Diabetic Foot Exam CPT Codes: Ops and Privacy Guide
A payer sends your billing manager a post-payment review letter naming 38 patients and asking for the chart documentation behind a year of foot care claims. Two of those charts contain a cell-phone photo of an ulcer that a medical assistant took on a personal device. One contains podiatry notes faxed over from an outside office. Your biller is about to upload all 38 records to a portal she has never used before.
That is the real shape of diabetic foot exam CPT work inside a practice: a small set of codes, a documentation checklist, and a long tail of records-handling and vendor decisions that land on the administrator's desk. This guide covers the operational mechanics first, then makes the privacy and vendor implications explicit. It is administrative guidance for your coding and compliance staff — not clinical direction, and not a statement that any code fits any particular patient.
What "Diabetic Foot Exam CPT" Actually Refers To on a Claim
There is no single code called "diabetic foot exam." Staff searching that phrase are usually looking for one of four different billing situations, and your front desk, coders, and quality lead each touch a different one.
LOPS evaluation and management (HCPCS G-codes)
Medicare established G0245, G0246, and G0247 for evaluation and management of a diabetic patient with diabetic sensory neuropathy resulting in loss of protective sensation (LOPS). G0245 covers an initial physician evaluation, G0246 a follow-up evaluation, and G0247 routine foot care furnished at the same encounter as one of those evaluations.
Frequency limits, the required elements of the evaluation, and which practitioner types may report them come from Medicare policy and your MAC's local coverage determinations. Have your coding lead pull the current descriptors and policy language from the CMS Medicare Coverage Database before anyone hard-codes these into an encounter template or a charge-capture favorites list.
Quality-measure reporting codes
Diabetes foot-exam performance has historically been reported with CPT Category II codes — 2028F is the one your quality lead will recognize — and, in some MIPS measure specifications, with G-codes for lower-extremity neurological evaluation. Category II codes carry no payment; they exist to document that a service or finding occurred.
Descriptors and measure specifications change by measurement year. Assign one person to reconcile your template's quality codes against the current specifications each January, and log the date they did it. That log is your defense when a plan disputes a numerator hit two years later.
Nail and callus procedures, and the routine foot care exclusion
Separate code families cover paring or cutting of benign hyperkeratotic lesions (the 11055–11057 range) and trimming or debridement of nails (11719, 11720, 11721, and HCPCS G0127). Medicare generally excludes routine foot care, and coverage often turns on documented systemic-condition findings reported with the Q7, Q8, and Q9 modifiers.
Operationally, this is where denials cluster. Your practice decides code selection based on what the rendering clinician documented, the payer's policy, and the modifier rules — never on what the front desk assumes the visit was.
Quick Answer: Which Codes Show Up on a Diabetic Foot Exam Claim?
Practices typically encounter four groups:
- LOPS evaluations: HCPCS G0245 (initial), G0246 (follow-up), G0247 (routine foot care at the same visit).
- Quality reporting: CPT Category II codes such as 2028F, plus any measure-specific G-codes in the current MIPS specifications.
- Procedures: callus paring (11055–11057) and nail trimming or debridement (11719–11721, G0127), with Q7/Q8/Q9 modifiers where the payer requires documented class findings.
- Office visits: a standard E/M code when the foot assessment is part of a broader visit and no separate foot-care code applies.
Code selection is made by the rendering clinician and coding staff from the documentation in front of them, against the current payer policy. Verify descriptors annually; they move.
Who Owns Each Step: A Role Map That Prevents Denials
Write this down and post it. Ambiguity here is what produces both denials and privacy incidents.
- Scheduler: books the visit type, captures whether the patient is coming for a scheduled foot assessment or a problem. Does not select codes.
- Medical assistant: completes intake fields the template requires — footwear check, prior ulcer history, whether monofilament testing was performed — as documentation, not as coding.
- Rendering clinician: documents findings and selects or confirms the code.
- Coder or biller: checks code-to-documentation alignment, modifier requirements, and frequency limits before release.
- Quality lead: reconciles measure numerators, owns the gap list, owns supplemental data feeds to plans.
- Privacy officer: owns the vendor list, the BAA file, the audit-response log, and the photo policy.
Two of those six roles are privacy roles. That is the part most practices under-staff.
The Gap List Is a PHI Problem Before It's a Quality Problem
Closing foot-exam measure gaps means someone generates a list: 140 patients with a diabetes diagnosis and no documented foot assessment in the measurement year. That list is a diagnosis-labeled roster of your panel. Treat it accordingly.
Three failure patterns show up repeatedly in practices:
- The list gets printed and left at the front counter, face up, where the next patient reads it.
- The list gets exported to a spreadsheet and emailed to a per-diem staffer's personal address for outreach calls.
- The list gets loaded into a texting or recall tool that nobody has a signed agreement with.
Fix the mechanics: gap lists stay inside the EHR or an access-controlled network folder, print jobs go to a tray behind the desk and get shredded the same day, and outreach happens from work accounts only. Reminder outreach for a needed service falls within treatment and health care operations, but keep the message content minimal — "we need to schedule your annual visit, please call" beats naming a condition on a voicemail a family member may hear.
