Due Diligence Checklist · Telehealth Platform

Telehealth Platform Buyer Due Diligence Checklist

A structured framework for evaluating HIPAA compliance, reimbursement sustainability, technology risk, and revenue quality before acquiring a telehealth business.

Acquiring a telehealth platform requires scrutiny beyond standard SaaS due diligence. Buyers must assess federal and state regulatory compliance, reimbursement model durability, clinical network integrity, and technology infrastructure capable of surviving EHR integration. Post-pandemic normalization has created both opportunity and hidden risk in this sector — revenue that appeared recurring may be tied to COVID-era flexibilities now expiring. This checklist organizes the five highest-stakes due diligence domains for lower middle market telehealth acquisitions in the $1M–$5M revenue range, helping buyers avoid regulatory liability, technology debt, and revenue concentration traps before signing a letter of intent.

CriticalImportantStandard
Find Telehealth Platform Businesses For Sale

Regulatory Compliance & HIPAA

Evaluate the platform's data privacy posture, security audit history, and Business Associate Agreement coverage across all vendor and client relationships.

critical

Request all HIPAA security risk assessments conducted in the last 3 years and any remediation documentation.

Unaddressed security gaps create post-close liability that can exceed the purchase price.

Red flag: No formal risk assessment exists or findings were documented but never remediated.

critical

Verify executed Business Associate Agreements with every vendor, subprocessor, and health system client.

Missing BAAs expose the acquirer to OCR enforcement actions and HHS penalties.

Red flag: BAAs are missing with cloud infrastructure providers, EHR vendors, or major clients.

critical

Review any data breach history, OCR complaints, or state attorney general investigations.

Prior incidents signal compliance culture and create undisclosed indemnification exposure.

Red flag: Any unresolved breach notification obligations or active regulatory investigations exist.

critical

Confirm state telehealth licensing, prescribing authority compliance, and provider credentialing documentation.

Operating without proper state licenses creates immediate shutdown risk post-close.

Red flag: Providers are practicing across state lines without valid licenses or credentialing files.

Reimbursement Model & Revenue Sustainability

Assess whether the platform's revenue depends on permanent payer policies or temporary flexibilities vulnerable to federal and state rollbacks.

critical

Map all revenue by reimbursement source: commercial insurance, Medicare Advantage, direct-to-employer, and self-pay.

Concentration in expiring COVID-era codes signals near-term revenue erosion risk.

Red flag: More than 50% of revenue relies on telehealth-specific CPT codes tied to emergency flexibilities.

critical

Review executed payer contracts including term lengths, renewal options, and reimbursement rate schedules.

Month-to-month payer relationships can be terminated without warning after close.

Red flag: No multi-year payer contracts exist or rates are significantly below market benchmarks.

important

Analyze historical reimbursement denial rates and revenue cycle management performance metrics.

High denial rates indicate billing workflow problems that compress actual realized revenue.

Red flag: Denial rates exceed 15% or the platform lacks a documented appeals process.

important

Request documentation of any direct-to-employer or health system contracts with committed annual spend.

Contracted B2B revenue is more defensible and transferable than fee-for-service volume.

Red flag: No signed employer or health system contracts exist beyond informal purchase orders.

Technology Stack & IP Ownership

Evaluate scalability of the platform's infrastructure, ownership of proprietary code, and integration complexity with EHR and billing systems.

critical

Obtain a technology architecture document covering hosting, APIs, third-party dependencies, and EHR integrations.

Undocumented architecture creates post-close integration risk and unexpected rebuild costs.

Red flag: No architecture documentation exists or core integrations rely on deprecated APIs.

critical

Confirm all source code, algorithms, and clinical workflow IP is owned by the company via assignment agreements.

Offshore or contractor-developed code without IP assignment may not transfer with the sale.

Red flag: Offshore developers hold undocumented contributions with no signed IP assignment agreements.

important

Review software development practices including security testing, version control, and vulnerability patching history.

Poor security hygiene creates HIPAA liability and patient data exposure post-acquisition.

Red flag: No penetration testing history or critical vulnerabilities remain unpatched for over 90 days.

important

Assess EHR integration depth and any revenue-critical dependencies on single third-party platforms.

Single-vendor EHR lock-in can block growth or create contractual restrictions on acquisition.

Red flag: The platform cannot function without a single EHR vendor that has change-of-control provisions.

Customer Concentration & Retention Metrics

Analyze revenue concentration by client, cohort-level churn trends, and patient satisfaction data to assess true revenue quality.

critical

Request a full customer revenue breakdown identifying any client representing more than 20% of total revenue.

