Your billing manager drops 412 lines onto the March claim batch, all of them chronic care management CPT codes, all of them generated by a vendor your practice contracted with eighteen months ago. Every one of those lines asserts that a specific quantity of staff time was spent on a specific patient in a specific calendar month. None of that time was documented inside your EHR. It lives in the vendor's portal, behind a login three people at your practice have and nobody has audited.

That is the operational problem this article addresses. Chronic care management CPT codes are time-based, month-based, and consent-dependent, which means the billing record and the privacy record are the same record. If you administer a practice, run billing, or own the compliance function, you need to know what the codes require of your workflow and what they expose in your vendor stack.

What the Chronic Care Management CPT Codes Cover

The CCM code family exists to pay for non-face-to-face work done between visits: outreach calls, medication reconciliation follow-up, coordination with specialists, care plan revision. The codes are defined by who spent the time, how much time, and how complex the month's decision-making was. Your clinicians determine which description fits; your job is to make sure the documentation supports whatever they chose.

The clinical-staff time codes

CPT 99490 describes at least 20 minutes of clinical staff time per calendar month, directed by a physician or other qualified health professional. CPT 99439 is the add-on describing each additional 20 minutes of that same clinical staff time in the same month.

CPT 99487 describes complex chronic care management — 60 minutes of clinical staff time with moderate or high complexity medical decision making — and 99489 describes each additional 30 minutes. The distinction between 99490 and 99487 turns on documented decision-making complexity and the care plan work performed, not on the diagnosis list alone.

The practitioner-time codes

CPT 99491 describes at least 30 minutes of chronic care management performed personally by the physician or QHP, and 99437 describes each additional 30 minutes. These are not billed for the same time counted under the clinical staff codes. Your time log has to make the distinction visible, because an auditor will.

The initiating visit add-on

HCPCS G0506 describes the comprehensive assessment and care planning work performed by the billing practitioner in addition to an initiating visit. Practices commonly need an initiating visit for patients new to the practitioner or not seen within the prior year. Build that check into your enrollment script rather than discovering it during a post-payment review.

The APCM bundle

Beginning in 2025, CMS established Advanced Primary Care Management HCPCS codes (G0556, G0557, G0558), which bundle care management elements into monthly per-patient payment tiers without the time thresholds that govern the CCM codes. Many practices now run both models across different patient populations. If yours does, your enrollment records must state which model each patient sits in, because the documentation obligations and the duplicate-billing rules differ. Check the current Physician Fee Schedule materials on CMS.gov before your annual code-set refresh.

The core chronic care management CPT codes are 99490 (20 minutes of clinical staff time per calendar month), 99439 (each additional 20 minutes), 99487 (complex CCM, 60 minutes of clinical staff time with moderate-to-high complexity decision making), 99489 (each additional 30 minutes), 99491 (30 minutes of physician or QHP time), and 99437 (each additional 30 minutes of practitioner time). HCPCS G0506 covers add-on care planning at the initiating visit. Eligibility generally requires two or more chronic conditions expected to last at least 12 months or until death, documented patient consent, a comprehensive electronic care plan, and 24/7 access to a care team member. Only one practitioner may bill CCM for a given patient in a given calendar month.

The Five Artifacts an Auditor Will Ask You to Produce

When a Medicare Administrative Contractor or a UPIC sends an additional documentation request against chronic care management CPT codes, the request is predictable. Assemble these in advance and store them where a records clerk can find them without asking the vendor.

  1. The consent record. Date, method (verbal or written), the staff member who obtained it, and evidence the patient was told about cost-sharing, the once-per-month single-biller rule, and the right to stop the service at any time.
  2. The comprehensive care plan. Problem list, expected outcome and prognosis, measurable treatment goals, medication management, planned interventions, and the responsible party for each. Plus proof a copy went to the patient or caregiver.
  3. The time log. Date, minutes, task description, and the identity and role of the person performing the work. Aggregated monthly totals with no per-entry detail do not survive review.
  4. The 24/7 access evidence. Answering service contract, after-hours routing configuration, and the on-call schedule for the months billed.
  5. The eligibility documentation. Which two or more chronic conditions supported enrollment, and where they appear in the chart.

Notice how many of those artifacts are generated outside your EHR when a vendor runs the program. That is the exposure.

The CCM consent conversation almost always includes a second, unstated disclosure: your practice is going to hand this patient's problem list, medication list, phone number, and care plan to a third party who will call them every month.

HIPAA permits that disclosure for treatment and health care operations under a business associate arrangement — no authorization required. But your Notice of Privacy Practices should describe it accurately, and your front desk should be able to answer "who is calling me and why do they have my chart?" without escalating to the practice administrator.

