A commercial payer sends your billing manager a letter requesting 90 charts for a post-payment review of office visit levels. You have 30 days to respond. Your coder pulls the notes, your scribe vendor's transcripts are embedded in half of them, and your outsourced coding auditor wants a login to the EHR so she can work faster.

That single request touches four separate compliance obligations at once. This guide covers how e and m coding actually runs inside a practice — who selects the level, what documentation supports it, how internal audits get staffed — and then makes the privacy, records-handling, and vendor implications explicit. It is administrative guidance for administrators, billers, and privacy officers. It is not clinical guidance, and it will not tell you which code fits which visit.

What E and M Coding Decides in Your Practice

Evaluation and management codes describe the cognitive work of a patient encounter — office and outpatient visits, hospital inpatient and observation care, emergency department visits, nursing facility and home or residence services, consultations. They drive the largest share of professional-fee revenue in most outpatient practices, which means they also drive the largest share of payer audit attention.

Your operational stake is straightforward. Code selection determines payment. Documentation determines whether the code survives review. Access to that documentation determines your HIPAA exposure. Those three sentences describe three different workflows that most practices run as if they were one.

The Two Paths CPT Provides

Since the 2021 revision to office and outpatient visits, and the 2023 revisions that extended the same framework to most other E/M categories, level selection rests on either medical decision making or total time on the date of the encounter. History and physical exam are still performed and documented as clinically appropriate, but they no longer function as the counting mechanism for level selection in these categories.

Medical decision making is assessed across three elements: the number and complexity of problems addressed, the amount and complexity of data reviewed and analyzed, and the risk of complications or morbidity from management decisions. Total time is the other path — cumulative provider time on the date of service, including non-face-to-face work such as record review and documentation.

Your job as an administrator is not to adjudicate those elements. It is to make sure the clinician has a way to record time reliably, that the note supports whichever path was used, and that the selection method is consistent enough to explain to an auditor.

How Does a Practice Determine an E and M Level?

The treating clinician selects the level. Support staff and certified coders review the documentation and flag discrepancies, but they do not substitute their judgment for the clinician's without a query and a documented response. In practice, the workflow looks like this:

  1. The clinician documents the encounter and selects a level based on medical decision making or total time.
  2. A coder or coding software reviews the note against the selected level before claim submission.
  3. Discrepancies go back to the clinician as a written query, answered in the record — not corrected silently by billing staff.
  4. The practice runs periodic retrospective audits on a defined sample and documents findings, education delivered, and re-audit results.
  5. Corrections after submission follow the payer's amended-claim process, with the reason retained in the billing file.

That five-step chain is what an auditor, a payer, and — if it ever comes to it — a regulator will ask you to describe. Write it down as a policy. Undocumented good practice is indistinguishable from no practice.

Who Touches the Chart During E and M Coding

Level selection requires the full clinical note. Not a claim line, not a superbill — the narrative. That makes coding one of the widest PHI access surfaces in an ambulatory practice, and it is usually mapped badly.

Build an access inventory specific to this workflow. For each party, record what they see, why, through which system, and under what agreement:

  • Clinicians and scribes — full chart access, treatment purpose.
  • In-house coders and billers — clinical documentation plus demographics and insurance; payment purpose.
  • Outsourced coding or billing company — business associate. Often uses named user accounts in your EHR, sometimes offshore subcontractors.
  • Coding audit or CDI consultant — business associate. Frequently gets a temporary login nobody remembers to disable.
  • Clearinghouse — business associate, claim-level data.
  • Ambient documentation or AI scribe vendor — business associate with audio and draft-note access.
  • Computer-assisted coding or E/M level-suggestion tooling — either an EHR module or a separate business associate.
  • Payer — not a business associate. A covered entity requesting records for payment and health care operations.

Then apply the standard. HHS is explicit that covered entities must limit uses and disclosures, and internal access, to the minimum necessary to accomplish the purpose. A coder reviewing E/M documentation for a dermatology visit generally does not need behavioral health notes from three years ago. If your EHR supports role-based restriction and break-the-glass logging, use it on the coding role — most practices leave that role wide open because it is easier.

The Vendor List You Probably Haven't Updated

Pull your business associate agreement register and compare it against the list above. Two gaps show up constantly.

First, the coding auditor engaged for a one-time project three years ago, whose EHR account is still active. Run a quarterly account review against your vendor register and terminate on the day the engagement ends, not the day someone notices.

