Understanding the work
What does a telemedicine software development company do?
A telemedicine software development company designs, builds, and supports the software that lets clinicians care for patients remotely. That includes live video visits, asynchronous store-and-forward consults, remote patient monitoring, scheduling and intake, e-prescribing, payments, and the integrations that connect a virtual visit to the EHR, pharmacy, and billing systems.
The video call is the visible part. Most of the work sits around it: confirming who the patient is and where they are, routing them to a clinician licensed in that state, documenting the visit, sending prescriptions, and billing correctly. Our software development company guide covers hiring in general; this page covers what is specific to virtual care.
Telemedicine software is software that delivers clinical services at a distance, through real-time audio and video, asynchronous exchange of images and messages, or remote collection of patient-generated health data, plus the scheduling, prescribing, and billing workflows around them.
How this differs from related work
A video conferencing vendor supplies the call but not the clinical workflow, and EHR vendors may offer built-in virtual visits tied to their own records. A telemedicine software development company builds the patient journey and care model around the call. For the wider landscape of patient apps, payer tools, and FDA questions, see our custom healthcare software development guide.
Types of telemedicine software
Telemedicine products combine a few building blocks: synchronous video visits, asynchronous store-and-forward consults, remote patient monitoring, e-prescribing, scheduling and intake, and payments. Virtual-first clinics use most of them; hospitals often add one or two to an existing EHR. The mix you need decides cost, regulation, and integration work.
| Type | Examples | What drives the effort |
|---|---|---|
| Synchronous video | Urgent care visits, therapy sessions, specialist consults, interpreter or caregiver join-ins | Call quality on weak networks, waiting rooms, multi-party calls, recording consent |
| Asynchronous (store-and-forward) | Dermatology photos, questionnaire-based visits, e-consults between clinicians | Structured intake, image capture and storage, clinician review queues, turnaround tracking |
| Remote patient monitoring (RPM) | Blood pressure, glucose, weight, and pulse oximetry readings sent from home | Device connectivity, data validation, alert thresholds, staff workload, device regulatory status |
| E-prescribing | New prescriptions, renewals, controlled substances where permitted | Certified e-prescribing networks, DEA requirements for controlled substances, drug interaction checks |
| Scheduling and intake | Booking, on-demand queues, eligibility checks, consent forms, location confirmation | State licensure routing, insurance verification, identity checks, accessibility |
| Payments | Copays, self-pay visits, memberships, subscriptions | Payment provider integration, PCI DSS scope, refunds, payer billing |
Scroll the table sideways to see all columns.
Requirements and rules
Telehealth rules that shape the software (as of October 2026)
Five areas of rules matter most for telemedicine software: HIPAA and business associate agreements for video and hosting vendors, state licensure and interstate compacts, DEA rules for prescribing controlled substances, Medicare telehealth coverage, and the FTC Health Breach Notification Rule for apps outside HIPAA. Several have deadlines in 2026 and 2027.
| Rule area | Status | Product impact |
|---|---|---|
| HIPAA for video vendors | Enforcement discretion ended May 11, 2023, with a transition period to August 9, 2023 | Video, chat, and hosting vendors handling PHI need a BAA |
| State licensure | Clinicians generally need a license where the patient is located | Capture patient location at each visit and route to licensed clinicians |
| DEA controlled substances | Telemedicine flexibilities extended through December 31, 2026; buprenorphine and VA telemedicine rules in effect since December 31, 2025 | Prescribing workflows need to switch when flexibilities change |
| Medicare telehealth | Flexibilities extended through December 31, 2027 | In-person visit requirements for tele-mental health return after that date |
| FTC Health Breach Notification Rule | Amended 2024 | Covers many direct-to-consumer health apps not covered by HIPAA |
Scroll the table sideways to see all columns.
HIPAA and video vendors
During the COVID-19 public health emergency, HHS did not penalize providers for using everyday video apps. That enforcement discretion ended May 11, 2023, with a transition period through August 9, 2023. Today, any video, messaging, transcription, or cloud vendor that handles protected health information for a covered entity is generally a business associate. HHS guidance on cloud computing confirms this covers hosting providers too.
