A payer audit letter arrives on a Tuesday. It asks for 40 charts, all of them established-patient office visits, and the reviewer wants the full encounter note plus anything used to support the level billed. Your billing manager pulls the list, your front desk starts printing, and within an hour there is a stack of protected health information sitting on a shared printer tray.

That is the real story of medical billing code 99213 inside a practice. It is not just a line on a claim — it is a documentation trail, a transmission path through two or three vendors, a records-request magnet, and a recurring PHI exposure point. This guide covers how the code moves through your operation and where your privacy obligations attach at each step. It is administrative guidance for administrators and billing staff, not clinical guidance.

What Medical Billing Code 99213 Is, in One Paragraph

99213 is a CPT code for an office or other outpatient visit with an established patient. Under the evaluation and management guidelines that took effect in 2021 and remain in force in 2026, the level is selected using one of two paths: the level of medical decision making documented for the encounter, or the total time the billing clinician spends on the date of the encounter. For 99213, the time path is 20 to 29 minutes; the MDM path corresponds to a low level of medical decision making. History and physical exam are still documented as clinically appropriate, but they no longer drive code selection for this family of codes.

That is the whole definition. Whether a given encounter meets it is a determination the billing clinician makes and documents — never something your billing staff, your coding software, or this article decides for them.

The Two Paths, and Why Your Documentation Policy Has to Name Which One Was Used

Time-based selection requires a time statement in the note. MDM-based selection requires the note to reflect the elements the clinician considered. Practices get into trouble when the note supports neither cleanly, and the claim goes out anyway because the encounter "felt like a 99213."

Write your internal policy so that every established-patient office visit note identifies the basis for the level. One sentence is enough. When an auditor asks eighteen months later, that sentence is the difference between a five-minute review and a repayment demand.

Who Touches the 99213 Decision on a Normal Clinic Day

Map the roles before you map the technology. In most small and mid-size practices the chain looks like this:

  • Front desk — verifies eligibility, captures demographics and insurance, flags established versus new patient status. Errors here create claim rejections, not coding errors, but they also create the first PHI touchpoint.
  • Clinical staff — rooms the patient, records vitals and intake. May run an ambient documentation tool or scribe service.
  • Billing clinician — performs the encounter, writes the note, selects the level of service.
  • Coder or billing specialist — reviews the note against the selected code, queries the clinician when documentation does not support the level, releases the claim.
  • Clearinghouse and payer — receive the claim as an electronic transaction and return remittance advice.
  • Practice administrator — owns denials, appeals, audit responses, and the vendor contracts underneath all of it.

Six roles, and at least four of them handle PHI outside the EHR at some point — in a spreadsheet, a work queue export, a scanned fax, or an email to a vendor rep. That is where your exposure lives.

The Documentation Trail Every 99213 Leaves Behind

A single established-patient visit billed at this level typically produces: the encounter note, the charge entry record, the electronic claim, the remittance advice, any denial correspondence, the patient statement, and — if the patient asked for one — a superbill or itemized receipt. Every one of those artifacts is protected health information. Several of them contain diagnosis codes, which is exactly the detail patients are most sensitive about.

Superbills and Itemized Statements Are a Front-Desk Privacy Problem

When a patient asks for a superbill at checkout, your staff hands over a document with diagnosis codes on it, often in a lobby, sometimes to a family member who drove the patient. Write a one-line rule: itemized documents go to the patient or a documented personal representative only, and staff confirm identity before handing anything across the counter. Put it in the front-desk training deck, not just the policy binder.

Minimum Necessary Applies to Payment, Not Just Marketing

A common misread: staff assume minimum necessary is about disclosures to outsiders. It applies to uses and disclosures for payment and health care operations too — including internal access. Your billing specialist reviewing a 99213 needs the encounter note for that date of service, not the patient's full longitudinal chart.

Role-based access in the EHR should reflect that. If your billing role has unrestricted chart access because it was easier to configure that way, you have a minimum necessary gap that will show up in your next risk analysis. HHS has published guidance on the minimum necessary standard that is worth handing to whoever administers your EHR permissions.

Every Vendor in the 99213 Pipeline Is Probably a Business Associate

Trace the claim. The note is written in an EHR. The charge crosses to a practice management system. A clearinghouse formats and transmits the electronic claim. A coding-assistance or documentation-integrity tool may have scanned the note. An outsourced billing company may have released the claim. A denial-management vendor may work the rejection. A shredding company disposes of the printed audit packet.

Every one of those entities creates, receives, maintains, or transmits PHI on your behalf. Every one needs a signed business associate agreement before the first record moves. This is where most practices discover a gap — not with the EHR, which came with a BAA in the contract packet, but with the small ones: the transcription contractor, the coding consultant who does quarterly chart reviews, the AI scribe someone piloted last spring, the answering service.

