A father calls your front desk on a Tuesday afternoon. He is not the policyholder, he is not the parent who brought the child in, and he has just seen an explanation of benefits that lists a behavioral diagnosis for his 14-year-old. He wants the full chart, and he wants it today. Your receptionist has about ninety seconds to decide what to say.

That call is the reason icd 10 odd coding is an operations problem and not just a coding problem. This guide walks through how the ODD code is selected and documented, where it travels once it leaves your building, who is legally entitled to see it, and which vendors on your list need a Business Associate Agreement before they touch it. Written for administrators, billers, and privacy officers — not for clinicians and not for patients.

Which ICD-10 Code Covers Oppositional Defiant Disorder?

In ICD-10-CM, F91.3 is the code titled "Oppositional defiant disorder." It sits inside category F91, conduct disorders, alongside F91.0 (conduct disorder confined to the family context), F91.1 (childhood-onset type), F91.2 (adolescent-onset type), F91.8 (other conduct disorders), and F91.9 (conduct disorder, unspecified).

Selecting between those codes is a clinical and documentation judgment made by the treating provider, supported by what is written in the note. Your coding staff do not decide which condition a patient has; they translate documented findings into the code set and query the provider when the documentation does not support a specific code. ICD-10-CM is updated annually with changes effective October 1, so your code tables, superbills, and EHR favorites lists need a scheduled review every fall. CMS publishes the official files and guidelines on its ICD-10 code resource page.

How Your Practice Documents Code Selection Without Drifting Into Clinical Judgment

The compliance failure in behavioral health coding is almost never a wrong opinion. It is a code that appears on a claim with nothing in the note to support it, usually because someone picked from a dropdown.

The four artifacts that need to exist for every behavioral diagnosis code

  • A signed, dated provider note that describes the findings, duration, and functional impact in the provider's own words.
  • A diagnosis list in the chart that matches the diagnosis list on the claim, in the same order.
  • A record of any coder query, with the provider's written response — not a phone call summarized by the biller.
  • An audit trail showing who added or changed the code and when.

The query workflow, with names attached

Assign it explicitly. Your coder opens a query when documentation is ambiguous between codes in the F91 family or when a code appears without supporting narrative. The query goes to the provider through the EHR's internal messaging, never through personal email or SMS. The provider answers in writing within two business days, and the answer is filed in the chart. Your billing lead holds the claim until the query closes.

If your practice uses an outside coding or revenue cycle company, that query loop crosses your walls. Write into the contract that queries are documented in your system, not in the vendor's ticketing tool, and that no code is added or upgraded without provider sign-off. A vendor that "optimizes" diagnosis codes from claims data alone is creating a documentation gap you will own during an audit.

Where an ICD 10 ODD Code Travels After You Hit Submit

Map this once and post the map in your billing area. Most staff have never seen the full path.

  1. Your EHR — the diagnosis enters the problem list, the encounter, and often the patient portal summary.
  2. Your clearinghouse — a business associate, receiving the code on the 837 claim file.
  3. The payer — including any behavioral health carve-out vendor and any prior authorization reviewer.
  4. The explanation of benefits — mailed or posted to the subscriber, who may not be the parent who consented to treatment.
  5. Downstream requesters — schools, courts, camps, sports programs, disability determination, and other treating providers.

Step four is where practices get burned. The EOB is generated by the payer, not by you, but the phone call lands on your front desk. Some states and some carriers offer confidential communication mechanisms for sensitive services; under HIPAA, a patient or personal representative can also request confidential communications from your practice, and you must accommodate reasonable requests. Train your staff to log every such request in writing and to route it to the privacy officer the same day.

Minors, Personal Representatives, and the Parent Who Isn't the Subscriber

Go back to the father on the phone. HIPAA generally treats a parent as the personal representative of an unemancipated minor, which means he may have access to the chart. But HIPAA defers to state law in several situations: when a minor consented to the care themselves and no parental consent was required, when a court has limited a parent's rights, and when a provider makes a documented professional judgment that access would endanger the minor. HHS explains the framework in its guidance on personal representatives.

Your front desk cannot make that determination. Give them a script and a hard stop:

"I can take your request in writing and route it to our privacy officer, who will verify who is authorized to receive the record. I'm not able to confirm or discuss any information over the phone."

What your privacy officer verifies before releasing anything

  • Custody documentation on file, and whether it restricts access to medical records.
  • Whether the minor consented to the specific service independently under your state's law.
  • Whether the treating provider has documented a safety concern about disclosure to that individual.
  • Whether the request includes psychotherapy notes, which under 45 CFR 164.501 are separately maintained, are excluded from the right of access, and require a valid authorization for most disclosures.

