A payer requests thirty infusion encounters for review. Your biller pulls the claims and finds that fourteen of them carry CPT 96375 on a second or third line, and four of those fourteen have no documented stop time for the base service. Nobody argues the drug wasn't given. The argument is about whether the record supports the charge — and the recoupment letter doesn't care about the difference.

This guide is for the people who own that problem: practice administrators, billing leads, and privacy officers. It covers what has to exist in the record before an add-on IV push line goes out the door, who inside and outside your organization touches that data, and where the HIPAA obligations attach. It is administrative guidance about documentation and workflow, not clinical guidance about what to give a patient or which code fits a clinical picture. Your clinicians and certified coders own that call.

What CPT 96375 Is, in Plain Operational Terms

CPT 96375 is an add-on code in the hydration, therapeutic/prophylactic/diagnostic injection and infusion family. The CPT descriptor covers each additional sequential intravenous push of a new substance or drug, and it is reported in addition to a primary service — never alone, never as the first line of an infusion encounter.

Three operational consequences follow from that single sentence:

  • It requires a parent line. An add-on code that arrives at the clearinghouse without an acceptable primary procedure on the same claim is a denial waiting to happen.
  • It depends on hierarchy and sequencing rules published in CPT guidelines and reinforced by payer policy. Which service is designated primary in a multi-service encounter is a coding determination, made by qualified staff against the documentation in front of them.
  • It is documentation-hungry. Substance identity, route, timing, and the order of events all have to be legible in the chart, because the code's definition turns on "additional," "sequential," and "new substance."

CMS reinforces the mechanics through the National Correct Coding Initiative edits and its add-on code files. Your billing lead should be checking the current-quarter files rather than relying on a printout from two years ago — see the CMS NCCI resources for Medicare.

The Six Documentation Elements That Decide Whether a CPT 96375 Line Survives

Build these into your infusion note template and your pre-bill audit checklist. If any element is habitually missing, that is a workflow defect, not a coder problem.

1. A signed, dated order

The order names the substance and the route. Verbal orders need an authentication path with a defined turnaround. Your policy should state the turnaround in hours, not "promptly."

2. Start and stop times for every timed service in the encounter

Push administrations still need administration times recorded, and the base infusion needs both ends of the clock. Missing stop times are the single most common finding I see when practices self-audit infusion charges.

3. Substance, dose, and sequence

The record has to show which substances were given and in what order. "New substance/drug" language in the descriptor means the sequence is the evidence.

4. Site and route

Route matters because it separates code families. Ambiguous route documentation forces the coder to query, and queries cost you days in A/R.

5. Who administered it

Name and credential, signed. Supervision requirements vary by setting and payer; your compliance file should record which standard you are operating under and why.

6. Medical necessity linkage

The diagnosis supporting the encounter has to be documented by the treating clinician. Coders translate; they do not supply.

Where a CPT 96375 Charge Is Actually Created — and Who Touches It

Map this for your own site. The generic version looks like this:

  1. Nursing documents administration in the flowsheet, often on a workstation in the infusion bay that ten people can see.
  2. The charge posts automatically from a flowsheet trigger, or a nurse enters it manually on a paper charge ticket. Manual tickets are where PHI goes to wander.
  3. A coder or charge-capture reviewer reconciles the encounter against CPT and payer sequencing rules.
  4. Your billing system or outsourced RCM vendor assembles the claim.
  5. A clearinghouse scrubs, translates, and transmits the 837.
  6. The payer adjudicates and may request records — which sends a bundle of chart pages back out through a release-of-information channel.

Every arrow in that chain is a disclosure of protected health information. Steps 4, 5, and 6 usually involve a business associate. Step 2, when it runs on paper, is the one that shows up in breach reports as "paper records left in a treatment area."

The Vendor Chain Behind a Single Add-On Line

Pull your vendor inventory and find every entity that could see an infusion encounter. In a mid-size practice that list typically includes the EHR host, the practice management system, the clearinghouse, an outsourced coding or RCM firm (sometimes with offshore staff), a denial-appeal or audit-defense contractor, a release-of-information service, a document-shredding company, and whatever analytics tool your CFO uses for payer-mix reporting.

For each one, you need three things on file:

  • A current, signed business associate agreement that names the right legal entity, not a d/b/a from a prior acquisition.
  • A written description of what data the vendor receives and whether it includes full chart pages or only claim-level fields.
  • Documentation of subcontractor arrangements — your RCM vendor's offshore coding partner is a subcontractor, and the agreement should say so.

