Last month a practice manager sent us a photo of a laminated encounter form still taped inside a nurse station cabinet. Top line: 99201 — New Pt, Level 1. The laminate was from 2019. The clinic had switched EHRs twice since then, and the form was still the fastest way for a float nurse to figure out what to check off.

The 99201 CPT code was deleted effective January 1, 2021. It has been invalid for more than five years. If it is still living in your templates, your self-pay price list, your patient estimates, or your archived claim data, you have three separate problems: a claims problem, a records-integrity problem, and a vendor problem. This guide walks administrators and billing staff through all three, with role assignments and a timeline.

The 99201 CPT Code Vanished on January 1, 2021 — Your Systems May Not Know

The AMA's 2021 revision to the office and outpatient evaluation and management family collapsed the new-patient set. Code 99201 was deleted, and the new-patient range became 99202 through 99205. The established-patient range kept its five levels, including 99211.

The reason was structural, not political. Under the revised framework, both 99201 and 99202 mapped to the same level of medical decision making, so one of them was redundant. Level selection moved to either total time on the date of the encounter or medical decision making, and history and exam stopped driving code level.

None of that is optional for your billing operation. Under HIPAA's administrative simplification rules, standard transactions must use the medical code set that was valid on the date of service. Submitting a deleted code on a current claim is not just a denial waiting to happen — it is a defective standard transaction, and your clearinghouse edits should be catching it before it leaves the building. If they are not, that is a finding you own.

Is 99201 Still Valid in 2026? The Short Answer

No. The 99201 CPT code was deleted effective January 1, 2021 and cannot be used for any date of service on or after that date. For new-patient office and outpatient visits, the valid range is 99202–99205. Code selection is driven by total time on the date of the encounter or by the level of medical decision making, as documented by the treating clinician. The code remains historically valid only for dates of service before January 1, 2021, which is why it still appears legitimately in archived claims, old remittance advice, and released records.

Payment rules and relative values for the surviving codes are published through the Medicare Physician Fee Schedule; your billing lead should be pulling the current file rather than relying on a spreadsheet someone built years ago. Start at the CMS Physician Fee Schedule resource and work down to your locality.

Six Places 99201 Is Probably Still Hiding in Your Practice

Deleting a code from a payer's system is one action. Deleting it from a clinic is dozens. Assign one owner per item and give them a due date.

Paper and PDF encounter forms

Superbills, urgent-care fast-track sheets, sports physical forms, laminated cheat sheets, and the after-hours packet in the on-call bag. Front-office supervisor owns the sweep. Physical destruction, not just replacement — an old form in a drawer will resurface.

EHR favorites, macros, and order sets

Most systems purged 99201 from the master code table years ago, but user-level favorites lists, saved charge templates, and custom quick-pick buttons can persist as orphaned entries that either fail silently or drop a blank charge. Your EHR administrator should run a report of user favorites referencing retired codes.

Fee schedules and self-pay price lists

This is the one that reaches patients. If your posted cash price list or good-faith estimate template still quotes a 99201 rate, you are publishing a price for a service you cannot bill. Revenue cycle manager owns it.

Payer enrollment and credentialing packets

Some contract exhibits and delegated-credentialing attachments list procedure codes by practice. Credentialing coordinator flags any exhibit still referencing the deleted code at the next contract cycle.

Training material and new-hire binders

Coding orientation decks, front-desk scripts about visit types, and internal wikis. Compliance lead owns the content review.

Reporting logic and dashboards

Productivity reports, wRVU calculations, and new-patient volume dashboards built before 2021 may still filter on a code that returns zero rows. That looks like a volume drop, and someone will make a staffing decision based on it.

How Your Practice Documents Code Selection Without Steering It

Administrators get into trouble when cleanup drifts into direction. Removing an invalid code from a pick list is administrative housekeeping. Telling a clinician which of 99202–99205 to select is not your role, and a policy that does it creates exactly the pattern auditors look for.

Keep the division clean and write it down:

  • The treating clinician selects the level and documents the basis for it — total time on the date of the encounter, or the elements of medical decision making.
  • Your certified coder or coding auditor reviews documentation against the code submitted and queries when the note does not support what was billed.
  • Practice administration maintains valid code tables, keeps the fee schedule current, monitors distribution patterns, and escalates outliers for education — not for a target.

Distribution monitoring is the piece administrators most often skip. Pull new-patient level distribution by clinician quarterly. You are not looking for a "correct" bell curve. You are looking for a clinician whose pattern shifted sharply without a change in panel or service mix, which is a documentation-review trigger, not an accusation.

