Broken 5th Metacarpal Foot: Coding, Claims, and PHI
A patient calls your office on a Monday and says she has a broken 5th metacarpal foot. Your scheduler types that phrase, word for word, into the reason-for-visit field. Six weeks later you are looking at a denied claim, a chart search that returns nothing, and a records request from a plaintiff's attorney that references an injury date your system says never happened.
This post is not about the fracture. It is about the paperwork trail one fracture encounter leaves behind — who touches the protected health information, which of those parties needs a signed business associate agreement, what belongs in the claim versus the chart, and how the records request lands on your desk two months later. If you run intake, coding, or compliance for a practice that sees musculoskeletal injuries, this is your workflow map.
Why the Phrase Broken 5th Metacarpal Foot Lands in Your Intake Field
Metacarpals are hand bones. Metatarsals are foot bones. Patients mix them up constantly, and so do referring front desks, urgent care intake screens, and the free-text boxes in online scheduling forms. A fifth metatarsal fracture is one of the more common foot injuries your orthopedic or podiatry colleagues see, and the phrase broken 5th metacarpal foot is what a fair number of those patients type or say.
That mismatch is a documentation problem long before it is a clinical one. Foot and toe fractures and hand fractures live in entirely different blocks of the ICD-10-CM injury chapter. If your scheduler's free-text note propagates into a superbill template, a prior authorization request, or an outsourced coder's work queue without a clinician correcting it, you get a code that does not match the imaging report, the body part on the DME order, or the site listed on the workers' compensation first report of injury.
Practical consequence: denials, rework, and — the part compliance officers care about — a second and third round of PHI moving between organizations to fix something that started as a typo. Every resubmission, appeal, and phone call to the payer is another disclosure.
Three Coding Fields That Cause the Most Rework
- Laterality. Left, right, or unspecified. Unspecified is a denial magnet on extremity injuries and a red flag in payer audits.
- Seventh character for encounter type. Initial, subsequent, or sequela. Follow-up visits coded as initial encounters generate downstream review requests that pull more records than the visit warranted.
- Site specificity. The bone named in the imaging report should match the bone named in the claim. Reconcile before submission, not after.
CMS maintains the current code files and annual updates; your coding lead should be pulling them from the CMS ICD-10 code set page rather than a third-party cheat sheet that may be two revisions old.
Who Sees PHI in a Single Foot Fracture Claim
Here is the short answer, suitable for anyone who asks you to justify the length of your vendor list. A routine extremity fracture encounter typically exposes PHI to:
- Your own workforce — scheduler, intake, medical assistant, treating clinician, coder, biller.
- Imaging — the radiology group reading the films, plus the PACS or image-exchange vendor storing and routing them.
- Transcription or ambient documentation — if the note is dictated or AI-assisted, that vendor holds the narrative.
- The clearinghouse that formats and transmits the 837 claim.
- The payer — commercial plan, Medicare Administrative Contractor, workers' compensation carrier, or auto liability insurer.
- A DME supplier if a boot, crutches, or a bone stimulator is ordered and billed separately.
- Referral recipients — orthopedics, podiatry, physical therapy.
- Patient-facing systems — portal, appointment reminder service, statement printing and mailing vendor.
- Collections, if the balance ages out.
That is nine to twelve organizations for one broken bone. Not all of them are business associates, and the distinction matters because it determines whether you need a contract, whether you owe breach notification when they lose data, and what you can send them without an authorization.
Business Associate or Not: Sorting the Vendor List
The Ones That Need a BAA
A vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate. In the fracture workflow that means your clearinghouse, your outsourced coding or billing company, your transcription or scribe vendor, your image-exchange platform, your statement mailer, your IT managed service provider with access to the server, your shredding company, and your collections agency. HHS keeps a plain-language breakdown on its business associates guidance page.
The Ones That Do Not
Health plans are not your business associates. Sending a claim to a commercial payer or a workers' compensation carrier is a disclosure for payment purposes, permitted without a BAA and without patient authorization. Neither is the orthopedic group you refer to — they are a separate covered entity, and treatment disclosures between covered entities stand on their own footing.
The DME supplier is usually a separate covered entity billing its own claim, not your business associate. Your building's cleaning crew, with incidental exposure and no access to systems, generally is not either — though your risk analysis should document why you reached that conclusion.
The Ones People Forget
The forgotten category is where audits find gaps: the fax-to-email service that routes incoming referral packets, the online scheduling widget capturing that free-text reason-for-visit field, the patient survey tool, the cloud backup for your imaging archive, and the answering service that takes after-hours calls about post-visit pain. Each one handles PHI. Each one needs a signed agreement on file, retained six years past termination.
If you are looking at that list and realizing three of them have no executed contract, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than waiting on a vendor's legal department to send you a template you will have to redline anyway.
