A surgical coordinator faxes your office fourteen pages at 4:40 p.m. on a Tuesday: a clearance request, a partial history, an anesthesia questionnaire, and a demand that everything come back before the Friday block. Your front desk has three days to schedule the visit, your coder has to pick the right ICD 10 preop code family, and somewhere in that scramble protected health information will move between four organizations. This guide walks the operational mechanics of preoperative examination coding and then makes the privacy, records-handling, and vendor implications explicit — because in most practices, the preop workflow is the least-documented high-volume process on the floor.

This is administrative guidance for administrators, billers, and privacy officers. It does not tell you which code fits a given patient. It tells you how to build the workflow that lets your coders make and defend that decision.

What "ICD 10 Preop" Refers To on a Claim

When staff say "the preop code," they are almost always referring to ICD-10-CM subcategory Z01.81-, Encounter for preprocedural examinations. The published descriptors in that subcategory are:

  • Z01.810 — Encounter for preprocedural cardiovascular examination
  • Z01.811 — Encounter for preprocedural respiratory examination
  • Z01.812 — Encounter for preprocedural laboratory examination
  • Z01.818 — Encounter for other preprocedural examination

These are Z codes: they describe the reason for the encounter, not a disease. Your coding staff select among them based on the documentation in front of them and the current ICD-10-CM Official Guidelines for Coding and Reporting, which are updated annually and posted alongside the code files on the CMS ICD-10 page. Nobody in the billing office should be selecting a preop code from memory or from a laminated cheat sheet printed three fiscal years ago.

The Sequencing Structure Your Coders Are Working Inside

The Official Guidelines address preoperative examinations directly, and the structure they describe is what drives your claim edits. In broad terms, the guideline instructs that a code from subcategory Z01.81- is sequenced first to describe the preprocedural evaluation, that the condition prompting the planned surgery is reported as an additional code, and that any findings identified during the evaluation are also coded.

Two operational consequences follow from that structure.

First, the requesting surgeon's reason for surgery has to reach your coder. If the referral packet arrives without the underlying condition, your coder is missing a required element of the claim. That is a front-desk intake problem, not a coding problem, and it is fixable with a checklist.

Second, the guideline applies to evaluations performed for preoperative clearance. An encounter that is not a preoperative evaluation is coded on its own terms. Your internal policy should say plainly that coders determine applicability from the documentation and the guidelines, and that scheduling notes, referral forms, and appointment types are not substitutes for the provider's note.

The Three Documentation Elements to Require at Intake

Build a one-page intake standard and hold the surgical coordinator to it:

  1. The planned procedure and the condition prompting it, in writing, from the requesting practice.
  2. The specific clearance being requested and the scheduled surgical date.
  3. A named recipient and verified destination for the completed evaluation — person, organization, fax number or portal address.

Element three is a privacy control disguised as a scheduling field. More on that below.

Role Assignment: Who Owns Each Step of the ICD 10 Preop Workflow

Preop clearance fails at handoffs. Assign owners by name in your written workflow, not by department.

Front desk (day 0): receives the request, verifies the requesting practice by callback to a number on file — not a number printed on the inbound fax — logs the request in the tracking sheet, and confirms the three intake elements. Missing elements go back the same business day.

Scheduler (day 0–1): books the visit against the surgical date with enough runway for labs or diagnostics to result. Flags any request landing inside 72 hours of surgery for supervisor review.

Clinical staff (visit day): completes the evaluation and documents the findings and the reason for the encounter in the note.

Coder or biller (day +1): selects and sequences codes from the documentation, applies the current guidelines, and routes anything ambiguous to a documented provider query rather than guessing.

Release of information (day +1 to +2): transmits only the clearance documentation to the verified recipient, records what was sent and to whom, and files the confirmation.

That last line is the one most practices skip. It is also the one that decides whether a misdirected fax is a five-minute correction or a reportable breach investigation.

Where Preop PHI Actually Travels — Map It Before You Secure It

A single preoperative evaluation typically generates disclosures to the surgeon's office, the facility or ambulatory surgery center, anesthesia, an outside laboratory, sometimes a cardiology or pulmonary consultant, and — on the back end — your clearinghouse and payer. That is six to eight organizations touching one encounter.

Disclosures to another provider for treatment purposes are permitted under the Privacy Rule without patient authorization. Two points administrators regularly get wrong:

Minimum Necessary Does Not Apply the Way Staff Think It Does

The minimum necessary standard does not apply to disclosures to a health care provider for treatment. It does apply to disclosures for payment and health care operations, and to most uses inside your own organization. HHS lays this out in its minimum necessary guidance.

Practically: sending the full relevant record to the operating surgeon is defensible. Sending the full chart to a payer's utilization reviewer because it was easier than pulling the relevant pages is not. Train those two situations as separate scenarios, because your staff experience them as the same button.