Script it. One paragraph, delivered at enrollment, naming the care management partner and what information they receive. Document delivery of that paragraph alongside the consent. Patients who understand the arrangement complain less, and complaints about unexplained third-party calls are a common trigger for OCR inquiries.

Your CCM Vendor Is a Business Associate — Treat It Like One

Outsourced CCM is a business associate relationship in every direction that matters. The vendor receives PHI, creates PHI (the time log and the care plan notes), stores PHI in its own platform, and often transmits PHI back to you as a monthly billing file. A signed business associate agreement is the floor, not the ceiling.

Pull your CCM contract and confirm five things:

  • The BAA is executed, current, and names the entity that actually holds the data — not a parent company or a defunct predecessor.
  • Subcontractors are disclosed. Many CCM operations run call centers offshore or through staffing intermediaries. Downstream BAAs must exist, and you should know which countries the calls originate from.
  • Breach notification timing is specified in days, not "promptly." Your 60-day clock under the Breach Notification Rule runs from discovery, and a vague vendor clause eats your runway.
  • Return-or-destroy obligations at termination cover the time logs and care plans, and the vendor will certify completion in writing.
  • The vendor will produce records directly to you within a defined window when a patient requests them or a payer audits you.

If any of those come back empty, fix the paper before you fix anything else. A signature-ready business associate agreement built through a guided wizard takes less time than the email thread you would otherwise start with the vendor's account manager.

Call recording and the state-law problem

Most CCM platforms record outreach calls for quality review. Recordings are PHI. They are also governed by state wiretap law, and several states require all-party consent. If your patient panel crosses state lines — and with telehealth, it does — your recording disclosure has to satisfy the strictest applicable state, not the state where your vendor's call center sits.

The care plan that lives outside your chart

When the authoritative care plan sits in the vendor's portal, three failures follow: your clinicians make decisions without seeing the current version, your records custodian cannot fulfill a request without a vendor ticket, and a vendor outage becomes a clinical documentation gap. Require a scheduled export into your EHR — monthly at minimum — and verify it happened. Do not accept a read-only web link as "integration."

The 30-Day Clock Applies to the Time Log Too

A patient enrolled in CCM asks for everything you have. Under the HIPAA right of access, you generally have 30 days, and the designated record set includes billing records used to make decisions about that individual. The monthly time log and the care plan sit squarely inside it.

Time yourself. Send a test request to your CCM vendor today and measure how many business days pass before usable records land in your inbox. If the answer is more than seven, your 30-day obligation is functionally the vendor's obligation, and you have no leverage in the contract to enforce it.

A Monthly Close Calendar That Survives Review

Assign owners by name, not by department. Here is a workable cadence for a practice billing chronic care management CPT codes across several hundred patients.

  • Days 1–25: Care management staff log time contemporaneously. Enforce same-day entry — reconstructed logs are the single most common audit finding in time-based services.
  • Day 26: Billing pulls the vendor time file and reconciles enrolled patients against active consents. Any patient with time logged and no consent on file is held, not billed.
  • Day 27: Clinical reviewer confirms the care plan was reviewed or revised for patients whose month included substantive changes, and that practitioner-time entries are attributed to the practitioner.
  • Day 28: Duplicate check. Any patient who transferred practices mid-month gets flagged against the single-biller rule.
  • Day 1 of the following month: Compliance samples ten charts. Five artifacts each. Findings logged, not emailed.

Ten charts a month is 120 a year. That is a real internal audit program, and it costs one afternoon.

Where This Connects to Your Security Risk Analysis

A CCM program adds a new system holding PHI, a new category of workforce access, a new transmission path into your billing system, and often a new class of recorded media. Each of those belongs in your risk analysis, which the Security Rule requires you to keep current — not to have performed once in 2019. NIST's SP 800-66r2 walks through how to scope that analysis around specific data flows rather than generic checklists.

If your last risk analysis predates your CCM contract, it does not describe your practice. Practices that need to close that gap quickly can generate a current HIPAA risk analysis and the supporting policy set rather than rebuilding the documentation from scratch every time a vendor is added.

Start With the Time Log

Pick one month already billed. Pull ten patients. Ask for the per-entry time detail, the consent date, and the care plan version in effect. Whatever you cannot produce in an afternoon is what a payer, a patient, or an investigator will find first — and the fix is almost always contractual, not clinical. Get the vendor paperwork and the risk analysis current this quarter, then let the monthly close calendar keep them that way.