A patient messages your practice through the portal on a Tuesday afternoon about a worsening problem. Over the next five days, the clinician reads the message, pulls two outside labs, exchanges four more portal replies, adjusts a prescription, and closes the thread. That is 24 documented minutes of work, and until someone in your office decides whether it gets billed, it is unpaid labor sitting inside a system your vendor hosts.

This is a practice-operations guide to the 99423 CPT code description — what the code covers, what your staff has to track to support it, and the records and vendor obligations that come attached the moment portal messaging becomes a billable service line. It is written for administrators, billing leads, and privacy officers. It is not clinical guidance, and it does not tell you which code fits a given encounter.

The 99423 CPT Code Description, in Plain Administrative Terms

CPT 99423 describes an online digital evaluation and management service, performed by a physician or other qualified health care professional, for an established patient, for up to seven days, cumulative time during the seven days: 21 or more minutes. The service is patient-initiated and delivered through a HIPAA-compliant secure platform that creates a permanent record of the exchange.

It sits at the top of a three-code time ladder:

  • 99421 — 5–10 minutes cumulative over seven days
  • 99422 — 11–20 minutes cumulative over seven days
  • 99423 — 21 minutes or more cumulative over seven days

A parallel series exists for qualified nonphysician health care professionals who may not independently report E/M services. Confirm the current numbering against your CPT book each January; the digital-service families have been reorganized more than once in recent cycles, and last year's superbill is not authority.

What counts toward cumulative time

Per CPT, the cumulative time reflects the qualified professional's personal work across the seven-day window: reviewing the patient's initial inquiry, reviewing pertinent records and prior data, interprofessional consultation and coordination with other clinicians, developing a management plan, generating prescriptions or ordering tests, and the subsequent digital communication with the patient. Clinical staff time is not counted. Your job on the administrative side is to make sure the time is documented as it accrues, not reconstructed at month-end.

The Seven-Day Clock and the Two Windows That Kill the Charge

Three timing rules drive nearly every denial and every audit finding in this family of codes. Build them into your billing edits, not into a training slide nobody reopens.

One report per seven-day period. The window opens with the clinician's first personal review of the patient's inquiry. Additional messages from the patient about the same problem inside that window roll into the same cumulative time — they do not generate a second charge.

The look-back. If the online exchange originates from an E/M service the patient had within the previous seven days for the same problem, CPT treats the digital work as part of that earlier service. No separate report.

The look-forward. If the exchange leads to an E/M visit or a procedure within seven days, the digital work is folded into that visit. This is the one that catches practices, because the charge is often dropped on day two and the patient is seen on day five. Your claim scrubber needs a hold rule, not a hope.

Also excluded: services rendered during a postoperative global period, and services for patients who are new to the practice. Patient-initiated means patient-initiated — a portal message your staff sent asking a patient to "check in and let us know how you're doing" does not start the clock.

Patients believe portal messages are free. Many have been free for a decade. The first time a coinsurance amount shows up for a message thread, your front desk absorbs the phone call.

Medicare's rules for communication technology-based services have generally required that the patient consent to the service and that consent be documented, with cost-sharing applying as it would to other Part B services. Verify current requirements with your MAC and the Medicare Physician Fee Schedule before you turn on billing, and confirm commercial payer policies separately — they vary more than most billing managers expect.

Operationally, this is three artifacts:

  1. A portal banner or intake notice stating that clinically substantive messages requiring clinician time may be billed, and that copays or coinsurance may apply.
  2. A documented consent captured in the record, timestamped, with a defined refresh interval consistent with payer policy.
  3. A front-desk script that answers "why am I being charged for a message?" in two sentences without escalating to the practice manager.

If a significant share of your panel is uninsured or self-pay, coordinate with whoever owns your good-faith-estimate process. A charge that appears without warning generates complaints — and complaints about billing have a way of turning into complaints about records, access, and privacy once the patient starts writing things down.

Every Billed Message Thread Is Part of the Designated Record Set

Here is where the compliance officer takes over from the billing lead. A portal thread that a clinician reviewed, acted on, and used to make care decisions is protected health information, and it is part of the designated record set. It is not "just a message."