Licensure and compacts
Clinicians generally must be licensed in the state where the patient is located during the visit. Compacts reduce the burden: the Interstate Medical Licensure Compact offers physicians an expedited path to licenses in member states, PSYPACT lets psychologists practice telepsychology across participating states, and the Nurse Licensure Compact gives nurses a multistate license. Your platform should store each clinician's licenses and block or reroute visits that fall outside them.
Prescribing controlled substances
The DEA extended its telemedicine flexibilities for prescribing controlled substances through December 31, 2026. A separate buprenorphine telemedicine rule and a VA rule took effect December 31, 2025. A permanent special registration rule had not been finalized as of October 2026. Build prescribing rules as configuration so a telemedicine software development company can adjust them quickly when policy changes.
Medicare and consumer apps
Medicare telehealth flexibilities run through December 31, 2027, after which the in-person visit requirement for tele-mental health returns. Direct-to-consumer apps outside HIPAA may fall under the FTC Health Breach Notification Rule, which treats unauthorized sharing of health data, for example with advertising platforms, as a breach.
This is general information, not legal advice; confirm with healthcare counsel, especially on licensure and prescribing.
Video architecture: WebRTC, video APIs, and low bandwidth
Most telemedicine video runs on WebRTC, either built and operated by your team or consumed through a commercial video API that hides the media servers. Building directly gives control and can lower long-run fees; an API speeds delivery and shifts operations to a vendor that must sign a BAA. Either way, design for weak connections and accessibility.
| Approach | Good fit when | Tradeoffs |
|---|---|---|
| Self-managed WebRTC | Large volumes, specialized workflows, or strict data residency needs | You run media servers (SFUs), TURN relays, monitoring, and scaling |
| Commercial video API or SDK | Faster launch, smaller teams, standard one-to-one or small group visits | Usage fees, vendor dependence, need to confirm BAA coverage and recording storage |
| Embedded EHR or vendor telehealth | Visits that stay inside an existing EHR workflow | Limited control over patient experience and branding |
Scroll the table sideways to see all columns.
Designing for real-world connections and users
- Run a pre-call device and network test, and adapt video quality to bandwidth automatically.
- Offer audio-only or callback fallback where clinically and legally appropriate, and record which mode was used.
- Use TURN relays so calls work behind hospital and corporate firewalls.
- Meet WCAG 2.2 Level AA: keyboard access, screen reader labels, captions, and adjustable text size.
- Support interpreters, caregivers, and multiple clinicians joining the same visit.
For a broader comparison of video platforms and their security models, see our guide to cloud video conferencing services.
Integrating telemedicine with the EHR, pharmacies, and devices
A telemedicine platform is only as useful as its connections. Visits need to read and write the EHR, typically through FHIR R4 APIs and SMART App Launch, send prescriptions through certified e-prescribing networks, bring device readings into the chart for remote monitoring, and pass charges to billing. Plan every connection during discovery.
- EHR context: launch the visit from the EHR schedule with SMART App Launch, pull the problem list and medications, and write notes and orders back.
- E-prescribing: route through an established e-prescribing network; controlled substances add DEA requirements such as identity proofing and two-factor authentication.
- Remote monitoring devices: decide between cellular devices and Bluetooth pairing with the patient's phone, and how readings reach clinicians without flooding them.
- Billing: capture visit modality, location, and duration needed for claims, and keep them editable as payer rules change.
- Identity and location: verify identity and confirm the patient's state at each visit for licensure and prescribing rules.
ASTP/ONC's HTI-4 rule, final August 4, 2025, added certification criteria for e-prescribing and electronic prior authorization. For certification, FHIR APIs, and building on EHR platforms in depth, see our EHR software development guide.
Decisions
Build, buy, or extend a telemedicine platform
Buy a white-label or SaaS telehealth platform when your care model is standard. Extend your EHR's virtual visit features when visits sit inside existing clinics. Build custom when the care model itself is your product, such as a virtual-first specialty service, or when no platform supports your workflows, integrations, or licensure logic.
