Your billing lead forwards a payer audit letter on a Tuesday morning: 38 telephone evaluation and management claims from 2023 and 2024, supporting documentation due in 30 days. Fourteen of them carry the 99443 CPT code. The physician who took most of those calls retired last spring, your phone system was replaced in 2024, and nobody can immediately say whether the call logs from the old vendor still exist.

This is a practice-operations guide, not a coding manual. It covers what the 99443 CPT code described, why it still lands on your desk in 2026 even though it no longer exists in current CPT, and — the part most practices skip — the records-retention, call-recording, and vendor obligations that telephone encounters created and left behind.

The 99443 CPT code was part of the telephone evaluation and management services family (99441–99443), used for a telephone encounter between a physician or other qualified health care professional and an established patient, parent, or guardian. Within that family, the three codes were distinguished by the length of medical discussion — 99441 for the shortest tier, 99442 for the middle tier, and 99443 for the longest tier, 21 to 30 minutes of medical discussion.

All three carried structural conditions: the service could not originate from a related E/M service within the prior seven days, and it could not lead to an E/M service or procedure within the next 24 hours or the soonest available appointment. CPT deleted 99441–99443 effective January 1, 2025, replacing them with the new telemedicine E/M code family (98000-series), which separates audio-video from audio-only encounters and covers both new and established patients.

Payer adoption of the replacement codes has not been uniform. Medicare's treatment of the new telemedicine E/M family has differed from CPT's, and commercial payers set their own policies. Your billing team should confirm the current status of each code against the applicable Physician Fee Schedule and each contracted payer's telehealth policy before submitting — not from memory, and not from a 2024 cheat sheet taped inside a cabinet door.

Why a Deleted Code Is Still Your Problem

Deletion from CPT stops future billing. It does not stop the paper trail.

Audits and appeals run on old dates of service

Payers and their contractors review claims years after adjudication. A 2023 date of service billed under 99443 can be pulled for documentation review in 2026, and the standard the reviewer applies is the standard in effect on the date of service — including the time-based tiering and the seven-day/24-hour conditions. Your job is retrieval, not re-coding.

Your data still carries the code

Practice management reports, denial worklists, revenue cycle dashboards, clearinghouse rejection queues, and any analytics extract you sent to a consultant in 2024 all still contain 99443 line items. Every one of those is protected health information sitting in a system you may or may not have a current agreement covering.

Patients request the encounter

A patient who sees a telephone visit on an explanation of benefits will occasionally ask what it was. That request is a right-of-access request, and the clock is the same as for any other record.

The Documentation a Telephone Encounter Should Have Produced

When you pull records for an audit, reviewers generally look for the same elements the practice should have captured contemporaneously. Build your retrieval checklist around these:

  • Who initiated the call and confirmation that the patient or guardian consented to the telephone encounter
  • Date, start time, and end time, or a stated total of medical discussion time
  • Identity verification — how staff confirmed they were speaking to the right person
  • The clinical content: reason for the call, history obtained, assessment, plan, and any prescribing
  • Statements addressing the exclusions — no related E/M in the prior seven days, no resulting E/M within 24 hours or the next available appointment
  • Rendering provider and, where applicable, supervising physician

Note the discipline here: the practice documents facts and time, and the clinician selects the code. Administrators build the template, enforce the timestamp, and audit for completeness. Administrators do not decide which tier a specific encounter met. When your internal review finds a chart with a 26-minute note and a low-tier code, or a three-line note with a high-tier code, the finding goes back to the clinician and the compliance officer — not into a unilateral rebill.

Assign the retrieval, then set the deadline

For a records request tied to old telephone claims, give one person ownership and a written internal due date at least seven days before the payer's. That person pulls the chart note, the appointment or call log, the claim as submitted, and the remittance advice. If the encounter predates a system migration, they also check the archive of the retired system — which is where most practices discover their legacy data access has quietly expired.

The Vendor List a Telephone Visit Touches

Here is where the 99443 CPT code stops being a billing question and becomes a privacy question. A single telephone encounter can move PHI through five or six external parties, and most practices have never listed them together.

