A commercial payer emails your billing manager on a Tuesday asking for 40 charts. Every one of them was submitted with the 99203 CPT code. You have 30 days to respond, the notes live in your EHR, your coding is done by a contractor in another state, and nobody on staff can tell you who last edited chart number 17. That is a coding problem, a records-handling problem, and a vendor problem at the same time — and this guide treats it as all three.

Below: how level selection for a new-patient office visit actually gets determined and documented, who in your practice owns each step, and exactly which HIPAA obligations attach the moment that claim leaves your building. This is administrative guidance for administrators and billing staff. Clinical judgment about what a given patient's visit represents stays with the clinician.

What the 99203 CPT Code Covers in Administrative Terms

99203 is one of the new-patient office or other outpatient evaluation and management codes in the 99202–99205 family. "New patient" means the patient has not received a face-to-face professional service from that clinician — or another clinician of the same specialty and subspecialty in the same group practice — within the prior three years. Your front desk registration workflow is what makes that determination auditable, not the note.

Since the office E/M revisions took effect on January 1, 2021, history and physical exam no longer drive the level. They must be medically appropriate and documented, but the level is selected using one of two paths: the level of medical decision making, or total time spent on the date of the encounter. 99201 was deleted in that same revision, so any legacy template or superbill in your practice that still lists it needs to be retired.

The Two Paths, and Why Your Templates Have to Support Both

Path one is medical decision making, scored across three elements: the number and complexity of problems addressed, the amount and complexity of data reviewed and analyzed, and the risk of complications from management options. Payers apply that grid; your job is to make sure the note contains enough substance for a reviewer to follow the clinician's reasoning without guessing.

Path two is total time. For 99203, the range is 30 to 44 minutes of the clinician's time on the date of the encounter, including qualifying non-face-to-face work such as chart review, ordering, and documentation. If your practice permits time-based selection, your documentation standard should require a stated total time — not "approximately 30 minutes" appended by a macro to every note. Auto-populated time statements are the single fastest way to turn a routine payer review into an extrapolated overpayment demand.

Note the practical asymmetry: the prolonged-services add-on for office visits applies only at the highest level of the new-patient family, so time above 44 minutes on a 99203-level encounter has no separate add-on. That matters for how you train staff to read time fields.

How Much Time Does the 99203 CPT Code Require?

Total time of 30–44 minutes on the date of the encounter, when the practice selects the level by time rather than by medical decision making. Time includes the clinician's pre-visit chart review, the face-to-face encounter, documentation, ordering, and care coordination performed that day — but not staff time, and not time already billed under a separate code. When the level is selected by medical decision making instead, time is irrelevant to code selection and should not be the deciding factor in the note.

Who Owns Each Step: Assigning Roles Before the Audit Arrives

Most practices lose coding audits on process, not on judgment. Write down who does what, and date it.

  • Front desk: verifies new-versus-established status against the three-year rule and the same-specialty-same-group test. Documents the check in the registration record.
  • Clinician: selects the level and states the basis — decision making or total time — inside the signed note. Not in a separate spreadsheet, not verbally to the biller.
  • Coder or coding vendor: reviews for documentation support, queries the clinician when the note does not support the submitted level, and records the query and the response.
  • Billing manager: owns the claim submission trail and the payer correspondence file, including every records request and what was sent in response.
  • Privacy officer: owns the vendor inventory, the BAAs, and the audit-log review schedule.

If the coder changes a level after the clinician signs, that change belongs in an addendum with an author and a timestamp — never as a silent overwrite. CMS publishes the Physician Fee Schedule and related payment policy at cms.gov; your internal policy should cite whichever payer rules you actually follow, and be reviewed when they change.

The Claim Is Part of the Chart a Patient Can Demand

Here is where administrators get surprised. The HIPAA designated record set is not just the clinical note. It includes billing and payment records used to make decisions about the individual. When a patient requests their record, the claim showing the 99203 CPT code, the itemized statement, and the payer correspondence are generally in scope.

You have 30 days from the request to act, with one 30-day extension available if you notify the patient in writing of the delay and the reason. You may charge only a reasonable, cost-based fee. HHS has published detailed guidance on the individual right of access, and access failures have been a durable enforcement theme for OCR for years. Practices get penalized for slow and expensive responses far more often than for exotic breaches.

When a Patient Disputes the Level Rather Than the Facts

Patients call about codes. A patient who says "I was only in the room for twelve minutes, so this code is wrong" is making a billing complaint, and possibly a request for amendment under HIPAA. You have 60 days to act on an amendment request, with one 30-day extension.