If a vendor was onboarded during an infusion-service launch and the BAA never got countersigned, fix it before the next audit cycle. If you need a clean paper trail fast, a signature-ready business associate agreement generator will get a defensible document in front of the vendor the same day.

Minimum Necessary, Applied to Infusion Billing

The minimum necessary standard is not a slogan; it is a rule your billing workflow either satisfies or violates. HHS guidance on the minimum necessary requirement expects covered entities to define role-based access and to limit routine disclosures to what the purpose requires.

Three concrete applications for infusion charge capture:

Records sent for a CPT 96375 denial appeal

The payer asked for the infusion encounter. Sending the patient's entire longitudinal chart because it was easier to export is an over-disclosure. Define a standard appeal packet: the order, the administration record with times, the encounter note, and the relevant diagnosis documentation.

Access rights for billing staff

A biller working denials needs the encounter, not the behavioral health notes from four years ago. If your system cannot scope that, document the compensating control — audit log review with a named reviewer and a stated cadence.

Spreadsheets

Someone in your practice keeps a spreadsheet of unbilled infusion charges. It has names, dates of service, drug names, and account numbers. It lives on a desktop, gets emailed to the RCM vendor, and has never appeared in a risk analysis. That file is ePHI, and it is the most common finding in a first-year assessment.

The Risk Analysis That Should Already Name This Workflow

The Security Rule requires an accurate and thorough assessment of risks to all ePHI you create, receive, maintain, or transmit. HHS Security Rule guidance and NIST SP 800-66 Revision 2 both frame this as an inventory-first exercise: you cannot assess what you have not listed.

An infusion service adds systems that older risk analyses miss — pump interfaces, drug-inventory tools, standalone charge-capture apps, and the shared drive holding scanned charge tickets. If your last assessment predates the service line, it is stale by definition.

Practices that keep this current without a full-time analyst usually automate the mechanics. Tools that generate a documented HIPAA risk analysis and the supporting policy set let you refresh the asset inventory and the associated safeguards when a new service line goes live, instead of rebuilding a spreadsheet from scratch every eighteen months. No product is government-certified — HHS does not endorse or certify compliance software — but a dated, complete, reviewable report is exactly what an investigator asks for first.

When a Payer Audit and a Patient Records Request Collide

These two events look similar to front-desk staff and are legally different.

A payer audit is a disclosure for payment purposes, governed by your BAAs, your ROI procedure, and minimum necessary. A patient asking for their infusion records is a right of access request, and the clock is 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS has enforced access delays repeatedly through its right-of-access initiative; see the HHS guidance on individuals' right to access health information.

Practical rules for your team:

  • Log every access request the day it arrives, including requests that come by phone or in person.
  • If a request is routed to an outsourced ROI vendor, the 30-day clock still runs against you.
  • Fees for access are limited to a reasonable, cost-based amount. Do not let a vendor bill the patient a per-page rate that exceeds it.
  • The designated record set includes billing records. A patient asking why a second infusion line appeared on their statement is often making an access request without using the words.

A 90-Day Cleanup Plan for Infusion Charge Capture

Days 1–30: Inventory and baseline

Practice administrator lists every system and every vendor touching infusion encounters. Billing lead pulls 25 recent encounters containing add-on push lines and scores them against the six documentation elements. Privacy officer confirms a signed BAA exists for each vendor named.

Days 31–60: Fix the template and the access map

Clinical informatics adds hard stops for start/stop times and substance sequence. Privacy officer defines the standard appeal packet and restricts billing-role access to encounter-scoped data. Any spreadsheet holding patient identifiers moves to a controlled, logged location or gets retired.

Days 61–90: Re-audit and document

Billing lead re-scores 25 encounters and reports the delta to the compliance committee. Privacy officer updates the risk analysis to reflect the new systems, records the remediation decisions, and sets the next review date. Everything gets dated and signed — an undated policy is an unenforceable one.

The Two Sentences Worth Repeating to Your Staff

First: a cpt 96375 line is only as good as the times, sequence, and substances written in the record, and coders determine the code from that record rather than the other way around.

Second: every one of those records travels through vendors you are responsible for, and the agreement, the access limits, and the risk analysis are what make that travel lawful.

If your infusion service went live before your last risk analysis, start there this quarter. Build the current risk analysis and policy set, attach the vendor inventory to it, and put a review date on the calendar — so the next records request or payer audit finds a documented program instead of a scramble.