99358 CPT Code Description: Billing, Records, Vendors
A payer audit letter lands on your desk asking for twelve charts, and every one of them involves prolonged non-face-to-face time. Your biller can produce the claims in four minutes. Producing the time documentation behind them takes three days, pulls records out of two systems, and surfaces a scribe vendor nobody in your office has a signed agreement with.
That is why the 99358 CPT code description matters to you as an administrator, not just to your coders. This code family is time-based, non-face-to-face, and heavily scrutinized — which means it generates unusual documentation trails, unusual audit requests, and unusual vendor exposure. This guide covers the operational mechanics, then makes the privacy and records-handling consequences explicit.
What the 99358 CPT Code Description Actually Says
CPT 99358 is defined in the code set as prolonged evaluation and management service before and/or after direct patient care; first hour. Its add-on companion, 99359, covers each additional 30 minutes.
Three structural facts drive every workflow decision downstream:
- It is non-face-to-face. The service happens before or after the encounter — record review, chart preparation, communication with other professionals — without the patient present.
- It is a companion service. The code set treats it as related to another E/M service with direct patient care. It is not a standalone visit.
- It is time-driven with a floor. Under CPT instruction, time totaling fewer than 30 minutes is not separately reported. That threshold is what auditors test.
Nothing in this article tells you whether the code fits a given clinical encounter. That determination belongs to the rendering provider and your certified coding staff, working from the current-year code set, the payer's published policy, and the documentation in the chart. Your job as an operator is to make sure the determination is reproducible six months later.
The Bundling Rule Office Practices Miss
Since the 2021 office and outpatient E/M overhaul, CPT guidelines have directed that prolonged non-face-to-face time is not separately reported alongside office/outpatient E/M codes 99202–99215. The time-based selection method for those codes already accounts for qualifying non-face-to-face work on the date of the encounter.
Practices that adopted time-based E/M selection in 2021 and never revisited their prolonged-services macros are the ones generating denials. Check your encounter templates for auto-populated prolonged-service prompts on office visits.
Medicare Treats This Differently Than Commercial Payers
Beginning with the CY 2023 Physician Fee Schedule, CMS stopped recognizing 99358 and 99359 for Medicare payment and directed practitioners to HCPCS G-codes for prolonged services instead — G2212 for office/outpatient, and G0316, G0317, and G0318 for inpatient/observation, nursing facility, and home or residence settings respectively. Those G-codes count total qualifying time on the date of service, including non-face-to-face work, rather than treating it as a separate line.
The practical consequence: a single service description can map to different reportable codes depending on payer. Your billing team needs a payer-by-payer matrix, not a single house rule. Verify current descriptors and payment status against the CMS Physician Fee Schedule and the MLN Evaluation and Management Services Guide each January, and confirm the descriptor language in the current-year CPT book rather than in a legacy cheat sheet.
Quick Answer: How Do Practices Document Time for 99358?
Practices that survive prolonged-services audits document five elements in the note itself: (1) the date the non-face-to-face work occurred, (2) the total minutes spent, (3) the specific activities performed — records reviewed, professionals contacted, materials prepared, (4) the related E/M encounter the time supports, and (5) the identity of the individual performing the work. Start and stop times are stronger than a total. A number with no activity list is the single most common audit failure.
A Workflow That Produces Defensible Time Records
Assign the Roles Before the Volume Arrives
Rendering provider: documents activities and minutes contemporaneously, in the chart, in their own note. Not in a spreadsheet, not in an email to the biller.
Coding lead: applies the current-year descriptor and the payer matrix. Holds the authority to reject a claim line when the documentation does not support separate reporting.
Billing manager: tracks denial patterns by payer and reports monthly. A prolonged-services denial rate above your practice baseline is an early warning of a template problem.
Privacy officer: owns the records-release side — audit responses, patient access requests, and the vendor inventory described below.
A Worked Example of the Paper Trail
A specialist reviews 180 pages of outside records transmitted by fax and portal, then confers by phone with two referring physicians, before an encounter later that week. The provider logs start and stop times and a one-line activity summary in the chart on the day the work occurs.
Now count the systems that hold PHI from that single episode: the EHR note, the fax server's stored images, the portal message thread, the phone system's call log, the outside records themselves (now duplicated into your chart), and whatever transcription or documentation-assist tool the provider dictated into. Six repositories. Your records-request workflow has to reach all of them.
