Medical Billing Code 99204: Records and Vendor Rules
Pull your last 200 new-patient claims and sort them by level. If medical billing code 99204 accounts for the overwhelming majority of them and your average note runs four sentences, you have an operations problem that will become a records problem the moment a payer asks for supporting documentation.
This guide is written for the administrator, billing manager, or privacy officer who owns that outcome. It covers what 99204 represents on a claim, how practices document level selection defensibly, who touches the chart between the exam room and the payer, and which of those parties needs a Business Associate Agreement on file before the first claim goes out. It is administrative guidance. Nothing here tells you which code fits a given patient encounter — that determination belongs to the rendering provider and your coding policy.
What Medical Billing Code 99204 Is, in One Paragraph
99204 is a CPT code for an office or other outpatient evaluation and management visit for a new patient. Since the AMA's January 1, 2021 revisions to the office/outpatient E/M family, level selection for these codes rests on one of two paths: the level of medical decision making, or the total time the billing provider spends on the encounter on the date of service. For 99204, the code descriptor pairs a moderate level of medical decision making with a total-time range of 45 to 59 minutes. History and exam are performed and documented as medically appropriate, but they no longer drive the level. That is the entire structural change your documentation policy has to reflect.
The Three-Year Rule Your Front Desk Actually Enforces
"New patient" is a registration determination, not a clinical one, and it is made at the front desk before anyone opens a note. Under CPT definitions, a patient is new if they have not received a face-to-face professional service from that physician or qualified health professional — or another provider of the exact same specialty and subspecialty in the same group practice — within the prior three years.
Two operational failure points show up in audits repeatedly:
- Group practice lookups that only search the scheduling provider. If your registration workflow checks whether Dr. A has seen the patient but not whether Dr. A's same-specialty partner has, you will bill new-patient levels on established patients.
- Specialty and subspecialty fields left blank in your provider table. The rule turns on taxonomy. If your credentialing data is stale, the lookup logic cannot work.
Assign this to a named role. In most practices it belongs to the registration supervisor, with a monthly reconciliation report reviewed by the billing manager. Document who owns it, because when a payer opens a new-patient-level review, the first question is process, not intent.
Two Documentation Paths, Two Different Audit Files
Path one: medical decision making
MDM under the current framework is built from three elements: the number and complexity of problems addressed at the encounter, the amount and complexity of data reviewed and analyzed, and the risk of complications from patient management. Two of the three drive the level. Your job as administrator is not to grade the MDM. Your job is to make sure the note contains the raw material an outside reviewer needs to see the provider's reasoning — the problems addressed, what data was reviewed and why, and what management options were considered.
Practices that survive audits well have a written internal coding policy stating that MDM level is selected by the rendering provider and reviewed on a sampling basis by a certified coder, with disagreements resolved before submission and logged. That log is your evidence of a functioning compliance program.
Path two: total time on the date of the encounter
Time-based selection counts the billing provider's total time on the calendar date of the encounter, including qualifying non-face-to-face work such as record review, ordering, and documentation. It does not include staff time, and it does not include time on other dates.
If your providers use the time path, your documentation standard needs to require a stated total and a description of the activities counted. "Time spent: 48 minutes" with no supporting narrative is thin. A time statement that conflicts with the EHR audit log — a 50-minute encounter documented on a chart open for nine minutes with no other activity attributable to that patient that day — is worse than thin, because the audit log is discoverable and the payer's reviewer knows it exists.
That last point deserves emphasis with your providers: the metadata is part of the record. Access logs, timestamps, and amendment histories are produced in audits and in litigation. Train to that reality.
Payer rules on prolonged services beyond the 99204 range diverge — some follow CPT's add-on code, Medicare uses its own HCPCS code — so maintain a payer-by-payer grid rather than a single house rule. Check current rates and policy against the CMS Physician Fee Schedule rather than a vendor's cached crosswalk.
Every Party That Touches a Single 99204 Claim
Map it once and you will never look at your vendor list the same way. A routine new-patient visit billed at this level typically passes through:
- Your EHR and practice management system, hosted by a vendor with database-level access to the note.
- Any ambient documentation, dictation, or transcription tool used to draft the note.
