A payer sends your office a letter requesting 30 charts to review level-4 office visits billed over the past eighteen months. Your billing company asks you to forward the records so they can assemble the response. Before anyone attaches a single PDF, two separate questions land on your desk: is the e/m coding in those notes documented the way your policy says it should be, and does the vendor about to receive 30 full charts have a signed Business Associate Agreement on file?

This guide is for the administrator, billing manager, or privacy officer who owns both questions. It covers how E/M levels get selected and documented as an operational workflow, who in your practice is accountable at each step, and where the privacy and vendor exposure sits. It is administrative guidance on process and records handling — not clinical guidance, and not a statement that any particular code fits any particular visit.

What Actually Changed in E/M Coding, in Operational Terms

For office and other outpatient visits, the 1995/1997 documentation guidelines stopped driving code selection in 2021. History and exam still get documented as clinically appropriate, but they no longer set the level. Level selection for those visits rests on medical decision making or on total time on the date of the encounter.

In 2023, the same structure extended across most other E/M families — inpatient and observation, consultations, emergency department, home and residence, and nursing facility visits. Observation codes were folded into the inpatient and observation code set. Practically, that means your internal audit tools, chart templates, and coder education all had to be rebuilt around two very different measurement systems: an element-based decision-making grid and a stopwatch.

Two more pieces of the current landscape affect your workflow more than they affect your clinicians:

  • Prolonged services. Add-on reporting depends on total time crossing defined thresholds, and Medicare has historically used its own add-on code rather than the CPT one. Whichever applies to a given payer, your documentation has to show time in a way an auditor can follow.
  • The visit complexity add-on. CMS began paying the office/outpatient complexity add-on code in January 2024. Whether your practice reports it is a policy decision your compliance lead should document once, in writing, rather than leave to individual habit.

Split or shared visit policy has been revised by CMS more than once. Do not rely on a memory of last year's rule — pull the current Physician Fee Schedule final rule language before you write your internal policy, and note the year on the policy itself. CMS maintains the fee schedule and its accompanying rules at cms.gov.

Who Decides the E/M Level in Your Practice?

The billing provider is responsible for the code submitted under their NPI. A certified coder, a scribe, or a software suggestion engine can propose a level; only the provider can attest that the documentation supports it. In practice, most groups run one of three models: provider-selected with coder audit after the fact, coder-selected with provider sign-off before claim release, or a hybrid where certain visit types route to a coder automatically. Whichever model you use, write it down, name the roles, and define what happens when the coder and the provider disagree.

That last part is the piece most practices skip. A documented disagreement path — who reviews, how long they have, who breaks the tie, where the decision is logged — is the difference between a defensible pattern and a pile of unexplained downcodes.

A Workable Role Split

  1. Provider: documents the encounter, attests to time or decision making, selects or confirms the level.
  2. Coder or billing specialist: reviews against the practice's internal checklist, flags mismatches, never changes a level without provider confirmation.
  3. Billing manager: owns the claim edit queue and the hold-and-release rules.
  4. Compliance lead: owns the audit calendar, the sample selection method, and the corrective-action log.
  5. Privacy officer: owns who outside the practice may read those notes, and under what agreement.

The Vendor List Hiding Inside Your E/M Coding Workflow

Walk the note from creation to claim and count the outside parties. An ambient documentation tool captures the visit. A coding-suggestion module reads the draft. A remote scribe finishes it. Your revenue cycle management company scrubs and submits the claim. A clearinghouse routes it. A denial-management contractor appeals it. An external auditor samples it. A translation service handled the visit itself.

Every one of those parties creates, receives, maintains, or transmits protected health information on your behalf. Every one of them needs a Business Associate Agreement in place before the first record moves. HHS publishes sample business associate agreement provisions, and they are a floor, not a ceiling — the sample text does not address subcontractor disclosure, breach notification timelines shorter than the outer statutory limit, or what happens to your records when the contract ends.

The gap I see most often in coding operations: a practice has a BAA with its RCM company but nothing with the offshore coding subcontractor that company uses, and no written confirmation that the subcontractor is under a downstream agreement. Ask for it in writing. Keep the answer in your vendor file.

If you have vendors reading your charts today under nothing more than a service order and an email thread, close that gap this week. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than waiting on a vendor's legal department to send you their template.

Minimum Necessary When a Payer Audits Your E/M Levels

A records request for a payment audit is a permitted disclosure. It is not permission to send everything you have. The minimum necessary standard still applies to disclosures for payment purposes, and HHS has published guidance on the minimum necessary requirement that your privacy officer should have on file.

