A Medicare contractor sends your practice a records request for 32 claims billed under Dr. Patel's NPI across a six-week stretch. Your nurse practitioner saw most of those patients. The reviewer wants proof that a physician was physically in the office suite when each service happened, and that the plan of care was already established. Your EHR notes name the NP. Your schedule lives in a different system. Your supervision log is a shared spreadsheet somebody stopped updating in November.

That is the operational reality of incident to billing, and this guide is written for the person who has to reconstruct it — the practice administrator, the billing manager, the privacy officer. It covers the documentation chain, who owns each piece, and the HIPAA and vendor exposure the chain creates.

What Incident to Billing Actually Requires

Incident to billing is a Medicare Part B payment mechanism. It lets services furnished by non-physician practitioners and auxiliary personnel be billed under the supervising physician's NPI when a defined set of conditions is met. When those conditions are not met, the service is generally billed under the rendering practitioner's own NPI at the reduced fee schedule rate.

CMS sets out the conditions in the Medicare Benefit Policy Manual, Chapter 15. The core elements your staff need to recognize:

  • Office or non-institutional setting. The rule does not apply in hospital outpatient departments; those visits fall under a different set of split/shared rules.
  • Established patient, established problem. A physician must have personally performed the initial service and set the plan of care. New patients and new problems fall outside.
  • Direct supervision. A physician must be present in the office suite and immediately available. Not in the same room. Not across town on a phone.
  • Ongoing physician involvement. The physician has to remain active in the course of treatment, not just sign off once a year.
  • Employment or contractual relationship. The person furnishing the service must be an employee, leased employee, or independent contractor of the billing physician or entity.
  • Scope of practice. The service must be within what state law and licensure permit for that practitioner.

Read the source language rather than a summary: the Medicare Benefit Policy Manual, Chapter 15 is the document a reviewer will cite back at you.

Commercial payers and Medicaid do not follow the same rules

Your Part C plans, commercial contracts, and state Medicaid program each set their own policy on supervision and NPP credentialing. Some require the NPP to be credentialed and billed directly. Some mirror Medicare. Some are silent, which is worse.

Build a one-page payer matrix and keep it with the contract file: payer, whether incident to billing is permitted, supervision definition, credentialing requirement, and the date somebody last verified it. Review it when contracts renew.

Auditors do not evaluate intent. They evaluate whether the record supports the claim. Assign each link to a named role, not to "the office."

Front desk and scheduling

Your schedulers are the first filter. They need a rule they can apply without clinical judgment: new patient or new complaint routes to a physician slot or an NPP slot billed under the NPP. Give them a script, not a decision tree that requires them to interpret symptoms.

Clinical staff

The visit note should identify the supervising physician by name and record that the physician was present in the suite. A note that says only "physician available" tells a reviewer nothing about location. Practices commonly build a discrete field or a template attestation rather than relying on free text.

The daily supervision record

This is the piece most practices are missing when the letter arrives. You need a contemporaneous, retrievable record of which physician was physically in the suite during which hours on which date. Time clock exports, physician schedules with in/out times, and signed daily attestations all work. A spreadsheet edited retroactively does not.

Billing and coding

Your billing staff apply payer policy and internal documentation standards to determine how a claim is submitted and under whose NPI. They do not decide what service was medically appropriate. Keep that boundary written into the job description — it protects the coder and it protects you.

Document how code selection was determined, not whether a code was clinically right. When a coder queries a provider, the query and response belong in the record.

Where Incident to Billing Breaks Down in Real Practices

Four failure patterns account for most of what internal audits turn up.

The physician stepped out. Hospital rounds, a procedure at the surgery center, an early departure. If the schedule shows the supervising physician left at 2:00 and the visit is timestamped 3:15, the claim fails on its face.

The problem was new. An established patient comes in for a follow-up and mentions something unrelated. The NPP addresses it. That portion of the encounter falls outside the established-plan-of-care requirement, and the claim as submitted may not hold.

The supervising physician on the claim never saw the patient. Practices sometimes default to a group's senior physician or a rotating "physician of the day" without confirming who established the plan. Reviewers cross-reference this against the historical record.

Nobody reconciles the claim to the note. The NP wrote the note, the claim went out under a physician NPI, and no one compared the two. Run a monthly sample — 20 to 30 encounters — reconciling rendering provider on the claim against the author of the note and the supervision record.

What to do when the sample fails

If your internal review identifies claims that were paid but not supported, the 60-day overpayment rule under Section 1128J(d) of the Social Security Act starts running once the overpayment is identified and quantified. That is a legal and financial process — loop in counsel and your compliance committee before the clock does anything interesting. Document the date of identification, the quantification method, and the decision path.

