A patient checks in Monday morning at your multi-specialty group. She saw one of your dermatologists 31 months ago, once, for a mole check. Today she is on the schedule with a dermatology PA who joined the group last summer. Your registration screen asks a single question — new or established — and whoever answers it just determined whether the visit gets billed with a new patient code or an established patient CPT code. Get it wrong and you either eat a denial or collect money you have to refund.

This guide is for the people who own that decision: practice administrators, billing leads, front-desk supervisors, and privacy officers. It covers how the determination actually gets made, who documents it, and — the part nobody builds a workflow for — which vendors touch the lookup and what your BAA inventory needs to say about them.

What an Established Patient CPT Code Is

An established patient CPT code is an office or other outpatient evaluation and management code used when the patient has already received professional services from your practice within a defined lookback window. CPT groups these as 99211 through 99215. New patient office visits use a separate range, 99202 through 99205.

The dividing line is CPT's three-year rule: a patient is new if they have not received any professional service from the physician or qualified health professional, or from another physician or QHP of the exact same specialty and subspecialty in the same group practice, within the prior three years. If they have, the encounter falls in the established range. The determination is factual and administrative — it depends on your records, not on how sick the patient is today.

Level selection within the established range is a separate step, driven by medical decision making or total time on the date of the encounter, documented by the treating clinician. Your staff should never infer a level from the reason for visit on the schedule.

The Three-Year Rule Is a Records Lookup, Not a Judgment Call

Treat this as a query with defined inputs. Three variables decide it, and your staff needs a documented answer for each.

Same group practice — usually the same tax ID

Group affiliation is what makes another clinician's prior visit count against your new-patient determination. When you acquire a practice, add a location, or bring on a physician who also bills under a second TIN, the boundary moves. Your billing lead should maintain a written map of which provider NPIs roll up to which billing entities, refreshed whenever credentialing changes. Payers do not accept "our system didn't show it" as a defense on a post-payment review.

Exact same specialty and subspecialty

Two clinicians in the same group can be different specialties for this purpose, and mid-level providers are generally treated as working in the specialty of the supervising physician for new-versus-established purposes. Medicare's guidance on this sits in the Claims Processing Manual and is worth having your coder cite in your internal policy. Start from the CMS Physician Fee Schedule resources and your MAC's local articles rather than a vendor's summary slide.

A "professional service" — not every touch

A face-to-face or otherwise billable professional service resets the clock. Interpreting a lab your practice never saw the patient for, or a records-only review, generally does not. Write your practice's interpretation down, apply it consistently, and note the source. Consistency is what survives an audit; improvisation is what generates refund demands.

The Registration Script That Prevents Most Denials

Give your front desk five steps and take the guesswork away.

  1. Search on more than the name. Date of birth plus last four of the SSN or a prior phone number. Maiden names and hyphenated changes are the single biggest source of duplicate charts, and a duplicate chart manufactures a false "new" patient.
  2. Pull the last encounter date and the rendering provider, not just "has chart / no chart."
  3. Compare against the provider-to-specialty-to-TIN map. This is why the map has to exist and be current.
  4. Record the determination in a discrete field with the date, the prior encounter it was based on, and the initials of the person who checked.
  5. Escalate anything ambiguous to the billing lead before the claim drops — not after the denial.

That fourth step is the one practices skip, and it is the one that saves you during a review. Your defensible position is not "we coded it right." It is "here is the record showing what we knew, when we knew it, and who verified it."

Documenting Level Selection Without Practicing Medicine

Administrators get nervous here, and they should stay in their lane. Your job is workflow, not clinical judgment.

Since the 2021 office visit revisions, level selection for an established patient CPT code rests on either medical decision making or total time the clinician spent on the encounter date. CPT attaches structure to each — 99211 sits outside the time-based framework and is the level historically used for services that may not require the presence of the billing clinician, which makes it the level most closely scrutinized for supervision documentation.

What your operation owns:

  • Making sure the note supports whichever basis the clinician used, without you telling them which to use.
  • Running a monthly distribution report by provider and flagging outliers for internal review by a credentialed coder.
  • Documenting who is permitted to change a code after signature, and logging every change with a reason.
  • Confirming that add-on codes — including the visit complexity add-on Medicare implemented for office and outpatient visits, and its modifier requirements when reported alongside preventive services — are configured correctly in your fee schedule and not auto-appended by a rule nobody reviewed.

