A letter arrives from a commercial payer. It lists 62 claim lines from the last eighteen months, all of them evaluation and management services billed with modifier 25 alongside a minor procedure. It gives you 30 days to send the complete medical record for each date of service. Your biller forwards it to you with the subject line "?"

This article is for the person who has to answer that letter. It covers what modifier 25 signals on a claim, who in your practice owns it, how to build an audit-response workflow that does not take three weeks of your life, and — the part almost nobody plans for — how to move 62 charts to a payer without creating a privacy incident. Coding decisions belong to your clinicians and certified coders. Everything downstream of that decision belongs to you.

What Modifier 25 Means on a Claim

Modifier 25 is appended to an evaluation and management code to indicate a significant, separately identifiable E/M service performed by the same clinician on the same day as a procedure or other service. Without it, payer edits generally bundle the E/M into the procedure's payment and deny or absorb the office visit line.

Three operational facts your staff should be able to recite:

  • It attaches to the E/M code, never to the procedure code.
  • It applies in the context of procedures with a 0- or 10-day global period, where the National Correct Coding Initiative edits and global surgical package rules would otherwise bundle same-day E/M work.
  • It is not interchangeable with modifier 57 or modifier 59. Each addresses a different bundling scenario, and using the wrong one produces a denial that looks like a coding error to the payer regardless of what the chart says.

Whether a given encounter supports separate reporting is a clinical and coding determination made by the treating clinician and your coding staff against payer policy and the documentation in the note. Your job as an administrator is to make sure that determination is documented, consistent, defensible, and reproducible eighteen months later when someone asks for proof.

Why Modifier 25 Draws Attention

Federal oversight reviews going back two decades have flagged same-day E/M billing as an area where documentation frequently fails to support the claim. That history has not faded. CMS maintains the NCCI edits and the associated policy manual that govern these pairings, and both are updated on a published schedule — you can track them through the CMS National Correct Coding Initiative page.

On the commercial side, several large payers have added payment reductions or pre-payment documentation requirements for E/M services reported with modifier 25. The practical effect is the same either way: a modifier that used to move quietly through adjudication now generates letters, and letters generate PHI disclosures.

Run a simple report before you do anything else. Pull the percentage of your E/M claims carrying modifier 25, broken out by rendering provider, for the trailing twelve months. If one clinician sits far above the others, you want to know that before a payer tells you.

Assigning Ownership Before the Letter Arrives

Most practices discover during an audit that nobody actually owns this. Fix that on paper, with names.

The Clinician

Documents the encounter. The note either supports a separately identifiable service or it does not. Nobody downstream can add that content later, and nobody should try.

The Coder or Billing Lead

Applies the modifier against current payer policy and NCCI guidance, and records the basis for the selection in your billing system's note field — not in a personal spreadsheet, not in an email thread. If your coding is outsourced, this person is a contractor at a business associate, which changes your obligations considerably.

The Practice Administrator

Owns the audit response: intake of the request, the deadline calendar, the transmission method, the disclosure log, and the appeal if one follows.

The Privacy Officer

Signs off on how records leave the building. In small practices this is the same person as the administrator. Write it down anyway, because OCR will ask who held the role, not how many hats they wore.

The 30-Day Response Workflow

Deadlines vary — Medicare Administrative Contractor additional documentation requests and commercial payer audits run on different clocks, and some are 30 days, some 45. Build the workflow around the shortest deadline you actually receive.

  1. Day 0 — Intake. Log the letter the day it arrives: payer, claim count, date range, deadline, contact. One person owns intake. Mail that sits in a billing inbox for nine days has already eaten a third of your window.
  2. Day 1–2 — Scope the request. Match every claim line to a date of service and a rendering provider. Identify which records live in the EHR, which live in a scanned document module, and which live in a paper chart nobody has touched since 2021.
  3. Day 3–10 — Assemble. Pull the notes, procedure documentation, and any orders or results the payer explicitly requested. Assemble to the request, not beyond it.
  4. Day 10–14 — Internal review. Your coding lead reviews each packet against what was billed. If a claim will not hold up, you want to know now, because voluntary refund is a different conversation than a post-audit extrapolation.
  5. Day 15–20 — Transmit. Use the payer's secure portal if one exists. Log the confirmation number.
  6. Day 20+ — Track. Calendar the expected determination date. Calendar the appeal deadline the moment a determination arrives.

Every Modifier 25 Audit Is a Bulk PHI Disclosure

Here is the part that gets skipped. Sixty-two complete medical records leaving your practice is one of the largest single PHI disclosures your organization will make in a given year, and it is being handled by whoever happened to open the mail.

