Evaluation and Management Coding Guide for Practices
A Medicare Administrative Contractor probe letter lands on your desk asking for 30 charts across a six-month window, all of them office visits billed at the second-highest level. You have 45 days. Your billing manager is on leave, your coding consultant is a contractor who works from a home office three states away, and nobody can tell you whether the practice's own internal audit from last fall is still saved anywhere.
This evaluation and management coding guide is written for the person who has to answer that letter — the administrator, billing lead, or privacy officer — not for the clinician documenting the visit. It covers how E/M levels get selected and documented, what an auditor will actually ask to see, and the HIPAA obligations that attach the second those records leave your four walls. Coding decisions belong to your providers and certified coders. Making sure the workflow, the paper trail, and the vendor contracts hold up is your job.
The Two Roads to an E/M Level: Medical Decision Making or Total Time
Since the 2021 CPT revisions to office and outpatient visits — extended in 2023 to hospital inpatient, observation, consultations, emergency department, nursing facility, and home or residence services — history and physical exam no longer drive level selection. They still must be performed and documented as medically appropriate, but they do not set the code.
Level selection now rests on one of two alternatives: the level of medical decision making, or the total time the billing practitioner spends on the encounter on the date of service. The practitioner picks whichever supports the higher level, and the documentation has to support whichever one they picked.
Total time, and what counts inside it
Total time includes both face-to-face and non-face-to-face work performed by the billing practitioner on the calendar date of the encounter — chart review before the visit, ordering tests, documenting in the record, coordinating care. It excludes clinical staff time and excludes work performed on other dates.
Operationally, this is where most practices bleed. If your EHR does not capture a defensible time entry, the provider is reconstructing it from memory at the end of a 22-patient day. Build a required field, put it in the note template, and audit whether it is being filled with real numbers rather than the same figure on every chart. Identical time entries across dozens of encounters are the fastest way to invite a probe.
Medical decision making, in three columns
The MDM table has three elements: the number and complexity of problems addressed, the amount and complexity of data reviewed and analyzed, and the risk of complications from patient management. Two of the three must be met or exceeded at a given level.
Your role is not to judge whether a specific diagnosis constitutes a moderate-risk problem. Your role is to confirm the note documents each element in a way a reviewer can find without hunting — problems addressed named explicitly, external records or independent interpretations identified as reviewed, and the risk-bearing decision stated rather than implied.
How Does a Practice Select an E/M Level? (Short Answer)
The billing practitioner selects the code using either the level of medical decision making or the total time spent on the encounter on that calendar date, whichever supports a higher level. History and exam are documented as medically appropriate but do not determine the level. The practice's job is to (1) capture time or MDM elements in a structured, auditable field, (2) run periodic internal reviews comparing documentation to the code billed, and (3) keep the review workpapers, since they are protected health information and discoverable in an audit. Code assignment is a clinical and coding judgment; the workflow, retention, and vendor controls around it are administrative.
Add-On Codes and Split/Shared Visits: Where Policy Drift Happens
Two areas change often enough that a written internal policy goes stale fast.
Prolonged services have separate codes under CPT and, for Medicare, separate HCPCS codes with different time thresholds. Practices that treat these as interchangeable generate denials and, worse, inconsistent documentation across payers. Assign one person to reconcile your prolonged-service policy against each major payer's published guidance annually.
CMS also pays an add-on code recognizing the inherent complexity of visits that are part of ongoing, longitudinal care, and it has expanded the circumstances in which that add-on may be reported alongside certain preventive services. Check the current Medicare Physician Fee Schedule materials rather than a summary you saved two years ago.
Split or shared visits — where a physician and a qualified health professional both contribute to the same encounter — hinge on the definition of the "substantive portion," and CMS has revised and delayed that definition more than once. Do not write your policy from memory. Pull the current-year final rule language, cite it in your policy document with the effective date, and put a calendar reminder to re-verify each January.
The Documentation Trail Your Auditor Will Ask For
When a payer requests records, you are not sending "the chart." You are assembling a package. Know in advance what belongs in it:
- The provider's note for the specific date of service, signed and dated, with attribution clear if a scribe or template was used.
- Orders, results, and any external records the note claims were reviewed.
- Time documentation, if the level was time-based.
- The signed attestation for any scribe-documented encounter.
- Proof of the patient's coverage and any advance beneficiary notice, where applicable.
Name the person responsible for assembly, the person who reviews before release, and the transmission method. Faxing 30 charts to a number typed from a letter is how records end up somewhere unintended. Use the payer's secure portal when one exists, and log every disclosure.
Who Touches Your Coding Records Before the Claim Goes Out
Walk the path a single encounter takes and write down every organization that sees it. Most practices are surprised by the length of the list.
These almost always require a Business Associate Agreement
- Outsourced coding and coding-audit firms, including individual contractor coders working from home.
- Billing and revenue cycle management companies, and any offshore subcontractor they use.
