Behavioral HealthTech in 2026: AI Risk, FDA Boundaries, and Unlocking DMHT & RTM Reimbursement
Behavioral HealthTech’s New Risk & Reimbursement Landscape: What Boards, Founders, and Investors Must Do Now
When COVID-19 hit, virtual mental health care transformed almost overnight from a novel convenience into an absolute necessity. Outpatient behavioral health facilities offering telehealth jumped from 33% in early 2020 to over 61% a year later. Now in 2026, that shift has created a global digital mental health market projected at $32 billion, with annual growth of 16.4% through 2030.
But with rapid growth comes a new level of regulatory scrutiny. Regulators, payers, and state licensing boards are now looking closely at how Behavioral HealthTech tools integrate compliance into every aspect of their digital health platforms.
Key Takeaway: The Behavioral HealthTech companies best positioned to capture this unique growth opportunity will treat regulatory compliance, patient safety, and billing integrity as core product requirements from the outset, rather than as an afterthought.
AI in Healthcare: From Admin Tool to Treatment
In the context of healthcare, AI often begins as an administrative tool to handle scheduling or serve as a scribe for an office visit, but its role can quickly expand. An AI chatbot that discusses psychiatric symptoms, suggests coping mechanisms, responds to distress, or generates treatment recommendations is likely functioning as a regulated clinical product.
Mental health chatbots create particular risk because users may treat humanlike responses as trusted clinical guidance, even when the product was designed only for general support. Engagement features can also encourage emotional reliance, making implementation of disclosures, crisis safeguards, age controls, and clear boundaries around use especially important.
The AI in Healthcare Risk Governance Spectrum
Low-Risk (Administrative Workflows):
Automated scheduling and administrative patient intake
Ambient scribing (non-diagnostic documentation)
Billing optimization and claims processing
Operational workflow automation
High-Risk (Clinical Interventions / Software as a Medical Device):
Symptom assessment, intake triage, and provisional diagnosis
Interactive therapeutic conversations and coping guidance
Real-time crisis detection and automated escalation handling
Automated generation of clinical treatment plans
Key AI Safety and Risk Management Best Practices
In addition to FDA at the Federal level, states are increasingly regulating mental health chatbots and clinical AI. Requirements vary by state, but common themes include human control over clinical decisions, informed consent, disclosure that users are interacting with AI, crisis-response protocols, limits on health-data use, and protections for minors. In general, best practices include:
Meaningful Human Oversight: "Human-in-the-loop" can’t just be a catch-phrase. If a licensed clinician routinely accepts AI-generated assessments or treatment plans without independent review, they are not truly “in the loop.” Workflows must be designed to actively mitigate automation bias and preserve real clinician accountability.
Thoughtful Product Design and Testing: To reduce the potential for liability, Behavioral HealthTech companies should test foreseeable high-risk interactions, including self-harm, abuse, and medication questions. Clinical review, escalation procedures, age-appropriate controls, incident monitoring, and documented safety decisions should all be part of product development. While disclaimers are important, they won’t mitigate risk for a product that behaves inconsistently with its stated purpose or limitations. And pre-launch testing isn't enough. Post-deployment, a company should implement continuous monitoring for algorithmic bias, accuracy shifts, and adverse clinical events.
Privacy beyond HIPAA: A growing number of states are regulating consumer health data outside of traditional medical records. Many require adequate notice and consent for patient-clinician conversations to be recorded and processed. The Federal Trade Commission regulates consumer health data sharing for purposes of advertising under the Health Breach Notification Rule and the Unfair and Deceptive Trade Practices Act. The FTC’s actions involving BetterHelp and Cerebral addressed alleged health-data sharing for advertising. A 2026 complaint against Hims & Hers raises similar issues and remains pending.
Third-Party Model Governance: A Behavioral HealthTech company’s contracts with Large Language Model (LLM) vendors must strictly govern permissible data uses, model training restrictions, data retention, security, drift, and incident response.
Is it a “Wellness Product” or “Software as a Medical Device”?
Pursuant to FDA guidance, "General Wellness" products fall under a safe harbor and are not actively regulated. FDA’s general wellness guidance applies to low-risk products intended to maintain or encourage a healthy lifestyle. Software that moves into diagnosing, treating, mitigating, or preventing a disease or condition can fall outside that category and may be considered Software as a Medical Device (“SaMD) by FDA.
Bottom line? The label you choose matters less than the actual product experience.
Revenue & Reimbursement Strategy: Navigating DMHT and RTM Codes
Building a Behavioral HealthTech tool is only half the battle. The other half is identifying a viable business model to pay for it. While Medicare has opened various pathways to reimburse digital behavioral health interventions, commercial adoption has been lacking.
CMS has established specific code sets aimed at digital behavioral health, including:
Digital Mental Health Treatment (DMHT) Codes (HCPCS G0552–G0554): These codes are designed for FDA-cleared prescription digital therapeutics (PDTs) or SaMD used under an established behavioral health treatment plan. G0552 covers the supply of the digital mental health device and initial onboarding, while G0553 and G0554 cover monthly clinician treatment management time.
Remote Therapeutic Monitoring (RTM) for CBT (CPT 98975, 98978, 98980–98981): This code set covers device setup and patient onboarding, device supply, and treatment management for tracking patient therapy adherence and response to Cognitive Behavioral Therapy (CBT).
Investor and Board Due Diligence
Before investing in or acquiring a Behavioral Health Technology company, stakeholders should understand:
How the company classifies its products and AI features
Whether safety testing covers minors, self-harm, and vulnerable users
Where patient/consumer health data flows
Whether clinical and marketing claims have adequate support
Whether reimbursement exists to support the services provided
Frequently Asked Questions (FAQs)
What is the difference between Remote Therapeutic Monitoring (RTM) and Digital Mental Health Treatment (DMHT) codes?
RTM codes (e.g., CPT 98978, 98980) monitor non-physiological data—such as therapy adherence and symptom response for Cognitive Behavioral Therapy (CBT). DMHT codes (HCPCS G0552–G0554) were established specifically for FDA-cleared prescription digital therapeutics or SaMD used under a formal behavioral health care plan.
Can a digital mental health startup bill Medicare for an AI conversational chatbot?
Not directly. To bill under the DMHT codes, the underlying software must have FDA clearance as a medical device and must be furnished by a credentialed billing practitioner as part of an established care plan, with interactive human management time.
How does the FTC regulate Software as a Medical Device apps that fall outside of HIPAA?
The FTC enforces the Health Breach Notification Rule (HBNR) and Section 5 of the FTC Act. Sharing sensitive health data with third-party ad networks without explicit consent, failing to secure consumer health data, or making unsubstantiated health claims constitutes deceptive trade practices subject to enforcement actions and civil penalties.
How Nixon Law Group Can Help
Nixon Law Group helps behavioral health technology companies translate emerging AI, privacy, licensing, and reimbursement requirements into practical product and operational controls. We work with founders, executives, investors, and boards to manage risk while supporting growth.
Contact Nixon Law Group today to schedule a consultation with our team.