99213 CPT Code Description: Admin and Privacy Guide
A commercial payer sends your office a letter requesting 40 charts. All 40 are established-patient office visits billed at the same level. Your biller forwards the request to a scanning vendor, who uploads the charts to a portal you have never logged into. Nobody checks whether a Business Associate Agreement exists. That sequence — not the coding itself — is where most practices get hurt.
This guide walks through the 99213 CPT code description as an operational matter: what the code represents, how practices document the basis for selecting it, and every point where protected health information leaves your building on its way to a payer. It is written for administrators, billing leads, and privacy officers. It is not clinical guidance, and it does not tell you which code fits which patient.
What the 99213 CPT Code Description Actually Says
CPT 99213 is an office or other outpatient visit for the evaluation and management of an established patient. Under the code set in effect since the January 1, 2021 E/M overhaul, level selection rests on one of two things: the level of medical decision making, or the total time the physician or other qualified health professional spends on the encounter on the date of service.
For 99213, the code descriptor points to a low level of medical decision making, or 20–29 minutes of total time on the date of the encounter. Its neighbors follow the same logic: 99212 for straightforward MDM or 10–19 minutes, 99214 for moderate MDM or 30–39 minutes, 99215 for high MDM or 40–54 minutes.
Two structural changes from the 2021 revision matter to your workflows. First, history and physical exam no longer drive code level — they are performed and documented as medically appropriate, but they do not count toward selection. Second, the old 1995 and 1997 documentation guidelines, with their bullet-counting exam grids, no longer govern office and outpatient E/M. If your templates or internal audit tools still count exam bullets to justify a level, they are auditing against a retired standard.
The three MDM elements, in the order your auditors will look at them
- Number and complexity of problems addressed at the encounter.
- Amount and/or complexity of data to be reviewed and analyzed — external notes, unique tests, independent interpretation, discussion with another professional.
- Risk of complications and/or morbidity or mortality of patient management, including the risk associated with treatment options considered but not selected.
Two of the three elements must be met or exceeded at a given level. That "two of three" rule is the single most common source of internal audit disagreement, and it is why your documentation policy has to require that the note show the clinician's reasoning, not just the outcome.
One licensing note your vendor manager should know: CPT is copyrighted by the American Medical Association. Any vendor that embeds code descriptors, crosswalks, or lookup tables in a product sold to you needs a license to do so. If a low-cost coding tool reproduces full descriptors with no attribution, ask about it before you standardize on it.
How Your Practice Documents Code Selection Without Practicing Medicine
Administrators do not choose codes. Clinicians do. Your job is to build the process that makes the choice defensible and repeatable.
Write a one-page code selection policy that states plainly: the rendering provider selects the level based on MDM or total time; the note must contain enough detail for a reviewer to reconstruct that basis; billing staff may query the provider but may not upcode, downcode, or select a level on the provider's behalf. Have every clinician sign it at onboarding and again after any material change to the code set.
If your providers use time-based selection, the note needs a documented total time on the date of service, and your policy should specify what counts — preparing to see the patient, obtaining and reviewing history, ordering, counseling, documenting in the record, care coordination. Vague phrases like "over 20 minutes spent" invite an audit finding.
The internal audit cadence that actually catches problems
Pull ten established-patient E/M notes per provider per quarter. Score them against the MDM table without looking at the billed level, then compare. Track the variance by provider, not just practice-wide — an aggregate distribution that looks normal can hide one clinician who bills 99213 for everything and another who never does.
Document the audit, the findings, the education delivered, and any refunds issued. That paper trail is what distinguishes a good-faith compliance program from a pattern. Refund obligations for identified overpayments run on their own timeline; loop your billing lead and counsel in early rather than after the third audit cycle.
The Note Behind a 99213 Is a Record You Will Have to Produce
Here is where the coding conversation turns into a privacy conversation. Every E/M note, every claim, and every remittance in your system is protected health information. So is the code itself when it travels with an identifier.
A patient's HIPAA right of access covers the designated record set, and that set includes billing and payment records — not just clinical notes. When a patient asks for "everything you have about my visit," the encounter note, the claim, the EOB, and the payment ledger are in scope. You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS has published detailed guidance on individuals' right to access health information, and OCR has enforced against practices that missed the clock.
Two adjacent scenarios your front desk should be trained on:
- A patient disputes the level billed and asks you to change it. That is a billing dispute, and it goes to your billing lead and the rendering provider. It is not a records request, and staff should not promise a change.
