Family History of Hypertension ICD 10: Practice Guide
A patient's intake packet reaches your front desk with three boxes checked under family history: mother, high blood pressure; father, high blood pressure; brother, stroke at 52. Within ten minutes that data is in your EHR's family history module. Within a day it may appear as a Z-code on a claim, feed a risk-stratification dashboard, and sync to whatever population health tool your ACO asked you to connect last quarter.
This guide covers the operational mechanics of family history of hypertension ICD 10 coding — where the code lives, who documents it, how it moves — and then the part most practices skip: family medical history is genetic information under HIPAA, which changes how you handle it in records requests, payer disclosures, employer physicals, and vendor contracts. Written for administrators, billing leads, and privacy officers, not for clinicians and not for patients.
Where Family History of Hypertension Sits in the ICD-10-CM Code Set
Family history codes live in the Z-code section of ICD-10-CM — specifically the Z80–Z84 range, "persons with potential health hazards related to family and personal history." Circulatory-system family history falls in category Z82, and coders reach the specific code through the Alphabetic Index entry for family history of hypertension, which routes to the subcategory covering ischemic heart disease and other diseases of the circulatory system.
That routing is a code-set fact, not a coding decision. Your certified coder or provider makes the actual selection based on what the note documents. Verify the exact code and any index changes against the current fiscal-year ICD-10-CM files published by CMS, which update every October 1. A code that was valid in FY2025 is not automatically valid in FY2026.
Who owns the October 1 verification in your practice
Assign it. In most practices this belongs to the billing manager or lead coder, with a calendar reminder set for early August so there's time to load new files, update superbills and favorites lists in the EHR, and retire deleted codes before the effective date. If nobody owns it, your first denial in October becomes the notification method.
Is Family History of Hypertension ICD 10 Coded From the Intake Form?
No. Under the ICD-10-CM Official Guidelines, code assignment is based on the provider's documentation in the medical record. A patient-completed questionnaire is a source document, not the coding source. The provider (or clinical staff acting within scope, per your policy) must review and record the family history in the encounter note before it supports a submitted code.
Practical consequence: if your intake tablet writes family history straight into a structured EHR field that your billing engine reads, you have built a path from unverified patient self-report to a submitted claim. Audit that path. The fix is usually a provider attestation step in the note template, not a change to the intake form.
Second consequence: family history Z-codes are generally supporting or secondary diagnoses. They rarely establish medical necessity on their own, and payer policies vary on whether they are payable in the first position. Your billing lead should keep a payer-by-payer note on this rather than guessing per claim.
Family Medical History Is Genetic Information Under HIPAA
This is the part that trips practices up. The HIPAA definition of genetic information at 45 CFR 160.103 includes "the manifestation of a disease or disorder in family members" of the individual. Your mother-had-hypertension checkbox is genetic information. So is the Z-code you derive from it.
Genetic information that is PHI is protected as PHI — same access rights, same minimum necessary standard, same breach notification obligations. But the 2013 Omnibus Rule added a specific restriction: health plans, other than long-term care issuers, may not use or disclose PHI that is genetic information for underwriting purposes. HHS maintains guidance on how the Privacy Rule treats genetic information, and your privacy officer should have read it.
You are probably a covered provider, not a health plan — so the underwriting prohibition binds the recipient, not you. That doesn't get you off the hook operationally. Three places where it bites:
- Your own employee health plan. If your organization sponsors a self-funded plan and staff on your payroll administer it, the plan is a covered entity with the underwriting restriction attached, and your firewall between clinical operations and plan administration matters.
- Records releases to insurers. A broad authorization for "complete medical records" sent to a life or disability carrier will carry family history out the door. Your release-of-information staff should know that these disclosures are authorization-based, not treatment-payment-operations, and should be logged accordingly.
- Employer-facing services. If your practice performs pre-placement exams, DOT physicals, or occupational health screenings, GINA Title II restricts employers from requesting family medical history. Your report back to the employer should not include family history fields. Check your occupational health report template today.
