95250 CPT Code Description: CGM Workflows and BAAs
A device rep leaves two professional CGM readers and a box of sensors at your front desk. Within a week your medical assistants are placing sensors, your clinicians are reading reports, and your billers are submitting claims. Nobody has signed a Business Associate Agreement with the company hosting the report data, and nobody knows who wipes the reader between patients.
That is the situation this guide addresses. The 95250 CPT code description describes a professional continuous glucose monitoring session performed with practice-supplied equipment, and the operational reality behind it touches scheduling, device inventory, cloud vendor management, records requests, and payer audits. If you run a practice that offers professional CGM — endocrinology, primary care, internal medicine, or a diabetes education program — this is your operations and privacy punch list.
The 95250 CPT Code Description in One Paragraph
CPT 95250 describes ambulatory continuous glucose monitoring of interstitial tissue fluid via a subcutaneous sensor for a minimum of 72 hours, using equipment provided by the physician or other qualified health care professional, and includes sensor placement, hook-up, calibration of the monitor, patient training, sensor removal, and printout of the recording. It is the technical component. A separate code covers the analysis, interpretation, and written report. The 95250 CPT code description does not include the interpretation, and it does not describe monitoring performed with the patient's own device. Always verify the current descriptor in the AMA CPT code set your coders license, and confirm coverage and frequency rules against each payer's published policy.
What the 95250 CPT Code Description Assumes About Your Workflow
Read the descriptor as a list of things your staff must actually perform and document. Every clause in it is a work step somebody in your building owns.
The 72-hour minimum is a documentation requirement
Your chart needs the placement date and time and the removal date and time, not just "CGM placed." If a sensor fails at hour 50, your coders need a documented decision path in advance: payers differ on whether a reduced-service modifier applies, whether the session is repeatable, or whether nothing is billable. Write that path into your billing policy and have your compliance lead approve it, so the decision is not made ad hoc by whoever is working the claim edit queue that afternoon.
Patient training is part of the service, so train and record it
The descriptor includes patient training. Build a short training attestation into your intake packet — what the patient was told about showering, adhesive care, logging meals, and who to call if the sensor detaches. Store it in the chart, not in a binder at the nurses' station. When a payer requests records eighteen months later, the binder will not be findable.
Practice-owned versus patient-owned equipment changes the code family
CPT includes a separate code for a professional CGM startup when the patient supplies the equipment, and another for the interpretation and report. Practices determine which code applies by documenting three facts: who owned the sensor and reader, who performed the placement and training, and who authored the interpretive report. Your billers should never infer equipment ownership from the visit type. Put an explicit "equipment source" field in the CGM encounter template and require it.
The Five-Touch CGM Session, With Roles Assigned
Practices that run professional CGM cleanly treat each session as a five-touch workflow with a named owner at each step.
- Scheduling and eligibility (front desk, day −7): confirm benefit, note any payer interval limit on repeat sessions, schedule both the placement visit and the removal visit at the same time. Unscheduled removals are the single largest source of incomplete sessions.
- Placement and training (MA or nurse, day 0): device serial number, sensor lot, placement time, calibration performed, training attestation signed.
- Wear period (patient, days 0–3+): your callback list. Someone owns a day-1 check-in call and logs it.
- Removal and download (MA, day 3–14): removal time, upload to the manufacturer's portal, report generated, report filed to the chart as a discrete document.
- Interpretation and report (clinician, within your stated turnaround): signed, dated, and stored where a records request will find it.
Assign a single owner for the device inventory log. Loaner readers walk out of practices constantly, and the reader is not just hardware — it holds glucose data.
The Vendor Portal Is Where Your PHI Actually Lives
Here is the part that gets skipped. The download from a professional CGM reader almost always passes through the manufacturer's cloud software. That platform receives identifiable patient data — name, date of birth, an internal patient ID, and days of glucose readings — and stores it on your behalf. Under HIPAA that makes the vendor a business associate, and it requires a signed Business Associate Agreement before the first upload, not after.
Practices routinely fail this in three ways. The rep sets up portal accounts during a lunch-and-learn and no contract is executed. The BAA exists but was signed with the distributor, not the software operator. Or a clinic-level account was created under a personal email address, so nobody at the practice can audit who has access.
