99204 CPT Code: A Practice Admin's Records Playbook
Forty-five minutes. That is the time floor in the published descriptor for the 99204 CPT code, and it is also roughly the amount of time your billing lead will spend reconstructing a single visit when a payer sends a records request eighteen months later.
This guide is for the people who run the practice — administrators, billing managers, privacy officers, and the RCM vendors who support them. It covers what the 99204 CPT code represents administratively, how practices build defensible documentation workflows around it, and — the part most coding articles skip — who touches that note, which of those parties needs a Business Associate Agreement, and what happens when the chart leaves your building.
Nothing here is clinical guidance. Code selection belongs to the treating clinician. Your job is to make sure the record supports whatever they chose and that it does not leak on the way to the payer.
What the 99204 CPT Code Is (Short Answer)
The 99204 CPT code is one of the four new-patient office or other outpatient evaluation and management codes (99202–99205). Under the E/M framework that took effect January 1, 2021, level selection for these visits is driven by either the level of medical decision making or the total time the reporting clinician spends on the date of the encounter — not by history and exam bullet counts. The published criteria for 99204 are a moderate level of medical decision making, or 45 to 59 minutes of total time on the date of the encounter.
History and physical exam still have to be performed and documented as medically appropriate. They simply no longer drive the level. That single change reorganized how practices audit charts, and most of the internal review checklists written before 2021 are now wrong.
The three-year, same-specialty, same-group test
"New patient" is a defined administrative status, not a gut call at the front desk. A patient is new when they have not received a face-to-face professional service from the billing clinician — or from another clinician of the exact same specialty and subspecialty in the same group practice — within the prior three years.
That test has to be run at registration, before the encounter, by someone with a documented procedure. In a single-site solo practice it is trivial. In a twelve-provider multispecialty group with two tax IDs and a shared practice management system, it is a query that crosses entities, and it is a query against protected health information.
The Registration Lookup Is a PHI Access Event
When your scheduler searches the practice management system to determine whether a caller is new or established, they are accessing PHI. Most administrators never think of it that way because the search is instantaneous and feels like a lookup in a phone book.
Three operational consequences follow.
- Role-based access applies. A scheduler needs enough visibility to see prior encounter dates and rendering provider specialty. They do not need the clinical note. If your system only offers all-or-nothing chart access, that is a finding to write up, not a quirk to live with.
- Cross-entity searches need a stated basis. If Entity A queries Entity B's records to establish new-patient status, that is a disclosure. Treatment and payment disclosures are permitted without authorization, but you should be able to name the basis in your policy rather than discovering it during an audit.
- Audit logs matter. The same log that proves a scheduler ran a legitimate eligibility check proves when someone ran an illegitimate one. Sample them.
Write the new-patient determination procedure down. Name the role that performs it, the fields consulted, and where the result is recorded. When a payer later argues the visit should have been billed as established, the contemporaneous record of how you made the call is worth more than anyone's memory.
Time Versus MDM: Two Different Documentation Pipelines
Your practice has to support whichever basis the clinician used. These are not interchangeable paperwork trails, and mixing them is how practices lose audits.
Time-based documentation
Total time on the date of the encounter includes the reporting clinician's face-to-face and non-face-to-face work that day — reviewing records beforehand, ordering, counseling, documenting, care coordination. It excludes clinical staff time and excludes time already reported under a separate code.
Operationally, that means the note needs an affirmative statement of total time by the person who spent it. EHR-generated encounter timestamps are a weak proxy: they capture when a chart was open, not what the clinician did. Practices that lean on timestamps discover, during review, that their strongest evidence is an audit log they never intended to produce and cannot easily redact.
Decide as a practice whether you require a total-time attestation, start and stop times, or both. Then enforce it in the template, not in a reminder email.
MDM-based documentation
Medical decision making is assessed across problems addressed, data reviewed and analyzed, and risk. The data element is where privacy and coding collide: it frequently involves outside records — prior imaging, an outside lab, a specialist's note, a hospital discharge summary.
Every one of those documents has to get into your practice through a release-of-information workflow, get attached to the chart, and then live there. Which brings up the point most billing departments have never been told.
Outside Records Used in MDM Become Part of Your Designated Record Set
Once your clinician reviews an outside record and uses it to make decisions about the patient, that document is in your designated record set. It is subject to the patient's right of access and right to request amendment, the same as a note your own clinician wrote.
Practically: a patient who requests "my records" from your practice is entitled to the outside hospital summary sitting in your chart, not just your own documentation. Your ROI staff cannot route that request back to the hospital and call it done.
The access clock is 30 days from the request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS maintains the current guidance on the individual right of access, and enforcement in this area has been steady and unglamorous — small practices, ordinary requests, missed deadlines.
