A patient calls your front desk on Monday and says she's new. Your scheduler registers her as new, the visit happens, and the claim goes out. Three weeks later the payer denies it: she saw one of your partners — same specialty, same tax ID — thirty-four months ago. That single registration error is why the cpt code for new patient office visit selection is an administrative problem before it is ever a coding problem. This guide is for the people who own that problem: practice administrators, billing leads, and privacy officers. It covers how practices determine and document the code, who does what, and where the privacy and vendor exposure sits.

Which CPT Codes Cover a New Patient Office Visit?

The CPT code set designates office or other outpatient evaluation and management visits for new patients as 99202 through 99205. Code 99201 was deleted effective January 1, 2021, when the office visit E/M section was restructured. Established patient office visits use a separate range, 99211 through 99215.

Since the 2021 restructuring, level selection for these codes rests on either the level of medical decision making or the total time the reporting clinician spends on the date of the encounter. History and exam are still documented as clinically appropriate, but they no longer drive the level. Your clinicians, using the current CPT manual and payer policy, decide which code fits a given encounter. Your job is to make sure the inputs they need — new-versus-established status, time capture, and a clean record — actually exist.

The Three-Year Rule Your Scheduler Enforces Without Knowing It

CPT defines a new patient as one who has not received any professional service from the physician or other qualified health professional — or another physician of the exact same specialty and subspecialty who belongs to the same group practice — within the past three years. Everything downstream depends on that determination, and the determination is usually made by whoever answers the phone.

Three failure points show up in nearly every audit I've run:

  • Duplicate chart creation. A patient with a new last name or a typo'd date of birth becomes a second record, so the prior encounter never surfaces.
  • Specialty mapping that nobody maintains. A multispecialty group needs a current list of which providers share exact specialty and subspecialty designations. If that list lives in one person's head, it will be wrong within a year.
  • Acquired practices. When you absorb another group, patients who saw the acquired clinicians may now count as established under your group. Your registration workflow has to account for the merged history.

Assign one person to own the specialty-mapping document, review it quarterly, and date-stamp each revision. When a payer audits, that document is your evidence that the new-patient determination followed a defined process rather than a guess.

Duplicate-Chart Cleanup Is a Privacy Task, Not Just a Data Task

Merging duplicate records is where practices accidentally combine two different humans. A wrong merge puts one patient's diagnoses into another patient's chart — that's an impermissible disclosure the moment the second patient views their portal or requests records. Require two-person verification on any merge, log who approved it, and treat a bad merge as a reportable incident until your privacy officer rules otherwise.

How Practices Document Code Selection for a New Patient Visit

Whichever path a clinician uses, the record has to show the reasoning. Administratively, that means your templates and your audit checklist look for specific artifacts.

If the Clinician Selects by Total Time

CPT assigns each level a time range for total time spent on the date of the encounter, and that time includes qualifying non-face-to-face work the reporting clinician personally performs that day — reviewing outside records, ordering tests, documenting, coordinating care. It does not include staff time, and it does not include work performed on a different calendar day.

Your operational obligations: a template field that captures total time as a number, a written internal policy on what counts, and periodic sampling to confirm times aren't defaulting to the same value on every note. Identical time entries across dozens of encounters are the pattern auditors look for first.

If the Clinician Selects by Medical Decision Making

The MDM path turns on the number and complexity of problems addressed, the data reviewed and analyzed, and the risk of complications from management. Your role is structural, not clinical: make sure the note has room to record what was reviewed and from whom, that external records actually attach to the chart, and that a diagnosis list exists rather than a free-text blob no coder can parse.

CMS maintains its own guidance on evaluation and management billing that your billing lead should read alongside the CPT manual — start at the agency's evaluation and management coding and billing resources. Payer-specific policies layer on top; keep them in a shared folder with an effective date on each one.

The Role Map: Who Owns Each Step

Write this down and post it. Ambiguity here produces both denials and privacy incidents.

  1. Scheduler. Runs the three-year lookup before assigning new-patient status. Documents the search performed if no prior record is found.
  2. Front desk. Verifies identity and demographics against a photo ID or an established verification script. Collects intake forms through a channel your privacy officer has approved.
  3. Clinician. Selects and documents the code level. Nobody else changes it without a query.
  4. Coder or biller. Reviews for internal consistency, queries the clinician in writing when documentation and code don't align, and never upcodes or downcodes unilaterally.
  5. Practice administrator. Runs a monthly report of new-patient E/M distribution by clinician and investigates outliers.
  6. Privacy officer. Confirms every vendor in the chain has a current Business Associate Agreement and that access levels match job function.