The Privacy Exposure Hidden Inside Time-Based Coding
Prolonged non-face-to-face services are, almost by definition, record-intensive. The clinical value comes from reviewing material generated elsewhere. That creates three specific compliance obligations most practices handle informally.
Inbound Records Become Your Records
Once outside records land in your chart, they are part of the designated record set. A patient requesting their chart is entitled to them under the HIPAA right of access, and your 30-day clock runs from the request — not from the day your staff finishes collating. HHS guidance on the individual right of access is explicit that fees must be reasonable and cost-based, and that you cannot condition access on payment of an unrelated balance.
Practices that batch-scan outside records into a generic "external documents" folder without indexing turn a routine request into a two-week manual search. Index at intake.
Payer Audits Are Disclosures — Apply Minimum Necessary
Sending twelve charts to a payer's audit contractor is a disclosure for payment purposes. Treatment disclosures are exempt from the minimum necessary standard; payment disclosures are not. Send the records responsive to the request, not the entire longitudinal chart because it was easier to export.
Log every audit response: date, requesting entity, records produced, and the staff member who released them. If the request comes from a contractor rather than the payer directly, verify the contractor's authority in writing before releasing anything.
Time Logs Are PHI
A spreadsheet listing patient names, dates, and minutes spent is protected health information. It belongs in the EHR or in a system covered by the same safeguards — not on a desktop, not in a shared drive with open permissions, not in a personal notes app. This is where prolonged-services documentation most often leaks out of governed systems, because the time tracking feels administrative rather than clinical.
Every Vendor Touching This Data Needs a Signed BAA
Run this inventory against your prolonged-services workflow. Each of these routinely creates, receives, maintains, or transmits PHI on your behalf:
- Ambient documentation, dictation, and transcription tools used to capture activity summaries
- Fax-to-email and cloud fax services receiving outside records
- Outsourced billing companies and revenue cycle vendors
- Coding audit consultants who review charts for you
- Time-tracking or care coordination add-ons layered on the EHR
- Document storage and scanning services handling inbound record volume
- Any analytics platform your billing manager exports denial data into
The coding audit consultant is the one practices forget. A firm you hire to review prolonged-services documentation reads charts — that is a business associate relationship, and an engagement letter is not a substitute for a business associate agreement. If you need one before Friday's kickoff call, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when a single new vendor triggers the need rather than an annual renewal cycle.
HHS publishes sample business associate agreement provisions that establish the required elements. Note that HHS does not certify or endorse any compliance product or vendor — no agreement template, yours or anyone's, carries a government seal.
A 30-Minute Annual Review for Your Compliance Calendar
Schedule this for the second week of January, when the new code set takes effect and payer policy updates have published.
- Verify the descriptor. Confirm the current-year 99358 CPT code description and status directly in the code book. Descriptors and reporting instructions change; institutional memory does not.
- Refresh the payer matrix. Medicare versus each commercial contract. Document the source and date for each entry.
- Audit five charts internally. Pull five encounters with prolonged-services time from the prior quarter. Can you reconstruct the activity list and minutes from the chart alone, without asking the provider? If not, fix the template.
- Re-run the vendor inventory. List every system that touched those five charts. Match each against your signed BAA file. Close the gaps in writing.
- Test one records request end to end. Time how long it takes to assemble a complete chart including outside records. If it exceeds a week internally, your 30-day access clock is at risk.
Practices that run this review find the same two problems repeatedly: an EHR template still prompting for prolonged non-face-to-face time on office visits where it is not separately reportable, and a documentation-assist vendor added by a single provider without administrative review.
Where This Leaves Your Practice
The 99358 CPT code description is short. The operational obligations behind it are not. Time-based, non-face-to-face reporting concentrates three risks in one place: documentation that must be contemporaneous, records that arrive from outside your walls, and a support cast of vendors who read charts to do their jobs.
Handle the coding determination through your certified coders and the current code set. Handle the rest as a records and vendor problem, because that is what it is.
If your vendor file has gaps — the transcription tool, the audit consultant, the cloud fax service — draft and export the agreements you're missing before the next audit letter arrives. If the broader documentation set needs attention, automated risk analysis and policy generation covers the layer underneath.