Your practice opens the mail on a Tuesday and finds a payer audit letter: 22 encounters, all submitted with medical billing code 99214, spanning the last three quarters. The letter gives you 30 days. Your biller is out until Thursday, your coding lead works two days a week, and the scribe vendor that drafted eleven of those notes has never signed anything past its order form.

This is a practice-operations guide for the administrator, billing supervisor, or privacy officer who has to answer that letter. It covers how practices document level-of-service selection, who owns each step, and the records-handling and vendor obligations that attach to every level-4 claim you send out the door.

What Medical Billing Code 99214 Means on a Claim Line

CPT 99214 is the office or other outpatient evaluation and management code for an established patient at the fourth of five service levels. Under the E/M framework that took effect January 1, 2021, level selection for these codes rests on one of two things: the level of medical decision making, or the total time the billing clinician spends on the encounter on the date of service. History and exam are performed as medically appropriate, but they no longer drive the level.

In the code set's own structure, 99214 corresponds to a moderate level of medical decision making, or to total time of 30–39 minutes on the date of the encounter. The American Medical Association maintains CPT and its guidelines; CMS sets the payment side through the Medicare Physician Fee Schedule.

That paragraph describes how the code set is organized. It is not a determination that any particular visit in your charts belongs at that level. Only the billing clinician, supported by your documentation and coding review process, makes that call.

How Your Practice Documents Code Selection Without Guessing

Audits rarely fail because a clinician made an indefensible judgment. They fail because the note does not show the reader what the clinician considered. Your job as an operator is to build templates, workflows, and review steps that surface the reasoning.

Support both selection paths in your templates

If your note template only has room for a problem list and a plan, your clinicians are documenting one path and leaving the other invisible. Practices that hold up under review give the clinician a place to record:

  • The problems addressed at the encounter and their status, in the clinician's own words
  • Data reviewed or ordered, including who else was consulted and when
  • Risk considerations tied to the management options actually discussed
  • A discrete total-time field for the date of service, when time is the basis for selection

Two rules keep this clean. Time-based and decision-making-based selection are alternatives, not a blend — the note should make clear which one the clinician used. And a prepopulated time value that never changes across a full schedule is the fastest way to draw a second audit letter.

Assign the roles in writing

Write down who does what, with names, not job titles alone. A workable split for a mid-size practice:

  1. Billing clinician selects the level and signs the note. Nobody else changes the level without going back to the clinician.
  2. Coding lead runs a pre-bill review on a defined sample — new clinicians at 100% for the first 90 days, everyone else at a fixed monthly sample — and queries the clinician when the note and the level do not line up.
  3. Billing supervisor owns claim submission, denial routing, and the log of every level change and the reason for it.
  4. Privacy officer owns the disclosure log, the vendor list, and the response packet whenever charts leave the building.

If one person holds three of those roles, that is a staffing reality, not a compliance excuse. Document it and note the compensating review step — an outside coding review each quarter, for example.

The Vendor Map Behind a Single 99214 Claim

Trace one level-4 established patient visit from door to payment and count the outside parties that touch protected health information along the way. In most practices the honest count is five to nine:

  • The EHR or practice management host
  • An ambient documentation or transcription vendor that drafts the note
  • A coding review service or contract coder
  • The revenue cycle management company that scrubs and submits
  • The clearinghouse in between you and the payer
  • A denial-management or appeals vendor
  • A patient statement and payment processor
  • Offsite backup and IT support with administrative access
  • Any AI-assisted coding suggestion tool sitting on top of the chart

Every one of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. Each needs a Business Associate Agreement in place before it touches data, not after the audit letter arrives. HHS publishes sample business associate agreement provisions that show the required elements — permitted uses, safeguards, subcontractor flow-down, breach notification timing, and return or destruction of PHI at termination.

Ambient scribe and AI coding vendors deserve a specific read. Ask, in writing: does the vendor retain encounter audio or transcripts, for how long, and does it use your patients' data to train models? Get the answer in the agreement, not in a sales email. If your vendor list has gaps — and after a year of new documentation tools, most do — you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase, and close the gap this week rather than next quarter.