Single client dependency creates catastrophic downside if that relationship does not transfer.

Red flag: One health system or employer client accounts for more than 40% of annual revenue.

critical

Review monthly cohort retention, gross revenue churn, and net revenue retention over the last 24 months.

Churn trends reveal whether post-pandemic utilization decline is stabilizing or accelerating.

Red flag: Gross revenue churn exceeds 20% annually or net revenue retention is below 90%.

important

Obtain NPS scores, patient satisfaction survey data, and any published clinical outcomes metrics.

Strong outcomes data supports payer contracting leverage and reduces post-close churn risk.

Red flag: No patient satisfaction or outcomes data has been collected or is unavailable for review.

critical

Confirm that all major client contracts include assignment provisions allowing transfer to a new owner.

Non-assignable contracts may terminate automatically upon a change of control.

Red flag: Key health system or payer contracts contain change-of-control termination rights.

Clinical Operations & Provider Network

Assess provider credentialing infrastructure, network scalability across states, and operational dependence on the founder's clinical relationships.

critical

Review provider credentialing files confirming active licenses, malpractice coverage, and DEA registration where applicable.

Uncredentialed providers create immediate regulatory and liability exposure post-close.

Red flag: Provider files are incomplete, outdated, or credentialing has never been formally documented.

critical

Evaluate whether clinical relationships and platform access are personally dependent on the founder or seller.

Founder-centric operations collapse provider networks and referral pipelines after transition.

Red flag: Key providers will not commit to staying post-close without the founder's personal involvement.

important

Assess geographic footprint of licensed providers and ability to expand into new states without significant cost.

Multi-state provider networks are a core competitive moat that take years to replicate.

Red flag: All providers are licensed in only one or two states with no expansion infrastructure in place.

important

Review clinical protocols, telehealth-specific informed consent procedures, and documented care coordination workflows.

Undocumented clinical protocols create liability and slow post-close operational scaling.

Red flag: No written clinical protocols exist or informed consent procedures are inconsistent across states.

Find Telehealth Platform Businesses For Sale

Vetted targets with diligence packages — skip the cold search.

Get Deal Flow

Deal-Killer Red Flags for Telehealth Platform

  • A single health system or employer client represents more than 40% of annual recurring revenue with no multi-year contract in place.
  • More than half of platform revenue is traceable to COVID-era emergency reimbursement codes with no permanent payer contract replacement strategy.
  • No third-party HIPAA security risk assessment has ever been completed or critical findings remain open and unresolved.
  • Source code was developed by offshore contractors without signed IP assignment agreements, leaving ownership legally ambiguous.
  • Key payer or health system contracts contain change-of-control clauses that allow immediate termination upon acquisition close.

Frequently Asked Questions

Is telehealth platform acquisition typically SBA-eligible?

No. Telehealth platform acquisitions are generally not SBA-eligible due to the passive income characteristics of SaaS-model businesses and the regulatory complexity involved. Buyers should expect to structure deals using private equity, strategic capital, or seller financing with earnouts tied to ARR milestones rather than SBA 7(a) loans.

What revenue multiple should I expect to pay for a telehealth platform in the $1M–$5M revenue range?

Lower middle market telehealth platforms with $1M–$5M in revenue and 70%+ gross margins typically trade between 3.5x and 6x ARR. Platforms with multi-year payer contracts, low churn, proprietary clinical workflows, and documented HIPAA compliance command the higher end. Businesses with reimbursement uncertainty or customer concentration trade toward the lower end of that range.

What is the biggest regulatory risk when acquiring a telehealth platform?

The most acute regulatory risk is HIPAA liability exposure from undisclosed data breaches, missing Business Associate Agreements, or unresolved OCR compliance findings. These violations can survive an asset purchase and expose the buyer to significant federal penalties. A third-party HIPAA audit prior to close is non-negotiable for any serious acquirer.

How do I assess whether a telehealth platform's revenue is truly recurring after COVID?

Request a cohort-level revenue analysis showing monthly retention by client and payer type for the last 24–36 months. Separate revenue tied to emergency-use telehealth reimbursement codes from revenue under permanent payer contracts or multi-year employer agreements. Net revenue retention above 100% indicates genuine expansion within the existing customer base and is the strongest signal of sustainable recurring revenue.

More Telehealth Platform Guides

More Due Diligence Checklists

Start Finding Telehealth Platform Deals Today — Free to Join

Stop cold-searching. Find signal-scored Telehealth Platform targets with seller motivation already identified.

Create your free account

No credit card required