Compliance Monitoring and Tools

Keeping track of denial patterns and refining workflows demands a solid monitoring system paired with the right technology. Together, these efforts not only guide internal audits but also highlight the importance of tools that provide ongoing compliance oversight.

Internal Audits and Compliance Reviews

Regular audits act as a safeguard against billing mistakes that could snowball into bigger issues. According to the American Medical Association, coding audits should be done at least once a year, though quarterly reviews might be more effective at catching problems early – before they lead to payer audits or recoupments [16].

A thorough audit involves four key steps: planning, fieldwork, reporting, and follow-up. During the planning stage, focus on high-volume codes like 90837 (individual psychotherapy, 53+ minutes) and payers with high denial rates. Fieldwork should verify often-overlooked details such as session start and stop times, 42 CFR Part 2 consents for substance use disorder (SUD) claims, and documentation of ASAM criteria for level-of-care decisions [13]. When reporting findings, the “Five C’s” framework can be helpful:

  • Criteria: What was required?

  • Condition: What was found?

  • Cause: Why did it happen?

  • Consequence: What are the risks?

  • Corrective Action: How can it be fixed? [15]

Common red flags include billing individual therapy codes for group sessions, using vague diagnosis codes like F41.9 when a more specific code such as F41.1 is supported by the clinical record, and mixing outpatient and inpatient codes on a single claim [16].

While audits provide valuable periodic checks, automated technology ensures that compliance is monitored continuously.

Technology Solutions for Compliance Support

Automated tools are a game-changer for ensuring compliance, especially for practices with multiple locations where manual checks aren’t practical. These systems handle real-time eligibility checks, flagging expiring authorizations, and ensuring claim accuracy – all of which are essential for reducing denials.

For example, automated systems can instantly verify eligibility and send alerts when authorizations are about to expire [1]. Claim scrubbing engines catch errors before submission, and for SUD claims, claim release gates can block submissions unless a valid 42 CFR Part 2 consent is on file [13].

Compliance dashboards give billing teams real-time insights into metrics like Clean Claim Rate, Denial Rate, and accounts receivable aging. These are often reviewed weekly to stay on top of performance [1]. Additionally, AI-powered documentation tools can provide instant feedback on clinical notes, flagging any missing elements before the notes are finalized [17].

Together, these tools help catch errors early, reduce denials, and maintain a strong compliance framework across the organization.

Maintaining a Compliance Documentation Trail

Even with the best technology and audits, your documentation needs to be rock-solid. Clinical records form the basis of every billing decision, so they must clearly support the services billed and the codes submitted [1].

Certain documentation practices can make a big difference during audits. For example, precise session times are crucial – documenting a 52-minute session instead of 53 minutes could mean the difference between being reimbursed for a lower code rather than CPT 90837 [1][13]. For Partial Hospitalization Program (PHP) claims, it’s essential to document total weekly structured programming hours, as most commercial payers require at least 20 hours per week to approve this level of care [1]. Progress notes should also explain why a patient isn’t ready to move to a lower level of care, instead of just summarizing daily activities.

Here’s a quick overview of key documentation elements and their compliance requirements:

Documentation Element

Compliance Requirement

Best Practice

PHP Programming

Minimum 20 hours/week

Clearly document total weekly hours in treatment records [1]

Time-Based Codes

Exact session duration

Use EHR rules to flag notes missing start/stop times [1]

SUD Claims

42 CFR Part 2 consent

Configure billing systems to block claim submission without verified consent [13]

Telehealth

POS 02 or 10

Confirm payer-specific POS codes and audio-only attestations [1]

Group Therapy

Individual participation

Document attendance and participation for each patient separately [1]

Credentialing records also need attention. Expired licenses or certifications can lead to recoupments of previously paid claims. Using tracking software to flag expiring credentials is a smart move [1]. Similarly, keeping CAQH ProView profiles updated quarterly can help prevent credentialing-related denials down the road.

Behavioral Health Billing Compliance Checklist

This checklist breaks down key steps into manageable daily, weekly, and monthly tasks to help ensure billing compliance for behavioral health services.

Before Every Session

  • Confirm active coverage and in-network behavioral health benefits for each patient. Check details like deductibles, copays, session limits, and prior authorization (PA) requirements.

  • If PA is needed, submit the request along with a clinical summary and set reminders for PA expiration dates to avoid disruptions in coverage [1].

