Sixty minutes. That is the threshold your monthly time log has to clear before anyone in your practice submits a claim under the 99487 CPT code, and it is the number that gets scrutinized first when a payer, a Medicare Administrative Contractor, or your own internal auditor pulls a sample. Complex chronic care management is one of the few services where the billing record and the clinical record are stitched together by a running clock kept by non-clinical software — often software your practice does not own.

This guide is for the administrator who signed the care management vendor contract, the billing lead who has to defend the units, and the privacy officer who will field the records request when a patient asks what the care manager wrote down. It covers the operational mechanics of complex CCM, then makes the privacy, records-handling, and vendor obligations explicit. Coding decisions belong to your clinicians and your coding policy; the job here is building a file that survives a look.

What the 99487 CPT Code Covers, in Plain Administrative Terms

The 99487 CPT code describes complex chronic care management services furnished over a calendar month: the first 60 minutes of clinical staff time directed by a physician or other qualified health professional, for a patient with two or more chronic conditions expected to last at least 12 months or until death, where those conditions place the patient at significant risk of death, acute exacerbation or decompensation, or functional decline. The code family also requires establishment or substantial revision of a comprehensive care plan and moderate-to-high complexity medical decision making by the billing practitioner.

99489 is the add-on for each additional 30 minutes of clinical staff time in the same month. Non-complex CCM sits in a separate lane (99490 with its own add-on), and practitioner-performed time sits in yet another. Whether a given month's work meets complex versus non-complex criteria is a clinical and coding determination your practice documents — not something an operations guide can decide for a specific patient.

Two structural rules drive most of the operational pain: only one practitioner may bill CCM for a given patient in a given calendar month, and the service must be supported by a time log, a documented consent, and an accessible care plan. Everything below follows from those three artifacts. Confirm current requirements and any changes against the CMS Medicare Learning Network booklet on Chronic Care Management Services and the current-year Physician Fee Schedule final rule before you change a workflow.

The Monthly File: Four Documents That Have to Exist Before the Claim Drops

Beneficiary consent is a billing prerequisite, and it is also a privacy document. The patient has to be told that CCM is available, that only one practitioner can furnish and bill it per month, that cost sharing may apply, and that they may stop the service at any time effective at the end of the calendar month. Medicare permits verbal consent documented in the medical record.

Decide now where that documentation lives and who can produce it in under ten minutes. A consent recorded only inside a vendor's care management portal is a consent you do not control. Require the vendor to write consent status back into your chart, or have staff document it in the chart directly. When a patient later disputes a copay, the consent note is the first thing billing will need.

2. The time log

Your log needs date, staff member, minutes, and a substantive description of the activity for every increment counted toward the month. Rounding up, block-entering identical durations across a panel, or logging time for staff who were not directed by the billing practitioner are the patterns that draw attention.

Assign one person to review time logs before the month-end billing run. That person's job is not to hunt for more minutes. It is to confirm that the minutes recorded actually happened, that descriptions are specific, and that any month falling short of the threshold does not get a claim.

3. The comprehensive care plan

The care plan is the clinical core of the service and the most commonly requested piece when a patient exercises their access rights. It has to be established, implemented, revised, or monitored during the month, and a copy must be provided to the patient or caregiver. It must be available electronically to care team members and shareable outside the practice as appropriate.

"Provided to the patient" is a transmission decision with HIPAA consequences. Portal delivery is clean. Mail is fine. If a patient asks for the care plan by unencrypted email, they may make that request, and you should document that you warned them of the risk and that they chose to proceed anyway.

4. The initiating-visit and eligibility trail

Keep the record of the qualifying visit that initiated the service and the documented basis for the patient's chronic conditions. Practices that let this drift end up with a panel of enrolled patients and no clean answer to "why this patient, this month."

One Practitioner Per Month: The Coordination Problem Nobody Owns

A patient enrolled in your program may also be enrolled by a cardiology group, a nephrology practice, or a health-plan-sponsored care management program. Only one entity bills. Denials arrive months later, and by then the care manager has already logged hours.

Build the check into enrollment, not into denial follow-up. Front-desk or care management staff should ask directly whether another practice or the patient's plan is already providing monthly care coordination, and document the answer. Re-ask at least annually and whenever the patient reports a new specialist.

Also map your overlap edits. Certain services furnished in the same month — transitional care management, home health or hospice supervision, some end-stage renal disease bundles — trigger payer edits against concurrent CCM billing. Your billing lead should maintain a written list of the edits your payers actually apply, sourced from payer policy, and revisit it each time a fee schedule cycle closes.

Your CCM Vendor Is a Business Associate — Scope the BAA Accordingly

Most practices do not staff complex CCM entirely in-house. They contract with a care management company that supplies nurses, a telephony platform, and a time-tracking tool. That company creates, receives, maintains, and transmits protected health information on your behalf. It is a business associate, and so is the platform vendor underneath it. HHS's business associate guidance is the baseline; your contract has to do the rest.

The exposure here is unusual because CCM vendors typically need broad chart access. They review medication lists, problem lists, recent encounters, labs, and discharge summaries. That is a legitimate need, and it is also the widest read access you will grant any outside party.

