99205 CPT Code: A Practice Operations and Privacy Guide
A payer sends your practice a letter requesting 22 charts for review. Nineteen of them are new patient visits billed at the top level. You have 30 days to respond, and the charts do not live in one place — they live in your EHR, in your billing company's document portal, in an AI scribe's transcript archive, and in a fax confirmation folder somebody set up in 2019.
That is the real problem with the 99205 CPT code. The coding question is only half of it. The other half is that a high-level new patient claim is more likely to be reviewed, and every review pulls protected health information through vendors your compliance file may not fully account for. This guide covers the operational mechanics of the code, then makes the privacy, records-handling, and vendor obligations explicit.
What the 99205 CPT Code Is, in Plain Administrative Terms
The 99205 CPT code is the highest-level office or other outpatient evaluation and management service for a new patient — meaning a patient who has not received professional services from the physician or another qualified health professional of the same specialty and subspecialty in the same group within the prior three years.
Since the 2021 revision of the office visit E/M guidelines, code level is selected on one of two bases: the level of medical decision making documented, or the total time the billing provider spends on the encounter on the date of service. For 99205, CPT specifies high-complexity medical decision making, or 60 to 74 minutes of total time. Above 74 minutes, prolonged service add-on rules apply, and those differ between AMA CPT instruction and Medicare policy.
Your coders and providers determine which basis applies to a given encounter and document accordingly. Administrators do not make that call, and neither does a billing vendor. What administrators own is the process: who selects, who reviews, what the documentation must contain, and where the record travels afterward.
The Two Roads to Code Selection, and What Each Demands From Your Chart
Time-based selection needs a number, a date, and a scope
If a provider selects a level based on time, the note needs the total time spent on the date of the encounter, attributable to that provider. Total time in this context includes qualifying non-face-to-face work performed on the same calendar day — chart review before the visit, ordering, documenting, care coordination — but excludes time billed separately under another code and excludes clinical staff time.
Practically, that means your note template should capture a stated figure and the date, not a template phrase that auto-populates. Auditors treat "greater than 60 minutes spent" appearing identically across 40 charts as a finding. Have your compliance lead run a quarterly query: pull every claim at the top new patient level, list the documented time value, and look at the distribution. If it is one number repeated, fix the template before a payer finds it.
MDM-based selection needs a reviewer to follow the reasoning
When level is selected on medical decision making, the note has to let an outside reviewer trace three elements: the problems addressed, the data reviewed and analyzed, and the risk of complications from management. Data elements in particular are where documentation thins out — a note may reference prior records or an independent historian without making clear that the review actually occurred.
Administrative fix: build a review checklist your coders apply before submission, not after denial. Ten charts a month per provider is enough to detect drift. Log the review, the reviewer, and the outcome, because that log becomes your evidence of a functioning compliance process if a payer or a federal reviewer asks. CMS publishes current physician fee schedule policy and E/M payment rules at cms.gov, and your billing lead should be checking it each January when values and prolonged-service instructions change.
Map Every Party That Touches a 99205 Chart Before It Gets Paid
Take one top-level new patient encounter and trace it. In most independent practices, the list looks something like this:
- The EHR vendor, hosting the note and the audit trail
- An ambient documentation or transcription service, holding the raw audio or transcript
- Your outsourced coding reviewer, if you use one
- The billing company or RCM vendor, holding the claim and often a copy of the note
- The clearinghouse transmitting the 837
- A secure file transfer or fax service used to send records for review
- Your cloud backup provider
- The document management platform your staff uses to store payer correspondence
That is eight business associates for a single claim, and most practices can only name five of them without looking. Every one of them creates, receives, maintains, or transmits PHI on your behalf, which means every one requires a signed business associate agreement before the first record moves.
The subcontractor layer people forget
Your billing company's offshore coding team is a subcontractor. Your ambient scribe vendor's speech-processing infrastructure may sit with a cloud provider under a separate agreement. You are not required to hold a BAA with a subcontractor directly, but you are required to have a BAA with the business associate that obligates it to bind its subcontractors to equivalent terms. Ask for that language in writing. "We're HIPAA compliant" in a sales deck is not a contractual commitment, and no vendor holds a government-issued HIPAA certification — HHS does not certify or endorse compliance products.