Minimum Necessary Applies to the Claim, Not Just the Chart
Payment disclosures are subject to the minimum necessary standard. The claim itself is usually fine — a compliant 837 carries diagnosis, procedure, dates, and identifiers, and nothing more. The problem is what your billers attach when a payer asks for documentation.
A worked example. The carrier requests medical records to support a claim for a fifth metatarsal fracture. Your biller pulls the encounter, then reflexively exports the full chart PDF: eleven years of visits, a behavioral health intake from 2019, a lab panel unrelated to the foot. That is an over-disclosure, and it is entirely avoidable with a documented attachment standard.
Write the standard down. For a fracture claim, the responsive set is normally the encounter note for the dates in question, the imaging report, the order, and the DME prescription if durable equipment was billed. Nothing older, nothing from another body system, nothing from another specialty. HHS explains the standard and its exceptions in its minimum necessary guidance.
Assign the Redaction Decision to a Named Role
Do not leave attachment scope to whoever happens to be working the denial queue that day. Name a role — billing supervisor, privacy officer, or the coder of record — who approves any records release over a set page count. Log the approval. When a payer or an auditor later asks why a psychiatric note ended up in an orthopedic claim file, you want a decision trail, not a shrug.
The Appeal Packet Is Where Practices Over-Disclose
Appeals are the highest-volume over-disclosure event in most small practices, because staff are trying to win an argument and instinct says send everything. Combine that with fax as a transmission method and you have the two most common breach patterns in ambulatory care: too much data, sent to a misdialed number.
Three controls that cost nothing:
- Confirm the payer fax or portal destination against the remittance advice, not against a sticky note or a number someone remembered from last year.
- Use the payer's secure portal when one exists. Portal uploads leave an audit trail your fax machine does not.
- Cover sheet with a named recipient and a callback number, and a same-day confirmation check that the transmission completed.
When a misdirected fax happens anyway — and it will — your breach risk assessment and the 60-day notification clock apply. Document the assessment even when you conclude notification is not required. The undocumented decision is the one that fails review.
The Records Request That Arrives Eight Weeks Later
Extremity injuries generate downstream paperwork out of proportion to the visit length, because a meaningful share of them are work-related or accident-related. That means three different request types arrive at your front desk, and staff routinely treat them as identical. They are not.
Patient Right of Access
The patient asks for their own records, or directs them to a third party in writing. You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. Right of access has been a sustained OCR enforcement priority, and the department's individual right of access guidance is the document to hand your records clerk.
Attorney Requests
A personal injury attorney requesting records for a client is not exercising the patient's right of access unless the request is a written patient directive meeting the requirements. Otherwise you need a valid HIPAA authorization signed by the patient. Check the expiration date, the scope, and whether the requested date range actually matches the injury. A request for "all records" on an authorization that names a single injury date is worth a phone call.
Workers' Compensation Carriers
Disclosures to workers' compensation carriers are permitted to the extent authorized by and necessary to comply with your state's workers' comp laws. State rules vary substantially on scope and timelines. Your front desk should not be interpreting those rules on the fly — put the state-specific answer in your records policy so the response is consistent.
A Vendor Map You Can Build in One Afternoon
Take a single closed fracture encounter — the one that started as a broken 5th metacarpal foot on the schedule and ended as a correctly coded metatarsal claim — and trace it. Pull the audit log. List every system the record entered and every organization that received a copy. Then check each against your BAA binder.
You will find gaps. Everyone does. The common ones are the fax service, the scheduling widget, the backup provider, and the collections agency whose contract expired when they were acquired. That vendor map feeds directly into your security risk analysis, which is required, must be current, and needs to reflect the systems you actually use rather than the ones you used when the last assessment was written. If your documentation set has drifted, tools that automate risk analysis reports and policy generation will get you to a defensible baseline faster than a blank Word document.
Assign the Roles Before the Next Fracture Walks In
Four assignments, four names, one page:
- Intake correction. Who reconciles the patient's description against the clinician's documented site before the claim is coded.
- Attachment approval. Who signs off on records sent with a claim or appeal, and above what threshold.
- Request triage. Who classifies an incoming records request as right of access, authorization-based, or workers' comp — and what the response deadline is for each.
- Vendor contracts. Who owns the BAA inventory, the renewal dates, and the six-year retention.
A broken bone in the foot is a routine encounter. The records trail behind it is not routine at all, and the phrase broken 5th metacarpal foot sitting in an intake field is a small, cheap early warning that your documentation chain needs a look.
Start with the contracts, because they are the fastest gap to close. Pull your vendor list, find the three organizations handling PHI without a signed agreement, and build a signature-ready BAA in six steps — PDF and DOCX export, one-time purchase. Then move on to the attachment standard, which is free and will save your billers an hour a week.