On a normal Tuesday your courier picks up eleven specimens from the back office. Each one leaves the building attached to a requisition carrying a patient name, date of birth, account number, ordering provider, and diagnosis codes. Your billing team may or may not have attached the 99000 CPT code to those encounters, and if they did, most of those line items will be denied or bundled.

This guide is for the administrator who owns both sides of that transaction: the charge capture rules that determine whether specimen handling gets reported at all, and the vendor and records-handling exposure created every time a labeled tube walks out your door. Coding decisions belong to your providers and coders. Building the policy, the documentation trail, and the vendor paperwork around them belongs to you.

What the 99000 CPT Code Covers — and What It Doesn't

CPT 99000 describes handling and/or conveyance of a specimen for transfer from the physician's office to an outside laboratory. It is a practice-expense code. It represents the office's work in packaging, labeling, logging, and arranging transport — not the collection procedure itself and not the lab analysis.

Three things it is not: it is not a venipuncture code, it is not a lab test code, and it is not a code that describes anything a clinician does to a patient. When the specimen is analyzed in your own office, there is no conveyance to an outside lab, and the handling premise disappears. That distinction drives most of the denial patterns your billers will see.

The short answer administrators keep searching for

Can you bill 99000? You can report it. Whether anyone pays it is a payer-by-payer question, and the answer is usually no. Medicare treats specimen handling as part of the practice expense already built into the office visit and does not make separate payment; commercial payers vary, with many following the same bundling logic through their own edits. Verify the current payment status yourself rather than relying on a coding forum — the CMS Physician Fee Schedule Look-Up Tool shows the status indicator and payment policy indicators for any HCPCS/CPT code by year.

Building a Written Charge-Capture Policy Instead of a Habit

Most practices do not have a policy on the 99000 CPT code. They have a habit — someone turned it on in the charge master in 2019, and it has been generating denials ever since, or someone turned it off and the practice never revisited it.

Habits fail audits. Written policy survives them. At minimum, your policy should state:

  • Which payers in your contract mix have a published policy on specimen handling, and where that policy is stored with a review date.
  • Who verifies that a specimen actually left the office for an outside lab before the charge is released — usually a clinical staff attestation in the encounter note or a courier manifest entry, not a coder's assumption.
  • Whether the practice bills patients for handling when a payer denies it as non-covered versus bundled, and what the financial policy says about that.
  • Who reviews the denial pattern quarterly and has the authority to suppress the charge.

The last item matters more than it sounds. If a code generates a 95% denial rate and nobody has authority to stop it, your practice is spending staff time on rework and, worse, sometimes shifting the balance to patients without a documented rationale. That is how a billing question becomes a complaint question.

The patient-balance trap

A bundled denial and a non-covered denial are not the same thing. Bundled generally means the payer considers the service paid within another line and the patient owes nothing. Non-covered may permit patient billing, but only if your participation agreement allows it and — for Medicare beneficiaries in the relevant circumstances — the notice requirements were met before the service.

Train your billers to read the remark code, not the dollar amount. A handling fee that lands on a patient statement without contractual support is a refund obligation and a credibility problem at the front desk, where your staff will absorb the call.

Every Specimen That Leaves Is a Disclosure of PHI

Here is where the operational story gets more interesting than the coding one. The workflow described by the 99000 CPT code is, in HIPAA terms, a routine outbound disclosure of protected health information that happens dozens of times a week and that almost nobody has documented.

The requisition is the exposure. It typically carries the patient's full name, DOB, address or account identifier, insurance information, ordering provider, and the diagnosis codes supporting medical necessity. It travels in a bag, in a car, driven by someone who does not work for you, sometimes with a stop or two along the way.

Disclosure to the reference lab itself is permitted — that is treatment, and the lab is a covered entity in its own right. You do not need a business associate agreement with the laboratory for treatment-purpose disclosures. The party in the middle is where practices get sloppy.

Is your courier a business associate?