Photos of Feet Are PHI, and Phones Are the Weak Point
Wound and lesion photography is common in this workflow, and it is the single most likely place for a foot-care encounter to become a reportable breach. A photo taken on a personal phone syncs to a consumer cloud backup within seconds, and the practice has no ability to retrieve or delete it.
Set a written rule and enforce it: images are captured only on practice-owned devices with the camera roll disabled from consumer sync, or through the EHR's native capture function, and they attach to the chart before the device leaves the room. Audit compliance quarterly by pulling a sample of image-bearing encounters and confirming provenance.
If your practice uses any imaging, remote monitoring, or thermometry product that stores foot images or sensor data outside your EHR, that product's vendor is a business associate. So is the analytics company reading the data. Browse the OCR breach portal for a few minutes and you will see how many incidents originate with a downstream vendor rather than the practice itself.
Every Vendor Touching Your Diabetic Registry Needs a BAA
Inventory the vendors that touch diabetic foot exam CPT data specifically. In most practices the list runs longer than the administrator expects:
- Clearinghouse and RCM vendor
- Outsourced coding or coding-audit firm
- Registry or QCDR used for MIPS submission
- Population-health or gap-closure platform
- Patient recall, texting, and appointment-reminder tools
- Chart abstraction contractors doing plan-driven medical record review
- Any remote monitoring or wound-imaging product
- Document scanning and release-of-information services
Each needs a signed business associate agreement on file before PHI moves, with the terms HHS requires — permitted uses, safeguards, subcontractor flow-down, breach notification timelines, and return or destruction of PHI at termination. If a vendor was onboarded during a scramble to hit a quality deadline and nobody chased the paperwork, you have a documentation gap that surfaces during an audit at the worst possible moment. When you find one of those, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon — one-time purchase, no subscription, so it works for the one-off vendor you did not plan for.
One nuance worth training your staff on: when a health plan's own abstraction vendor requests records for quality measurement, that vendor holds a BAA with the plan, not with you. Your obligation is to verify the requester's authority and disclose the minimum necessary — not to sign their agreement.
When the Payer Asks for 38 Charts: Minimum Necessary in Practice
Disclosures for payment purposes, including post-payment review, are permitted without patient authorization. That does not make the request self-executing. Build a standing response procedure:
- Verify. Confirm the requester is the payer or its authorized agent, using a number you look up independently — not the one printed on the letter.
- Scope. Pull only the date ranges and encounters named. A request about foot care claims does not entitle a reviewer to the entire chart, including unrelated behavioral health notes.
- Transmit securely. Payer portal or encrypted transfer. Never unencrypted email, and never a fax to an unverified number.
- Log. Date, requester, patient count, records sent, staff member, transmission method. Keep it for six years.
HHS guidance on the minimum necessary standard is the reference to hand your biller. The practical translation: someone reviews what leaves the building before it leaves.
Access and Amendment Requests Tied to Foot Exam Documentation
Patients who track their own diabetes care ask for these records, and sometimes dispute them. Two clocks matter.
The 30-day access clock
You have 30 days to act on a right-of-access request, with one 30-day extension if you notify the patient in writing of the reason and the new date. Outside podiatry notes you received and maintain are part of the designated record set — you produce them, you do not redirect the patient to the other office. Fees are limited to what the access rules permit; "per page" pricing pulled from an old state schedule is a common error. Review the current HHS right of access guidance with whoever handles records at your front desk.
The amendment request
If a patient says a documented foot assessment never happened, that is an amendment request, not a complaint to brush off. You have 60 days to act, you either amend or deny in writing with the reason and appeal rights, and if the entry drove a quality-measure numerator, notify your quality lead so the submitted data gets corrected too. Do not delete the original entry; amendments append.
A Quarterly 45-Minute Review That Catches Most of This
Put it on the calendar with named owners:
- Pull 10 foot-care encounters; confirm documentation supports the codes billed and that modifier use matches payer policy.
- Pull 5 image-bearing encounters; confirm capture device and storage location.
- Reconcile the vendor list against the BAA file; flag anything missing or expired.
- Review the disclosure log for payer and abstraction requests.
- Confirm gap-list handling: where stored, who can access, print destruction.
- Verify current-year code descriptors and measure specifications; note the date checked.
Six items, one hour, documented. That record of ongoing review is worth more in an investigation than a binder nobody has opened since onboarding. If your underlying risk analysis and policy set are also overdue for a refresh, automated HIPAA risk analysis and policy generation will get the documentation baseline in place faster than rebuilding it from templates.
Start With the Vendor List
Coding accuracy protects your revenue; records handling protects your license to keep operating. The diabetic foot exam workflow touches both, and the vendor list is where the two intersect. Pull yours this week, mark every party that receives diagnosis-labeled patient data, and draft the Business Associate Agreements you are missing before the next records request forces the question.