A payer sends your office a letter requesting the complete records for 20 established patient visits billed at the highest level over the past 14 months. You have 30 days to respond. Somewhere in that stack are charts your front desk pulled, a billing company touched, an AI scribe transcribed, and a coding consultant reviewed. Before you print a single page, you need two things: an accurate understanding of the cpt code 99215 definition your clinicians and coders were working from, and a records-handling process that does not turn a payment dispute into a privacy incident.

This guide covers the administrative mechanics of that code, then makes the privacy, records, and vendor implications explicit. It is written for the people who sign the vendor contracts and answer the letters.

What Is CPT Code 99215? The Short Answer

CPT 99215 is the highest-level office or other outpatient evaluation and management (E/M) service code for an established patient — someone your practice or a same-specialty clinician in your group has seen within the prior three years. Under the E/M office visit framework in effect since 2021, code level for 99202–99215 is selected on one of two bases: the level of medical decision making documented, or the total time the reporting clinician spends on the encounter on the calendar date of service. For 99215, that time threshold begins at 40 minutes.

History and exam are still performed and documented as clinically appropriate, but they no longer drive the code level. That single change is why the cpt code 99215 definition matters to administrators as much as clinicians: the defensibility of the claim now rests on documentation of decision making or a time statement, not on a checklist of bullet points.

The two selection paths, in operational terms

  • Medical decision making. The clinician documents the problems addressed, the data reviewed and analyzed, and the risk of the management options considered. Your coders read that documentation; they do not supply it.
  • Total time on the date of the encounter. Face-to-face and non-face-to-face work by the reporting clinician on that date — chart review before the visit, the visit itself, ordering, documentation, care coordination. Time by clinical staff does not count toward it.

Which path applies is a clinical documentation decision made by the treating clinician. Your job is to make sure the record supports whichever path was used, and that nobody in your billing chain is quietly upgrading codes to hit a revenue target.

Why the CPT Code 99215 Definition Shows Up in Audit Letters

High-level established patient visits attract review for an obvious reason: they pay more, and utilization patterns are easy to graph. Payers and contractors compare your distribution of 99212–99215 against peers in your specialty. An outlier pattern is not fraud, but it is a reliable trigger for a records request.

Two documentation gaps produce most of the recoupments practices see. The first is a time-based selection with no time statement — the note says the visit was extensive but never states total time on the date of service. The second is a decision-making selection where the note describes a complex patient but not the complexity of what the clinician actually addressed and managed that day.

Neither gap is a coding problem you can fix retroactively from the billing office. Both are documentation-template and training problems, which puts them squarely in the practice administrator's lane. CMS publishes the current physician fee schedule and E/M policy materials at cms.gov; keep the version you relied on for a given date of service, because audits look backward.

Who is allowed to change a code, and how you prove it

Write this down as policy if you have not already:

  1. Clinicians select the code and sign the note.
  2. Certified coders and billing staff may query the clinician when documentation and code do not align. They may not change the level unilaterally.
  3. Every query and every resulting change is logged with a date, the person who raised it, and the clinician's response.
  4. Your EHR audit log retains who edited the note and when. Do not disable that.

That log is your defense in both directions — against a payer alleging upcoding, and against an allegation that administrative staff pressured clinicians. It is also protected health information, which means it lives inside your HIPAA scope, not in a spreadsheet on someone's desktop.

The Records Request Workflow: 30 Days, Minimum Necessary, One Log

When the audit letter arrives, assign a single owner. Diffused responsibility is how the wrong chart ends up in the envelope.

Disclosures to a health plan for payment purposes are permitted under the Privacy Rule without patient authorization. That does not make them unlimited. The minimum necessary standard applies: send the records for the dates of service and patients identified, not the full longitudinal chart because exporting it was easier.

A workable sequence

  1. Day 1. Log the request — requester, legal authority cited, patients, date range, response deadline. One tracker, one owner.
  2. Days 2–5. Pull records to the exact scope. Redact or exclude other patients' information from shared documents such as group scheduling exports or lab batch reports.
  3. Days 5–10. Have a coder and the treating clinician review each chart against the documentation that supports the level billed. Document any self-identified errors; a voluntary correction is far cheaper than a finding.
  4. Days 10–20. Transmit through an encrypted channel the payer supports. Fax to an unverified number and portal uploads to the wrong account are both common breach sources.
  5. Day 20+. Archive exactly what you sent, in what format, to whom, on what date. If a dispute follows a year later, you will need the transmitted set, not a fresh export.

