It's 4:40 on a Thursday and your portal queue has forty-one unread patient messages. Six of them are substantive clinical questions from established patients. Two of those six will consume fifteen minutes of a physician's evening. Right now, none of that is billed, none of it is timed, and the audit log that would prove any of it lives inside a vendor system nobody at your practice has reviewed since implementation.

That gap is what the 99421 CPT code addresses — and what it exposes. This guide is written for practice administrators, billing leads, and privacy officers who need to understand the operational mechanics of online digital evaluation and management services, then handle the records, consent, and vendor obligations that come attached. It is administrative guidance on documentation and workflow, not clinical guidance on when a service is medically appropriate.

What the 99421 CPT Code Describes

CPT 99421 is the first of three time-tiered codes for online digital evaluation and management services — commonly called e-visits. The descriptor covers an online digital E/M service for an established patient, for up to seven days, cumulative time during the seven days: 5–10 minutes. CPT 99422 covers 11–20 minutes, and 99423 covers 21 minutes or more.

Three structural features drive everything downstream:

  • The patient initiates it. A clinician reaching out first does not start the clock.
  • Time is cumulative across a seven-day window, not per message.
  • The exchange happens through a HIPAA-compliant secure platform. That phrase appears in the code family's own guidelines, which means your billing decision and your privacy posture are welded together.

A parallel family, 98970–98972, exists for qualified nonphysician health care professionals who cannot independently report E/M services. Your billing lead needs to know which credentialed staff fall into which family before anyone touches a claim.

What does not count

CPT guidelines exclude non-evaluative communications: appointment scheduling, a bare prescription refill request, a lab result delivered without clinical assessment, or an administrative message about a referral. Reporting is also restricted when the online inquiry relates to an E/M service the clinician performed within the previous seven days, when it leads to an E/M service or procedure within the following seven days, or when it falls inside a global surgical period. In those cases the work folds into the other service.

Payer policy varies. Medicare treats these as communication technology-based services with their own coverage conditions rather than as telehealth visits, and commercial payers set their own modifier, frequency, and cost-sharing rules. Your billing lead should pull current policy from each contracted payer and from the CMS Physician Fee Schedule before the first claim goes out, not after the first denial comes back.

The Seven-Day Window Your Billing Staff Has to Reconstruct

Here is where operations get hard. The billable unit is not a message — it is the clinician's total time across a rolling seven-day episode, counted from the initial patient inquiry.

Time typically includes the clinician's review of the patient's inquiry, review of relevant records and prior data, interaction with clinical staff about the issue, development of a management plan, generation of prescriptions or orders, subsequent communication with the patient through the portal, and documentation. It is clinician time. A medical assistant's fifteen minutes of triage does not roll into a physician's total.

Your practice needs a single answer to a single question: where does that time get recorded? Options in descending order of defensibility:

  1. A structured e-visit field in the chart where the clinician enters cumulative minutes and the note references the initiating message thread by date.
  2. A free-text attestation in the encounter note stating total cumulative time and the seven-day span.
  3. Nothing, and the biller estimates from message timestamps. This will not survive review.

Assign the field. Train to it. Then have your compliance lead sample ten e-visit encounters per quarter and confirm the note contains the initiating date, the cumulative minutes, and a statement that the patient initiated the exchange.

Patients are frequently surprised that a portal message generated a bill. That surprise becomes a complaint, and complaints about billing have a way of turning into complaints about records and privacy.

Medicare requires patient consent for communication technology-based services, and that consent can generally be obtained once annually and documented in the medical record. Build it into your workflow at the same point you refresh demographics and insurance — the annual check-in, not a separate campaign.

Practical assignments:

  • Front desk: captures and dates the annual consent; flags patients without it.
  • Portal configuration: displays a plain-language notice on the message composition screen explaining that clinical questions may result in a billable service with applicable cost-sharing.
  • Billing: holds any e-visit claim where consent is not documented for the applicable period.

Document the notice language you display and the date you changed it. When a patient disputes a charge eighteen months later, you want to show what the screen said on the day they typed.

"HIPAA-Compliant Platform" Is in the Descriptor — Now Prove It

No product is HIPAA-certified. HHS does not certify, endorse, or approve compliance software or portals, and any vendor claiming otherwise is selling you a marketing badge. What you can actually establish is a documented chain: a signed Business Associate Agreement, a current risk analysis that includes the portal, and technical safeguards you have verified rather than assumed.

When you begin reporting the 99421 CPT code, your patient portal stops being a convenience feature and becomes a system of record for billed services. Treat it accordingly.

