On a Tuesday afternoon your front desk takes a call from a 24-year-old patient who is still on a parent's insurance plan. She wants to know why an explanation of benefits arrived at her father's house listing a behavioral health visit. Nobody at your practice mailed anything. The payer did — because the claim you submitted carried a diagnosis code.

This is a practice-operations guide to icd 10 panic disorder coding for administrators, billers, and privacy officers. It covers who selects the code, what documentation supports it, and — the part most coding articles skip — where that code travels after it leaves your building, which vendors touch it, and what your obligations are when a patient asks you to keep it quiet.

None of this is clinical guidance. Code selection belongs to the treating clinician working from the record. Your job is the workflow around it.

Where the ICD 10 Panic Disorder Code Actually Lives in Your Workflow

A diagnosis code is not a billing artifact that appears at the end. It is created in the encounter note, pulled into the charge capture screen, transmitted on the 837 claim, stored in your clearinghouse, returned on remittance advice, printed on the patient's EOB, and — under the information blocking rules — often surfaced in the patient portal within seconds of the note being signed.

That is at least six systems and, depending on your setup, three or four separate companies. Every one of them is a place where a behavioral health diagnosis can be seen by someone the patient did not expect.

The F40–F41 neighborhood, as an administrative matter

ICD-10-CM places panic disorder in the F41 category, "Other anxiety disorders." F41.0 carries the title Panic disorder [episodic paroxysmal anxiety]. A related code, F40.01, carries the title Agoraphobia with panic disorder, and the Tabular List includes an Excludes1 note that separates the two — meaning the code set treats them as mutually exclusive at the same encounter.

Neighboring codes in the same block include F41.1 (generalized anxiety disorder), F41.8, and F41.9. Your coders should be working from the current Tabular List and Alphabetic Index, not from a cheat sheet taped inside a desk drawer. CMS publishes the annual files and the Official Guidelines for Coding and Reporting on its ICD-10 code page, updated each October 1.

What your practice controls is not which code is right for a given patient. It is whether the code your clinician selected is the code that actually went out on the claim, and whether the documentation in the chart supports it if a payer asks.

Who picks the code, and who never should

Write this into your policy manual in plain language:

  • The treating clinician selects and documents the diagnosis.
  • The coder or biller may query the clinician when documentation and code don't line up, and may correct a transposition or a code that no longer exists in the current file year. They do not upgrade, downgrade, or substitute a clinical judgment.
  • The front desk never selects a diagnosis code, including on prior authorization forms and referral faxes.
  • The privacy officer owns the question of who receives the code once it leaves the chart.

If your EHR lets a scheduler drop a diagnosis onto an encounter to clear a validation error, turn that permission off. That single configuration decision has resolved more coding-integrity findings than any training session I have run.

Quick Answer: What Is the ICD-10 Code for Panic Disorder?

In ICD-10-CM, panic disorder is classified under F41.0, titled Panic disorder [episodic paroxysmal anxiety]. When agoraphobia is documented alongside it, the code set directs the coder to F40.01, Agoraphobia with panic disorder, and an Excludes1 note prevents reporting both at the same encounter. Code assignment must be supported by the clinician's documentation for that specific visit. Verify against the current fiscal-year Tabular List before submission.

The EOB Problem: How a Diagnosis Code Reaches the Wrong Mailbox

Back to the Tuesday phone call. Under the Privacy Rule at 45 CFR 164.522(b), an individual may request that you communicate protected health information by alternative means or at an alternative location. For health plans, that request must be accommodated when the individual states that disclosure could endanger them. For providers, you must accommodate reasonable requests — and you may not demand an explanation.

Your practice cannot control what the payer mails. You can control three things, and you should build all three into intake:

  1. Ask at registration. Add a line to your intake form: "Is there an address, phone number, or email we should not use to reach you?" Capture the answer in a field your staff actually reads before mailing statements.
  2. Route the request. When a patient asks for confidential communications, the front desk logs it and hands it to the privacy officer the same day. Set an internal service level — 72 hours to configure the alternate contact in every system, including the statement vendor and the appointment-reminder tool.
  3. Tell the patient what you cannot control. Document that you explained the payer sends its own EOB and gave them the plan's member-services number to make the same request directly.

HHS maintains specific guidance on sharing information related to mental health that your privacy officer should read once a year. It also addresses the self-pay restriction at 164.522(a)(1)(vi): if a patient pays in full out of pocket for an item or service, and asks you not to bill the plan, you must honor that request. That is the cleanest way a patient can keep a behavioral health diagnosis off a claim entirely — and your billers need to know how to flag the encounter so it doesn't sweep into the next batch.

Psychotherapy Notes Are a Separate File — Your Release Workflow Has to Know That

The Privacy Rule defines psychotherapy notes narrowly at 45 CFR 164.501: notes recorded by a mental health professional documenting or analyzing a counseling session, maintained separately from the rest of the record. They exclude medication prescription and monitoring, session start and stop times, modalities and frequencies, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress.

