Skip to main content
v2026.11,772 entries · CC-BY 4.0

Telemedicine Credentialing by Proxy: The 482.12(a)(8)-(9) Pathway

How the 42 CFR 482.12(a)(8)-(9) proxy pathway lets a hospital rely on a distant-site hospital or telemedicine entity’s own credentialing decision, what the written agreement has to establish, and why the adverse-event feedback duty back to the distant site does not go away.

Ask CASRAI · included with Regulatory Radar

Ask about Telemedicine Credentialing by Proxy: The 482.12(a)(8)-(9) Pathway

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Written and maintained by CASRAI Editorial Board

Last updated

Credentialing by proxy is the mechanism that lets a hospital rely on a distant-site hospital’s or telemedicine entity’s own credentialing decisions instead of independently re-credentialing every telemedicine practitioner itself — it exists at 42 CFR §482.12(a)(8) and (a)(9), and it is optional, not a shortcut a hospital has to take. Without it, an originating hospital with telemedicine agreements across a dozen specialties would have to run its own full credentialing and privileging process, criteria by criteria, for every practitioner at every distant site — duplicating work the distant site has typically already done. Proxy credentialing lets the originating hospital’s governing body grant privileges based on the distant site’s own credentialing decision, provided specific conditions are met.

Scope. This describes the federal Condition of Participation and the parallel Joint Commission accreditation standard as published. It is not legal advice and does not confirm that a specific written agreement satisfies a specific surveyor on a specific day — confirm current agreement language with legal counsel and your accreditor before relying on it.

Two distinct pathways, not one rule

482.12(a) treats a distant-site hospital and a distant-site telemedicine entity (a group practice, a physician staffing company, a telehealth vendor — anything that is not itself a hospital) as two separate cases, each with its own paragraph:

  • 482.12(a)(8) — distant-site hospital. The written agreement must specify that the distant-site hospital’s own governing body is responsible for meeting the credentialing and privileging requirements in 482.12(a)(1)–(7) for its physicians and practitioners providing telemedicine services. The originating hospital’s governing body may then grant privileges to those practitioners based on its medical staff’s recommendations, and those recommendations may rely on the distant-site hospital’s credentialing information rather than being independently re-derived.
  • 482.12(a)(9) — distant-site telemedicine entity. Because the entity is not itself a Medicare-participating hospital, the agreement instead treats it as a contractor of services under 482.12(e) — it must furnish the contracted telemedicine services in a manner that lets the originating hospital continue to comply with all applicable Conditions of Participation, including the same (a)(1)–(7) credentialing criteria applied to the entity’s own physicians and practitioners.

The distinction matters at the drafting stage: an agreement written for a distant-site hospital under (a)(8) will not, on its own, cover a telemedicine staffing company correctly — the contractor language and the compliance-flow-through language in (a)(9) has to be there instead.

What the written agreement actually has to establish

Both pathways route back through the same underlying governing-body obligations that apply to any medical staff appointment. 42 CFR §482.12(a)(6) requires the governing body to “ensure the criteria for selection are individual character, competence, training, experience, and judgment,” and 482.12(a)(7) prohibits granting staff membership or privileges “solely upon certification, fellowship, or membership in a specialty body or society.” A credentialing-by-proxy agreement does not waive either requirement — it changes who performs the evaluation against them, not whether the evaluation happens. In practice, the agreement needs to name:

  • which pathway applies — (a)(8) hospital-to-hospital or (a)(9) hospital-to-entity;
  • that the distant site’s credentialing and privileging process meets or exceeds the originating hospital’s own medical staff criteria;
  • the scope of privileges being recognized (telemedicine services only, tied to the specific privileges the practitioner holds at the distant site); and
  • the performance-monitoring and reporting obligations described below, since delegating the credentialing decision does not delegate ongoing performance oversight.