- Your coding review resource — in-house coder, contract coder, or an outsourced coding firm.
- Your billing company or RCM vendor, if billing is not in-house.
- The clearinghouse that formats and routes the 837P claim transaction.
- The payer, and the payer's contracted review or audit vendor.
- Your denial-management or appeals vendor, if a records request follows.
- Your document storage or fax service, when the chart is transmitted for review.
- Your patient-statement and collections vendors on the back end.
Items 1 through 5, plus 7 through 9, are business associates. The payer is not — it is a covered entity receiving PHI for payment purposes. The payer's audit contractor works under the payer's agreements, not yours, but you still owe a minimum-necessary analysis on what you send.
Count the agreements you actually have signed against that list. Most practices find at least one gap, usually the transcription tool a provider adopted independently or the fax service nobody thinks of as a vendor. HHS publishes sample business associate agreement provisions that define the required floor, and if you need a signature-ready document rather than a starting template, you can generate a complete Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Close the gap this week, not at your next annual review.
Minimum Necessary When the Payer Requests the Chart
Disclosures for payment do not require patient authorization. They do require you to limit what you send to the minimum necessary for the stated purpose, and this is where billing staff most often overshoot.
A payer reviewing level selection for a specific date of service needs that encounter note, the relevant orders and results referenced in it, and the claim. It does not need the patient's full longitudinal chart, unrelated specialty consults, or behavioral health notes that carry separate protections. "Send the whole record, it's easier" is a policy decision that increases your breach surface for no operational benefit.
Build a records-response template with three fields: the specific date(s) of service requested, the document types authorized for release, and the reviewer's name who approved the scope. HHS guidance on the minimum necessary requirement is worth putting in front of your billing team once a year, because the rule is easy to state and easy to ignore under deadline pressure.
Also log the disclosure
Payment disclosures are exempt from the accounting of disclosures a patient can request, but your internal log still matters for tracking what left the building and when. If a breach investigation follows, that log is the difference between a two-hour scope determination and a two-week one.
The Billing Record Is Part of the Designated Record Set
Patients have a right of access to billing and payment records, not just clinical notes. A patient who asks for "everything you used to bill my visit" is making a valid access request, and your 30-day clock starts on receipt.
Two practical consequences for your workflow:
- Your billing vendor holds designated record set material. Your BAA needs a turnaround commitment that lets you meet the 30-day deadline, and someone at your practice needs a named contact there. "We emailed them and waited" is not a defense.
- Amendment requests can target billing records. A patient who disputes the level billed may request an amendment. You are not obligated to change a code, but you are obligated to respond within the required timeframe and, on denial, to accept and attach the patient's statement of disagreement.
Access complaints remain one of the most common categories that reach the Office for Civil Rights. You can review the pattern of reported incidents on the OCR breach portal — it is a useful reminder that vendor-side incidents account for a substantial share of affected individuals.
A 60-Day Cleanup Plan You Can Assign Today
Days 1–10. Run a distribution report on new-patient E/M levels by provider for the last twelve months. Outliers are not violations, but unexplained outliers are audit bait. Have your coder review a sample of 20 charts per outlier provider.
Days 11–20. Rewrite your internal coding policy to name the two selection paths explicitly, state who selects, who reviews, and how disagreements resolve. One page. Signed by the medical director.
Days 21–35. Complete the vendor map above. Match every entity against your executed BAA file. Execute the missing ones.
Days 36–50. Build the records-response template and train billing staff on scoping. Test it with a simulated payer request.
Days 51–60. Update your risk analysis to reflect the vendors you just discovered. If your risk analysis has not been refreshed since your last EHR change, it is stale — and a current one is the document OCR asks for first. Practices that need to rebuild the full policy set can automate the risk analysis and supporting documentation rather than restarting from a blank Word file.
The Short Version
Medical billing code 99204 is not a compliance topic on its own. It becomes one because level selection invites scrutiny, scrutiny produces records requests, and records requests move protected health information through a chain of vendors most practices have never fully mapped. Fix the documentation standard, fix the vendor list, and the audit becomes an inconvenience instead of an event.
If your review turns up a vendor handling claims data without a signed agreement, resolve it before your next billing cycle — build the Business Associate Agreement, get it signed, and file it with the rest.