A payer's post-payment review letter arrives asking for 30 charts, all established-patient office visits from the last 18 months. Your biller pulls the notes. Two of them were dictated through an AI scribe you signed up for last spring, four were coded by a contractor in another state, and one patient had asked — in writing — that the visit never be sent to her health plan. Choosing the CPT code for a follow up visit is a billing task. Producing the records behind it, and accounting for everyone who touched them, is a compliance task. This guide covers both, in the order your practice actually encounters them.

How Your Practice Determines the CPT Code for a Follow Up Visit

"Follow-up visit" is scheduling language, not coding language. There is no CPT code named "follow-up." What your practice bills is an evaluation and management (E/M) service, and the first fork in the road is whether the patient is new or established.

The three-year rule your front desk enforces without knowing it

Under CPT conventions, a patient is established if they received a face-to-face professional service from a physician or qualified health professional of the same specialty and subspecialty in the same group practice within the prior three years. Your front desk makes this determination every time it books an appointment type, and your scheduling template usually encodes it silently.

That means a registration error is a coding error. If your staff creates a duplicate chart for a returning patient — new insurance card, married name, misspelled last name — the encounter can flow downstream as a new-patient visit. Duplicate charts also fracture the designated record set, which becomes a real problem the day someone requests their complete file.

Medical decision making or total time — the practice picks one per encounter

Since the 2021 office visit revisions, and their extension to other E/M categories in 2023, level selection for office and outpatient E/M rests on either medical decision making (MDM) or total time spent on the date of the encounter. History and exam are still documented as clinically appropriate, but they no longer drive the level.

Your role as an administrator is not to decide which level fits a given patient. It is to make sure the documentation supports whichever method the clinician used, and that your templates do not quietly default everyone to the same level. CMS publishes the payment and policy framework for these services under the Physician Fee Schedule, and your coding staff should be working from current-year CPT guidance, not a laminated card from 2019.

Time-based documentation creates a specific audit artifact

When a clinician selects a level by total time, the note has to state the time. "Approximately 30 minutes" in a template footer that appears on every chart is a pattern an auditor will notice. Build a quarterly report that flags identical time statements across a provider's panel, and route the outliers to your coding lead — not to the provider directly, and not by email attachment containing the full note.

Which CPT Codes Cover Follow-Up Office Visits?

Follow-up appointments for a patient your practice has already seen are generally reported with the established patient office or other outpatient E/M code family, 99211 through 99215. Level selection within that range depends on either the complexity of medical decision making or the total time the clinician spends on the date of service, as documented in the note. The lowest level in the family, 99211, is the one commonly associated with visits that do not require the presence of a physician, and it carries its own supervision and documentation requirements. Practices with telehealth follow-ups should confirm payer-specific rules, because CPT's dedicated telemedicine E/M code set introduced for 2025 is not recognized uniformly across payers, and Medicare telehealth policy has moved through repeated statutory extensions.

The Documentation Trail Between the Exam Room and the Clearinghouse

Map who touches a follow-up encounter before the claim leaves. In most small practices the chain looks like this:

  • Front desk registers and verifies eligibility — touches demographics and insurance
  • Clinical staff rooms the patient and enters vitals — touches the chart
  • Clinician documents, possibly through a dictation or ambient scribe tool
  • Coder or biller reviews the note and finalizes the code
  • Claim goes to a clearinghouse, then to the payer
  • Remittance comes back, and denials get worked

Every arrow in that chain is a disclosure or a use of protected health information. Write the chain down. If you cannot name the entity at each step and produce a signed agreement for the external ones, you have found your first gap.

Coder queries and chart amendments are two different things

When a coder cannot support a level from the note, they query the clinician. If the clinician adds information, that addition is an addendum — dated, timestamped, attributed, and preserved alongside the original entry. It is not an edit.

Keep this distinct from a patient-requested amendment under 45 CFR 164.526, where the patient asks you to change something they believe is inaccurate. Your practice has 60 days to act on that request, with one 30-day extension, and a denial has to be in writing with a stated basis. Front-desk staff routinely confuse "the coder needs more detail" with "the patient disagrees with the note." Train the difference.