- Buy if you need video visits fast for an existing practice and can accept the vendor's workflow, branding limits, and per-visit or per-seat pricing.
- Extend if your clinicians live in the EHR and visits must appear on its schedule and in its notes without extra steps.
- Build if asynchronous protocols, multistate routing, RPM programs, or a consumer brand are central to the business.
- Mix by buying video and e-prescribing components and building the intake, routing, and patient experience around them.
A good telemedicine software development company will say when buying is the better answer. Startups should keep the first release small; our MVP development guide covers how to scope it.
How a telemedicine software project runs
An experienced telemedicine software development company adds clinical protocol design, state-by-state rule mapping, video and device testing on real networks, and a staged launch by state or service line to the usual software lifecycle. Clinicians should be involved from the first workshop, because visit flow and documentation decide adoption more than features do.
- Care model and protocolsDefine which conditions you treat virtually, which visit types (video, audio, async), and when patients must be seen in person.
- Rule mappingList launch states, licensure, prescribing limits, and payer rules, and turn them into configurable product rules.
- Vendor and BAA selectionChoose video, messaging, e-prescribing, and hosting vendors and sign BAAs before any PHI flows.
- Design and usability testingTest patient join flows on older phones and slow networks, and test clinician flows during simulated clinic sessions.
- Build and integrateDeliver in short cycles, integrating EHR sandboxes and device feeds early.
- PilotLaunch in one state or service line, monitor call failures and visit times, and fix friction before expanding.
- OperateMonitor call quality, watch policy deadlines, and update rules as flexibilities change.
What drives the cost of telemedicine software
The video call is rarely the main cost. When a telemedicine software development company estimates a platform, the big drivers are EHR integration, e-prescribing, remote monitoring device support, multistate licensure and prescribing logic, accessibility and low-bandwidth design, and ongoing video and hosting fees. Ask for an estimate that separates build effort from run costs.
| Driver | Why it adds effort |
|---|---|
| EHR integration | Sandbox access, vendor review processes, and writing notes and orders back reliably |
| E-prescribing | Network certification, drug databases, and extra controls for controlled substances |
| Remote monitoring | Device procurement and logistics, data validation, alerting, and clinician workload tools |
| Multistate rules | Licensure routing, state-specific consent and prescribing rules, and keeping them current |
| Video approach | Self-managed media infrastructure versus usage-based API fees over the life of the product |
| Accessibility and device coverage | Testing across browsers, phones, assistive technologies, and weak networks |
| Security and compliance evidence | Audit logging, penetration testing, BAAs, and answering customer security reviews |
Scroll the table sideways to see all columns.
This guide does not quote prices. A short paid discovery that produces a rule map, an integration list, and an itemized estimate is the most reliable starting point. The cost section of our main guide explains pricing models.
Contracts, BAAs, and ownership
A contract with a telemedicine software development company should include a BAA covering the developer and every subprocessor that handles PHI, clear ownership of code, accounts, and data, rules for recordings and messages, uptime and support commitments for live clinical sessions, and an exit plan that lets you move patients, history, and integrations to another provider.
- BAA chain: confirm BAAs with the developer and with video, messaging, transcription, and hosting vendors.
- Recordings and transcripts: whether they are created at all, where they are stored, who can access them, and how long they are kept.
- Service levels: uptime targets and incident response suited to live clinical care, with a fallback plan when video fails.
- Ownership: custom code assigned to you; cloud, video API, and app store accounts in your name.
- Exit: exportable visit history, documentation, and configuration, plus transition support.
This is general information, not legal advice; have counsel review your agreements.
How to choose a telemedicine software development company
Choose a telemedicine software development company that has shipped live clinical video in production, understands licensure and prescribing rules, has integrated with EHRs and e-prescribing networks, designs for accessibility and weak connections, and signs a BAA covering its whole vendor chain. A paid discovery or pilot is the best test of fit.
Evaluation criteria
- Production video experienceLive clinical visits at scale, with call quality metrics they can show you.
- Regulatory awarenessThey raise licensure, DEA, and Medicare questions before you do.
- Integration track recordEHR, e-prescribing, and device integrations they have delivered.
