Your provider treated eleven warts on one patient's foot Tuesday morning, documented "multiple plantar warts, cryotherapy performed," and moved on. Your coder now has to decide how many lesions were treated, whether the count crosses a threshold that changes the code, and whether the payer considers the service medically necessary at all. If the answer is no, the patient pays cash — and the moment they do, a HIPAA obligation attaches that has nothing to do with billing.

This guide covers how practices select and support the CPT code for wart removal from an administrative standpoint: what the code families are organized around, what the chart has to say for the claim to survive review, and where the privacy, records, and vendor exposure sits. It is written for administrators, billers, and privacy officers — not for clinicians deciding what to do at the bedside.

Which CPT Code Families Cover Wart Removal?

There is no single CPT code for wart removal. Code selection is driven by three documented facts: the method used, the anatomic site, and the number of lesions treated. Your coders work from these families:

  • Destruction of benign lesions (17110, 17111). Split by lesion count — one range covers up to 14 lesions, the other covers 15 or more. The descriptor is method-agnostic: cryosurgery, electrosurgery, laser, chemical destruction, and surgical curettement all fall inside it. Skin tags and cutaneous vascular lesions are expressly excluded.
  • Site-specific destruction codes. Anogenital lesions have their own families by site — anal (the 46900 range), penile (the 54050 range), and vulvar (the 56501 range). Site documentation, not lesion type alone, drives which family applies.
  • Shaving, excision, and biopsy codes. The 11300 shaving range and 11400 benign excision range are keyed to lesion diameter and body area, and they carry different documentation requirements than destruction.

Your practice does not pick a code from a keyword. Your coder reads the operative note, matches the documented method and site to the correct family, applies the payer's policy, and queries the provider when the note is silent on a required element.

The Four Chart Elements That Decide the Code

Build these into your note template or your provider query script. Missing any one of them stalls the claim or forces a downcode.

Lesion count, stated as a number

"Multiple" is not a count. "Several" is not a count. Because the destruction family splits at a specific lesion threshold, a note that fails to state a number cannot support the higher-count code. Train providers to write the integer, and train coders never to infer one.

Anatomic site, specific enough to route the code

"Right plantar surface" and "perianal" send the claim to entirely different code families and, in some cases, different coverage policies. Laterality belongs in the note even when the code set does not require a modifier.

Method of destruction or removal

The destruction codes cover many methods, but the note still has to say which one was used. That single line is what separates destruction from shaving from excision when a payer requests records.

Medical necessity language

Pain, bleeding, gait interference, spread, functional limitation, failed prior treatment, immunocompromise — these are the facts payers look for. Your coders cannot add them. Your providers have to document them contemporaneously, at the visit, in their own words.

Diagnosis coding

ICD-10 codes in the B07 range describe viral warts by type, and A63.0 covers anogenital venereal warts. The diagnosis your provider selects determines both coverage and, as covered below, how sensitive the claim is.

Coverage Policy Is Local, and It Changes

Many payers treat benign skin lesion removal as cosmetic and non-covered unless specific symptomatic criteria are documented. For Medicare, coverage of benign lesion removal is set by your Medicare Administrative Contractor through local coverage determinations and related billing articles rather than by a single national rule. Assign one person to pull the current policies for your MAC and your top three commercial payers each quarter from the CMS Medicare Coverage Database, and to check global periods and relative values in the Physician Fee Schedule Search tool.

Two operational consequences follow. First, if your Medicare patient may receive a service the program will not cover, your front desk needs the Advance Beneficiary Notice workflow — the right form, completed before the service, with a copy to the patient and a copy in the record. Second, your commercial payer contracts may require written financial notice with different timing. Put both on a single laminated sheet at the check-in desk rather than expecting staff to remember which payer requires what.

Self-Pay Wart Removal Triggers a Mandatory HIPAA Restriction

Here is the part most billing workflows miss. Under the Privacy Rule, when a patient pays for a service out of pocket in full and asks you not to disclose information about that service to their health plan, you must honor the request. That restriction is not discretionary the way most restriction requests are. The rule sits at 45 CFR 164.522(a)(1)(vi); HHS maintains the regulation text and supporting guidance in its HIPAA rules and guidance library.

Wart removal is exactly the service where this comes up, because a meaningful share of these encounters get billed to the patient rather than the plan. A patient with anogenital warts, or an adolescent on a parent's policy, may specifically not want an explanation of benefits arriving at the policyholder's address.

Your workflow needs four things:

  1. A one-page restriction request form the front desk can hand over without escalating to the privacy officer.
  2. Payment collected in full at the time of service, documented as such.
  3. A flag in the practice management system that suppresses the claim and blocks the encounter from any plan-directed submission, including secondary and eligibility-driven batch runs.
  4. A log entry the privacy officer reviews monthly, confirming no claim went out.

