On the fifth business day of every month, someone in your practice exports a spreadsheet. It has one row per claim line, a provider name, a date of service, a CPT code, a patient account number, and a work RVU value. It gets emailed to a compensation consultant, uploaded to a dashboard, or dropped into a shared drive folder that eleven people can open. That file is a medical RVU productivity report, and in most practices it is also an undocumented disclosure of protected health information.

This guide is for the administrator, billing manager, or privacy officer who owns that file. It covers how RVU-based reporting actually works, then makes the records-handling and vendor obligations explicit — because the reporting workflow almost always outruns the paperwork.

What a Medical RVU Is, in Four Sentences

A medical RVU (relative value unit) is the unit CMS uses to express the relative resources required to furnish a service under the Medicare Physician Fee Schedule. Every payable code carries three RVU components: work (physician time, skill, intensity), practice expense (staff, supplies, space, equipment), and malpractice. Each component is adjusted by a geographic practice cost index for the locality, then the total is multiplied by a dollar conversion factor to produce the allowed amount. Practices reuse the work RVU component separately as a productivity and compensation metric, which is where the privacy exposure begins.

The Formula Your Finance Team Is Using

Payment = [(work RVU x work GPCI) + (practice expense RVU x PE GPCI) + (malpractice RVU x MP GPCI)] x conversion factor.

Two operational notes. First, practice expense RVUs differ by site of service — the facility value and the non-facility value are separate numbers, and using the wrong one is one of the most common modeling errors in a homegrown spreadsheet. Second, the values change. CMS publishes the PFS Relative Value Files and updates them during the year, and beginning with CY2026 the fee schedule uses separate conversion factors for qualifying APM participants and everyone else. If your model still hardcodes a prior-year conversion factor, your variance reports are wrong before anyone touches a privacy question.

Where RVU Data Comes From and Who Touches It

Map the flow before you try to govern it. In a typical multi-provider practice, medical RVU reporting involves five hops:

  1. Practice management system. Charges are posted with codes, modifiers, units, dates of service, rendering provider, and patient identifiers.
  2. Extract. Someone runs a canned report or a custom query. This is where columns get selected — or, more often, where every available column gets selected because it was easier.
  3. Local file. The extract lands as CSV or XLSX on a workstation, a laptop, or a personal cloud drive.
  4. External recipient. A compensation consultant, an RCM vendor, a benchmarking survey, an accountant, or a BI/analytics platform.
  5. Derivative artifacts. Board decks, provider scorecards, comp calculations, recruiting pro formas. Each one gets forwarded again.

Provider names and provider compensation are not PHI on their own. But a row that pairs a patient account number, a date of service, and a procedure code is health information about an identifiable individual. Bundling it under the label "productivity report" does not change what it is.

When Your RVU Vendor Becomes a Business Associate

The test is functional, not titular. If a person or company outside your workforce creates, receives, maintains, or transmits PHI to perform a function on your behalf, they are a business associate and you need an executed agreement before the data moves. HHS explains the scope on its business associates guidance page.

Run your RVU distribution list against that test:

  • Compensation consultant receiving claim-line detail. Business associate. Needs a BAA.
  • Compensation consultant receiving only aggregate wRVU totals per provider per month. Likely no PHI at all — but only if the file genuinely contains no patient-level rows and no free-text notes.
  • Benchmarking survey submission. Usually aggregate-only by design. Read the submission template line by line; some ask for encounter-level files.
  • BI or analytics platform holding a copy of your charge data. Business associate, including the hosting provider underneath it as a subcontractor.
  • Your CPA doing a valuation off patient-level detail. Business associate. Professional licensure is not an exemption.
  • Your own employed analyst. Workforce member — no BAA, but role-based access controls and audit logging still apply.

If you find a recipient on that list without a signed agreement, close the gap the same week. A signature-ready Business Associate Agreement built through a guided six-step wizard gets a defensible document in front of the vendor faster than routing a redline through outside counsel, and it exports to PDF and DOCX for your vendor file.

Applying Minimum Necessary to an RVU Extract

Minimum necessary is a Privacy Rule requirement, not a best practice, and it applies to internal use as well as external disclosure. HHS summarizes the standard in its minimum necessary guidance. For productivity reporting, the practical question is simple: what does the recipient need to compute wRVUs?

A Worked Column Trim

Here is a common export and what a defensible version looks like.

Before: patient last name, patient first name, patient DOB, patient address, MRN, account number, insurance ID, date of service, place of service, CPT code, modifiers, units, rendering provider NPI, charge amount, payment amount, work RVU, diagnosis codes, appointment note.

