A payer audit letter lands on your desk asking for the complete records supporting 30 encounters, all of them coded 99213, across a six-month window. You have 45 days on most Medicare additional documentation requests, less on some commercial contracts. Every chart you pull, every page you fax or upload, and every vendor who touches that transmission is now inside your compliance perimeter. This guide covers how billing code 99213 actually moves through a practice — who selects it, what documentation supports it, who handles the claim downstream — and the privacy, records-access, and vendor obligations that attach at each step. It is written for administrators and billing staff, not clinicians.

What Billing Code 99213 Is on Your Claim

99213 is the CPT code for an office or other outpatient visit for the evaluation and management of an established patient. CPT is maintained by the American Medical Association; Medicare payment amounts are published in the CMS Physician Fee Schedule lookup tool, which your billing lead should be checking against your fee schedule at least annually.

Since the January 1, 2021 revisions to the office and outpatient E/M codes, level selection for 99202–99215 rests on one of two things: the level of medical decision making, or the total time the billing clinician spends on the encounter on the date of service. History and exam are still documented as clinically appropriate, but they no longer drive the level.

For 99213 specifically, the published criteria are a low level of medical decision making, or total time of 20 to 29 minutes on the date of the encounter. Your job as an administrator is not to decide whether a given visit meets either criterion. Your job is to make sure the note contains what a reviewer needs to see, that the code on the claim matches the code in the note, and that nobody outside the workflow touches the record without authority to do so.

The Snippet Answer: How Is 99213 Selected and Documented?

The billing clinician selects the level either by medical decision making or by total time on the date of the encounter. If time is used, the note must state the total time and the clinician must be the one who spent it. If medical decision making is used, the note must support the number and complexity of problems addressed, the data reviewed, and the risk involved. Administrative staff verify that the documented basis exists and matches the submitted code — they do not choose the level.

The Five Hands That Touch a 99213 Claim Before It Leaves Your Building

Map this for your own practice and write it down. Most offices have never done it, and it is the fastest way to find a vendor with no signed agreement.

  1. Front desk. Verifies the patient is established, confirms eligibility, captures the copay. Eligibility checks run through a clearinghouse or portal — that is a disclosure of PHI for payment purposes.
  2. Clinician. Documents the encounter and selects the code, often through an EHR picklist that pre-populates from a template.
  3. Coder or biller. Reviews the note against the submitted code, appends modifiers, resolves conflicts. This person may be an employee or a contracted revenue-cycle vendor.
  4. Clearinghouse. Scrubs and routes the 837 transaction to the payer. When the clearinghouse is handling identifiable information on your behalf, it is a business associate.
  5. Statement and collections vendor. Prints and mails the patient balance, runs the payment portal, and in some practices places the collection call.

Five hands, and in a typical small practice at least three of them belong to outside companies. Each one needs a business associate agreement on file, dated, signed by someone with authority, and findable in under ten minutes.

Documenting Level Selection Without Practicing Medicine

Administrators get into trouble two ways: by telling clinicians what to code, and by ignoring documentation gaps entirely. Neither is the job. The job is process control.

Time-Based Documentation

If your clinicians use time to support billing code 99213, the note needs an explicit total-time statement for the date of the encounter. Build it into the template so it cannot be skipped, and make sure the template does not auto-populate a default number. A pre-filled "25 minutes" on every note is the single easiest pattern for a reviewer to spot, and it undermines every legitimate claim in the sample.

Have your billing lead run a monthly frequency report on documented times. If 90% of time-based visits land on the same value, that is a template problem, not a coding problem, and you fix it with an IT ticket and a five-minute conversation.

Medical Decision Making Documentation

When MDM drives the level, the reviewer is looking at problems addressed, data reviewed or analyzed, and risk of complications from management. Your administrative check is narrower: does the note contain an assessment and plan that names what was addressed, and does it reference the external records, labs, or consults it claims to have reviewed? A note that says "labs reviewed" with no labs in the chart creates an audit finding.

Addenda and Late Entries

Write a policy on this and enforce it. Addenda must be identifiable as addenda, timestamped, and attributed. Your EHR audit log will show the edit whether or not the note does, and an addendum entered the week the audit letter arrived reads very differently than one entered two days after the visit. Never permit anyone to edit a note after a records request has been received without documenting the change as a post-request addendum.

Responding to a Records Request for 99213 Encounters

When a payer, a Medicare Administrative Contractor, or a recovery audit contractor requests documentation, you are making a disclosure for payment purposes. That disclosure is permitted without patient authorization — but it is still subject to the minimum necessary standard.

In practice that means you send the records that support the encounters listed in the request. Not the full chart. Not the entire problem list history for a patient whose one flagged visit was for a rash. Assign one person to redact and one person to verify before anything transmits, and log what went out, to whom, and on what date.