The Privacy Side Nobody Puts in the Billing Manual

Everything you just built is protected health information. Supervision logs tied to patient encounters, coder queries, audit workpapers, extrapolation samples — all of it identifies individuals and relates to treatment or payment.

Responding to a payer audit

Disclosures to a health plan for payment purposes are permitted under the Privacy Rule without patient authorization. That does not make the transmission method a free-for-all. If your MAC or a UPIC requests 32 charts, the operational questions are: how are those records transmitted, who assembled them, what was the encryption path, and what did you log.

Practices routinely blow this by emailing a zip file from a personal account or uploading to a portal nobody vetted. Write the audit-response transmission method into your policy set before the first request arrives, and name the person authorized to send.

Minimum necessary applies to your own workpapers too

When an outside coding consultant reviews 200 encounters, do they need full charts, or a defined data set? When your RCM vendor's offshore team touches claims, what fields do they see? Minimum necessary is a design constraint on access, not a memo you circulate.

Patient access requests intersect with all of this

A patient who received a bill listing a physician they never met will call. Some of them will submit a records request. You have 30 days under 45 CFR 164.524 to respond, with one 30-day extension available and notice required. HHS keeps its guidance on the right of access on its Privacy Rule pages, and OCR has enforced the access right steadily.

Decide in advance what the designated record set includes for these requests and train your release-of-information staff on the answer. Billing records are generally part of it. Internal audit workpapers generally are not — but that determination should be documented, not improvised at the counter.

Your Vendor List Grows Every Time You Touch This Workflow

Incident to billing pulls in more third parties than most administrators realize. Each one that creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a signed agreement before access is granted.

  • Billing and RCM companies submitting under your physicians' NPIs
  • Clearinghouses routing the claims
  • Coding auditors and consultants reviewing charts
  • Time-tracking or credentialing platforms that hold supervision data linked to encounters
  • Transcription and documentation support services touching the notes
  • Outside counsel or audit-defense firms, depending on the engagement structure

HHS explains the scope of the business associate relationship in its guidance for covered entities. If a vendor you engaged during a payer audit is not on your BAA inventory, that gap is yours to close. A signature-ready business associate agreement takes minutes to produce; explaining an undocumented vendor relationship to a regulator takes considerably longer.

Offboarding is the step people skip

The consultant finished the review in October. Is their EHR account still active in January? Put vendor account termination on the same checklist as employee termination, with a named owner and a date field.

A practice supporting incident to billing typically maintains, for each encounter: (1) a prior physician note establishing the patient and the plan of care for that problem; (2) the current visit note identifying the rendering practitioner and the supervising physician by name; (3) a contemporaneous record showing the supervising physician was physically present in the office suite at the time of service; (4) evidence of the employment or contractual relationship; and (5) the claim showing the supervising physician's NPI. Payer policy governs the specifics, and non-Medicare payers may require direct billing under the practitioner's own NPI instead.

Fold This Into the Risk Analysis You Already Owe

The Security Rule requires an accurate and thorough assessment of risks to electronic PHI under 45 CFR 164.308(a)(1)(ii)(A). Supervision logs, audit response packages, and RCM vendor access are all in scope, and they change every time you add a location, a practitioner, or a payer contract.

If your risk analysis predates your current billing workflow, it is describing a practice that no longer exists. Tools that generate risk analysis reports and the supporting policy set shorten the reconstruction work considerably — the analysis, the policies, and the documentation trail come out of one process instead of three disconnected ones. No product carries government endorsement, and no vendor can certify you; what they can do is produce the artifacts you will be asked to show.

A 30-Day Cleanup Plan

  1. Week 1: Pull your payer matrix together. Confirm which contracts permit incident to billing and which require direct NPP billing.
  2. Week 2: Audit a 25-encounter sample. Reconcile claim NPI, note author, and supervision record. Log every mismatch.
  3. Week 3: Inventory every vendor touching this workflow. Confirm an executed BAA for each. Terminate stale accounts.
  4. Week 4: Write the audit-response procedure — who assembles, how it transmits, what gets logged — and update the risk analysis to reflect what you found.

Assign each week to a named person with a due date. "The practice will review" is not an assignment.

Next Step

Start with the documentation gap that would sink you tomorrow: the supervision record. Once you know what you actually have, build the risk analysis and policy documentation around the workflow as it really runs — not the one described in a manual written three practitioners ago.