Query documentation matters more than most administrators expect. A written, non-leading query in the chart shows an auditor that the coding conversation happened inside a controlled process. A hallway conversation shows nothing.

Every New Patient Visit Creates a Vendor Trail

Trace one new patient encounter end to end and count the outside organizations that touch protected health information. In a typical small practice: the online intake form vendor, the EHR host, the ambient documentation or transcription tool, the coding-assistance software, the billing company, the clearinghouse, the patient statement printer, the payment processor's PHI-adjacent records, the answering service, and whoever backs up your data.

Each of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. HHS explains the scope and required terms in its business associate guidance. Two recurring gaps I find during vendor reviews:

  • The billing company's subcontractors. Offshore coding support, a document-imaging vendor, an AR follow-up call center. Your BAA needs to obligate the billing company to bind its subcontractors, and you should be able to name them.
  • Tools adopted by a single clinician. An AI scribe someone signed up for with a credit card is a business associate relationship you never papered. These surface constantly, and they surface after the fact.

If your vendor inventory has names without matching signed agreements, close that gap before your next audit cycle. You can produce a signature-ready agreement quickly using this six-step Business Associate Agreement generator, which exports to PDF and DOCX on a one-time purchase — useful when you discover three unpapered vendors on a Tuesday and need documents out the door by Friday.

Minimum Necessary Applies to Billing Disclosures

Sending a vendor the entire chart when it needs a claim, a diagnosis list, and a time entry is a minimum-necessary problem. Review what your interfaces actually transmit — not what the contract says they transmit. HHS's minimum necessary guidance is the standard to measure against, and interface field mapping is where you'll find the surprises.

Coding Records Are Part of the Designated Record Set

When a patient asks for their record, billing and payment records maintained by or for you are generally within the designated record set. That includes the claim, the encounter note supporting the level, and often the coding query. You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS's right of access guidance is worth re-reading annually, and right-of-access failures have been a persistent OCR enforcement theme — the resolution agreements are searchable through the OCR portal.

Practical consequence: if your billing lives with an outside company, your access workflow must include a defined turnaround from that company. Put a specific number of business days in the BAA or the service agreement. "Promptly" will not help you on day 28.

Patients also have the right to request amendment. A patient disputing a code level is usually disputing the underlying documentation. Route those through your amendment process with dates and written outcomes rather than letting billing staff argue it over the phone.

When an Audit Finds the Level Was Wrong

Internal audits exist to find problems, so plan for the day one appears. Under the federal 60-day rule, an identified overpayment on a Medicare or Medicaid claim generally must be reported and returned within 60 days of identification. Your written policy should define who declares an overpayment identified, who calculates the refund, and who signs the transmittal.

Sequence it this way: sample at least ten new-patient encounters per clinician per quarter, document the sample selection method, record findings in writing, retrain on specific findings rather than general reminders, and re-audit the same clinician in the following quarter. Keep the audit workpapers — they demonstrate an active compliance program, and they are the difference between an error and a pattern.

Note that an audit performed by an outside consultant with chart access is also a business associate arrangement. Paper it before the first chart is opened, not after the report arrives.

A Five-Line Front Desk Script

Train it, post it, and test it during onboarding:

  1. "Have you been seen by anyone in our practice in the last three years?"
  2. Search by last name, then by date of birth, then by phone number — all three, every time.
  3. Confirm identity before discussing any chart content.
  4. If a prior record exists, flag it for the clinician rather than deciding the status yourself.
  5. If you find nothing, note in the chart which searches you ran.

That last line does more work than the rest combined. It converts an unverifiable assumption into documented diligence.

Retention and Access Review

HIPAA requires six-year retention for required documentation such as policies and authorizations; state medical record retention laws are separate and frequently longer. Keep both timelines in one schedule so nobody purges a chart that supports a claim under appeal.

Review role-based access twice a year against a current staff roster. Billing staff generally need claims and encounter documentation, not the entire clinical history of every patient in the practice. Terminated employees should lose access the day they leave — check the clearinghouse and the billing portal, not just the EHR.

Your Next Step

Pick one thing this week: pull your vendor list and mark every name without a signed, current agreement. If that list has gaps, generate the missing documents with the BAA wizard and get them signed. If the gaps run deeper than paperwork — no current risk analysis, stale policies, no documented audit process — the broader HIPAA risk analysis and policy toolset will get the documentation set built faster than starting from a blank page. Getting the cpt code for new patient office visit right is a coding exercise; keeping the record and the vendor chain defensible is the part that lands on your desk.