Two operational consequences follow.

First, the diagnosis code itself is never a psychotherapy note. It sits in the designated record set and is subject to the right of access like any other element.

Second, the separation requirement is physical and technical, not conceptual. If your clinicians type session process notes into the same encounter note that carries the assessment and plan, you do not have psychotherapy notes — you have a chart. Most releases of psychotherapy notes require a specific authorization under 164.508(a)(2), so a clinician who assumes protection that the file structure doesn't support is setting up a disclosure they didn't intend. Audit this by pulling five behavioral health charts a quarter and checking where the notes actually live.

February 16, 2026: The Part 2 Compliance Date Nobody Sorted Out

The 2024 final rule modifying 42 CFR Part 2 carries a compliance date of February 16, 2026 — under three weeks from today. It aligns Part 2 more closely with HIPAA: a single patient consent can cover treatment, payment, and health care operations; HIPAA breach notification requirements extend to Part 2 records; and the notice requirements change.

Here is the clarification your staff needs, because it comes up every time behavioral health coding is discussed: Part 2 applies to records from federally assisted substance use disorder programs. A general psychiatry or primary care practice that documents an anxiety-spectrum diagnosis is not a Part 2 program by virtue of that diagnosis alone. But if any part of your organization holds itself out as providing SUD diagnosis, treatment, or referral, the segmentation question is live, and the calendar is short.

If you receive Part 2 records from another entity, your policies need to say what happens to them — including whether they get filed into the general chart, where they will be swept up by the next routine disclosure.

The Vendor List: Every Company That Touches F41.0

Pull your vendor inventory and mark every entry that can see a diagnosis code. In a typical outpatient practice, the honest list includes:

  • The EHR vendor and any hosting provider beneath it
  • The clearinghouse
  • An outsourced billing or RCM company
  • The patient statement and payment processor
  • Appointment reminder and secure messaging tools
  • E-fax and transcription services
  • Telehealth platform
  • Answering service and after-hours triage
  • Release-of-information vendors and record copy services
  • Analytics, scheduling widgets, and any script running on the pages where patients log in

That last category deserves its own review. OCR's guidance on online tracking technologies has been litigated and partially vacated, but the underlying exposure is unchanged: if a marketing pixel on your authenticated patient portal transmits appointment or diagnosis context to an ad network, you have made a disclosure you cannot paper over. The FTC has also pursued health-data sharing cases under the FTC Act and the Health Breach Notification Rule, which reaches entities outside HIPAA's direct scope.

Every vendor on that list needs a current, signed business associate agreement with defined subcontractor flow-down, breach notification timing, and return-or-destruction terms at termination. If you found three vendors without one — and most practices do on first pass — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, and considerably faster than routing a redline through counsel for a $200-a-month reminder tool.

The 30-Day Clock on a Records Request That Includes a Behavioral Health Diagnosis

Under 45 CFR 164.524, you have 30 calendar days to act on an access request, with one 30-day extension available if you notify the individual in writing of the reason and the new date. The clock does not pause because the chart contains sensitive content, and "our clinician is uncomfortable" is not a denial ground.

Practical rules for your release desk:

  • Provide the record in the form and format requested if you can readily produce it, including electronic copies of an electronic record.
  • Charge only a reasonable, cost-based fee. Per-page state fee schedules do not automatically apply to individual access requests.
  • Log the request date, the fulfillment date, the format, and the delivery method. That log is the first thing OCR asks for in a right-of-access complaint.
  • Route any denial through the privacy officer, in writing, with the review rights explained.

HHS keeps a detailed individuals' right of access guide. Print the fee section and tape it above the release-of-information workstation.

Five Checks Before Your Next Payer Review

  1. Code file currency. Confirm your EHR and clearinghouse are on the current fiscal-year ICD-10-CM file. Assign an owner and a calendar reminder for October 1.
  2. Permission audit. Verify that non-clinical roles cannot add or modify diagnosis codes.
  3. Alternate-contact fields. Test that a confidential communications flag actually propagates to your statement vendor and reminder tool. Run a live test, not a screenshot review.
  4. Portal release timing. Know when signed notes and diagnoses become visible to patients, and how your clinicians handle results delivery under the information blocking rules.
  5. BAA coverage. Every vendor with diagnosis-level access has a signed, current agreement on file — with a copy your privacy officer can produce in under ten minutes.

Where to Start This Week

Take one afternoon. Trace a single encounter carrying an icd 10 panic disorder code from the note through every downstream system, and write down each company that saw it. Then match that list against your signed agreements.

For the gaps you find, build the missing BAAs and get them signed before the next quarter closes. If the exercise turns up broader holes — no current risk analysis, stale policies, no documented workflows for access requests — automated risk analysis and policy generation will get the document set built faster than starting from a blank template. Diagnosis codes are the most-copied piece of data in your practice. Know where yours go.