Consultation CPT Codes: A Practice Ops and Privacy Guide
A cardiology practice we talked to last quarter had 38 claims sitting in a denial bucket for the same reason: the requesting physician's name was in the chart note, but nothing in the record showed the request had actually arrived before the visit. Every one of those encounters had been billed with consultation CPT codes. Every one had to be reworked, and each rework meant another round of records moving between two organizations.
This guide is for the person who owns that bucket — the practice administrator, billing lead, or privacy officer. It covers how consultation CPT codes function operationally, which payers still recognize them, what documentation your staff has to capture, and — the part most billing guides skip entirely — the HIPAA and vendor exposure that the request-and-report loop creates.
What Consultation CPT Codes Are and Which Payers Still Recognize Them
Consultation CPT codes are evaluation and management codes used when one physician or qualified health professional requests another's opinion or advice about a patient's condition, and the consulting clinician sends a written report back. The current CPT code set includes office/outpatient consultation codes 99242–99245 and inpatient, observation, or nursing facility consultation codes 99252–99255. The lowest-level code in each family (99241 and 99251) was deleted effective January 1, 2023, when the AMA restructured the E/M code set so that level selection rests on medical decision making or total time on the date of the encounter.
The payer split is the operational fact your billing team lives with. Medicare has not paid separately for consultation codes since January 1, 2010; Medicare Administrative Contractors instruct practitioners to report the appropriate office/outpatient or hospital care E/M code instead. Many commercial and some Medicaid managed care plans continue to accept the consultation family. Some commercial plans have followed Medicare's lead. That means the same encounter can be billed two different ways depending on which card the patient handed your front desk, and your fee schedule logic has to reflect that. CMS publishes the governing payment policy through the Physician Fee Schedule.
Who decides which code goes on the claim
The rendering clinician selects the code based on the documented encounter. Your coding staff verifies that the documentation supports what was selected and that the payer accepts the code family. Administrators do not choose codes for clinical scenarios and neither does your billing vendor — what you build is the process: a payer matrix, a documentation checklist, and a query pathway when the note and the code do not line up.
The Three Elements Every Consultation Claim Rests On
Payers that still recognize consultation CPT codes generally look for the same three things. Build your chart audit around them.
- Request. Documentation that another physician or appropriate source asked for the opinion, and the reason. This should appear in the consulting practice's record, not just the referring practice's.
- Render. The consulting clinician's evaluation, documented at the level supported by medical decision making or total time.
- Report. A written report communicated back to the requesting clinician, with evidence of transmission and date.
The failure mode is almost never the middle element. Notes are usually thorough. What goes missing is proof that the request preceded the visit and proof that the report went out. Both of those are front-desk and back-office artifacts, not clinical ones — which is exactly why they fall through.
Assigning the Consultation Workflow by Role
Write this down and post it. Ambiguity about who captures the request is what generates the denial bucket.
Scheduler or intake coordinator
Captures the requesting clinician's name, NPI, practice, and the stated reason for the request at the moment the appointment is booked. Attaches the referral document, secure message, or portal request to the encounter. If the request arrived by phone, documents the caller, the date, and the reason in a structured field — not a free-text sticky note.
Clinical staff
Confirms at rooming that the encounter is proceeding as a requested opinion rather than a patient-initiated visit. That distinction changes the coding path and it changes what your records staff will need to send back.
Billing and coding
Runs the payer matrix before the claim drops. Checks that the request documentation and the report transmission record are both present. Holds, rather than submits, any claim missing either.
Records or referral coordinator
Sends the report to the requesting practice through a channel your practice can prove it used, and logs the send. A timestamped entry in the EHR's communication log, a direct secure messaging receipt, or a fax confirmation attached to the chart — pick one standard and enforce it.
The Records Traffic That Consultation CPT Codes Generate
A consultation encounter moves protected health information in both directions before a dollar is ever billed. Records come in from the requesting practice. A report goes back out. Sometimes imaging, labs, and prior notes travel with each leg. This is more PHI movement per encounter than a routine follow-up visit, and it involves a second covered entity you do not control.
The good news for your workflow: HIPAA permits these disclosures without patient authorization. Sharing PHI for treatment purposes — including sending records to a consulting specialist and returning a consultation report — is a permitted disclosure under the Privacy Rule. HHS spells this out in its permitted uses and disclosures guidance. You do not need an authorization form, and treatment disclosures are excluded from the accounting of disclosures requirement.