Build the list from your accounts payable ledger, not from memory. Then check each name against your BAA file. For the ones missing an agreement, you can produce a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which matters when you are closing eight gaps at once and do not want eight recurring line items. HHS also publishes sample business associate agreement provisions so you can see what the required elements look like before you sign anything.

The AI Scribe Question Your Coding Workflow Now Has to Answer

Ambient documentation tools have moved into ordinary practices, and they interact directly with level-of-service documentation. Before one touches an encounter, get three answers in writing: is there an executed BAA, is PHI used to train models outside your practice, and how long is audio retained. "We are HIPAA compliant" on a sales page is not an answer, and no product carries a government HIPAA certification — HHS does not certify or endorse compliance products or vendors.

When a Payer Requests 40 Charts: A Records-Request Workflow That Does Not Leak

Disclosures to a health plan for payment purposes are permitted without patient authorization. That does not make the transmission method your choice of convenience.

  1. Log the request. Date received, payer, reviewer contact, date range, response deadline. One log, one owner.
  2. Scope the pull. Pull the requested dates of service, not the entire chart. Over-disclosure to a payer is still over-disclosure.
  3. Choose the channel deliberately. Payer portal upload beats fax. Fax beats unencrypted email, always. If the payer insists on fax, verify the number by phone against the letter — misdirected faxes remain one of the most ordinary breach causes in small practices.
  4. Track what left. Keep a copy of exactly what you sent, page count included. Appeals go badly when nobody can prove what the reviewer received.
  5. Destroy the working copies. The printed stack on the credenza is not a record. Shred it under your disposal policy when the response is out the door.

When the Patient Asks Why They Were Billed a 99213

This call reaches your billing line, and staff often treat it as a customer-service question. It is frequently a records request under the individual right of access at 45 CFR 164.524.

Billing records are part of the designated record set. If a patient asks for their encounter note and the billing detail behind the charge, you have 30 days to provide it, with one 30-day extension available if you notify the patient in writing of the reason and the new date. You may charge a reasonable, cost-based fee — copying labor, supplies, postage — not a search or retrieval fee.

Two operational fixes: give your billing staff a scripted handoff so access requests get routed to the privacy officer instead of dying in a phone queue, and start the clock on the day the request arrives, not the day someone gets around to it. Missed access deadlines have been a durable enforcement theme for OCR, and they are entirely preventable with a shared tracking sheet.

Internal Coding Audits Without Spraying PHI Across Your Network

Most practices run periodic level-of-service reviews — pulling a sample of established-patient visits and checking documentation against the code billed. Useful practice. Also a common source of shadow PHI.

The audit spreadsheet gets emailed to a consultant. Screenshots land in a chat channel. A summary deck with patient identifiers sits in someone's downloads folder for a year. Set the rule before the audit starts: reviews happen inside systems you control, identifiers are stripped from summary reporting, and any outside reviewer signs a BAA first.

If you have never inventoried where billing PHI actually lives, that inventory belongs in your security risk analysis — the same analysis that must be reviewed and updated periodically, not once in 2019. Tooling that automates the risk analysis and supporting policy set can shorten that from a month of evenings to an afternoon, but the vendor list and workflow map still have to come from you.

Payment Mechanics Worth Knowing on the Administrative Side

Reimbursement for established-patient office visits changes annually through the Medicare Physician Fee Schedule, and beginning in 2026 statute splits the annual update into separate conversion factors depending on qualifying alternative payment model participation. That affects your revenue modeling, not your coding decisions.

Keep the two firmly separate in staff training. Level selection follows documentation. Payment rates follow the fee schedule. Anyone who conflates them is describing a compliance problem. Current rates and rule documents are published at the CMS Physician Fee Schedule page.

A 90-Day Cleanup Plan

  • Days 1–15: Build the vendor list from accounts payable. Flag every entity that touches billing data.
  • Days 16–30: Match vendors to executed BAAs. Note the gaps and the expiration dates nobody has looked at.
  • Days 31–45: Close the BAA gaps. Assign one owner and a completion date per vendor.
  • Days 46–60: Review EHR role permissions for billing staff against the minimum necessary standard.
  • Days 61–75: Write and test the payer records-request workflow. Run one dry run with a real request.
  • Days 76–90: Train the front desk on superbill handoffs and route billing-related access requests to the privacy officer.

None of this requires new software. It requires someone owning the list.

Start With the Agreements

The fastest thing to fix is the paperwork you are missing. Pull your vendor list this week, find the names without a signed agreement, and generate the business associate agreements you need in an afternoon. Every claim your practice sends touches at least three outside parties — the contracts should exist before the next audit letter does.