Walk the call, one hop at a time

  1. The phone system. A cloud VoIP provider that transmits and often stores call detail records and voicemail is handling PHI. Landline carriers acting as mere conduits are treated differently; a hosted platform storing voicemail transcriptions is not a conduit.
  2. The answering or triage service. After-hours vendors take symptom information and route it. They are business associates, full stop.
  3. Call recording and storage. If your system records, the recordings are PHI in the designated record set when they document the encounter.
  4. Transcription and scribe tools. Any tool converting audio to a note — human or automated — is processing PHI.
  5. The EHR and practice management host. Where the note and the claim live.
  6. The clearinghouse and billing company. Where the claim goes next.

Every one of those needs a signed business associate agreement that is current, names the right legal entity, and addresses breach notification timelines and return-or-destruction at termination. HHS publishes sample BAA provisions you can compare your executed agreements against. If you have vendors on that list without a paper agreement — the answering service you inherited, the transcription tool a physician started using independently — you can produce a signature-ready business associate agreement through a guided wizard and close the gap this week rather than during an investigation.

Recording a clinical phone call implicates HIPAA and separate state wiretap and consent law. They are not the same analysis and one does not satisfy the other.

Under HIPAA, a recording that documents the encounter is part of the record and is subject to access, amendment, accounting, and safeguard rules. Under state law, roughly a dozen states require all-party consent to record a conversation, and your obligation follows the patient's location as well as your own. A practice with a multi-state telehealth footprint needs the consent script to assume the strictest rule, not the local one.

Three operational decisions to make explicitly and write down:

  • Do you record clinical calls at all? If the answer is no, confirm your phone platform has recording disabled at the account level, not just at the handset.
  • How long do recordings persist? Set a retention period that matches your record retention policy and enforce automatic deletion. Recordings kept indefinitely because nobody chose a number are pure liability.
  • Who can retrieve them? Access to the recording archive should be role-limited and logged, the same as chart access.

The enforcement discretion is gone

The COVID-era Notification of Enforcement Discretion for telehealth ended in August 2023. Since then, remote communication technology used for patient encounters must meet the Security Rule on its own terms — no grace period, no consumer video app exception. OCR's telehealth guidance, including its guidance on audio-only telehealth, remains the reference point for how the Privacy and Security Rules apply to phone-based care.

When a Patient Asks for the Telephone Visit Record

The right of access applies to the note and, where it exists, the recording. Your response window is 30 days from receipt, with one 30-day extension available if you notify the patient in writing with a reason and a date.

Practical rules for the front desk:

  • Log the request date the moment it arrives, in whatever form it arrives — portal message, phone call, letter, or a request handed to a nurse.
  • Fees must be reasonable and cost-based. Producing an audio file is not a license to invent a research charge.
  • Honor the requested format if you can readily produce it. "We only provide the typed note" is not an answer when the recording exists and is requested.
  • If the recording has already been deleted under your retention schedule, say so in writing and cite the policy.

A 45-Day Cleanup Plan You Can Actually Run

Days 1–7 — Inventory. Pull a claims report for all historical telephone E/M codes, including 99443, by date of service and rendering provider. Note which systems those encounters live in and whether you still have access to any retired ones.

Days 8–20 — Vendor reconciliation. List every vendor in the call path above. For each, confirm a signed BAA, the executing entity name, the effective date, and the termination provisions. Flag anything missing or older than your last material scope change.

Days 21–30 — Recording and retention decision. Confirm whether recording is on, where files live, how long they are kept, and who can pull them. Write the policy. Have the privacy officer sign it.

Days 31–45 — Update the risk analysis. Telephone and audio-only encounters are a distinct workflow with distinct systems. If your security risk analysis still describes a practice that only sees patients in person, it does not reflect how you operate. Automating your HIPAA risk analysis and policy document set gets this refreshed in an afternoon instead of the six weeks it takes when someone tries to edit last year's Word file around a full-time job.

What to Do This Week

Pull the claims report. Walk one telephone encounter end to end and write down every system and vendor it touched. Compare that list to your signed BAAs. Whatever does not match is your first task, and it will take less time to fix now than to explain later.

If the exercise reveals that your risk analysis, policies, and vendor documentation have drifted from how your practice actually delivers care, generate a current compliance document set and start from an accurate baseline. Deleted codes stop generating revenue. They do not stop generating obligations.