Separately, do not confuse this with a patient's own request. When a patient asks for their chart, you are on the right-of-access clock — generally 30 days, with one 30-day extension and written notice. HHS guidance on the individual right of access also governs fees, which are far more limited than the rates some copy vendors quote. Patients requesting the note behind a high-level visit charge are common; billing disputes drive access requests.

Every Vendor That Touches a 99215 Claim Needs a BAA

Map this out once and keep it current. For a single established patient visit billed at the highest level, the entities that may see identifiable data include:

  • Your practice management and EHR host
  • The clearinghouse transmitting the claim
  • An outsourced billing or revenue cycle company
  • A coding audit or documentation improvement consultant
  • An ambient AI scribe or transcription service capturing the encounter
  • A patient statement and payment processing vendor
  • A telehealth platform, if the visit was virtual
  • An analytics or benchmarking tool showing your E/M level distribution

Each of these is a business associate. Each needs an executed agreement before it receives PHI, and each subcontractor beneath them needs one too. The benchmarking tool is the one practices forget — if a dashboard shows your 99215 rate by provider using identifiable claim data, that vendor is in scope even though nobody thinks of it as a clinical system. If you have gaps, you can produce a signature-ready business associate agreement without waiting on outside counsel for a routine vendor.

AI scribes and the time-based path

Ambient documentation tools create a specific tension with time-based code selection. The tool generates a note; the clinician attests to total time. Ask your vendor three questions and get the answers in writing:

  • Does the product record, store, or timestamp anything that could be read as a competing account of encounter duration? If so, where does it live and how long is it retained?
  • Is audio retained after the note is generated, and can you configure that?
  • Is de-identified or aggregated data used for model training, and does your BAA actually permit that use?

The third question is where contracts quietly go sideways. A vendor's standard terms may grant broad data rights that your BAA is supposed to constrain. When the two documents conflict, you will be the one explaining it.

The Documentation Trail Is Now Also a Security Surface

Time-based E/M selection means your systems are generating metadata that did not matter operationally five years ago: portal message timestamps, chart-open durations, pre-visit review activity, telehealth session logs. That data supports your coding. It also expands what an attacker or a careless export can expose.

Your Security Rule risk analysis should reflect this. If you added an AI scribe, switched clearinghouses, or turned on a coding analytics dashboard in the last 18 months and your risk analysis does not name those systems, it is out of date — and an outdated risk analysis is among the most frequently cited findings in OCR enforcement. Practices that need to close that gap quickly can generate a current risk analysis and the supporting policy set rather than restarting a document project from scratch every audit cycle.

One more operational note: information blocking rules apply to the clinical notes behind these visits. If a patient requests the note supporting a high-level charge and your policy is to route it through a slow manual review, read the ONC information blocking guidance before you defend that policy.

A 30-Day Cleanup Checklist for Your Practice

Nothing here requires a consultant or new software.

  1. Pull your E/M distribution by provider for the last four quarters. Not to judge clinical decisions — to know your numbers before a payer tells you.
  2. Sample ten high-level established patient charts. Confirm each one shows either a documented time statement or documented decision-making elements. Note which path each used.
  3. Audit your query log. If code changes exist with no corresponding clinician response, fix the process this month.
  4. Reconcile your vendor list against your BAA file. Anything on one list and not the other is a finding waiting to happen.
  5. Confirm the CPT license covering the code descriptors in your templates and internal reference sheets. CPT is AMA-copyrighted; verbatim descriptors in staff-facing materials carry licensing obligations.
  6. Time a records request end to end. If you cannot produce a scoped, encrypted response in 15 business days, your process is the risk, not your coding.

Where the Coding Question and the Privacy Question Meet

Administrators who treat the cpt code 99215 definition as purely a billing matter end up managing two separate crises — a recoupment demand and, later, an incident report from the same records pull. The two are one workflow. The chart that proves your code was supported is the chart you must disclose narrowly, transmit securely, and log accurately.

Get the boring parts right: one owner per request, one tracker, current BAAs, a risk analysis that names the systems you actually use, and a query log that shows clinicians made the coding decisions. Then a high-level visit code is just a code, not an exposure.

If your vendor inventory and risk analysis have drifted since your last software change, start there — build the current document set and work from something accurate the next time a letter arrives with a 30-day deadline attached.