Questions to answer in writing before the first enrollment

  • Scope of access. Is the vendor's EHR role limited to enrolled patients, or does it see the full patient index? Ask for a screenshot of the role's permission set, not a verbal assurance.
  • Subcontractors. Which telephony, transcription, SMS, and analytics vendors sit behind the platform? Each needs a downstream agreement. Get the list and keep it with your vendor inventory.
  • Location and workforce. Are care managers remote? Offshore? What device controls apply? Who terminates access when a vendor nurse leaves?
  • Call recording. If outreach calls are recorded, recordings are PHI. Where are they stored, for how long, and can you retrieve one for a patient request or an investigation?
  • Data return and destruction. On termination, do you get the time logs and care plan history in a usable export, or do you lose the audit trail that supports claims you already billed?
  • Breach notice timing. Set a contractual clock measured in days, not "promptly."

If your current agreement is a generic template that predates the CCM contract, replace it. You can produce a signature-ready business associate agreement through a guided six-step wizard and have the vendor sign before enrollment starts rather than three months into the program.

24/7 Access Means Another Vendor Touching PHI After Hours

CCM requires 24/7 patient access to care team members for urgent needs. In practice that means an answering service, a nurse triage line, or an on-call routing platform. All three are business associates. All three handle unencrypted voice, callback numbers, and clinical detail at 2 a.m. with nobody from your practice watching.

Ask your after-hours vendor for two things: the retention period for call logs and recordings, and the process for getting an after-hours contact documented back into the chart. If the contact never reaches the chart, you have a service gap and a records gap at the same time.

Every New Data Flow Belongs in Your Risk Analysis

Standing up complex CCM adds systems: a care management platform, a time tracker, an SMS outreach tool, a remote workforce, an after-hours line, possibly device data feeds. The Security Rule requires an accurate, current risk analysis covering all electronic PHI your organization creates, receives, maintains, or transmits — which now includes every one of those. NIST SP 800-66r2 is the practical reference for structuring that work, and HHS has a pending proposal that would tighten expectations around asset inventories and vendor verification.

Most practices discover the gap during a payer audit or after a vendor incident, when someone asks for the risk analysis and the newest entry predates the CCM program by two years. If yours is in that state, generating an updated risk analysis and the supporting policy set is a faster path than rebuilding the documentation by hand while a records request sits open.

When the Patient Asks for the Care Plan

A CCM patient calls and asks for everything the care manager has written about them. You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS's right of access guidance is explicit on both points, and access failures remain one of the most consistently enforced categories of HIPAA violation.

Here is where CCM programs stumble: the responsive records sit in the vendor's platform, not your EHR. Your medical records staff searches the chart, sends what they find, and misses the care manager's notes entirely. That is an incomplete response even if nobody acted in bad faith.

Fix it with a written designated record set map that names every system holding CCM-related information, including the vendor platform, and a contractual turnaround commitment from the vendor short enough to fit inside your 30 days. Ten business days is a reasonable ask.

Text Messages, Personal Phones, and Remote Care Managers

Care managers text patients. Patients text back with symptoms, photos, and questions. If that traffic runs through personal phones and consumer messaging apps, you have PHI outside your control with no retention policy and no way to produce it in response to a request.

Set the rule and enforce it: outreach happens through approved channels only, and any patient-initiated message that arrives elsewhere gets documented in the chart and the conversation moved. Remote care managers need the same workstation controls as onsite staff — screen locks, encrypted drives, no shared household devices, no printing to a home printer.

What Auditors and Investigators Actually Ask For

Assume two separate reviews, because they come from different directions. A payer or contractor reviewing claims under the 99487 CPT code wants the time log, the consent documentation, the care plan with revision history, the initiating visit note, and evidence of practitioner direction. An OCR inquiry following a vendor incident wants your risk analysis, the executed business associate agreement, your access-termination records, and your breach notification timeline.

Both reviews hit the same vendor. If the vendor cannot produce granular time logs on request, you have a billing problem. If the vendor cannot produce access logs and a subcontractor list, you have a privacy problem. Test both capabilities before you need them — send a written request for a sample month and time how long the answer takes.

A short pre-launch checklist

  1. Signed BAA with the care management vendor and a current subcontractor list on file.
  2. Vendor EHR role reviewed and scoped to enrolled patients where feasible.
  3. Consent script written, consent location standardized in the chart.
  4. Time log format defined; monthly pre-billing review assigned by name.
  5. Care plan delivery method chosen; unencrypted-email requests documented.
  6. Designated record set map updated to include the vendor platform.
  7. Risk analysis updated for every new system and data flow.
  8. After-hours vendor agreement in place with retention and chart-writeback terms.

Next Step

Complex CCM is a good program run carelessly by a lot of practices. The billing side gets attention because revenue depends on it; the privacy side gets attention after something breaks. If your CCM vendor is live and your risk analysis, policy set, and business associate documentation have not been touched since onboarding, close that gap with an automated HIPAA risk analysis and document set before your next audit letter or records request forces the issue.