The BAA Gap That Surfaces During a Payer Audit
Here is the sequence that catches practices. A payer requests 22 charts. Your office manager, moving fast, uploads them through a portal or emails them to a document-prep contractor who assembles the packet. That contractor is now a business associate. If no agreement exists, you have made an impermissible disclosure — and you did it while trying to demonstrate compliance with a different set of rules.
Same risk with the temp you bring in for two weeks to pull charts, if that person works through a staffing agency rather than as a workforce member under your direct control. Same risk with a coding consultant engaged for a one-off review of your top-level E/M claims.
Before any of those engagements starts, get the agreement signed. If you need one drafted quickly for a new billing vendor, coding consultant, or document service, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when the engagement itself is one-time.
Minimum Necessary When You Send Records for a 99205 Review
Disclosures for payment purposes are permitted without patient authorization, but they are still bound by the minimum necessary standard. A request for documentation supporting one date of service does not entitle a payer to the entire longitudinal chart.
Write a standing procedure. When a request arrives, your records custodian identifies the specific dates of service and the specific elements requested, pulls only those, and logs what was sent. If the request is vague — "all records" — call and narrow it in writing. HHS guidance on the minimum necessary requirement is short enough to attach to your policy as a reference.
Two practical rules for the packet itself: strip out records from other providers that were scanned into the chart unless they are the basis for the data element being reviewed, and never send a batch export that includes other patients' identifiers in headers or index pages. The second one happens more often than anyone admits.
The 30-Day Clock When the Patient Asks for the Same Chart
A patient who receives a large bill after a lengthy first visit frequently asks for the note. That request is a right of access request, and the timeline is 30 days from receipt, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
You may charge a reasonable, cost-based fee limited to labor for copying, supplies, and postage. You may not charge for search and retrieval, and you may not condition release on payment of the outstanding balance. Front desk staff need that stated plainly in training, because refusing records over an unpaid bill is one of the more reliably enforced access failures. Review the HHS individuals' right to access guidance with your team annually.
AI Scribes and Time Documentation: A Specific Exposure
Ambient documentation tools now generate a large share of new patient notes, and they create two problems at the top of the E/M range.
First, the audio recording and transcript are PHI. Ask your vendor three questions in writing: how long is raw audio retained, is it used to train models, and can retention be disabled per-practice. Get the answers into the BAA or an addendum, not into an email thread.
Second, some tools estimate or infer time. A tool's estimate is not the provider's attestation of total time spent. If your note carries a machine-generated time value that the provider never verified, and the claim was leveled on time, you have a documentation problem that will not survive review. Configure the workflow so the provider enters or confirms the figure.
A 90-Day Cleanup Plan With Names Attached
- Days 1–15 — Practice administrator. Build the vendor inventory. One row per vendor: what PHI they touch, BAA on file yes/no, execution date, renewal date, subcontractor language yes/no.
- Days 16–30 — Privacy officer. Close every "no." Prioritize billing, coding, scribe, and file-transfer vendors, since those handle the records most likely to be pulled in a review.
- Days 31–45 — Billing lead. Run a distribution report on new patient E/M levels by provider for the trailing 12 months. Flag outliers for internal review, not for correction — you are looking for documentation gaps, not target percentages.
- Days 46–60 — Compliance lead. Rewrite the records-release procedure with minimum necessary steps, a disclosure log field, and a scripted response for vague payer requests.
- Days 61–90 — Everyone. Train front desk on the 30-day access clock and the no-conditioning rule. Document attendance. Keep it for six years.
What to Log So the Next Review Doesn't Start From Zero
Keep a single audit file per payer request: the request letter, the date received, the list of records sent, who assembled them, the transmission method, the vendor involved, and the response. Six-year retention applies to your HIPAA documentation, and payer contracts frequently specify their own look-back periods.
Practices that lose these reviews rarely lose on coding judgment. They lose because nobody can reconstruct what was sent, when, by whom, or under what agreement. If you are also rebuilding your underlying policy set and risk analysis, tooling that automates HIPAA risk analysis reports and the full compliance document set will get you further faster than another folder of templates.
Start with the vendor list, though. Every 99205 CPT code claim your practice submits is a record that will eventually move through someone else's system, and the agreement governing that movement either exists or it does not. If a vendor on your list has no BAA on file today, draft and export one this afternoon before the next records request arrives.