A physician walks into your office in April holding a compensation statement and a screenshot from a specialty society forum. She says her new-patient visits are being credited at a lower work value than she expected, and she wants to know which number your group used. You now have two problems: reconciling the 99205 RVU your compensation model applied, and explaining who else has seen the encounter-level report that produced it.

This guide is for the administrator, billing manager, or privacy officer who owns both problems. It covers where relative value units for CPT 99205 come from, who inside your practice should be responsible for keeping them current, and — the part most operations guides skip — the HIPAA obligations attached to every productivity file, coding audit, and analytics vendor that touches those numbers.

What the 99205 RVU Is, in One Paragraph

CPT 99205 is the highest-level office or outpatient evaluation and management code for a new patient. Its relative value units are published by CMS in the Medicare Physician Fee Schedule and consist of three components: work RVUs (physician effort), practice expense RVUs (staff, supplies, equipment), and malpractice RVUs. Since the CY2021 E/M revaluation, the work component for 99205 has been 3.50. Total RVUs differ between facility and non-facility settings, get adjusted by geographic practice cost indices for your locality, and are then multiplied by a conversion factor to produce a dollar amount. Verify every one of those numbers against the current-year RVU file before you use it in a contract or a compensation calculation.

The File You Should Actually Be Pulling

Forum screenshots, vendor slide decks, and last year's spreadsheet are not sources. CMS publishes the relative value files directly, and it updates them quarterly — the January release is superseded by later releases when corrections or new codes land.

Your source of record should be the CMS Physician Fee Schedule page for the RVU files and the Physician Fee Schedule Look-Up Tool for locality-adjusted amounts. Download the file. Save it with the release name and the date you pulled it. That timestamp is what settles the April conversation described above.

Three components, three different reasons they change

  • Work RVUs change when CMS revalues a code through rulemaking. For 99205 this last happened in the E/M overhaul effective CY2021.
  • Practice expense RVUs move more often, because CMS periodically revises its practice expense methodology and its facility versus non-facility allocations.
  • Malpractice RVUs are updated on a slower resource-based review cycle.

Read the current year's final rule summary before you assume a stable number carried forward. Beginning in CY2026, statute also provides for two separate conversion factors depending on whether a clinician qualifies as a participant in an advanced alternative payment model — which means one practice can legitimately compute two different payment amounts from the same RVU total.

Facility versus non-facility is not a rounding error

If your group bills the same new-patient code from a leased suite in a hospital outpatient department and from a freestanding office, the practice expense component differs and so does the total. Compensation models that credit work RVUs only are insulated from this; models that credit total RVUs or collections are not. Document which model you use, in writing, in the compensation plan itself.

Who Owns the 99205 RVU Number Inside Your Practice

Assign this explicitly or it defaults to whoever built the spreadsheet three years ago.

  1. Billing manager — pulls the quarterly RVU file, updates the fee schedule tables, logs the release version.
  2. Practice administrator — validates that payer contracts referencing "a percentage of the Medicare Physician Fee Schedule" specify which year and which release. Contracts that say "current" without a year invite disputes.
  3. Compliance or privacy officer — reviews who receives encounter-level productivity reports and confirms each external recipient is covered by a business associate agreement.
  4. Compensation committee chair — receives only what the model requires, which is usually aggregated totals, not patient-level detail.

Put the four roles on one page with names, not titles. When a clinician challenges a number, you want a named person and a dated file, not a search through shared drives.

Code Selection Is a Documentation Question, Not a Target

Here is the line your practice should never cross: RVU benchmarks describe what was billed, they do not determine what should be billed. The code descriptor for 99205 establishes a medical decision making level and a total-time range on the date of the encounter, and the treating clinician selects the level based on one or the other. Administrators support that process; they do not steer it.

What you can operationally own:

  • A written coding policy stating that level selection rests with the rendering clinician and is supported by the documented encounter.
  • A periodic internal audit sampling new-patient E/M documentation against the selected level, performed by a certified coder.
  • An escalation path when an audit finds a pattern — education first, records-based, documented.
  • A prohibition on productivity dashboards that display target RVU thresholds next to specific unbilled encounters.

Distribution curves that sit far outside specialty norms are a signal to review documentation quality, not evidence of wrongdoing and not an instruction to change behavior. Write that sentence into your policy.

