10120 CPT Code: Records, Vendors, and Audit Trails
A patient walks into your urgent care at 4:40 p.m. with a metal fragment in the forearm. Twenty minutes later the provider has removed it, a medical assistant has taken three photographs on a shared tablet, the fragment is sitting in a specimen cup, and someone has written a procedure note. By Friday, that encounter has touched your EHR, your billing company, a clearinghouse, a photo library, and possibly a police report. The 10120 CPT code is the billing shorthand for the clinical event — but the operational and privacy footprint is much wider than one line on a claim.
This guide is for the administrator, biller, or privacy officer who owns that footprint. It covers what the code describes, what documentation your coders need in front of them, and exactly where the PHI generated by these encounters leaks out of your control.
What the 10120 CPT Code Describes — a Short Answer
CPT 10120 is the code for incision and removal of foreign body, subcutaneous tissues; simple. Its companion, 10121, describes the same procedure when it is complicated. Both live in the integumentary surgery section of CPT, and both are separate procedural services — not evaluation and management.
Whether a given encounter meets the definition of "simple" or "complicated" is determined by the provider's documentation and your coder's application of CPT and payer rules to that documentation. Your job as an administrator is not to decide the answer. It is to make sure the note contains enough detail that the answer is defensible, and that nobody is guessing.
What coders look for in the note
- Anatomic site and laterality, stated specifically
- Depth — dermal, subcutaneous, deeper — and what tissue planes were entered
- Whether an incision was made, versus superficial extraction without incision
- Anesthesia used, type and volume
- Identity and disposition of the object removed
- Extent of exploration, dissection, irrigation, or debridement performed
- Closure, if any, and closure materials
- Time, complications, and post-procedure instructions
Missing depth and missing incision language are the two gaps that generate the most coder queries in practices I have audited. Build both into your procedure note template so the provider has to affirmatively address them.
Global period and bundling — verify, don't remember
Minor surgical codes carry global period indicators that govern whether a same-day or follow-up visit is separately reportable. Do not run your billing rules off a coder's memory or a five-year-old cheat sheet. Pull the current global days, status indicator, and relative values for the code from the CMS Physician Fee Schedule Look-Up Tool, and note the retrieval date in your internal coding reference. Payers change policy; your documentation of what you relied on is your defense.
The same discipline applies to modifier use when a separately identifiable evaluation happens alongside the procedure. That is a documentation-supported determination made encounter by encounter, not a default setting in your practice management system. If your billing software auto-appends modifiers, find that setting this week and confirm a human reviews it.
The Documentation Packet One 10120 Encounter Generates
Think of the encounter as producing a packet, not a note. Every item in the packet is PHI, and every item has a different storage location and a different retention risk.
- The procedure note. In the EHR, ideally on a structured template.
- Informed consent. Often paper, often scanned late, often the item missing when a payer audits.
- Wound photographs. Before, during, after. The highest-risk artifact in the packet.
- Specimen record. If the object went to a lab or was retained, there is a chain of custody.
- Immunization record. Tetanus status and any administration.
- The claim. Which travels to your billing vendor and clearinghouse with diagnosis codes attached.
- Any external request. Employer, workers' compensation carrier, law enforcement, or the patient's attorney.
When a payer requests records for a foreign body removal claim, they typically want items 1 through 5. If your consent forms live in a scan queue and your photographs live on a device, you will assemble that packet by hand under a deadline. That is how records get emailed from personal accounts.
Wound Photographs Are PHI, and Your Camera Roll Is Not a Chart
Foreign body removals produce clinical photography more often than almost any other minor procedure. Photographs of an identifiable wound, tied to a date of service and a patient name in the filename, are protected health information. Where they sit determines your exposure.
Three failure patterns show up repeatedly:
- Personal phones. A medical assistant photographs the wound, texts it to the provider, and the image auto-syncs to a consumer cloud backup outside your control. You now have PHI in an environment with no agreement and no audit log.
- Shared clinic tablets. Images accumulate in a general camera roll, viewable by anyone who picks up the device, and are never deleted after upload.
- Desktop folders. Someone builds a "Wound Photos 2026" folder on a workstation for "before and after" comparisons. It gets backed up somewhere nobody documented.
The fix is procedural and cheap. Photographs are captured only through the EHR's native capture function or an approved managed device, uploaded to the chart before the patient leaves, and deleted from local storage as part of room turnover. Assign that deletion step to a named role — the person who cleans the room — and audit ten charts a month against device storage. The HHS Security Rule guidance library is a reasonable starting point when you write the device policy that backs this up.
One more item: if your practice uses photographs for anything beyond treatment, payment, and operations — teaching slides, a website gallery, a conference talk — you need a HIPAA authorization, not the general consent to treat. Marketing use of a wound photo without authorization is a straightforward, easily proven violation.