The failure mode is mechanical, not malicious: the account sits unflagged, a month-end sweep picks it up as unbilled, and the claim goes to the plan. Test this deliberately. Create a dummy self-pay encounter with a restriction flag and run your normal claim batch to confirm it stays put.

Sensitive Diagnoses, Minors, and Confidential Communications

A63.0 is a sexually transmitted infection diagnosis. It travels on the claim, on the EOB, in the patient portal, and in any records release your staff processes. Several states give minors independent authority to consent to STI treatment and restrict disclosure to parents, and those rules do not always align with how your portal proxy access is configured by default.

Three concrete tasks for your privacy officer:

  • Audit portal proxy access for patients aged 12 and up. Confirm what a parent proxy sees — visit type, diagnosis list, problem list, billing statements. Document the age at which proxy access narrows or ends in your system, and whether that matches your state's rule.
  • Operationalize confidential communication requests. Patients may ask you to send communications to an alternative address, phone, or email. Under 45 CFR 164.522(b) you must accommodate reasonable requests for that. Make sure the alternate contact field actually drives statements and recall letters, and not just appointment reminders.
  • Restrict who can see the encounter internally. Minimum necessary applies to your own staff. If your system supports sensitive-encounter flags, use them for anogenital diagnoses and audit access reports quarterly.

Clinical Photographs Are PHI, and Yours Are Probably on a Phone

Wart treatment often generates before-and-after images to support medical necessity or track response. Those photographs are protected health information the moment they exist. Ask a plain question at your next staff meeting: which device took the last lesion photo in this practice, and where does that image live now?

If the answer involves a personal phone, a text thread, or a consumer photo-sharing app, you have three problems at once — an unencrypted device holding PHI, a disclosure to a vendor with no business associate agreement, and an image outside the designated record set that a patient can still request. Your policy should require capture through the sanctioned application, immediate association with the chart, and verified deletion from the device's local storage.

Separately: using a patient's lesion photograph in marketing, on your website, or in social media requires a valid HIPAA authorization. Consent to treatment is not authorization to publish.

The Vendor List Behind One Wart Removal Claim

Walk the encounter end to end and count the outside parties handling the data. A typical practice finds seven or eight: the EHR host, the clearinghouse, the outsourced coder or billing company, the transcription or ambient documentation tool, the image capture application, the patient statement printer, the payment processor, and the cloud backup provider. Add an e-fax service if you send records to a referring dermatologist.

Every one of those is a business associate, and every one needs a signed agreement on file with a named term and breach-notification timeline. If your vendor inventory is a spreadsheet someone updated in 2023, it is not an inventory. Practices that need to close this gap quickly can generate the risk analysis, policy set, and supporting compliance documentation rather than assembling it from templates over six months, and use a signature-ready business associate agreement for the vendors currently missing one.

The Security Rule requires an accurate, current risk analysis covering everywhere electronic PHI lives — which includes the photo app and the billing vendor's environment, not just your server closet. HHS explains the expectation in its Security Rule guidance materials.

When the Patient Requests the Record

Patients denied coverage frequently request their records to appeal, and the right of access clock is 30 days from the request with one 30-day extension available on written notice. The designated record set for one of these encounters includes the operative or procedure note, the lesion photographs, the pathology report if tissue was submitted, the ABN or financial notice, and the billing record.

Two things your release staff get wrong. They omit the images, because the photos live in a module they do not normally export. And they overcharge, because they bill a flat administrative fee instead of the labor-and-supplies-based cost permitted under the access rule. Fix both, and give your release-of-information staff a written checklist naming every module they must check for procedure encounters.

Five Assignments for This Quarter

  1. Billing lead: pull current lesion-removal coverage policies for your MAC and top three commercial payers; update the financial notice sheet at check-in.
  2. Clinical documentation lead: add a required numeric lesion-count field and a method field to the procedure template.
  3. Privacy officer: test the self-pay restriction flag against a live claim batch; document the result.
  4. Practice manager: inventory every device and application that has captured a clinical photograph in the last twelve months; confirm a BAA for each hosted service.
  5. Release-of-information staff: rebuild the access-request checklist to include image modules and recalculate your permitted fee.

The coding question — which CPT code for wart removal applies to a given documented encounter — belongs to your coder and your provider working from the note. The obligations that attach around that code belong to you. Start with the two that carry the most exposure: the self-pay restriction flag and the vendor agreements. If your risk analysis and policy set are older than your current vendor list, generate a current documentation package and work the gaps from there.