99245 CPT Code: Consult Billing and Privacy Workflow
Your specialty office pulls a fax at 8:14 a.m.: a primary care physician asking for an opinion on a patient's arrhythmia workup. That one page decides whether the encounter your physician documents three weeks later can be billed as a consultation at all — and whether a claim carrying the 99245 cpt code survives a payer review nine months from now.
This guide is for the administrator, biller, or privacy officer who owns that workflow. It covers what the consultation family requires administratively, which payer rules change the answer, and — the part most practices skip — the records-handling and vendor obligations created every time a consult request comes in and a written report goes back out. No clinical guidance here. Code selection belongs to your clinicians and certified coders; your job is making sure the documentation, routing, and safeguards exist to support whatever they select.
What the 99245 CPT Code Requires Before You Bill It
99245 is the highest-level code in the office or other outpatient consultation family (99242–99245), reportable for a new or established patient. Under current CPT guidance, level selection rests on either the level of medical decision making documented or total time spent on the date of the encounter — 55 minutes or more for 99245. Beyond level selection, every code in the consultation family carries three administrative requirements:
- A request. Another physician or an appropriate source must request an opinion or advice, and that request must be documented in the patient's record.
- A reason. The record must state why the opinion was requested — the clinical question being asked.
- A written report. Findings and recommendations must go back in writing to the requesting party, and a copy must live in your chart.
Miss any one of the three and you do not have a billable consultation, regardless of how much time the physician spent or how complex the decision making was. That is why the 99245 cpt code is an operations problem before it is a coding problem: two of the three requirements are generated by your staff, not your clinicians.
Modifier 32 and mandated consultations
When a consultation is mandated by a third party — a payer, a workers' compensation carrier, a governmental entity — CPT provides modifier 32. Your billing lead should know which of your referral sources produce mandated consults, because those cases usually arrive with their own release paperwork and their own disclosure limits. Treat them as a separate intake path.
Medicare Does Not Recognize Office Consultation Codes — Build a Payer Matrix
CMS stopped recognizing the CPT consultation codes for Medicare payment years ago. For Medicare patients, practices report the appropriate office or other outpatient visit codes instead, even when the encounter meets every consultation requirement. Some state Medicaid programs and many commercial payers still recognize consultation codes; others do not, and some pay them only with specific documentation attached.
The operational fix is a one-page payer matrix, owned by your billing manager and reviewed quarterly against current payer policy and the CMS evaluation and management guidance. For each payer, record: does it recognize 99242–99245, does it require the referring provider's NPI on the claim, and does it request the consult request and report on review? Without that matrix, your billers guess, and guessing shows up later as recoupment.
The Consult Request Is a Record You Must Retain, Not a Sticky Note
Requests arrive by fax, by secure message, through a referral portal, through a health information exchange, or as a phone call from a colleague's nurse. All of those are fine as sources. None of them are fine if the artifact never lands in the chart.
Assign a single owner — usually the referral coordinator — and one rule: the request document, or a contemporaneous note of a verbal request naming the requesting provider and the clinical question, is scanned or filed into the patient record the same business day it arrives. Verbal requests need the coordinator's name, the date, the caller, and the question. "PCP wants ortho eval" is not a documented reason for a request.
Two records problems follow. First, a request that arrives before the patient has been registered creates PHI you are holding for a person who is not yet in your system — decide where that lives and who can see it. Second, fax-to-email gateways and referral portals mean the request typically passes through a vendor before it reaches your staff. That vendor is handling protected health information on your behalf.
The Report Back to the Referring Physician Is a Disclosure
The written report closing the consultation loop is a disclosure of PHI to another covered entity for treatment purposes. HIPAA permits it without patient authorization; HHS guidance on disclosures for treatment, payment, and health care operations is explicit on that point. Three practical consequences your staff should understand:
Minimum necessary does not apply to treatment disclosures to another provider. You may send the full consultation note. That is a legal permission, not a mandate — many practices still send a focused report because it is cleaner and reduces the chance of misrouted sensitive content.
Accounting of disclosures does not capture it. Treatment disclosures are excluded from the accounting a patient can request under the Privacy Rule, so your log burden here is low. Your routing burden is not.
Transmission security is where the failures happen. Reports go to the wrong fax number, to a prior practice address, to a physician who left the group, or to a personal email account because "that's how Dr. R prefers it." Verify destination numbers and addresses at least annually, log every outbound report with date and destination, and treat a misdirected report as a potential breach requiring a risk assessment — not a shrug.