Disclosures to a health plan for payment purposes do not require patient authorization. They do require you to follow your own policies, and the minimum necessary standard applies to payment disclosures. A payer asking for records tied to specific dates of service is not entitled to the patient's entire longitudinal chart because that was the easiest export button to find.

Where This Actually Goes Wrong

  • Over-disclosure by export. Staff run a full-chart PDF export because pulling the specific encounter takes longer. Sixty-two full charts instead of sixty-two encounters.
  • Wrong-patient packets. Assembly errors under deadline pressure. A record sent to a payer for the wrong patient is an impermissible disclosure, and it is the single most common way a routine audit becomes a reportable incident.
  • Staging folders that never get cleaned up. Someone creates \\shared\\audits\\PayerName2026 on a drive the whole office can read, drops 62 charts in it, and leaves it there. That folder outlives the audit by years.
  • Fax and email fallback. The portal times out, so someone faxes to a number typed from memory or attaches a zip file to unencrypted email.
  • Personal devices. A biller works the packet from home on a laptop your practice does not manage.

Treat the audit response like a defined process with a checklist, not an errand. Two-person verification on patient identity for each packet, a designated encrypted staging location with a deletion date, and one approved transmission method with a documented fallback.

Logging: What You Must Do and What You Should Do

The HIPAA accounting-of-disclosures requirement excludes disclosures made for treatment, payment, and health care operations, so an audit response to a payer generally does not go into a patient's accounting. That is the floor, not the target.

Keep an internal disclosure log anyway: date, payer, claim range, patient count, who assembled, who verified, transmission method, confirmation reference. When a patient calls in eight months asking why their insurer has their surgical note, you answer in ninety seconds instead of reconstructing a fifteen-month-old email chain. Retain compliance documentation for six years as HIPAA requires; medical record retention itself runs on your state's schedule, which is often longer.

Your Modifier 25 Workflow Just Expanded Your Vendor List

Walk the path a chart takes during an audit response and name every company that touches it:

  • Your EHR and practice management vendor
  • Your clearinghouse
  • Your outsourced billing or revenue cycle management company
  • Any external coding consultant or coding-audit firm you hired to review modifier 25 usage
  • Your release-of-information or document management vendor
  • Cloud storage or file transfer tools used for staging
  • Secure fax or secure email services
  • Any AI-assisted coding, documentation, or charge-capture tool that suggests modifiers
  • Your shredding and IT support vendors

Each of those creates, receives, maintains, or transmits PHI on your behalf. Each needs a signed business associate agreement on file, and each should appear in your risk analysis. HHS publishes sample BAA provisions that establish the baseline terms.

The one that catches practices off guard is the coding-audit consultant. You hire them precisely because you are worried about modifier 25 utilization, you hand them a stack of charts, and half the time the engagement letter is the only paper in the file. If you need to close that gap quickly, you can generate a signature-ready business associate agreement before the consultant sees a single record.

The Question to Ask AI Coding Vendors

If a tool suggests modifiers based on note content, ask three things in writing: does patient data leave your environment, is any of it retained or used to train models, and who at the vendor can access identifiable records. Get the answers into the contract, not the sales deck. "We are HIPAA compliant" is a claim, not a control — and no government body certifies compliance products.

Building the Review Before the Payer Builds It for You

Quarterly, pull a small sample of modifier 25 claims per provider and have your coding lead review documentation against payer policy. Record the results, the education delivered, and the follow-up sample. That file is your evidence of an active compliance program, and it is worth more in an audit response than any argument you make about a single chart.

This is also where the coding side and the privacy side converge. The same self-audit that shows you a provider's modifier 25 rate should show you who is pulling bulk chart exports and where those exports land. Both are risk analysis inputs, and HIPAA requires that analysis to be current and documented — a point HHS reinforces in its Security Rule guidance. If your last risk analysis predates your current billing vendor, your current AI tools, or your current audit-response process, it is not current. Practices that would rather not rebuild that document from scratch every year can automate the risk analysis and the supporting policy set and keep the vendor inventory attached to it.

Do These Five Things This Quarter

  1. Run the modifier 25 utilization report by provider for the trailing twelve months.
  2. Name the intake owner for payer audit letters and put the name in your policy manual.
  3. Write a one-page audit response procedure: staging location, verification step, approved transmission method, deletion date.
  4. Reconcile your vendor list against your signed BAAs, including coding consultants and AI tools.
  5. Confirm your risk analysis reflects every system that touches a chart during an audit response.

The audit letter will come eventually. The difference between a two-day response and a three-week scramble is entirely in what you built before it arrived — and so is the difference between a clean payment disclosure and a breach notification. Get your risk analysis and policy set current while the mail is still routine.