Your Productivity Dashboard Is a PHI System

This is where most practices under-scope their compliance program. A report that lists encounter dates, patient account numbers, rendering provider, CPT code, and diagnosis is protected health information. It does not become something else because finance produced it instead of the clinical team.

Three consequences follow immediately.

Minimum necessary applies to internal distribution

A compensation committee reviewing quarterly work RVU totals per physician does not need patient-level rows. Give them the aggregate. If someone needs to audit the aggregate, that is a defined role with defined access — not a monthly email blast with an attached workbook.

Exports leave your controls behind

The moment a billing analyst exports encounter detail to a spreadsheet and saves it to a laptop, your EHR access controls stop applying. Encrypt endpoints, restrict export permissions, and audit who is pulling large extracts. Personal email forwarding of RVU workbooks is a recurring, entirely preventable breach pattern.

The analytics platform belongs in your risk analysis

The HIPAA Security Rule requires an accurate and thorough assessment of risks to all electronic PHI you create, receive, maintain, or transmit. Business intelligence tools, RCM dashboards, and the reporting server your clearinghouse feeds all qualify. If your last risk analysis inventoried the EHR and nothing else, it is incomplete. Practices that need to rebuild that inventory and the policy set around it can generate a documented risk analysis and the supporting policies rather than starting from a blank template — the value is in having current, dated documentation you can hand to an auditor.

Every Vendor That Touches the 99205 RVU Data Needs a BAA

Walk your revenue cycle end to end and list every organization that sees encounter-level data on the way to producing an RVU report:

  • Your practice management or EHR vendor
  • The clearinghouse transmitting claims
  • An outsourced billing or coding company
  • A third-party coding audit firm
  • Any standalone analytics or benchmarking platform ingesting claim data
  • Consultants building or validating the compensation model
  • Offsite backup and hosting providers for any of the above

Each of those is a business associate and requires a signed agreement before PHI moves. HHS maintains guidance on business associate obligations that is worth re-reading annually, particularly the part covering subcontractors — your billing company's analytics subcontractor is your exposure too.

The clean exception: a compensation consultant who receives only aggregate work RVU totals per physician, with no patient identifiers and no encounter-level rows, is not handling PHI. That is a real design choice, and it removes a vendor from your risk surface entirely. Make it deliberately, and document the data specification you sent them.

If you find a vendor on that list without a current agreement, close the gap before the next data transfer. A signature-ready business associate agreement takes minutes to produce and is a far better use of an afternoon than explaining the omission during an investigation.

Billing Records Are Part of the Designated Record Set

Patients can request their billing records, not just their clinical chart. The designated record set includes billing and payment records used to make decisions about the individual. Your front desk and your billing office need the same answer to that request.

The operational specifics your staff should know cold:

  • You have 30 days to act on a request, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
  • Fees must be reasonable and cost-based, and the permitted components are narrow.
  • You cannot require a patient to explain why they want their billing record.
  • If a patient asks in electronic form and you maintain it electronically, you provide it electronically.

Review the HHS right of access guidance with your records staff annually. Access failures remain one of the most consistently enforced areas of HIPAA, and a billing-side request that never gets routed to the person with the 30-day calendar is a common way practices miss the deadline.

A Quarterly Calendar You Can Actually Run

Month 1 of each quarter: billing manager downloads the current CMS RVU release, updates internal tables, and records the file version and pull date in a change log.

Month 2: compliance officer reviews the access list for the productivity dashboard and any reporting tool, removes departed staff, and confirms export permissions match role.

Month 3: internal coding audit sample reviewed; findings routed to education, not to compensation adjustments.

Annually, after the Physician Fee Schedule final rule publishes: administrator reads the E/M and practice expense sections, models the impact on the compensation plan, and confirms every payer contract referencing the fee schedule names a specific year.

Annually, or after any material system change: update the risk analysis to include every system holding encounter-level data, and re-verify the BAA inventory against the actual vendor list.

The Number and the Record Behind It

The 99205 RVU is a published, verifiable figure. What separates a practice that handles it well from one that does not is the record surrounding it: the dated file, the named owner, the documented compensation methodology, and the vendor agreements covering everyone who saw the underlying data.

If your last risk analysis predates your current analytics stack, or your BAA folder does not match the vendor list you just wrote out, start there. Build the documentation set that turns your risk analysis and policies into current, dated artifacts, then run the quarterly calendar above. The next time a physician arrives with a screenshot, you will have an answer and a file to back it.