The Payer Records Request Workflow
High-level new-patient E/M codes draw review attention. That is not an accusation; it is a statistical fact about how payers select samples. If you bill 99204 at volume, plan for additional documentation requests as routine operations, not as a crisis.
Build the workflow once:
- Intake and log. Every request gets a tracking entry: date received, requester, patient, date of service, response deadline. Deadlines in payer letters are shorter than HIPAA deadlines and are the ones that actually cost you money.
- Verify the requester. Confirm the request came from the payer of record through a channel you recognize. Records requests are a known social engineering vector.
- Assemble to the request, not to the chart. Send the date of service requested and the specific supporting documents. Resist the reflex to export the entire chart because it is one click. The minimum necessary standard applies to disclosures for payment.
- Keep an exact copy of what you sent. Not a list — the actual production set, timestamped.
- Route the determination. Denials, downcodes, and takeback notices go to a named owner with a calendared appeal deadline.
One clarification your billing staff will ask about: a health plan requesting records for payment purposes is not your business associate. That is a permitted disclosure between covered entities. You do not sign a BAA with the payer. Disclosures for treatment, payment, and health care operations are also excluded from the accounting-of-disclosures requirement — but log them anyway, because your own audit defense depends on knowing what left the building.
Every Vendor That Touches the Note Needs a BAA
Trace a single new-patient encounter end to end and count the third parties. In a typical practice the list runs longer than the administrator expects.
The usual suspects
- Ambient AI documentation or scribe services. Audio of the entire visit, plus a generated note that may itself carry a suggested code. Business associate. Ask where the audio is retained, for how long, and whether it is used for model improvement.
- Transcription vendors. Business associate, including any offshore subcontractor. Get the subcontractor chain in writing.
- Outsourced coding and RCM. Business associate. They see the full note.
- External chart auditors and coding consultants. Business associate, even when engaged for a one-time review of thirty charts.
- Clearinghouses. Business associate.
- Document storage, fax-to-email, and secure messaging platforms. Business associate.
- Your malpractice carrier or defense counsel reviewing an audit. Typically a business associate relationship; confirm rather than assume.
If you cannot produce a signed, current BAA for every name on that list within an hour, you have a gap that shows up during any OCR inquiry. HHS publishes sample business associate agreement provisions, but sample text is a starting point, not an execution-ready document. When you onboard a new coding vendor or scribe platform mid-quarter and need paper before they touch a chart, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you are papering a single vendor and not building a program.
Retention note: HIPAA requires you to keep required documentation — including BAAs and policies — for six years from creation or last effective date, whichever is later. Medical record retention itself is set by state law and payer contract, not by HIPAA. Keep the two clocks separate in your policy manual.
A Quarterly Internal Review That Takes Four Hours
Do not wait for a payer to tell you your documentation is thin. Run your own sample.
- Pull ten new-patient charts per clinician per quarter, weighted toward the higher levels.
- Check the new-patient determination against the three-year, same-specialty, same-group test. Log any misclassification and whether it changed the code family.
- Check the stated basis. If time, is total time affirmatively documented by the reporting clinician? If MDM, are the problems, data, and risk elements visible in the note rather than implied?
- Check outside records handling. Did reviewed documents get attached to the chart and indexed so ROI staff can find them on an access request?
- Check the vendor trail. If an AI-generated note was edited, is the final signed version the one that would be produced under audit?
Findings go to the clinician and to the template, in that order. Coding education that does not change the template does not change behavior.
Payment Amounts: Look Them Up, Do Not Quote Them
Allowed amounts for the 99204 CPT code vary by locality, payer, and year, and they change annually with the Medicare Physician Fee Schedule. Do not let anyone in your practice circulate a memorized dollar figure. Pull the current values from the CMS Physician Fee Schedule Look-Up Tool and rebuild your fee schedule analysis each January.
If your practice is modeling revenue impact by shifting visit-level distribution, keep that analysis out of clinician-facing communications. A spreadsheet showing the revenue delta between code levels, forwarded to the people selecting those levels, is the single worst exhibit a practice can hand an auditor.
What Goes in the Binder
By the end of this quarter, a compliance lead should be able to produce, on demand: the written new-patient determination procedure, the documentation standard for time and MDM attestations, the payer records request log with response copies, the ROI procedure covering outside records in the designated record set, and a current BAA for every vendor that touches an encounter note.
If assembling that set means opening six folders and emailing two former employees, start with the vendor inventory — it is the fastest gap to close and the one most likely to appear in an OCR data request. You can review reported incidents and their causes on the OCR breach portal to see how often vendor relationships sit at the center of them.
Then close the paperwork gap: build the BAAs you are missing for the coding, scribe, and storage vendors on your list, and if your broader policy set and risk analysis are also overdue, the full compliance document set is the next thing to schedule. A defensible 99204 CPT code claim is a documentation problem and a vendor problem before it is ever a coding problem.