The BAA question your vendor list should already answer

Your portal vendor creates, receives, maintains, and transmits PHI on your behalf. That is a business associate relationship. So is the messaging module if it is licensed separately, the SMS notification service that tells patients "you have a new message," and any translation or transcription service touching message content.

Pull the agreements. Confirm each one addresses breach notification timelines, subcontractor flow-down, return or destruction of PHI at termination, and — specifically relevant here — your ability to obtain audit logs and message archives on request. If a vendor cannot produce a message-level audit trail, you cannot substantiate a time-based code. If you need to close a gap quickly, you can generate a signature-ready Business Associate Agreement and get it in front of the vendor this week rather than next quarter.

The risk analysis that now has to name the portal

The Security Rule requires an accurate and thorough assessment of risks to electronic PHI. If your last risk analysis predates your portal messaging rollout, it is out of date the moment you bill your first e-visit. HHS maintains Security Rule guidance and risk analysis materials that define the expected scope, and HHS published proposed updates to the Security Rule in early 2025 that would tighten documentation expectations — track its status with counsel rather than assuming today's baseline holds.

Small practices rarely have a spare month to rebuild a risk analysis by hand. Tools that automate HIPAA risk analysis reports and the supporting policy set let a two-person compliance function produce documentation that reflects the systems you actually run, including the portal, the messaging module, and the vendors behind them.

Portal Messages Are Part of the Designated Record Set

This is the implication administrators most often miss. Once a clinician uses a portal message thread to evaluate a patient and bases a management decision on it, that thread is clinical documentation. It sits in the designated record set, and the patient has a right of access to it.

Under 45 CFR 164.524, your practice generally must act on an access request within 30 days, with one 30-day extension available if you notify the patient in writing with a reason and a date. HHS's right of access guidance is the operative reference, and OCR has pursued a long list of enforcement actions under its right of access initiative — most involving small practices that simply did not respond.

So: when a patient requests "my complete record," does your release-of-information process export portal message threads? For most practices the honest answer is no. The ROI clerk pulls encounter notes, labs, and imaging from the chart and never touches the messaging module.

Fix it with three steps. Document which portal content constitutes designated record set material. Confirm your vendor supports an export of that content in a usable electronic format. Add the export to your ROI checklist with a named owner.

State medical record retention periods apply to these threads. Check whether your portal purges messages after a fixed interval — some do, by default, and a purge that deletes the substantiating documentation for a billed service is a problem in two directions at once. Disable automatic deletion or configure the system to archive into the chart before purge.

Trackers on the Login Page and Other Quiet Exposures

The portal login and messaging screens are authenticated pages carrying PHI. Third-party analytics, advertising pixels, session-replay scripts, and chat widgets on those pages transmit information to companies that are almost certainly not your business associates.

OCR's bulletin on online tracking technologies drew a firm line around authenticated pages. A 2024 federal court ruling in Texas narrowed part of that guidance as applied to unauthenticated public pages, but nothing in that decision helps you if a pixel is firing behind a patient login. Have your web or IT contact run a tag inventory on the portal domain and give you a written list. Then reconcile it against your vendor inventory.

Two more items for the same review:

  • Notification content. Email and SMS alerts should say a message is waiting, not what it says. Configure this; defaults are often chattier than you want.
  • Access scope. Who reads the portal queue? Minimum necessary applies to internal routing. A shared triage inbox that every staff member can open is a finding waiting to be written.

A Quarterly Review Your Compliance Lead Can Run in Two Hours

Put these on a recurring calendar item and assign each line to a person:

  1. Sample ten e-visit encounters. Confirm patient-initiated, established patient, cumulative time documented, seven-day span stated.
  2. Verify annual consent is on file for every patient with an e-visit claim in the period.
  3. Confirm a signed, current BAA exists for the portal vendor and any subcontracted messaging or notification service.
  4. Run a tag scan on authenticated portal pages; document results.
  5. Pull the portal access report. Confirm terminated staff have no active accounts.
  6. Test one records request end to end and verify portal threads were included in the export.

Six lines, one owner each, documented results. That file is what you hand an auditor, and it is what protects your clinicians when a payer questions a time-based claim two years after the fact.

Start With the Documentation You Can't Fake

Billing the 99421 CPT code is not a coding decision your administrative team makes in isolation — it is a claim that your portal is secure, your consent is documented, your time records are real, and your vendor relationships are papered. Every one of those is a document you either have or you don't.

If your risk analysis is older than your portal, close that gap first. Build a current risk analysis and the supporting policy set, then run the six-line review above at the end of this quarter. The e-visit revenue is worth having. The documentation behind it is what makes it defensible.