Telemedicine adds a wrinkle. CPT's telemedicine E/M family and Medicare's coverage treatment of those codes have not moved in lockstep, and virtual encounters still count as professional services for the three-year lookback. Verify current Medicare telehealth policy directly with CMS before you change a billing rule — this area has shifted on short legislative timelines.

Every Vendor That Touches the New-vs-Established Decision Needs a BAA

Now the part that lands on the privacy officer's desk. The determination requires querying prior encounter history, and in most practices that query passes through systems you do not own.

Walk your own workflow and count the outside parties:

  • Online scheduling and pre-registration tools that ask "are you a new or existing patient?" and capture a reason for visit before anyone verifies identity.
  • Eligibility and insurance-discovery vendors that return claim history — which is exactly the data that reveals a prior encounter.
  • Clearinghouses processing the claim with the code on it.
  • Outsourced billing and RCM firms whose staff resolve the ambiguous cases you escalate.
  • Coding audit consultants who read full charts to validate level selection.
  • Legacy archive hosts holding the old system's data that your three-year lookback depends on.

Each is a business associate. Each needs an executed agreement that names the permitted uses, requires breach notification with a defined timeline, and addresses return or destruction of data at termination. HHS explains the requirement and what the contract must contain in its business associate guidance. If you audit your list and find a coding consultant or an archive host operating on nothing but an invoice and a handshake, you can produce a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon — one-time purchase, no subscription to manage.

The scheduling widget on your website

An unauthenticated "new or established patient?" form on your public site, wired to analytics or ad tracking, can transmit identifiers alongside a reason for visit. OCR addressed tracking technologies on covered entity websites in its online tracking bulletin, and portions of that guidance have been litigated — but the operational takeaway has not changed. Inventory every script on your scheduling pages, know what each one sends and where, and get a BAA or remove the tag.

When a Patient Asks Why They Were Billed as a New Patient

This request arrives monthly. Handle it as a right-of-access matter, not a billing dispute.

Billing records live in the designated record set. A patient can request the visit note, the claim, and the itemized statement, and you generally have 30 days to respond, with one 30-day extension available if you notify them in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS's individual right of access guidance is the reference to keep in your policy binder and in your front-desk training deck.

Two practical notes. First, if the patient believes the new-versus-established determination was factually wrong, that is a coding correction and a possible corrected claim — not an amendment request under 45 CFR 164.526, though they may file one and you must respond to it on its own track. Second, if you are refusing or delaying access to electronic health information through your portal, consider whether an information blocking exception actually applies. "Billing is reviewing it" is not one.

Payer Audits and E/M Level Validation Requests

When a payer or its contracted review vendor requests twenty charts to validate your established patient CPT code distribution, disclosure for payment purposes is permitted. That does not make the response casual.

  • Verify who the requester is and confirm in writing that they act on the payer's behalf.
  • Apply minimum necessary — send the dates of service requested, not the entire chart.
  • Log the disclosure, including what was sent and by whom.
  • Use a transmission method your policy actually authorizes. A ZIP file on a personal cloud drive is a breach waiting for a subject line.

You Cannot Apply a Three-Year Lookback to Data You Deleted

Retention decisions have direct coding consequences. If a system migration left three years of encounter dates in a read-only archive that only two people can search, your front desk will default to "new" — and your denial rate will tell you so within a quarter.

Before you decommission any system, confirm three things: encounter dates and rendering providers are queryable by registration staff, the archive host has a current BAA, and your retention schedule reflects both your state's requirement and the operational need for the lookback. Then document the decision. That documentation belongs in the same file as your risk analysis and policy set, because a system nobody can search is both a billing problem and a security-rule gap.

A Two-Week Cleanup You Can Actually Finish

  1. Days 1–2: Print your provider-to-specialty-to-TIN map. If it does not exist, build it with credentialing.
  2. Days 3–5: Add a discrete new-vs-established field with verifier initials to registration. Retrain the desk on the five-step script.
  3. Days 6–8: Pull twelve months of new patient claims and check each against prior encounter history. Quantify your exposure before a payer does.
  4. Days 9–11: Inventory every vendor in the workflow above. Match each against your executed BAAs and close the gaps.
  5. Days 12–14: Audit the scripts on your scheduling pages. Document your access-request timeline in writing.

Coding accuracy and privacy discipline run on the same rails here: a documented determination, a named owner, and a contract behind every system that touches the data. If step four turned up vendors you cannot produce an agreement for, generate the BAAs you are missing and get them signed before your next audit letter arrives.