Run this check today: list every CGM-related platform your staff log into, identify the legal entity behind each one, and confirm you hold a countersigned agreement for each. HHS publishes sample business associate agreement provisions that show the required elements — permitted uses, safeguards, subcontractor flow-down, breach reporting timelines, and return or destruction of PHI at termination. If you find a gap and need a signature-ready document this week rather than next quarter, you can generate a Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for the vendor's signature. One-time purchase, no subscription — which matters when you are papering four device vendors at once.
Two contract terms worth negotiating for device platforms
- Data return and deletion at termination. When you stop using the platform, what happens to three years of glucose reports? Get the answer in writing, with a timeline.
- Notification window for security incidents. "Without unreasonable delay" is the floor. Negotiate a specific number of days so your own 60-day breach notification obligation is not consumed by a vendor's silence.
Loaner Readers, Shared Workstations, and Media Sanitization
A professional CGM reader is reusable media that goes home with patients. Before it is reassigned, the prior patient's data must be off it. Your device log should record, for each session: patient identifier, issue date, return date, and the initials of the staff member who cleared the device. NIST's guidance in Special Publication 800-88, Guidelines for Media Sanitization is the reference your risk analysis should cite for how you clear, purge, or destroy storage media — including small clinical devices.
Then look at the workstation used for downloads. In most practices, one back-office PC has the vendor's desktop utility installed and a Downloads folder full of PDF reports going back years. That folder is unmanaged PHI. Fix it with three controls: full-disk encryption on that machine, a scheduled purge of the local download path, and a documented rule that the chart — not the desktop — is the system of record for CGM reports.
When a Patient Asks for Their CGM Report
The interpretive report and the underlying glucose printout are part of the designated record set. A patient request triggers a 30-day response clock, with one 30-day extension available if you notify the patient in writing of the delay and the reason. Fees are limited to a reasonable, cost-based amount, and you must provide the record in the electronic form and format requested if you can readily produce it. HHS's individual right of access guidance is the document to hand your records clerk.
Two CGM-specific wrinkles catch practices out. First, patients often ask for the raw data file rather than the summary report — if you hold it and can readily produce it, produce it. Second, if the data sits in the vendor's portal and your staff cannot export it, you have an access problem that is yours, not the vendor's. Test the export path before a patient tests it for you.
What about data from the patient's own consumer app?
If a patient shares readings from a personal device or app and your clinician incorporates that data into the chart to inform care, treat it as part of the record from that point forward. Do not let staff accept screenshots by personal text message. Route patient-supplied device data through your portal or a documented secure channel, and note in the chart where it came from.
Payer Audits, Frequency Limits, and Minimum Necessary
Coverage for professional CGM varies by payer, and several payers impose limits on how often a session is payable and require a defined interval between repeat sessions. Do not rely on a rep's summary. Pull the payer's own medical policy, and for Medicare check the Medicare Coverage Database for applicable national and local coverage determinations. Save a dated PDF of each policy in your billing compliance folder so you can show what you relied on at the time of service.
When an audit request arrives, apply minimum necessary. The auditor asked for records supporting a specific date of service; that is not a license to send the entire chart. Build a standard CGM audit packet: the order, the placement and removal documentation, the training attestation, the device log entry, the report, and the signed interpretation. Log the disclosure. Accounting-of-disclosures requests are rare, but the log is also how you reconstruct what left your building if a shipment goes astray.
Ten-Item Checklist Before Your Next CGM Session
- Signed BAA on file with every CGM software platform your staff use.
- Portal accounts issued under practice email addresses, with a named administrator.
- Quarterly access review; terminated staff removed within one business day.
- Device inventory log with issue, return, and sanitization fields.
- Encrypted download workstation with a scheduled purge of local report files.
- Encounter template capturing equipment source, placement time, removal time, and calibration.
- Training attestation stored in the chart.
- Written policy for sensor failure before the documented minimum wear time.
- Dated copies of each payer's current coverage policy.
- Tested patient-facing export path for CGM reports and raw data.
Nothing on that list requires new software. It requires an owner for each line and a date by which it is done.
Where to Start This Week
Pick the two items with the highest exposure: the missing vendor agreements and the unwiped loaner devices. Both are documentable in an afternoon. If your BAA inventory has holes, build the agreements you need and export them for signature before your next device order goes out. If your broader documentation set — risk analysis, policies, workforce training records — has not been refreshed since the CGM program launched, generating an updated compliance document set is the cleaner path than patching a three-year-old binder.
The clinical value of professional CGM is not in dispute. The administrative exposure sits entirely in the paperwork around it, and that part is yours.