- Accessibility and usabilityWCAG 2.2 testing and research with patients who are older or less comfortable with technology.
- Security and BAAsA documented security program and BAAs across subcontractors.
- Operational supportMonitoring and on-call coverage during clinic hours.
Questions to ask a telemedicine software development company
- How do you handle a visit when the patient's video fails mid-call?
- How does your design capture patient location and match it to clinician licenses?
- How would you adapt prescribing workflows if the DEA flexibilities end on December 31, 2026?
- Which video approach do you recommend for us, and what would change your recommendation?
- Which vendors in your stack will touch PHI, and do all of them sign BAAs?
Red flags
- A telemedicine software development company that proposes a consumer video app with no BAA.
- No plan for patient location, licensure, or prescribing limits.
- Demos only on fast office Wi-Fi, with no low-bandwidth testing.
- Recording visits by default without a consent and retention policy.
For general partner selection, see how to choose a software development company, and for monitoring after launch, our guide to cloud security managed services.
Reference
Telemedicine software development company FAQs
Can we use a regular video app for telehealth visits?
Not for visits involving protected health information unless the vendor signs a business associate agreement. HHS enforcement discretion for everyday video apps ended May 11, 2023, with a transition period that closed August 9, 2023.
Do clinicians need a license in the patient's state?
Generally, yes. Clinicians usually must be licensed where the patient is located during the visit. Compacts such as the Interstate Medical Licensure Compact, PSYPACT, and the Nurse Licensure Compact make multistate practice easier, but your platform still needs to check location and licenses.
Can controlled substances be prescribed by telemedicine?
As of October 2026, DEA telemedicine flexibilities allow it through December 31, 2026, and a buprenorphine telemedicine rule has applied since December 31, 2025. A permanent special registration rule had not been finalized, so build prescribing workflows that can change.
How long do Medicare telehealth flexibilities last?
They are extended through December 31, 2027. After that, the in-person visit requirement for tele-mental health services returns, so behavioral health platforms should plan scheduling and tracking for in-person visits.
Should we build on WebRTC or use a video API?
A video API is usually faster for a first release and suits smaller teams, provided the vendor signs a BAA. Self-managed WebRTC gives more control and can make sense at high volume or with special requirements, but you take on media servers, relays, and monitoring.
Does a direct-to-consumer telehealth app fall under HIPAA?
It depends on whether a covered entity offers it or it acts on one's behalf. Apps outside HIPAA may fall under the FTC Health Breach Notification Rule, amended in 2024, and state privacy laws. Confirm the answer with counsel before launch.
What usually costs the most in a telemedicine platform?
Integrations usually cost more than video. EHR read and write access, e-prescribing, remote monitoring devices, and multistate licensure logic all add significant effort, along with accessibility testing and ongoing video and hosting fees.
Sources and further reading
Regulatory dates and standards in this guide come from the following primary sources.
- HHS, Guidance on HIPAA and Cloud Computing
- HHS, Sample Business Associate Agreement Provisions
- HHS, Telehealth policy updates
- DEA, DEA extends telemedicine flexibilities to ensure continued access to care
- Interstate Medical Licensure Compact Commission, Interstate Medical Licensure Compact
- PSYPACT Commission, Psychology Interjurisdictional Compact
- NCSBN, Nurse Licensure Compact
- FTC, Complying with FTC's Health Breach Notification Rule
- ASTP/ONC, HTI rules, including HTI-4
- W3C, WebRTC: Real-Time Communication in Browsers
- IETF, RFC 8825: Overview of Real-Time Protocols for Browser-Based Applications
- W3C, Web Content Accessibility Guidelines 2.2
- US Department of Justice, Guidance on Web Accessibility and the ADA
- HL7, SMART App Launch
About this guide
This guide is published by Crecso as an independent educational resource and is part of our software development guide. It names platforms, standards, and regulations as examples only, is not affiliated with any software vendor or development firm, and does not describe services offered by Crecso. It is not legal, regulatory, or medical advice.
Last reviewed on . If you spot something that has changed, please let us know through our contact page.