- A patient submits a written amendment request under HIPAA. That is a formal process. You may deny it if the record is accurate and complete, but you must respond in writing within 60 days, explain the basis, and tell the patient about their right to file a statement of disagreement.
Every Party That Touches a 99213 Claim Belongs on Your Vendor List
Trace a single encounter from exam room to deposit and count the entities. Practice management system. EHR. Clearinghouse. Outsourced coding review. Statement printing and mailing service. Patient payment processor. Collections agency. Cloud backup. Document scanning. That is nine business associates for one claim, and most practices have never mapped it.
Each one needs a signed Business Associate Agreement in place before PHI moves. HHS publishes sample BAA provisions that establish the floor, but the sample is a floor, not a contract. Your version should address breach notification timelines shorter than the outer statutory limit, subcontractor flow-down, data return or destruction at termination, and — increasingly — whether the vendor may use your PHI to train models.
If you are still chasing signatures over email threads, a structured six-step Business Associate Agreement wizard that exports signature-ready PDF and DOCX will close the gap faster than another round of attachments.
Offshore coding and after-hours billing support
Offshore coding vendors are common and lawful under HIPAA, but they carry specific diligence obligations. Ask where the data physically rests, whether individual coders work from home on personal devices, how access is logged, and what happens to your records if the contract ends. Some state laws and some payer contracts impose additional restrictions. Get the answers in writing and attach them to the BAA as an exhibit.
AI Scribes and Coding Assistants: The Newest Business Associate
Ambient documentation tools now draft the note that supports the level billed. If a tool listens to an encounter, transcribes it, and suggests an E/M level, it is handling PHI and it is a business associate. No exception applies because the output is a "suggestion."
Before you sign, get written answers to five questions: Does the vendor retain audio, and for how long? Does it use your data to train or improve models, and can you opt out? Who are the subcontractors, including the underlying model provider? What is the breach notification window? Can you export and delete on termination?
Then handle the operational risk. A tool that suggests a level introduces a documentation-integrity question your auditors will ask about. Your policy should state that the clinician reviews, edits, and attests to the note before signature, and that the suggested level is advisory only. Cloned or templated language that repeats verbatim across dozens of encounters is a well-known audit trigger, and generative drafting makes it easier to produce.
Every one of these vendors also belongs in your Security Rule risk analysis — the required assessment of risks to electronic PHI across all systems, not just the EHR. If your last risk analysis predates your scribe tool, your payment processor, and your current clearinghouse, it is out of date. Practices that need to close that gap quickly can generate a current HIPAA risk analysis, policy set, and supporting compliance documentation rather than rebuilding the whole binder by hand.
Payer Audits and the Minimum Necessary Question
When a payer requests 40 charts, disclosure for payment purposes is permitted — but the minimum necessary standard applies to payment disclosures. You are not obligated to ship the entire chart when the request concerns three dates of service.
Build a records-request intake procedure with four steps and assign an owner to each:
- Verify the requester. Confirm the payer, the contract, and the authority for the request. Call a known number, not the one on the letter.
- Scope the request. Identify exact patients, dates of service, and document types. Push back in writing on open-ended requests.
- Log the disclosure. Record what went out, to whom, when, and under what authority.
- Transmit securely. Payer portal or encrypted transfer. Never unencrypted email, never a personal cloud drive.
The failure mode is mundane. Someone assembles 40 charts under deadline pressure, includes records for a patient who is not on the list, and now you have an impermissible disclosure requiring breach analysis. The OCR breach portal is full of incidents that started as ordinary administrative work performed too fast.
A 90-Day Checklist for Billing and Compliance Leads
- Confirm your coding templates and internal audit tools reflect the post-2021 MDM and time framework, not retired exam-bullet guidelines.
- Publish a one-page code selection policy and collect provider signatures.
- Run a ten-chart-per-provider audit of established-patient E/M and log the results.
- Map every vendor that touches a claim, from clearinghouse to statement printer, and reconcile that map against your signed BAAs.
- Get written answers on retention, model training, and subcontractors from any AI documentation vendor.
- Refresh your Security Rule risk analysis to include every system added in the last 18 months.
- Train front desk on the difference between a billing dispute, an access request, and an amendment request — with the applicable clock for each.
The 99213 CPT code description is a two-line descriptor. The operational footprint behind it spans your clinicians, your billers, your vendor contracts, and your response to the next records request that lands. Treat it as a workflow, not a lookup.
If your vendor map and risk analysis are the weakest part of that workflow — and for most practices they are — start there. You can produce a current risk analysis and the full supporting policy set in less time than it takes to schedule the next compliance committee meeting, then spend that meeting on the findings instead of the formatting.