The Third-Party Problem: This Data Describes Someone Who Isn't Your Patient
The record says the patient's mother has hypertension. The mother never signed anything, never saw your Notice of Privacy Practices, and has no relationship with your practice. The information is still the patient's PHI — it appears in the patient's designated record set and travels with it.
That produces two recurring front-office situations.
Right-of-access requests
When a patient requests their chart, family history goes with it. There is no carve-out for information about relatives. Your 30-day clock under the right of access applies to the full designated record set, with one 30-day extension available if you notify the patient in writing. Refresh your ROI staff against the HHS right of access guidance — access denials over third-party content are a well-worn path to an OCR complaint.
Amendment requests
Patients do ask you to remove family history entries — after a family estrangement, after learning a relative's diagnosis was wrong, or because they now regret disclosing it. Handle it as a formal amendment request: written, logged, answered within 60 days with a 30-day extension available. You do not delete the original entry; you append. Train front desk not to promise deletion at the window.
Vendor Implications: Everyone Who Touches the Family History Field
Pull your vendor list and mark every system that receives structured family history or diagnosis codes. In a mid-size primary care practice this is typically longer than administrators expect:
- The EHR and its hosting environment
- The patient intake or digital forms vendor collecting the questionnaire
- The clearinghouse transmitting claims carrying the Z-code
- Risk-adjustment or HCC coding review vendors
- Population health and care-gap analytics platforms, including ACO-mandated ones
- Patient outreach and recall messaging tools that segment by diagnosis
- Any research registry, quality reporting, or public health interface you feed
Each of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. Each needs a signed, current BAA on file — not a marketing page claiming HIPAA compliance, and not a clause buried in a click-through terms of service you never exported.
The gap I see most often is the intake forms vendor. Practices sign a BAA with the EHR and assume it covers the tablet app collecting the questionnaire, because the app writes into the EHR. It does not. If you find an unpapered vendor during this review, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than waiting three weeks for the vendor's legal team to send a template you'd have to redline anyway.
Also check downstream flow. An analytics vendor that subcontracts hosting or model processing needs subcontractor BAAs in place, and your agreement should require them. Ask for the list. If the vendor won't name subcontractors, that answer is itself information.
A Two-Week Cleanup Plan You Can Actually Run
Days 1–3 — Map the field. Have your EHR administrator document every interface, export, and report that includes the family history module or Z-code range. Name the receiving system for each. Practice administrator owns the output.
Days 4–6 — Match against BAAs. Privacy officer compares that list to your executed BAA file. Flag anything missing, anything signed before 2013, and anything signed with an entity that has since been acquired or renamed. Assignment clauses matter here.
Days 7–9 — Review the intake-to-claim path. Billing lead and clinical lead confirm the provider attestation step exists between patient self-report and code submission. Pull ten recent charts with family history Z-codes and verify provider documentation supports each. Document the sample and the result.
Days 10–12 — Fix the outbound templates. ROI staff and occupational health staff review release templates and employer report formats. Confirm family history is excluded from employer-directed reports and that insurer disclosures run on valid authorizations.
Days 13–14 — Update policy and train. Add a paragraph to your privacy policy stating that family medical history is treated as genetic information, note the underwriting restriction, and record a fifteen-minute staff training with an attendance roster. Your risk analysis should reflect the updated data flow — if you maintain that documentation manually, an automated risk analysis and policy set keeps the mapping current when interfaces change.
Five Questions an Auditor Will Ask
- Who verifies ICD-10-CM code validity each October 1, and where is that documented?
- What is the provider documentation source for family history codes on submitted claims?
- Do you have a current BAA with every vendor receiving diagnosis-coded data, including intake and analytics tools?
- How does your release-of-information process handle authorizations from insurers?
- Does your amendment process log requests involving family history, and does it meet the 60-day response requirement?
If you can answer all five with a document rather than a description, you're in reasonable shape. If two of them get "I think so," start there.
Start With the Contracts
Coding accuracy is a billing problem you'll eventually notice through denials. An unpapered business associate holding family history data is a problem you notice through a breach notification letter. Run the vendor mapping first, then close the gaps — draft and export the BAAs you're missing this week, before the next intake form goes out.