Second, tooling that arrived through a clinician rather than through procurement — an ambient scribe trialed by one physician, a coding assistant bought on a credit card. Those need executed agreements before they touch a chart. If you need one drafted quickly, a six-step BAA wizard that exports a signature-ready agreement beats forwarding a fifteen-year-old template. HHS publishes guidance on business associate obligations; read it before you accept a vendor's own paper.

When a Payer Requests 90 Charts

Payer record requests for payment purposes do not require patient authorization. That is the easy part. The operational discipline is in what you send.

Send the encounters requested. Not the entire chart, not the whole problem-list history, not unrelated specialty notes that happen to sit in the same PDF export. Over-disclosure to a payer is still a disclosure you have to defend, and bulk PDF exports are how psychotherapy notes and unrelated diagnoses end up in a claims file.

Assign one owner. In most practices that is the billing manager, with the privacy officer copied on any request touching more than a handful of records. Log the request date, the response date, what was disclosed, and the transmission method. Encrypted portal or SFTP — not a personal email account, not an unencrypted fax to a number nobody verified.

Track the deadline in a shared calendar, not one person's inbox. Payer appeal and audit clocks are short, and a missed timeline turns a documentation question into a repayment demand. CMS publishes program and payment policy for physician services through the Physician Fee Schedule resources; keep the current-year materials with your billing policies so staff aren't working from a printout from two Januaries ago.

When a Patient Disputes the Level

A patient reads their explanatory statement, sees a higher-level visit than they expected, and calls your front desk. Two HIPAA rights are now in play, and they are not the same thing.

The right of access lets the patient obtain the record supporting that encounter, generally within 30 days, at a reasonable cost-based fee. Train your front desk to route this as a records request, not as a billing complaint. The clock starts on the day of the request.

The right to request an amendment is separate. If the patient asserts the note is inaccurate, you must accept or deny the request in writing, with a reason, and honor the process even when you deny. Coding disagreements frequently arrive wearing amendment clothing. Your privacy officer decides which it is; billing staff should not.

Document both paths in the same log you use for other records requests. When a regulator reviews your practice, patterns matter more than individual outcomes.

Ambient AI and Coding Assistance: Contract Terms That Matter

Ambient documentation tools now draft substantial portions of the notes your coders review, and several offer level suggestions. Whatever the clinical merits, the vendor contract determines your exposure. Four terms to confirm before signing:

  • Training use. Does the vendor use your patients' audio or text to improve models? If so, under what authority, and can you opt out? A business associate agreement alone does not authorize secondary use.
  • Audio retention. How long is the recording kept, where, and who at the vendor can replay it? Recordings are PHI, and they are far more sensitive than a text note.
  • Subcontractors. Named, or a blanket right to use anyone? Ask specifically about offshore human review.
  • Breach notification timing. Vendor discovery-to-notice windows shorter than the regulatory maximum, in writing.

Add these systems to your security risk analysis as named assets. If your last analysis is a spreadsheet that predates your ambient scribe, it no longer describes your practice. Tools that generate a current risk analysis and the supporting policy set save the week of drafting that most administrators never actually find, and they force you to enumerate exactly the systems this workflow depends on.

The Internal Audit Cadence That Holds Up

Set a schedule and staff it before an external auditor sets one for you.

Quarterly, sample a defined number of encounters per clinician — many practices use ten — across the E/M categories they actually bill. Have a credentialed coder review documentation against the selected level. Record the sample, the findings, the education delivered, and the re-audit date. Where distribution shifts sharply for one clinician, treat it as a question to answer in writing, not a verdict.

Two records-handling notes. Audit workpapers contain PHI; store them where the rest of your PHI lives, under the same access controls, and cover them in your retention schedule. And keep HIPAA compliance documentation — policies, risk analyses, training logs, BAAs — for six years, separate from whatever your state requires for medical records.

If a coding review ever surfaces an impermissible disclosure rather than a coding error, your breach assessment process starts immediately. Reportable incidents are published in the OCR breach portal, and the entries involving billing vendors and misdirected records are a useful reminder of how ordinary the root causes are.

Your Next Two Hours

Pull the vendor register. Confirm a signed BAA for every party in your e and m coding chain, including anything a clinician adopted independently. Review active EHR accounts against current engagements and terminate the stale ones. Name one owner for payer record requests and one for patient access requests, and make sure they are not the same overloaded person.

Then make the paperwork match. Automated risk analysis and policy generation gets your documentation current against the systems you are actually running today — including the coding and documentation vendors that arrived after your last review. Start with the risk analysis; the policies follow from it.