Your care coordinator logs 18 minutes on a patient in April. On May 2 she spends another 9 minutes closing the loop with the therapist. Your billing lead sees 27 minutes and drops a charge. That charge is wrong, and the reason it's wrong is the single most common operational failure around CPT 99484: the time clock resets on the first of every calendar month.

This guide is for the people who run the behavioral health integration program, not the people delivering it. If you're an administrator, billing manager, or privacy officer standing up general BHI services, you need three things nailed down before the first claim goes out: a defensible time log, documented patient consent, and a signed agreement with every vendor whose software touches the registry. Miss any one and you have either a payment problem or a breach problem.

What CPT 99484 Covers — The Short Answer

CPT 99484 describes general behavioral health integration care management services: at least 20 minutes of clinical staff time per calendar month, directed by a physician or other qualified health care professional, for a patient with a behavioral health or psychiatric condition. The service elements CMS describes include an initial assessment or follow-up monitoring using validated rating scales, behavioral health care planning with revision for patients who aren't progressing, facilitation and coordination of treatment, and continuity of care with a designated member of the care team.

It is billed once per calendar month per patient. It does not require a designated psychiatric consultant or the structured registry-plus-care-manager model that the Collaborative Care Model codes (99492, 99493, 99494) require. Code selection is a clinical and documentation determination made by the treating professional — your job as an administrator is to make sure the record supports whatever was selected, not to select it. CMS publishes the service definitions and billing conditions in its Behavioral Health Integration Services education material, and payment amounts appear in the Physician Fee Schedule.

The Calendar-Month Clock and Who Is Allowed to Run It

Twenty minutes, one calendar month, no rollover. Minutes on April 30 and minutes on May 1 belong to two different claims. Build that boundary into your tracking tool as a hard stop, not a report filter someone has to remember to set.

Whose Minutes Count

Time counted is clinical staff time directed by the billing professional. Front-desk scheduling, insurance verification, and chart pulls by administrative staff are not care management minutes. Neither is the billing team's own review. Write a one-page list of countable and non-countable activities, post it where the care coordinators work, and audit against it quarterly.

If your care coordinator is contracted rather than employed, incident-to and supervision rules matter and so does your vendor paperwork. A contracted coordinator working in your registry is handling PHI on your behalf. That relationship needs a business associate agreement unless the person is functioning as a member of your workforce under your direct control — and "functioning as workforce" is a determination you should document in writing, not assume.

Care management services carry patient consent expectations, including informing the patient that cost sharing may apply and that only one practitioner may furnish and bill the service in a given month. Get it once, document it, and make it retrievable in under a minute.

Practical rule: consent lives in a structured field, not a scanned PDF buried in "Miscellaneous." When a payer auditor asks for consent on 30 patients, you should be running a report, not opening 30 charts. Record the date, the person who obtained it, the method (verbal or written), and the fact that the patient was told they may stop the service at any time.

The Audit Trail a Payer Will Actually Ask For

Assume every 99484 claim will eventually be reviewed. The file you want to be able to produce contains six things:

  • Documented consent with date and method
  • The behavioral health care plan, with evidence of revision when the patient isn't improving
  • Rating scale results with dates administered
  • A time log with per-entry start/stop or duration, activity description, and staff member
  • Evidence of the directing professional's involvement and supervision
  • Confirmation the same month wasn't billed by another practitioner for the same service

The time log is where most practices are thin. Free-text notes that say "followed up with patient, ~10 min" won't hold up well. Require structured entries. If your care management module can't produce a per-patient, per-month minute total on demand, that's a gap worth fixing before volume grows.

The Overlap Rules That Trip Up Billing Staff

General BHI, Collaborative Care, chronic care management, principal care management, and transitional care management have interaction rules that vary by code pair and by payer. Some can't be billed in the same month by the same practitioner; some can, provided time isn't double counted. Never count the same minute toward two codes.

Give one person ownership of a payer-by-payer overlap matrix and a review date on it. When a policy changes, the matrix changes, and the billing team gets a two-line notice. That beats discovering the change through a takeback eighteen months later.

Why CPT 99484 Creates Privacy Exposure Ordinary Care Management Doesn't

Here's the part nobody assigns to anyone. General BHI generates a concentrated stream of behavioral health data — PHQ-9 and GAD-7 scores, medication adherence notes, substance use screening results, safety plan details — and moves it through tools that were often bought by the clinical side without a privacy review.