Every Code Selection Creates a Vendor List

The CPT code for a follow up visit gets to the payer only by passing through outside parties. Each of them is a business associate, and each needs a business associate agreement executed before PHI moves.

The usual list in an outpatient practice: billing company, coding contractor, clearinghouse, transcription or ambient documentation vendor, telehealth platform, patient-payment processor that stores statement data, appointment reminder service, document storage or shredding vendor, and the IT firm with administrative access to your servers. Add any analytics or denial-management tool your biller signed up for on a credit card.

The failure mode is almost never the big vendor. It is the small one adopted mid-year by a department that did not loop in compliance — a scribe pilot, a fax-to-email service, a coding audit consultant hired for six weeks. If you are onboarding a vendor this quarter and need paper on file before the first claim flows, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, and it beats forwarding a decade-old template with another practice's name still in the signature block.

HHS publishes sample business associate agreement provisions covering the required elements. Read them once so you know what you are looking at when a vendor sends you their version — vendor-drafted BAAs often narrow breach notification timelines in the vendor's favor.

Minimum Necessary Applies to What You Send the Biller

A billing vendor coding your established-patient visits needs the encounter note, the diagnosis list, and the demographic and insurance data. It rarely needs the patient's full longitudinal chart, scanned records from a prior practice, or unrelated behavioral health notes.

Payment activities are subject to the minimum necessary standard. Check what your system actually exports when your biller opens a work queue. In practice, many integrations grant full-chart visibility because that was the easiest permission to configure. Ask your vendor to scope the role, get the answer in writing, and record the date you asked.

The Patient Who Asks for an Itemized Bill

Billing records are part of the designated record set. When a patient asks for the itemized statement showing the codes billed for their follow-up visits, that is a right-of-access request, not a courtesy.

You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. You must provide the records in the form and format requested if you can readily produce them, and fees are limited to a reasonable, cost-based amount. HHS maintains detailed guidance on individuals' right of access, and access failures have been a sustained enforcement focus.

Operational fix: your access log should record the request date, the requested format, the response date, and who fulfilled it. If your billing system and your clinical system are separate, name one person responsible for merging both into a single response. Splitting the request between two staff members is how the 30-day clock gets missed.

The Self-Pay Restriction That Blocks the Claim Entirely

Under 45 CFR 164.522(a)(1)(vi), a patient can require your practice not to disclose PHI to a health plan for payment or operations purposes when the patient pays out of pocket in full for that service. Your practice must honor it. This is one of the few restriction requests you cannot refuse.

It usually surfaces at a follow-up visit — a sensitive diagnosis, a family member on the same policy, a custody situation. The operational problem is that your billing workflow is built to submit claims automatically. Build a hard stop:

  1. Front desk documents the restriction in writing at check-in and collects payment in full
  2. A chart-level flag fires that suspends the encounter from the claim batch
  3. Biller confirms suppression before the day's batch transmits
  4. Compliance lead reviews restricted encounters monthly against transmitted claims

Test this once a quarter with a dummy encounter. A restriction that exists only as a sticky note on a monitor is not a restriction.

Retention: Two Clocks, Not One

HIPAA requires six-year retention of required documentation — policies, risk analyses, BAAs, access logs — from creation or last effective date. Medical record retention itself is set by state law and payer contract, and those periods often run longer.

Overpayment lookback windows are a third clock. Coordinate all three before you approve a destruction schedule, and get the retention terms of your billing vendor in writing: what they keep, for how long, and what happens to the data if you terminate. Termination provisions in a BAA are the section nobody reads until the relationship ends badly.

A Ninety-Minute Review You Can Run This Month

Pull ten established-patient encounters at random from the last quarter. For each one, confirm the note states the level-selection method used, the addenda are timestamped and attributed, no restriction flag was overridden, and every external party that touched the record appears on your BAA inventory with a current signature. Document what you found and the date you did it — the review itself is compliance documentation.

If that exercise surfaces vendors with no agreement on file, close the gap before the next claim batch: build the BAA and get it signed. And if your broader document set — risk analysis, policies, workforce training records — has drifted out of date alongside it, automating the full compliance document set is a faster path than rebuilding it a file at a time.