The part that gets missed: performance monitoring doesn’t transfer

The proxy pathway is a credentialing shortcut, not a performance-monitoring one. 42 CFR §482.22(a)(3)(iv) and (a)(4)(iv) require that where privileging is delegated under 482.12(a)(8) or (a)(9), the originating hospital must still maintain evidence of an internal review of the distant-site practitioner’s performance of those privileges, and must send that information — at minimum, all adverse events resulting from the telemedicine services and all complaints received — back to the distant site for use in its own periodic appraisal of the practitioner. The obligation runs from the originating hospital to the distant site, not the other way around: the site actually delivering care in front of the patient is the one required to generate and forward the safety signal, precisely because it is the one positioned to observe an adverse event or receive a complaint that the distant site would otherwise never see.

The Critical Access Hospital parallel

Critical Access Hospitals have their own, separately-numbered version of the same mechanism at 42 CFR §485.616(c): the distant-site hospital’s governing body handles credentialing and privileging for the telemedicine practitioner according to the listed criteria. Unlike 485.616(a) and (b) — the CAH network-hospital agreement provisions for referrals, transfers, and shared communications systems, which apply only when the CAH is a member of a rural health network — the (c) telemedicine credentialing standard is not conditioned on network membership. It applies whenever a CAH furnishes services under a distant-site telemedicine agreement, network member or not.

The accreditation layer on top

For Joint Commission-accredited hospitals, the survey standard governing this sits in the Leadership chapter (LD.04.03.09), which requires the same underlying discipline the federal rule does: every licensed independent practitioner responsible for a patient’s care, treatment, or services delivered via a telemedicine link must be credentialed and privileged, and where the originating hospital relies on the distant site’s credentialing decision, it must be monitoring the contracted telemedicine service against defined performance expectations, not simply accepting the distant site’s file and moving on. A distant-site telemedicine entity (as opposed to a distant-site hospital) generally needs to itself be either Joint Commission-accredited or enrolled in the Medicare program for the originating hospital to rely on its credentialing decision under the accreditation standard, mirroring the federal (a)(9) contractor-compliance requirement above. Confirm the current Element of Performance wording directly with Joint Commission before finalizing agreement language — accreditation standards are revised on their own cycle, independent of the federal rule.

Where proxy credentialing doesn’t fit

The mechanism only removes duplicate credentialing work — it does not remove the originating hospital’s own governing-body accountability. A governing body cannot proxy its way out of 482.12(a)(6)’s character/competence/training/experience/judgment standard, cannot rely on a distant site whose own credentialing process is weaker than its own, and cannot use the agreement to grant privileges broader than what the practitioner actually holds at the distant site. And because the performance-monitoring duty in 482.22 runs independently of the credentialing pathway, a hospital that adopts credentialing by proxy specifically to reduce administrative burden should not expect it to reduce the ongoing incident-reporting and periodic-appraisal workload — that part of the job stays exactly where it was.

Frequently asked questions

Is credentialing by proxy mandatory?

No. 482.12(a)(8) and (a)(9) describe a permitted alternative to full independent credentialing; a hospital’s governing body can still choose to fully credential every distant-site telemedicine practitioner itself instead of relying on the distant site’s decision.

Does credentialing by proxy apply to non-hospital telemedicine vendors?

Yes, but under the separate (a)(9) pathway rather than (a)(8) — the entity is treated as a contractor under 482.12(e), and the agreement has to establish that its own credentialing process meets or exceeds the originating hospital’s (a)(1)–(7) criteria.

Who is responsible for reporting an adverse event involving a telemedicine practitioner — the originating hospital or the distant site?

The originating hospital. Under 482.22(a)(3)(iv)/(a)(4)(iv), the site where the care was actually delivered is the one required to maintain the performance review and forward adverse-event and complaint information to the distant site for that practitioner’s periodic appraisal.

Does a Critical Access Hospital use the same regulation as a full-service hospital?

No — CAHs have their own citation, 42 CFR §485.616(c), which establishes an equivalent distant-site credentialing standard that is not tied to CAH network membership, unlike the neighboring 485.616(a)/(b) provisions.

Related reading: medical staff bylaws requirements, the credentialing and privileging process, delineation-of-privileges forms, CMS Conditions of Participation for hospitals, Critical Access Hospital Conditions of Participation, what is Joint Commission accreditation, deemed status and the CMS-accreditor relationship, and Evidence of Standards Compliance submissions. For the survey-readiness landscape this sits inside, see the patient safety pillar.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.