It depends entirely on what the courier does. HHS has taken a narrow view of the so-called conduit exception, describing it as limited to transmission-only services for PHI — the postal service, common carriers, and their electronic equivalents — where any access to the information is transient and incidental to transport. Read the agency's guidance on business associates before you decide.

Apply that to your actual courier arrangement and ask:

  • Does the courier hold specimens overnight in a facility, or is transport continuous and same-day?
  • Does the courier handle, sort, or reconcile requisition paperwork, or only move sealed containers?
  • Does the courier deliver printed results back to your office?
  • Does the courier operate a scanning or manifest app that captures patient identifiers on a device the courier company controls?

Continuous same-day transport of sealed containers looks like a conduit. Overnight storage, paperwork handling, results delivery, or an identifier-capturing app looks like a business associate relationship, and you need a signed agreement. When the analysis is genuinely close, get the agreement — the cost of executing one is near zero and the cost of arguing about it during a breach investigation is not. If you need one on paper this week, a signature-ready business associate agreement is a one-afternoon task, not a legal project.

The other vendors hiding in this workflow

Specimen handling touches more of your vendor list than the courier. The lab's results interface or portal, the interface engine that routes results into your record system, any third-party billing company that sees the requisition data, and the shredding vendor that destroys duplicate requisition copies all sit inside this process. Pull your vendor inventory and check each one against a current, signed agreement with a known expiration date.

If your vendor inventory lives in someone's memory or a spreadsheet last touched two years ago, that is the actual finding. Practices that automate their HIPAA risk analysis and policy documentation tend to catch these routine, high-frequency disclosures precisely because the assessment forces an inventory of every place PHI moves — including the ones that feel too mundane to write down.

Minimum Necessary Applies to the Requisition

Treatment disclosures are not subject to the minimum necessary standard. But the requisition often carries more than treatment data — full insurance details, guarantor information, sometimes an entire face sheet stapled to the back because it was easier than typing.

Audit ten requisitions from last week. If they contain fields the lab does not need to perform and bill the test, trim the template. HHS's minimum necessary guidance is the standard your privacy officer should cite when the clinical team pushes back on removing a field.

Chain of custody as a breach-investigation artifact

Keep a daily specimen manifest — date, time, number of specimens, courier name or ID, and a signature or electronic capture. Most practices already have some version of this for clinical reasons. Fewer treat it as a privacy record.

When a bag goes missing, that manifest determines whether you can identify which patients were affected within your notification timeline or whether you are guessing. A practice that cannot reconstruct what left the building on a given afternoon will end up notifying a wider population than necessary, because it has no basis to narrow the set.

A Thirty-Minute Audit Your Team Can Run This Quarter

  1. Pull 90 days of 99000 CPT code line items. Count paid, bundled, denied, and patient-balance outcomes. If the paid column is empty across all payers, decide deliberately whether to keep reporting it.
  2. Sample five encounters with the charge. Confirm the record shows a specimen was collected and sent to an outside lab, and that in-house testing was not what actually happened.
  3. Check any patient balances that resulted. Match each to a remark code and a contract provision. Refund anything you cannot support.
  4. Name your courier and pull the contract. Determine conduit versus business associate using the four questions above. Document the determination in writing, with a date and a signer.
  5. Photograph a completed requisition, redacted. Circle every data element. Delete the ones the lab does not need.
  6. Verify the manifest exists and is retained. Set a retention period and store it where your privacy officer can reach it without asking clinical staff.

Who Owns What

Assign these explicitly or they will drift. Your billing lead owns the payer policy file and the quarterly denial review. Your clinical supervisor owns the manifest and the requisition template. Your privacy officer owns the courier determination, the vendor inventory, and the agreement expiration calendar. Your practice administrator owns the decision to keep or suppress the charge.

None of this requires a consultant. It requires someone to write down what already happens and check it against the paperwork you should already have.

If the courier question above sent you looking for an agreement that nobody can find, treat that as the starting point rather than the exception. Running a structured risk analysis with the supporting policy set generated alongside it will surface the rest of the routine disclosures your practice makes every week — the ones that never show up on a claim and never get reviewed until something goes missing.