The Records Request Problem: Old Dates of Service Still Carry 99201

Here is where a retired code becomes a privacy issue rather than a billing one.

A patient requests a complete billing history. A plaintiff's attorney subpoenas five years of records. A payer opens a retrospective audit reaching back to 2019. All of those responses will legitimately contain the 99201 CPT code, because it was valid for those dates of service. Your staff must not "correct" historical data to a current code. Altering an archived claim record to make it look current is falsification, full stop.

Train your release-of-information staff on two rules. First, historical codes are released as they were recorded. Second, if a requester asks why a code appears that "doesn't exist," the answer is a one-line factual statement about the 2021 code set change — not an interpretation of the visit.

Watch the clock, too. The HIPAA right of access generally requires you to act on an individual's request within 30 days, with one 30-day extension available if you notify the requester in writing. Retrieval from an archived or decommissioned system does not stop that clock. HHS's right of access guidance is the document to hand your ROI clerk.

Retention: don't purge the code out of existence

Cleanup means removing an invalid code from active use. It does not mean deleting historical claim data. HIPAA requires six years of retention for required Security and Privacy Rule documentation, while medical and billing record retention is set by state law and payer contract — commonly longer. If your practice decommissions a legacy billing system, the export you keep must remain readable and searchable for as long as those obligations run. A tape nobody can restore is not retention.

Minimum Necessary: What Billing Data Actually Leaves Your Building

Every code in your system eventually travels. It goes to a clearinghouse, a billing company, an audit vendor, a statement print-and-mail service, an analytics platform, and sometimes a consultant's laptop.

The minimum necessary standard applies to those disclosures. A coding auditor reviewing new-patient E/M documentation needs the note and the claim line. That auditor does not need your full demographic export, your unrelated encounter history, or every patient in the practice. Scope the extract to the sample. HHS's minimum necessary guidance is the standard your data-request approval process should cite by name.

Practical control: require a written data request form for any external code review. Fields — requester, purpose, date range, patient count, fields included, destruction date. Your privacy officer signs before anything exports. Ten minutes of friction prevents the 40,000-row spreadsheet that nobody remembers sending.

The Vendor List Behind Your Code Set

Run this exercise: name every organization that has seen a claim line from your practice in the last twelve months. Most administrators can name four and then stall out. The usual full list runs longer — clearinghouse, RCM or billing service, coding audit firm, EHR host, scanning and document-imaging vendor, statement printer, collections agency, payer-side portal aggregator, and whoever built that custom reporting extract two years ago.

Each of those creates, receives, maintains, or transmits PHI on your behalf. Each one needs a signed business associate agreement in place before the data moves, and each agreement needs to actually address subcontractors, breach notification timing, and what happens to your data at termination. HHS's business associate guidance spells out the required provisions.

The gap is almost never the big vendors. It is the small coding consultant hired for a six-week audit, the temp billing contractor, or the freelance analyst who built the dashboard. If you need an agreement in place before Monday's kickoff call and legal is three weeks out, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — which matters when the need is a single engagement rather than an ongoing program.

A Four-Week Cleanup Plan With Names Attached

Week 1 — Inventory. Billing lead runs a claim-level query for any submission containing 99201 with a date of service on or after January 1, 2021. Zero results is the expected answer; anything else is an immediate remediation item. EHR administrator pulls user-favorites and template reports.

Week 2 — Physical and document sweep. Front-office supervisor collects and destroys paper forms. Revenue cycle manager reconciles the posted self-pay price list and estimate templates against the current fee schedule. Every removal gets logged with date and initials.

Week 3 — Vendor reconciliation. Privacy officer builds the definitive list of every entity receiving claim data, matches each against a signed BAA, and opens a remediation ticket for each gap. Note the contract expiration and the termination-data-return clause while you are in the file.

Week 4 — Training and documentation. Compliance lead updates orientation material, briefs ROI staff on releasing historical codes unaltered, and files the completed inventory as evidence. If your broader policy set and risk analysis are also stale, this is the natural moment to refresh the full compliance document set rather than patching one policy at a time.

What to Keep So an Auditor Can Follow Your Reasoning

The artifact that matters is not a clean system. It is a dated record showing you looked, found what you found, and fixed it. Keep the query output, the destruction log, the vendor reconciliation spreadsheet with signature dates, and the training attendance sheet.

A retired code is a small thing. But an administrator who can produce a four-week remediation file for the 99201 CPT code is demonstrating the exact control an auditor wants to see applied to bigger exposures — and one who cannot produce it is telling a different story.

Start with the vendor column. If any organization on your claim-data list lacks a current signed agreement, close that gap first — build the BAA, get it signed, and file it with the rest of your Week 3 evidence.