Minimum necessary does not apply here — but verification does
The minimum necessary standard does not apply to disclosures to or requests by a health care provider for treatment. Your records staff can send the full relevant chart to a consulting clinician without trimming it. HHS guidance on minimum necessary is clear on the treatment carve-out.
What still applies is verification of identity and authority. Before your coordinator sends a chart in response to a request, someone has to confirm the request came from the clinician it claims to come from. Fax-back requests on letterhead from unfamiliar practices are a well-worn social engineering path. Build a callback step for any request from a practice not already in your referral directory, using a phone number you look up independently rather than the one printed on the request.
Wrong-recipient sends are the most common breach in this workflow
Misdirected faxes and portal messages sent to the wrong practice account for a steady share of small-provider breach reports. In a consultation workflow the risk is elevated because the recipient list is long and changes constantly. Two controls cut most of it: a maintained referral directory with verified transmission endpoints, and a second-person check on any outbound record set above a defined page threshold.
Also worth knowing: refusing or slow-walking a legitimate request for records that another clinician needs can raise information blocking questions under the 21st Century Cures Act rules. ASTP/ONC maintains information blocking guidance and exceptions. A privacy exception exists, but it has conditions — you cannot use "HIPAA" as a blanket reason to sit on a consultation request.
Every Vendor Touching a Consultation Claim Needs a Signed BAA
Walk the path of a single consultation encounter through your systems and list what it touches. A typical list:
- Referral management or e-referral platform
- Cloud fax service
- Direct secure messaging provider or HIE
- Transcription or ambient documentation service
- Outsourced coding review
- Clearinghouse
- Denial management and A/R follow-up vendor
- Document storage and release-of-information service
- Backup and archive provider
Every one of those is a business associate. Each needs a Business Associate Agreement executed before PHI flows, and each needs it refreshed when the relationship changes scope. HHS explains the requirement and the required contract provisions in its business associate guidance.
The gap we see most often is the cloud fax service and the denial management vendor. Both get added mid-year by a billing manager solving an immediate problem, and neither ends up on the privacy officer's vendor list. If you just found one of those on your own list while reading this, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Get it signed before the next batch of consultation reports moves through that channel.
The Rework Loop and Its Privacy Footprint
When a claim built on consultation CPT codes is denied, the appeal usually requires sending the chart note plus proof of the request and the report. That is a second disclosure of the same PHI, this time to a payer rather than a clinician — a payment disclosure, which is subject to minimum necessary.
Train your appeals staff to send the documentation the payer asked for and nothing more. A full chart dump in response to a request for one encounter note is a minimum necessary problem and it is entirely avoidable. Define a standard appeal packet: the encounter note, the request documentation, the report transmission proof, and the payer's own request letter.
A worked example of the timeline
Day 0: request arrives by secure message, logged with requesting NPI and reason. Day 4: encounter occurs. Day 5: report transmitted, receipt attached to chart. Day 6: coding review confirms payer accepts the consultation family; claim drops. Day 41: denial arrives citing insufficient documentation of request. Day 44: appeal packet assembled from the Day 0 and Day 5 artifacts, sent through the payer portal, logged. If your Day 0 and Day 5 artifacts do not exist, Day 44 becomes a phone call to another practice asking them to reconstruct a record — which is a disclosure and a request you now have to justify.
A Quarterly Self-Check You Can Actually Run
- Pull 20 encounters billed with consultation CPT codes. Confirm the request artifact and the report transmission proof exist in each.
- Re-verify the payer matrix against current commercial plan policies. Plans change position on this code family more often than you would like.
- Reconcile your referral directory endpoints against the last quarter's outbound sends. Retire anything unverified.
- Cross-check the vendor list against the systems that actually touched a consultation encounter. Every name needs a current BAA on file.
- Sample five appeal packets. Confirm nothing beyond the requested scope went out.
Log the results. If a regulator ever asks how you manage records exchange with outside practices, a dated quarterly review beats a policy document nobody has opened.
Next Step
Start with the vendor list, because it is the item with a hard legal requirement and a same-day fix. Map the consultation workflow, name every system in the path, and confirm a signed agreement for each. If any are missing, draft and export the BAA you need and route it for signature this week. If your broader documentation set — risk analysis, policies, workforce training records — is also thin, automated HIPAA risk analysis and policy generation will close that gap faster than a consultant's discovery call.