Verification Is a Rule, Not a Courtesy

The Privacy Rule requires you to verify the identity and authority of a person requesting PHI when you do not already know them. "The fax says it's from Dr. Whoever's office" is not verification. Callback to a number in your own directory is. Every practice that has reported a misdirected-records incident can trace it to a destination nobody confirmed.

Fax, Portal, and the Three Failure Points in Preop Transmission

Preop clearance is still fax-heavy, and fax is where the incidents live.

Failure point one: the stored fax entry. A surgical practice moves offices, the old number gets reassigned, and your fax machine's speed dial does not know. Audit stored fax destinations quarterly and date the audit.

Failure point two: the cover sheet with no cover. Fourteen pages of PHI sitting in an unattended tray in a shared suite is an impermissible disclosure waiting for a witness. Confirm receipt for anything above a page count you define.

Failure point three: unencrypted email as the fallback. When the fax fails at 4:55 p.m. on a Thursday, somebody will attach the PDF to regular email. Write the alternative into the policy — portal upload, secure messaging, encrypted transport — so staff have a compliant option under time pressure. Policies that only prohibit do not survive a Friday surgical block.

If a transmission does go to the wrong recipient, you run a breach risk assessment against the four factors in the Breach Notification Rule and document the outcome either way. Small breaches from the prior calendar year are submitted to HHS no later than 60 days after the year ends — meaning your 2025 log is due by March 1, 2026. If you have not pulled that log yet, this is your reminder.

The 30-Day Clock When a Patient Asks for Their Preop Chart

Patients request preoperative records more often than administrators expect — for second opinions, for disability paperwork, for disputes about a surgery that was postponed. The HIPAA right of access gives you 30 calendar days to respond, with one 30-day extension available if you notify the individual in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS maintains detailed right of access guidance, and access failures have been a sustained enforcement priority.

The preop-specific wrinkle: the record a patient wants often lives partly with you and partly with the surgeon, the lab, or the facility. You owe the individual what is in your designated record set. Train staff to fulfill that promptly rather than deferring to "the surgeon's office has the whole file." Deferral is how 30 days becomes 45.

Every Vendor That Touches a Preop Encounter Needs a BAA

Walk the workflow and list who touches the data on your behalf: the coding or billing service, the clearinghouse, the transcription vendor, the release-of-information company, the fax-to-email provider, the EHR host, the secure messaging platform, the document shredding service, the IT contractor with remote access to workstations.

Each of those is a business associate, and each requires a written agreement with the required elements — permitted uses, safeguards, subcontractor flow-down, breach reporting timelines, and return or destruction at termination. HHS publishes the underlying requirements and sample provisions in its business associate guidance. If you find gaps during this exercise — and most practices find at least two — you can produce a signature-ready business associate agreement without waiting on outside counsel for a routine vendor.

The other provider offices in the chain are a different category. A surgeon's practice receiving records for treatment is not your business associate, and you do not need an agreement with them. Staff routinely confuse the two and either chase unnecessary paperwork or skip the paperwork that matters.

Tie the Workflow to Your Risk Analysis

The Security Rule requires an accurate and thorough risk analysis covering all electronic PHI your organization creates, receives, maintains, or transmits. Preop data is textbook ePHI in motion: it crosses organizational boundaries on a deadline, through channels staff choose under pressure. NIST's SP 800-66 Rev. 2 is the standard implementation reference for working through that analysis systematically.

If your current risk analysis does not name the fax service, the coding vendor, the portal, and the transmission fallback path, it does not describe your practice. Rebuilding that document from scratch every year is exactly the kind of work worth automating — you can generate your HIPAA risk analysis, policies, and supporting document set and spend the reclaimed hours on the workflow itself. No product, including that one, is a government-issued certification; HHS does not certify or endorse compliance tools. What it produces is documentation you can hand to an auditor.

A Ten-Item Preop Audit You Can Run This Quarter

  1. Pull 20 preop encounters from the last 90 days. Confirm each has the planned procedure and reason for surgery in the intake record.
  2. Confirm each has a documented, verified destination for the completed clearance.
  3. Confirm your coders are working from the current-year Official Guidelines, and record the version date.
  4. Review provider queries: are ambiguous cases documented, or resolved verbally?
  5. Audit stored fax destinations against your verified directory.
  6. Test the secure transmission fallback with a staff member, unannounced.
  7. Confirm every vendor in the preop chain has a current, signed BAA on file.
  8. Check access-request turnaround times for the last two quarters against the 30-day clock.
  9. Confirm your 2025 small-breach log is submitted or scheduled before March 1.
  10. Date and file the audit. Undated compliance work is indistinguishable from no compliance work.

Preop clearance will keep arriving at 4:40 p.m. on Tuesdays. What you control is whether the request meets a defined workflow with named owners, or a scramble that leaves your coders guessing and your PHI moving through whatever channel is open.

Start with the vendor list and the risk analysis — those two documents determine how defensible everything downstream is. If yours are out of date, build the current set now and use the preop workflow above as the first process you map into it.