Special categories that need a second look
Substance use disorder treatment records subject to 42 CFR Part 2, psychotherapy notes, and state-protected categories such as HIV or reproductive health information can carry restrictions tighter than HIPAA's treatment permission. If your specialty regularly touches those categories, your consult report template needs a hard stop and a named reviewer before it transmits.
Every Vendor That Touches the Consult Loop Needs a BAA
Walk the path of a single consult and count the outside companies involved. A typical specialty practice finds five to eight:
- The fax-to-email or cloud fax service that receives requests
- The referral or care-coordination platform your hospital system pushes to you
- Transcription or documentation-assistance services that produce the note supporting time or decision-making detail
- Scribe staffing agencies, if scribes are contracted rather than employed
- Your billing or revenue-cycle company submitting the claim
- Outside coding auditors who review your consultation levels
- Secure messaging or direct-messaging providers carrying the report back
- Document storage and release-of-information vendors responding to payer requests
Each of those is a business associate under HIPAA, and each needs an executed agreement with the required terms before it handles PHI. HHS explains the scope in its business associate guidance. In practice, the gaps cluster in two places: the coding auditor engaged for a one-time chart review, and the fax gateway someone in IT signed up for on a credit card three years ago.
If you find a gap, close it in writing rather than in email. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — which is usually faster than waiting on a vendor's own template and then negotiating its carve-outs.
A Worked Example: One Consult, Fax to Report Back
Use this as the skeleton of your written procedure. Names are roles, not people, so the workflow survives turnover.
- Day 0, 8:14 a.m. — Referral coordinator. Retrieves the request from the fax gateway. Confirms requesting provider, NPI, clinical question, and payer. Scans into the patient record or the pre-registration holding folder. Logs receipt.
- Day 0, by close — Front desk. Verifies payer status against the consultation payer matrix. Flags the encounter type in scheduling so the physician knows a report-back is expected.
- Day 14 — Clinician. Sees the patient. Documents the request and reason inside the note, not only as a scanned attachment. Documents decision making and, where relevant, total time on the date of the encounter.
- Day 14–16 — Clinician, then coding staff. Note is finalized. A certified coder reviews level selection against documentation and payer policy, and queries the clinician rather than adjusting the level unilaterally.
- Day 16 — Referral coordinator. Transmits the written report to the verified destination for the requesting provider. Records date, method, and destination in the outbound log. Files the report copy in the chart.
- Day 17 — Billing. Submits the claim with the referring provider captured. Holds nothing waiting on the report, because the report is already sent.
- Month 9 — Privacy officer and billing manager. A payer requests records on the claim. Release-of-information pulls only the encounter, the request, and the report.
That last step matters. Disclosures for payment purposes are subject to the minimum necessary standard. Sending a payer the patient's entire longitudinal chart to defend one consultation claim is an over-disclosure, and it is the kind that surfaces later as a patient complaint.
Where 99245 Claims Actually Fall Apart in Audit
From the administrative side, the recurring failure patterns are dull and preventable:
- The request exists in a fax folder but never in the chart, so the reviewer cannot find it.
- The note documents a thorough evaluation but never names the requesting provider or the question asked.
- No copy of the report back exists, because it was faxed from a workstation without a saved confirmation or filed copy.
- Time is asserted in a template phrase that appears identically across dozens of encounters, with no per-encounter substance behind it.
- The payer never recognized the consultation family, and nobody checked before submitting.
Run an internal sample yourself: pull ten consultation claims from the last quarter and try to assemble request, reason, and report for each without asking a clinician. Whatever you cannot assemble in ten minutes, a payer reviewer will not find either. Track your pass rate and repeat it quarterly.
Five Controls to Put in Place This Quarter
- Name one owner for consult request intake and one for report-back transmission, in writing, with a named backup.
- Refresh the payer matrix for the consultation code family, including whether each payer recognizes 99242–99245 at all.
- Reconcile your vendor inventory against the consult loop above and confirm a current, executed BAA for every entry — including short-term coding auditors.
- Verify outbound destinations for your top 25 referring providers and document the verification date.
- Add misdirected reports to your incident-response procedure with an explicit breach risk assessment step, and train staff to report them without fear.
Those five controls also feed your security risk analysis, since they describe real flows of PHI in and out of your practice. If your written policies, risk analysis, and procedure set are stale or scattered, you can build the full compliance document set from the workflows you just mapped rather than from a generic template.
Start with the vendor list. Pull the eight-line inventory, find the two or three companies handling consult requests or reports without a signed agreement, and produce the agreements you need this week. The coding questions around the 99245 cpt code will keep evolving with payer policy; the obligation to paper your vendors will not.