That means the thread is subject to the individual right of access. Under HIPAA, you generally have 30 days to respond to a written access request, with one 30-day extension available if you notify the patient in writing of the reason and the expected date. HHS has been unambiguous that the right extends to records held in electronic systems, and its right-of-access guidance remains the practical reference for your records staff.

Three questions to ask your records team this month

  • When you produce a chart, does the export include portal message threads, or does your standard record set stop at encounter notes? If the threads are billed as clinical services, an export that omits them is incomplete.
  • Can you produce the thread in the form and format requested — including a readable electronic copy — without a manual screenshot process that takes an hour per patient?
  • When a patient requests an amendment to something in a message thread, does your workflow know where to put the amendment and how to flag it downstream?

Add one more: retention. If your portal vendor purges messages after 12 or 24 months, and your state requires longer retention of clinical records, you have a gap that nobody discovers until a subpoena arrives. Check the vendor's retention default. Do not assume it matches your policy.

The Vendor List Grows the Day You Turn This On

Billing for online digital E/M usually means at least one new business associate, and often three. Walk the data path and name every party that touches the message content:

  • The patient portal or secure messaging platform that stores and transmits the thread.
  • Any AI drafting or message-triage tool your clinicians use to compose or summarize replies — these process PHI, full stop, and the vendor's terms need to say so.
  • Your billing company or clearinghouse, which now receives claims tied to encounters that exist only as digital exchanges.
  • Any translation service handling non-English message threads.
  • The backup or archival provider holding portal data at rest.

Each one needs a signed Business Associate Agreement in place before PHI moves, with the required provisions on permitted uses, subcontractor flow-down, breach notification timelines, and return or destruction of PHI at termination. HHS publishes sample BAA provisions, but sample text is a starting point, not a finished contract.

If you are adding a messaging or AI-assist vendor this quarter and the agreement is the thing holding up go-live, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Get it signed before the first billed thread, not during the first audit.

Two vendor questions specific to digital E/M

Audit logging. Can the platform show who opened a thread, when, and from which account? If a front-desk staffer with broad portal permissions reads clinical messages they have no business reading, your only evidence is the log. Minimum necessary is a permissions problem before it is a policy problem.

Time capture. Does the system timestamp clinician activity in a way that supports the cumulative-time documentation the code requires, or is your clinician typing "22 minutes" into a free-text box from memory? Both can be defensible. Only one survives a payer request for supporting documentation without a fight.

A Six-Step Rollout You Can Run in Two Weeks

  1. Day 1–2: Inventory every system that touches portal message content. Assign an owner to each. Confirm a current signed BAA for each non-workforce party.
  2. Day 3–4: Review portal role permissions. Restrict clinical message visibility to those who need it. Turn on audit logging and confirm log retention length.
  3. Day 5–6: Write the consent language and the front-desk script. Route both through whoever approves patient-facing materials.
  4. Day 7–8: Build billing edits for the look-back and look-forward windows, the established-patient check, and the global-period exclusion. Test with five historical threads.
  5. Day 9–10: Confirm with your records team that chart exports include message threads, and update your access-request checklist accordingly.
  6. Day 11–14: Train clinicians on contemporaneous time documentation. Train billing on the seven-day rules. Document that the training happened, with names and dates.

Reference HHS telehealth billing resources when you brief clinical leadership, and keep a dated copy of the payer policies you relied on. Policies change; your file should show what was in effect when you made the decision.

What This Actually Changes About Your Risk Profile

Before you bill digital E/M, portal messaging is a convenience feature. After, it is a documented clinical service, a revenue stream, a records-request target, and a vendor dependency. The 99423 CPT code description is the smallest part of that shift — the operational weight lands on consent capture, permissions, retention, and contracts.

Treat this like any other new PHI workflow: update the risk analysis, note the new data flows, and confirm your policies name the systems by name. If your documentation set is stale, tools that automate risk analysis reports and the supporting policy set will get you to a defensible baseline faster than a shared spreadsheet will.

Then do the one thing that is easy to skip: pull the signed BAA for your portal vendor and read the breach-notification clause. If you cannot find the agreement, or it predates the systems you are actually using, build a current one and get it signed this week. Everything else in this guide assumes that contract exists.