The vendor list is an operations document, not a binder

Keep one spreadsheet with the vendor name, what PHI it touches, BAA execution date, renewal date, subcontractors named, and the internal owner. Review it when you onboard any tool that touches the chart or the claim. A new coding assistant that a clinician enabled on a free trial is a new business associate, whether or not anyone told you.

Records Requests: The 30-Day Clock and the Billing File

Patients have a right of access to the protected health information in your designated record set, and that set includes billing and payment records — not just the clinical note. When a patient asks why a visit was billed at a level 4, they are frequently entitled to the underlying records that show it.

You have 30 days from receipt to act on the request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Review the details in the HHS individual right of access guidance, and put the clock somewhere your staff can see it. A sticky note on a monitor is not a tracking system.

Front-desk workflow that keeps you inside the window:

  1. Date-stamp every request the moment it arrives, by any channel, including verbal.
  2. Log it in one place with the requester, the scope, the format requested, and the owner.
  3. Route clinical and billing components to the right people the same day.
  4. Send the extension letter at day 20 if the packet is not assembled, rather than at day 29.
  5. Record the date and method of delivery, and the fee charged, if any.

Answering a Payer Audit on Medical Billing Code 99214

Disclosures to a payer for payment purposes are permitted without patient authorization. That does not make the request a blank check. The minimum necessary standard still applies to what you send.

Practical translation. If the letter names 22 dates of service, you send those 22 encounters and the records that support them — not the full chart, not unrelated behavioral health notes, not the whole family's history because they share an account. Build a redaction and scoping step into the response, owned by the privacy officer, before anything leaves.

Then document the disclosure: date, recipient, scope, purpose, and who approved it. When a patient later asks for an accounting, or when your own counsel asks what you handed over, that log is the only reliable answer.

Transmission matters as much as scope. A 300-page audit packet sent as an unencrypted attachment to a general payer inbox is the kind of avoidable event that shows up on the OCR breach reporting portal. Use the payer's secure portal, or encrypted delivery with tracked receipt.

When the Audit Comes Back Against You

Suppose the reviewer downcodes nine of the 22 encounters. Two operational obligations follow, and they run on different tracks.

First, the money. Identified overpayments carry a 60-day report-and-return obligation, and the clock starts when the overpayment is identified, not when you finish arguing about it. Decide in advance who signs off on refunds and who documents the calculation.

Second, the pattern. One reviewer's opinion on nine charts is not proof your process is broken, but it is a trigger for internal review. Pull your own sample — distribution of levels by clinician, by payer, by visit type — and look for the outlier. Then handle it with education and documentation, and record what you did. A practice that can show the review, the training date, and the follow-up sample is in a materially different position than one that can only show a refund check.

Keep coding education separate from clinical judgment in how you write it up. You are training clinicians on documenting what they did, not telling them what level a given patient warrants.

A 30-Day Checklist for Your Practice

  1. Days 1–3: Rebuild the vendor list. Every tool that touches a chart or a claim, with BAA status and internal owner.
  2. Days 4–7: Execute or update BAAs for every gap, including scribe, AI coding, and statement vendors.
  3. Days 8–12: Audit your note template against both level-selection paths. Confirm the total-time field is discrete and not prepopulated.
  4. Days 13–17: Write the role assignments for level selection, pre-bill review, and level-change logging. Names, not titles.
  5. Days 18–22: Stand up one request log covering patient access requests and payer audit responses, with date-stamping at intake.
  6. Days 23–27: Run a small internal sample of level-4 established patient claims. Document findings and any education delivered.
  7. Days 28–30: Train the front desk on the 30-day access clock and the extension letter, and confirm the secure channel used for audit packets.

None of this requires new software. It requires a named owner, a date, and a written record that the step happened.

Where to Start This Week

Pick the vendor list. It is the item most practices can complete in an afternoon and the one that causes the most damage when it is stale — because an unpapered vendor with chart access is a finding regardless of how well your coding holds up.

Once you know who is on the list, produce the Business Associate Agreements you are missing and get them signed. If your broader documentation set needs the same treatment, automated risk analysis and policy generation covers the rest of the file. Either way, the goal is the same: when the next audit letter names 22 encounters coded with medical billing code 99214, you spend your 30 days assembling records rather than reconstructing who agreed to what.