Transmission method matters more than most practices admit. A fax to a number typed by hand at 4:45 PM is your most common misdirected-disclosure vector. Prefer the contractor's secure upload portal. If you must fax, use a stored destination entry, cover-sheet every transmission, and confirm receipt.

Track the response deadline on a shared calendar with a named owner, not in someone's inbox. Missed ADR deadlines convert into automatic denials and, in Medicare's Targeted Probe and Educate process, into another round of review.

Billing Records Are Part of the Designated Record Set

Here is the obligation practices forget: when a patient asks for their records, billing and payment records maintained by or for your practice are inside the designated record set. That includes the itemized statement showing the 99213, the explanation of benefits you hold, and payment history.

You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Any fee you charge must be reasonable and cost-based — labor for copying, supplies, postage, and preparing an explanatory summary if the patient agreed to one in advance. Search and retrieval time is not billable. HHS keeps its right of access guidance current and detailed; print it and give it to whoever staffs your records desk.

OCR has resolved dozens of enforcement actions under its Right of Access Initiative, and a recurring pattern is a small practice that treated a billing-records request as a business dispute rather than a HIPAA obligation. If your billing is outsourced, your BAA must obligate the vendor to produce records within a window that lets you meet the 30 days — not "promptly," which means nothing when the clock is running.

The Self-Pay Restriction Nobody Trains On

A patient who pays out of pocket in full for a service can require you not to disclose that encounter to their health plan. That is a mandatory restriction, and it is operationally awkward: the claim has to be stopped before it reaches your clearinghouse. Build a flag in your practice management system, train the front desk to raise it at check-in rather than after the encounter, and confirm with your billing vendor exactly how they suppress a held claim. Test it once with a dummy account.

Every Revenue-Cycle Vendor Is a Business Associate

Pull your vendor list and check it against this set: outsourced coding and billing, clearinghouse, statement printer, patient payment portal, collections agency, EHR host, transcription or ambient documentation service, credentialing consultant with chart access, and the document-shredding company. Each handles PHI on your behalf.

Three specific gaps show up repeatedly in practices of every size:

  • Subcontractors offshore. Your coding vendor may route work overseas. HIPAA permits it if the chain of BAAs holds, but your agreement should require notice and your risk analysis should account for it.
  • Ambient documentation tools. If a tool records the visit and drafts the note that supports the level selection, it is processing PHI and it needs an executed agreement plus a review of its retention and model-training terms.
  • Verbal-only arrangements. The local biller who has worked with the practice for twelve years and never signed anything. That is the one OCR asks about.

HHS publishes sample business associate agreement provisions as a starting point. If you need something signature-ready rather than a template to negotiate from scratch, a guided BAA generator that exports a completed agreement will close the gap in an afternoon.

Where the Risk Analysis Fits

The Security Rule requires an accurate and thorough assessment of risks to electronic PHI — and claims data is ePHI. The 99213 workflow you just mapped is a risk-analysis input: five handoffs, three vendors, one fax machine, one payment portal. NIST's SP 800-66 Revision 2 is the practical companion for working through it without a security background.

HHS proposed a significant overhaul of the Security Rule in January 2025 that would tighten documentation expectations around risk analysis, asset inventories, and vendor oversight. Whatever its final form, the direction is clear: "we did one a few years ago" will not survive a review. If assembling that documentation is the thing that keeps getting pushed to next quarter, a platform that automates the risk analysis report and the supporting policy set gets you a current, dated, defensible file instead of another calendar reminder.

A 30-Day Cleanup Checklist for the Billing Workflow

  1. Week 1. Map the five handoffs for a single claim. Name the owner at each step.
  2. Week 1. Pull the BAA file. List every vendor without a signed, current agreement.
  3. Week 2. Run a frequency distribution of your E/M levels by clinician for the last 12 months. Look at outliers as a documentation question, not a coding directive.
  4. Week 2. Audit ten notes supporting billing code 99213 against the submitted claim. Check for time statements, template defaults, and referenced-but-absent data.
  5. Week 3. Write the records-request procedure: intake, minimum necessary redaction, second-person verification, transmission method, disclosure log, deadline owner.
  6. Week 3. Test the self-pay restriction flag end to end.
  7. Week 4. Confirm your billing vendor's turnaround commitment for patient access requests is written into the BAA.
  8. Week 4. Date and file the updated risk analysis.

Note that disclosures for payment are excluded from the accounting of disclosures a patient can request — but your internal disclosure log still matters. It is how you reconstruct what happened when a patient calls to ask why their employer's plan received records for a visit they paid for in cash.

Start With the Vendor List

The coding side of 99213 is well documented and your clinicians own it. The parts that land on you are the handoffs, the agreements, the deadlines, and the paper trail proving all three were managed. If your BAA file has holes or your risk analysis is more than a year old, generate the current document set before the next audit letter arrives — the request always comes with a clock already running.