Where the Removed Object Goes — Specimens, Evidence, and Disclosure Logs
The foreign body itself creates a records question most practices have never written down. Three destinations, three different rules.
To a pathology or reference lab
The lab is a covered entity receiving PHI for treatment purposes. That disclosure is permitted, and it does not require a business associate agreement. Log the requisition, and make sure your specimen labeling process does not leave requisitions with full identifiers sitting in an unlocked courier box.
Returned to the patient
Document that you did it, in the note. "Fragment returned to patient" closes the chain of custody question before an attorney asks it six months later.
Requested by law enforcement
A metal fragment from an assault, or any object with evidentiary value, will eventually draw a request. Your staff should not hand over the object, the photographs, or the record on the strength of a badge at the front desk. Route every law enforcement request to the privacy officer, in writing, and check it against the permitted-disclosure conditions in the HHS guidance on disclosures to law enforcement. Then record the disclosure in your accounting log, because these are exactly the disclosures a patient later asks about.
The Vendor List Behind a Single 10120 CPT Code Claim
Run the encounter forward and count the third parties. In a typical small practice, a foreign body removal claim passes through:
- The EHR and practice management platform (business associate)
- A hosting or cloud infrastructure provider underneath it (subcontractor business associate)
- A transcription or ambient documentation service, if the note was dictated (business associate)
- Your outsourced billing company (business associate)
- The clearinghouse (business associate)
- An e-fax or secure messaging service used to send records to the payer (business associate)
- A coding audit consultant who reviews procedure claims quarterly (business associate)
- An answering service that took the post-procedure callback (business associate)
- A collection agency, if the patient balance ages out (business associate)
- The reference lab (covered entity, treatment disclosure — no BAA)
That is eight or nine agreements for one splinter. When I ask administrators to produce signed, current BAAs for that list, the gaps are almost always in the same three places: the e-fax service somebody signed up for with a credit card, the coding consultant retained on a handshake, and the answering service inherited from the prior office manager.
If you find a gap, close it before the next claim goes out. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than routing a redline through counsel for a $40-a-month fax vendor. Keep the executed copies in one indexed folder with renewal dates, not scattered across email.
While you are in the vendor file, verify that each BAA actually addresses subcontractors, breach notification timelines that let you meet your own 60-day obligation, and return or destruction of PHI at termination. A signed agreement with none of those terms is decoration. Practices that also need the surrounding policy set and risk analysis documentation can automate the full compliance document set rather than rebuild it in a word processor each year.
Records Requests: The 30-Day Clock, and Whether Photos Are Included
They are included. A patient's right of access covers the designated record set, and clinical photographs used in treatment decisions sit inside it. So does the procedure note, the consent, and the billing record.
Your obligations, in operational terms:
- Act on the request within 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
- Provide the records in the form and format requested if readily producible — including electronic images to a specified email address, after you have advised the patient of the risk of unencrypted email.
- Charge only a reasonable, cost-based fee. Labor for copying, supplies, postage, and preparation of an explanation if requested. Not search time, not retrieval time, not per-page schedules that exceed actual cost.
The HHS individual right of access guidance is the document to hand your front desk. Right-of-access complaints have been an OCR enforcement priority for years, and the typical fact pattern is mundane: a patient asked for images, the practice sent only the narrative note, and nobody logged the request.
Payer and audit requests are different
Disclosures for payment purposes are permitted without authorization, but send only the dates of service and documents actually requested. Pulling the entire chart because it is easier to print is a minimum necessary problem. Assign one person to fulfill payer requests, keep a log with the request date, the responder, and exactly what was sent, and set a calendar reminder for appeal deadlines.
A Two-Week Fix List for Your Practice
- Template. Add mandatory fields for depth, incision, anesthesia, object disposition, and closure to your foreign body removal note. Owner: clinical lead.
- Photography. Ban personal devices in writing, route capture through the EHR, and add camera-roll clearing to room turnover. Owner: office manager.
- Vendor inventory. List every third party that touches these claims, match each to an executed BAA, and close the gaps. Owner: privacy officer.
- Fee schedule reference. Refresh global periods and status indicators from the CMS tool, date-stamp the reference, and disable blind auto-modifier logic. Owner: billing lead.
- Request routing. One inbox for patient access requests, one for payer requests, one escalation path for law enforcement. Log all three. Owner: privacy officer.
None of this is exotic. It is the difference between a clean, auditable encounter and a scramble that ends with wound photographs on someone's phone and no agreement covering the fax vendor that sent them.
Start with the vendor list, because it is the item you can finish this week. Pull your contracts, find the services with no agreement on file, and put a signature-ready BAA in front of each one before the next batch of claims leaves your office.