- Clearinghouses that route claims and remittance.
- Transcription and scribe services that are not your own workforce.
- Ambient AI documentation vendors and coding-suggestion tools that ingest note text or audio.
- Analytics platforms that receive claim-level or encounter-level data to benchmark your E/M distribution.
These generally do not
A health plan receiving records to adjudicate a claim is acting as a covered entity, and disclosure for payment purposes does not require a BAA. Neither does a disclosure to a MAC or other CMS contractor performing oversight functions. HHS's business associate guidance is the place to settle these arguments internally, not a vendor's sales deck.
If your list has more names than your BAA folder has signed agreements — and for most practices doing a real inventory, it does — close the gap before the next audit does it for you. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX, one-time purchase, which is faster than routing a request to outside counsel for a contractor coder you onboard next Monday.
Minimum Necessary When a Payer Asks for 30 Charts
A request for documentation supporting 30 dated encounters is not a request for 30 complete longitudinal records. Sending the entire chart because it is easier to export is a minimum-necessary problem, and it hands the payer material for questions nobody asked.
Build a standing rule: release the dates of service specified, plus documents the note explicitly relies on. If a reviewer needs more, they will ask, and that second request becomes part of your disclosure log. HHS's minimum necessary guidance supports role-based limits — apply the same thinking to outbound audit packages that you apply to internal chart access.
Two more habits worth enforcing. First, internal audit workpapers — the spreadsheet where your consultant lists patient names, dates, codes billed, and codes recommended — are PHI. They belong in your document management system under access control, not in a shared drive folder called "Coding 2026" and certainly not in a consultant's personal email. Second, de-identify or aggregate before you circulate E/M distribution charts to a provider meeting.
Ambient Scribes and Coding Suggestion Tools: Four Contract Terms
Any tool that listens to encounters or reads note text and proposes an E/M level needs more than a signed BAA. Before it goes live, get written answers to four questions:
- Retention. How long is audio and transcript kept, and can you set it to zero after the note is finalized?
- Model training. Is your PHI used to train or improve models, and is the opt-out contractual or a setting someone can toggle?
- Subcontractors. Which cloud and speech-processing subcontractors are in the chain, and are they covered downstream?
- Attribution. Does the finished note make clear the provider reviewed and adopted it? A suggested code that no human verified is a compliance exposure, not a productivity gain.
Also decide who is responsible when the tool's suggestion is wrong. The practice bills the claim. The practice owns the attestation. A vendor's accuracy claim is not a defense.
A Twelve-Month Internal Review Calendar
An evaluation and management coding guide is worthless without a cadence attached. Here is a workable one for a mid-sized practice.
- January: Reconcile policy documents against the current fee schedule and CPT changes. Update effective dates in writing.
- Quarterly: Pull E/M level distribution by provider and compare to specialty benchmarks. Investigate outliers with documentation review, not accusation.
- Twice yearly: Prospective review of 10 charts per provider — coder reviews before the claim drops, feedback goes back within five business days.
- Annually: Refresh the vendor inventory, confirm every BAA is current and signed by an authorized party, and confirm subcontractor lists have not changed.
- Annually: Re-run your risk analysis to account for new tools in the documentation and coding workflow. If that process is ad hoc today, tooling that produces risk analysis reports and the supporting policy set beats a rebuilt spreadsheet.
Log each cycle: date, sample size, reviewer, findings, corrective action, and follow-up date. That log is what turns "we audit our coding" into something you can hand a reviewer.
When the Patient Asks Why the Visit Was a Level 4
Front-desk staff will get this question. Train the answer. Patients have a right of access to their records, including the note that supported the code, and your normal access workflow and timeline apply — the request goes to the records custodian, not resolved verbally at the window.
Billing questions about the amount owed route to billing. Requests for the underlying documentation route to records. Do not let a coding dispute become an unlogged, undated disclosure of chart contents over the counter. And if a patient disputes the level, that is a billing inquiry with a documented response — not an invitation to alter a signed note. Amendments follow your amendment policy, with the original preserved.
Five Failure Points Worth Fixing This Quarter
- Identical time entries across a provider's panel.
- Audit workpapers containing patient identifiers stored outside access-controlled systems.
- Contractor coders working without a signed BAA.
- Full-chart releases in response to date-specific payer requests.
- Split/shared and prolonged-service policies citing rules that changed two cycles ago.
Any of those five will show up in a probe. All five are fixable with process, not software.
Your Next Step
Print your vendor list — coding contractors, billing company, clearinghouse, scribe or ambient documentation tool, analytics platform — and put the signed BAA date next to each name. Every blank line is an open exposure sitting between a patient's chart and a third party. If you have blanks, build the missing agreements now and get them signed this week, then attach the completed list to your review log as evidence that the coding workflow described in this evaluation and management coding guide is actually governed.
Practices that get audited on E/M rarely fail because a coder chose wrong. They fail because nobody could show who reviewed what, when, and under which agreement.