Train your front desk to route these to one named person rather than answering off the cuff. The staff response should never be an explanation of why the clinical level was appropriate — that is the clinician's determination. The response should be procedural: we received your request, here is the timeline, here is what we reviewed, and here is the outcome in writing. A denial must state the basis and the patient's right to submit a statement of disagreement.

Every Hand That Touches a 99203 Claim Is a Vendor Relationship

Count the parties that see protected health information on the path from encounter to payment. The EHR vendor. The ambient documentation or transcription tool that drafted the note. The outsourced coding firm. The billing company. The clearinghouse. The eligibility-check service. The document-shredding company that destroys your printed remittance batches. Possibly a denial-appeals consultant and a collections agency.

Each of those is a business associate, and each one needs a signed agreement in place before it handles PHI. HHS explains the scope of business associate relationships and required contract terms. Two traps show up repeatedly in practice audits:

  • The clearinghouse assumption. A clearinghouse is itself a covered entity, which leads people to conclude no agreement is needed. When it performs functions on your behalf, it acts as your business associate and the contract requirement applies.
  • The tool nobody procured. A billing supervisor signs up for a free spreadsheet-sharing service or an AI note-cleanup tool to speed through a backlog. No agreement, no risk analysis, no inventory entry. That is an unvetted disclosure, and it typically surfaces during a breach investigation.

If you just realized your coding contractor or your appeals consultant has no agreement on file, close that gap before the next claim batch goes out. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription — which is faster than routing a template through outside counsel for a vendor you onboarded last quarter.

Minimum Necessary When the Payer Asks for 40 Charts

Disclosures for payment purposes do not require patient authorization. They are still subject to the minimum necessary standard, and that standard is where practices over-disclose out of convenience.

When a payer requests documentation supporting encounters billed at a given level, send the records for the dates and patients identified. Do not export entire longitudinal charts because it is one fewer click. Do not include unrelated specialty consults, behavioral health notes, or family history unrelated to the encounter under review. HHS guidance on the minimum necessary requirement expects you to have policies and criteria that limit routine disclosures, not case-by-case improvisation.

Two operational rules worth writing into policy:

  1. Log every payer records request: date received, requester, patients and dates involved, exactly what was sent, by whom, and by what transmission method.
  2. Never fax or email a chart bundle without confirming the destination against the payer's published contact of record. Misdirected records disclosures are a common, entirely preventable breach category.

Payment disclosures are excluded from the accounting of disclosures requirement, but that exclusion does not mean you should keep no internal record. Your request log is what proves the scope of a disclosure two years later when a patient asks what the payer received.

Audit Logs, Late Edits, and the Documentation That Survives Review

The Security Rule requires audit controls and a regular review of information system activity. For coding integrity, those two requirements do real work. Your EHR audit log tells you when a note was signed, whether it was amended afterward, and who did the amending. A pattern of levels being adjusted upward after signature, by someone other than the clinician, is the finding that turns a records review into something worse.

Set a monthly review: pull a sample of new-patient encounters, compare the submitted level to the signed documentation, and check the audit log for post-signature edits. Document that you did it. A reviewer's opinion of your practice changes substantially when you can produce twelve months of self-audit records.

How Long to Keep What

Two separate clocks. Medical and billing record retention is set by state law and payer contract — check yours, and check the longest applicable period rather than the shortest. HIPAA's own six-year retention requirement applies to your compliance documentation: policies, BAAs, risk analyses, training records, breach determinations, and the records of the reviews described above. Practices routinely retain charts diligently and lose the compliance paperwork that proves how those charts were governed. The ONC's health IT resources are a reasonable starting point for EHR-side documentation expectations.

A Two-Week Cleanup for Billing and Compliance Staff

Concrete, assignable, and finishable:

  • Day 1–2: List every vendor and tool that touches encounter, claim, or remittance data. Include anything a supervisor signed up for independently.
  • Day 3–4: Match each entry to a signed BAA. Flag the gaps and stop the data flow to anything unpapered.
  • Day 5: Audit templates and superbills for deleted codes and for auto-populating time statements.
  • Day 6–8: Write the one-page level-selection documentation standard: state the basis, state the total time if time-based, no post-signature silent edits.
  • Day 9–10: Build the payer records request log and the patient access log. Name one owner for each.
  • Day 11–14: Run a ten-chart self-audit of new-patient encounters and file the results.

None of that requires new software. All of it requires someone's name next to it.

Close the Vendor Gap First

Coding accuracy protects your revenue. Records handling protects your license to operate. The 99203 CPT code sits at the intersection: a routine administrative decision that generates a document trail touching six or more outside parties.

Start with the paperwork you can finish today. Draft the missing agreements with the BAA generator, then work through the broader policy and risk-analysis set at hipaa.app so the self-audit records exist before someone asks for them.