At the Point of Documentation

  • Record precise session start and stop times (e.g., “10:00 AM to 10:45 AM”) and complete notes within 24–72 hours of the session [18][20].

  • Ensure documentation supports the care level provided. Link symptoms to functional impacts (e.g., missed workdays, disrupted sleep) and detail the therapeutic techniques used, such as CBT cognitive restructuring or DBT distress tolerance. Include patient responses to treatment [19].

  • Use tools like the PHQ-9 or GAD-7 to provide measurable data on symptom severity instead of vague descriptions.

Before Claim Submission

  • Scrub every claim to identify issues like NCCI bundling conflicts, missing modifiers, or mismatched diagnosis and procedure codes before submitting to payers [1].

  • Regularly track key billing metrics to maintain efficiency:

Metric

Target Benchmark

Clean Claim Rate

≥ 95%

Days in AR

< 40 days

Denial Rate

< 5%

AR > 90 Days

< 15% of total AR

Time to Bill

< 3 business days

Ongoing Credentialing and Denial Management

  • Update CAQH ProView profiles every 90 days and monitor license renewal deadlines using tracking software to avoid recoupments [1].

  • Address claim denials immediately, as recovery rates drop significantly after 60 days. For medical necessity denials, request a peer-to-peer review within 10–14 days, as these reviews have a 40%–60% success rate for overturning denials [4].

Periodic Compliance Reviews

 

  • Perform quarterly internal audits, reviewing 20–30 claims per provider to spot documentation gaps, coding errors, or missed authorizations [18].

  • Maintain payer-specific checklists for Medicare, Medicaid, and private insurers to account for varying authorization and documentation requirements [20].

Conclusion and Key Takeaways

Navigating behavioral health billing compliance demands constant attention, and the stakes are high. In fiscal year 2024 alone, False Claims Act settlements surpassed $2.9 billion, with over $1.67 billion linked directly to healthcare cases [21]. For organizations, establishing compliant workflows not only ensures they collect what they’re owed but also promotes long-term financial stability.

As discussed earlier, compliance challenges often stem from clinical documentation issues. When records fail to clearly justify medical necessity or lack detailed session times, claims are jeopardized before they even reach submission. This link between precise documentation and successful billing outcomes has been a recurring theme throughout this guide.

To see real improvements, organizations should focus on three critical practices: verifying coverage and including ASAM-specific language in authorization requests before every session, and tracking key performance indicators (KPIs) weekly instead of waiting for audits to reveal problems. For example, the multisite behavioral health group mentioned earlier introduced benefit verification scripts during scheduling and set up EHR alerts at 75% of authorized session usage. These proactive steps slashed their denial rate from 18% to under 6% in just one quarter [14], proving that prevention is far more effective than reaction.

FAQs

What should I document to prove medical necessity?

To support medical necessity in behavioral health billing, it’s essential to document the patient’s clinical presentation in detail. This includes noting symptom onset, severity, and duration, as well as outlining any recent stressors and functional impairments. Be sure to justify the timing, frequency, and level of care provided, explaining why intervention is required at this specific moment. Additionally, assess and document any safety risks, such as suicide risk, to reinforce the urgency of care. Clear, detailed documentation not only aligns with payer requirements but also validates the need for the services rendered.

How do I avoid prior authorization and carve-out denials?

To help cut down on prior authorization and carve-out denials, start by verifying benefits to see if behavioral health benefits are handled separately from medical benefits. Use a calendar to track authorizations, keeping an eye on review dates so you can escalate issues before deadlines pass. Dive into denial data – like CARC/RARC codes and appeal results – to spot patterns and refine your workflows. These actions can simplify processes and lower the chances of denials.

What are the key rules for billing telehealth sessions?

When it comes to billing for telehealth services in behavioral health, precision is key. Here’s what you need to know:

  • Accurate Documentation: Clearly record telehealth sessions, including the platform used and the patient’s location during the session. This ensures transparency and compliance.

  • Use Correct Codes and Modifiers: Apply the appropriate CPT/HCPCS codes along with modifiers like GT or 95 to indicate telehealth services.

  • Follow Payer-Specific Requirements: Insurance rules and regulations can vary significantly by state and payer. Double-check the specific guidelines for each insurer to avoid complications.

Staying informed about updates to telehealth billing regulations can help you maintain compliance, reduce the risk of denials, and steer clear of potential audit issues.

Get more behavioral-health operations playbooks

One email a month, no fluff. Unsubscribe anytime.