After, for a comp consultant: rendering provider ID (internal, not NPI), month of service, place of service, CPT code, modifier, units, work RVU. Nothing else.

That trim removes every direct identifier and collapses dates to month. If you need to go further and hand a file to a party you will not contract with, review the HHS de-identification guidance and apply the Safe Harbor method fully — all eighteen identifier categories removed, dates reduced to year, ZIP codes truncated to three digits, no actual knowledge of re-identifiability. Half-measures produce a limited data set at best, and a limited data set still requires a data use agreement.

The Diagnosis Column Nobody Questions

Diagnosis codes ride along in most charge extracts because they are in the source table. They are not needed to sum work RVUs. Drop them by default. When someone insists they need diagnosis mix for a service-line analysis, that is a separate request with a separate justification, and it should go to a recipient under a BAA rather than into a general-circulation spreadsheet.

Documenting Code Selection Without Making Clinical Calls

Because wRVUs attach to codes, and codes drive compensation, your practice needs a written record of how code selection happens. That record is administrative. Your compliance function documents the process; the treating clinician documents the service and selects the code.

Build the file around these elements:

  • Who selects. Name the role. Provider-selected, coder-assigned, or provider-selected with coder review.
  • Reference sources in use. Current code set publications, payer policies, and the CMS fee schedule files, with the version and effective date recorded.
  • Query process. How a coder raises a documentation question, how the clinician responds, and how the resolution is stored. Queries touch PHI — they belong in the record system, not in a text thread.
  • Audit cadence. How many charts per provider per quarter, who reviews, how findings are communicated, what triggers re-education.
  • Change control. When annual code set and fee schedule updates load, who verifies the medical RVU values in your fee schedule table, and who signs off.

Keep audit results and compensation analyses separated in your filing. Chart audit workpapers contain PHI and belong under records retention with access controls. The comp calculation derived from aggregate wRVUs is a personnel record with a different audience.

A Monthly RVU Close Calendar With Named Owners

Assign the steps or they will happen informally, which is how PHI ends up in personal email.

  • Business day 1-3 — Billing lead. Confirm charge entry is complete through month-end and holds are cleared.
  • Business day 4 — Billing lead. Run the approved, saved report definition. No ad hoc queries. The saved definition is the control that enforces your column trim.
  • Business day 4 — Privacy officer or designee. Spot-check the output header row against the approved column list. This takes ninety seconds and catches the most common failure in the entire workflow.
  • Business day 5 — Administrator. Transmit to external recipients through the encrypted portal or secure transfer method named in the vendor's BAA. Log the transmission: date, recipient, file name, record count.
  • Business day 8 — Administrator. Distribute provider scorecards individually. One provider, one scorecard. Do not attach the all-provider file to a group email.
  • Business day 10 — Billing lead. Delete working copies from local drives per your retention schedule.
  • Quarterly — Privacy officer. Reconcile actual recipients against the BAA inventory and access logs.

Five Failure Points That Show Up in Real Reviews

The shadow spreadsheet. A provider or manager maintains a personal copy of the full extract to check their own numbers. It lives on an unmanaged device and never appears in your asset inventory.

The stale conversion factor. Nobody owns the annual fee schedule update, so RVU-to-dollar modeling drifts and someone rebuilds a parallel spreadsheet to "fix" it, doubling the number of PHI copies.

The consultant with no BAA. Engaged by the owner-physician directly, paid from a different budget line, never entered in the vendor register.

The analytics trial. A vendor demo that ingested real charge data instead of test data. The trial ended; the data stayed.

The unlogged export. Your practice management system records who ran the report, but nobody reviews those logs, so a departing employee's month-end pull of every provider's detail goes unnoticed.

Each of these belongs in your Security Rule risk analysis as an identified risk with a documented disposition — not as a footnote you remember during an audit. If your current risk analysis does not name your reporting exports, your analytics vendors, and the devices holding those files, it is not describing your practice. Tools that generate a documented HIPAA risk analysis alongside the matching policy set shorten the gap between what your workflow actually does and what your paperwork says it does.

What to Do This Week

Pull the last three monthly medical RVU exports your practice produced. Open the header row. Count the identifier columns, list every human and system that received the file, and check each recipient against your signed agreements. That single exercise usually surfaces one missing BAA and two columns that never needed to leave the practice management system.

Then fix the saved report definition so the trim is automatic, and put your findings into the risk analysis so next year's reviewer sees a decision instead of a gap. If your documentation set has not kept pace with how your reporting actually works, build the risk analysis and policy package around the workflows you just mapped — starting with the one that runs on the fifth business day of every month.