Build a repeatable audit-response procedure:

  • Log the request. Date received, requester, legal basis, patients named, date range, deadline.
  • Scope it. If the payer asked for encounters on specific dates of service, send those encounters and the records that support them — not the entire longitudinal chart.
  • Review before release. One named person checks the outbound package against the request. Two sets of eyes on anything over ten charts.
  • Transmit under control. Payer portal or encrypted channel. Not personal email, not an unencrypted fax to an unverified number.
  • Retain the package. Keep a copy of exactly what you sent. When the audit findings arrive eight months later, you will need to know what the auditor actually saw.

One relief valve worth knowing: disclosures for treatment, payment, and health care operations are excluded from the accounting of disclosures a patient can request. That does not excuse you from logging payer audits internally — you need that log for your own defense — but it means your payment-audit log is an operations record, not a patient-facing one.

When the Patient Asks Why They Were Billed That Level

Billing records sit inside the designated record set. A patient who asks for the documentation behind a charge has a right of access to it, and your clock is 30 days with one 30-day extension available if you notify them in writing of the reason and the new date. HHS covers the mechanics in its individuals' right of access guidance.

Train the front desk to route these requests to the records custodian rather than answering them at the window. A staffer who explains E/M level selection off the cuff creates a statement your practice may have to live with later. The correct response is to process the access request and let the documentation speak.

Ambient AI Scribes and Coding Suggestion Tools: Six Questions Before You Sign

These tools ingest full clinical encounters, sometimes including raw audio. Get answers in writing, from the contract and not from the sales deck:

  1. Is a BAA executed, and does it cover audio recordings and derived transcripts as PHI?
  2. Does the vendor use your data to train models? If yes, on what legal basis, with what de-identification method, and can you opt out contractually?
  3. Where is data stored and processed, including any subprocessors and any work performed outside the United States?
  4. What is the retention period for audio, and can you set it to a shorter window?
  5. What audit logging does the vendor provide you — not just what it keeps for itself?
  6. What happens at termination? Deletion certificate, export format, timeline.

Also confirm who is accountable when a suggestion engine proposes a level the documentation does not support. The answer is your billing provider, every time. A vendor's accuracy marketing does not transfer liability for a claim submitted under your practice's NPI, and your compliance policy should say so in plain language so no clinician assumes otherwise.

A Quarterly Internal Audit Cadence That Doesn't Create New Exposure

Run internal E/M coding audits on a fixed schedule so the sample is defensible and the workflow is boring. A cadence that holds up:

  • Monthly: five charts per billing provider, mixed new and established, pulled by the compliance lead using a documented random method.
  • Quarterly: distribution curve by provider against practice and specialty norms. Outliers get a conversation and a written note, not an accusation.
  • Annually: full policy refresh against the current-year fee schedule rule, plus refreshed training with attendance records.
  • Event-driven: new provider onboarding, new service line, any payer audit, any denial pattern.

The privacy side of auditing gets ignored. Audit worksheets are PHI. If your coder builds a spreadsheet with patient names, dates of service, and documentation excerpts, that file needs the same access controls as the chart it came from — and it should not live on a desktop or a personal drive. If you bring in an outside auditor, they get a BAA and a scoped data set, not a login with broad chart access. Role-based access, plus a review of who actually has coding-module permissions, belongs in your annual risk analysis alongside the rest of your HIPAA policies and risk documentation.

Retention: Who Keeps What, and for How Long

Two clocks run in parallel and people conflate them. HIPAA requires covered entities to retain required documentation — policies, BAAs, risk analyses, training records, audit logs of your compliance activity — for six years from creation or last effective date. Medical record retention itself is governed by state law and payer contract, and those periods vary. Your retention schedule should list both, per record type, with the citation next to each line.

For coding operations specifically, keep the audit worksheets, the corrective action logs, the version history of your internal E/M policy, and copies of every records package you sent to a payer. When an auditor asks how you determined a level three years ago, the policy in effect on that date is your best evidence.

Your Next Three Moves

Pull your vendor inventory and mark every party that reads clinical documentation — scribes, coders, RCM, denial management, auditors, AI tools. Confirm a current signed BAA for each, including subcontractor coverage. Then write the one-page E/M coding audit-response procedure your staff will follow the next time a payer letter arrives, and name the person who owns it.

If any row in that vendor inventory comes up empty, fix it before the next chart leaves your building. Start with a Business Associate Agreement you can put in front of a vendor today — six steps, PDF and DOCX export, one-time purchase — and get the signature before the records move, not after.