That data is PHI under HIPAA like any other, but it carries higher practical risk. A leaked A1c is a problem. A leaked suicidality screen is a different order of problem for the patient and for your organization's exposure. HHS maintains guidance on HIPAA and mental health information that is worth putting in front of your clinical leads, because the sharing questions come up constantly in coordination calls.

Part 2 and State Law Sit on Top of HIPAA

If any portion of your organization operates as a federally assisted substance use disorder program, 42 CFR Part 2 applies to those records and imposes consent requirements that go beyond HIPAA. Coordinating BHI with an outside SUD treatment program does not give you a free pass to redisclose what you receive.

State law adds another layer. Many states impose stricter rules on mental health and psychotherapy records than HIPAA does — special authorization forms, narrower disclosure permissions, sometimes shorter response windows for patient access. Your BHI release workflow must be built to the strictest applicable standard, and your front desk needs a decision tree, not a judgment call.

Minimum Necessary Inside the Care Plan

Coordination means talking to therapists, psychiatrists, community programs, and sometimes family. Each conversation is a disclosure decision. Apply the minimum necessary standard deliberately: the counselor confirming an appointment does not need the full assessment narrative.

Train coordinators on a simple habit — before each outbound disclosure, name the purpose and send only what serves it. Log the disclosure. Behavioral health accounting requests come in more often than you'd expect.

Every BHI Tool You Add Extends Your Vendor List

Stand up a general BHI program and you typically add three or four vendors within a year: a care management or registry module, a screening instrument platform, a secure messaging or outreach tool, sometimes a contracted care coordination staffing partner. Each one is a business associate. Each one needs a signed BAA on file before PHI moves.

The failure pattern is predictable. A clinical director pilots a screening tool with ten patients "just to see." No contract, no BAA, no security review. Six months later it's in the standard workflow and nobody remembers it was never papered. When you find one of these, don't argue about it — paper it or shut it off. If you need a defensible agreement quickly, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX; it's a one-time purchase with no subscription, which makes it practical for the one-off vendor that shows up mid-quarter.

Three questions to ask every BHI vendor before signature:

  1. Do you use, aggregate, or de-identify our data for product development or any secondary purpose? Get the answer in the contract, not in an email.
  2. Which subcontractors touch PHI, and where is it stored and processed?
  3. What is your breach notification timeline to us, and does it start at discovery or at confirmation?

Also check what's running on any patient-facing screening page. Third-party analytics and advertising trackers on pages that collect behavioral health information are an enforcement magnet, and the FTC has been active on health data sharing beyond HIPAA's reach. Have someone technical review the page source before launch.

When the Patient Asks for the BHI Record

Behavioral health integration records are part of the designated record set. A patient access request covers the care plan, rating scale results, and care management notes. Your standard access timeline applies, and psychotherapy notes — if they exist and are kept separate — follow their own rules.

Make sure your release staff knows where BHI documentation lives. If the care plan sits in a third-party registry rather than the main chart, a records clerk pulling only the chart will produce an incomplete response. Map every system that holds designated record set content and keep that map current. It's also the map you'll need for breach scoping.

A 30-Day Rollout Checklist

  • Days 1–5: Inventory every system that will touch BHI data. Confirm a signed BAA for each. Note gaps.
  • Days 6–10: Build the structured consent field and the time-log template. Test the calendar-month boundary.
  • Days 11–15: Write the countable-activity list and the payer overlap matrix. Assign an owner to each.
  • Days 16–20: Train coordinators on minimum necessary and disclosure logging. Train front desk on the behavioral health release decision tree.
  • Days 21–25: Add BHI systems to your designated record set map and your incident response scope.
  • Days 26–30: Run a mock audit on five charts. Fix what you can't produce in ten minutes.

Do this before volume, not after. Reconstructing time logs for 400 retroactive claims is a project nobody survives cheerfully.

Next Step

If your BHI vendor paperwork has gaps — and it almost certainly does the first time you look — close them before the next patient is enrolled. You can produce a signature-ready BAA in a few minutes for the registry, screening, and messaging vendors already in your workflow, and if you're rebuilding the broader documentation set behind the program, automated risk analysis and policy generation will get you further than another spreadsheet. Paper the vendors, structure the time log, and CPT 99484 stops being a liability and starts being a service line you can defend.