Document the determination in a disclosure log with the date, the requester, what was released, and the legal basis. In a custody dispute, that log is the only thing standing between your practice and an accusation of taking sides.

The 30-Day Clock That Starts When a Parent Asks for the Chart

Once you have verified the requester, HIPAA gives you 30 calendar days to provide access, with a single 30-day extension that requires written notice explaining the delay. Fees must be limited to the cost-based charges HIPAA permits; you cannot charge for search and retrieval time. HHS's right of access guidance is the reference to keep printed in your records desk binder.

Practical timeline for a behavioral health record request in a pediatric practice:

  • Day 0 — request received, logged, requester identity and authority verification opened.
  • Day 1–3 — verification closed; privacy officer flags psychotherapy notes and any third-party information for exclusion.
  • Day 3–7 — treating provider reviews for safety concerns if the request involves a minor's sensitive diagnosis.
  • Day 7–20 — record assembled in the requested format, fee estimate communicated in advance.
  • Day 30 — delivered, or written extension notice sent.

Also build an amendment path. Parents dispute behavioral diagnoses more often than almost any other chart entry. You are not required to change a code because someone disagrees, but you are required to respond to an amendment request in writing within 60 days and, if you deny it, to file the request, your denial, and any statement of disagreement with the record.

School Districts, IEP Requests, and the Authorization That Is Never Broad Enough

A school psychologist faxes a one-page "records release" from a district form. It asks for "all medical and psychological records." Half of these forms are not valid HIPAA authorizations — they lack an expiration date, a description of the specific information, or the required statement about the right to revoke.

Your records clerk should have a checklist taped to the fax machine covering the core elements of 45 CFR 164.508. If an element is missing, you send it back with a compliant form rather than releasing under a defective authorization. Note also that FERPA governs the district's handling of what you send; it does not authorize your disclosure. Once a record containing an ICD 10 ODD code enters a student file, you have no control over who inside the district reads it.

One more boundary: if a co-occurring substance use disorder is being treated by a federally assisted Part 2 program, those records carry separate confidentiality requirements beyond HIPAA. The 2024 final rule aligning 42 CFR Part 2 more closely with HIPAA carries a compliance date in mid-February 2026, so if your practice or a partner program falls under Part 2, that consent and notice language needs a fresh read this month.

The Vendor List: Who Actually Touches This Diagnosis

Sit down with your billing lead and inventory every outside party that can see a diagnosis code. In a typical pediatric or behavioral health practice, the list is longer than the administrator expects:

  • Clearinghouse and claim scrubbing service
  • Outsourced coding, billing, or revenue cycle management firm
  • EHR host and any analytics or reporting module
  • Transcription or ambient documentation vendor
  • Release-of-information / copy service
  • Secure messaging, fax-to-email, and patient reminder platforms
  • Care coordination or school-based services portal
  • Shredding and offsite storage
  • IT support with administrative access to the EHR

Every one of them is a business associate, and every one needs a signed BAA on file with a current date, named security contact, breach notification timeline, and subcontractor flow-down language. If your inventory turns up a vendor operating without one — and the reminder platform or the fax bridge is usually the gap — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you need three agreements this week and none next quarter.

Then close the loop: record the BAA execution date in your vendor register, set a review reminder, and note which vendors handle behavioral health data specifically. When a breach happens, the first question is which records were involved. "We think the billing vendor had diagnosis codes" is not an answer.

A Fifteen-Minute Self-Audit You Can Run This Week

  1. Pull five recent claims carrying an F91-series code. Does the note support the specific code, in the provider's own words?
  2. Pull the coder query log. Are provider responses in writing and in the chart?
  3. Check whether any diagnosis code was added or changed by a non-clinical user. Who, and on whose authority?
  4. Review the last three minor-patient record requests. Is the authority determination documented?
  5. Check your front desk script for the "non-custodial parent calls" scenario. Does it exist in writing?
  6. Inventory vendors against signed BAAs. Note every gap with a name and a date.
  7. Confirm your ICD-10 tables were updated after the most recent October 1 revision.

Items one through three protect your revenue. Items four through six protect your license to keep operating quietly. Both come from the same discipline: the code, the note, the disclosure, and the contract all say the same thing.

Next Step

Start with the vendor gap, because it is the one you can close today. Build the list, then generate the missing agreements with the BAA wizard and file them in your vendor register before the next records request forces the question. If your broader policy set and risk analysis are also overdue, automated HIPAA risk analysis and policy generation will get the documentation built faster than a spreadsheet rewrite will.