Take one completed neuropsychological testing episode from last month — a six-hour battery over two visits, a technician for administration, a psychologist for interpretation and feedback, one prior authorization, one claim. Now count the organizations that touched some piece of that record. Most practices stop counting at four and are wrong by half. This post walks the administrative trail behind a testing claim: what the time units actually document, which parties see clinical narrative for payment purposes, and where your business associate agreements are probably missing.

Nothing here is clinical guidance. It is a records-flow and vendor-inventory exercise for the person who signs the contracts and answers the audit letters.

One Testing Claim, Nine Sets of Eyes

Run the trace yourself. For a typical outpatient testing episode billed to a commercial payer, PHI moves through some version of this chain:

  1. The psychologist or physician who performed the evaluation.
  2. The psychometrist or technician who administered and scored instruments.
  3. The referring clinician who receives the report — a treatment disclosure.
  4. Your scheduling and EHR platform, plus whoever hosts it.
  5. A computerized scoring or test-delivery platform, if any instrument was administered or scored electronically.
  6. A transcription service or scribe, if the report wasn't typed in-house.
  7. Your billing company or in-house biller.
  8. A clearinghouse.
  9. The payer's utilization review unit — and, on appeal, an external review contractor the payer chose, not you.

Then add the requests that arrive later: a school district, a disability carrier, an attorney, a guardianship proceeding, a Social Security field office. Those are not treatment or payment disclosures, and they follow different rules.

Nine to fourteen organizations is normal. The compliance question is simple and uncomfortable: for each one, do you have either a signed business associate agreement, a valid authorization, or a documented permitted-disclosure basis? If you can't answer for all of them in under ten minutes, you don't have a vendor inventory — you have a hunch.

What the Time Units Actually Document — and Why It's All PHI

Testing services are time-based, and that single fact drives most of the documentation exposure. The code families your coder works with separate professional evaluation time from administration time, and administration by a physician or other qualified health professional from administration by a technician. Automated single-instrument administration with an automated result sits in its own place. Payer policies on units, spanning dates of service, and which base code anchors the episode vary — that's your coder's and your payer contract's problem, not this article's.

The privacy consequence is what matters here. To support time units, your record has to show who did what, for how long, on which date. In practice that means:

  • Start and stop times, or documented minutes, for each component.
  • The identity and credential of the person performing each component.
  • The instruments used and the fact that they were scored.
  • Non-face-to-face interpretation and integration time, distinguished from face-to-face time.
  • The report itself, plus any interactive feedback session.

Every one of those elements is PHI when it carries the patient identifier. And unlike a fifteen-minute office visit, a testing episode produces a documentation package thick enough that payers routinely ask for the whole thing on review.

Technician time creates a workforce documentation problem

When a technician administers instruments, your record must identify that person. That means your workforce roster, credentialing files, and supervision documentation become part of the audit trail supporting the claim. Two administrative habits pay off: assign each technician a stable identifier that appears consistently in the chart, and keep the supervision attestation in a place your biller can reach without emailing the clinical team a screenshot. Screenshots emailed to billing are one of the quietest ways PHI leaves a controlled system.

The scoring platform nobody put on the vendor list

If any instrument is administered on a tablet, scored through a publisher's web portal, or normed against an online database with the patient's identifier attached, that publisher or platform is handling PHI on your behalf. It is a business associate. Test publishers generally have agreement language available, but somebody in your organization has to request it, sign it, and file it — and in a lot of practices the clinician set up the account with a credit card and nobody in compliance ever heard about it.

Ask a narrower question than "is it HIPAA compliant." Ask: does the account store identifiable examinee records on the vendor's servers, and do we have a countersigned agreement on file? If the answer is yes and no, that's a gap you can close this month. HHS publishes sample business associate agreement provisions you can use as a baseline for what the contract has to cover. If you'd rather not redraft from a sample every time a new platform appears, a six-step BAA generator that exports signature-ready PDF and DOCX gets you a usable document the same afternoon, one-time purchase rather than another subscription line item.

Prior Authorization Sends Clinical Narrative to a Payer

Most commercial payers require prior authorization for extended testing batteries. That means someone on your staff writes a justification — referral question, prior workup, functional concerns, planned instruments, anticipated hours — and transmits it to a utilization reviewer who is not your business associate and not your treating colleague.

This is a permitted payment disclosure. It is also subject to minimum necessary, because the treatment exception to minimum necessary does not cover disclosures to payers. HHS's guidance on the minimum necessary requirement expects you to have policies and, for routine disclosures like these, a standard limited set of information rather than an ad hoc judgment call every time.

Practical version: build a prior-auth template for neuropsychological testing that contains the fields the payer's policy actually names. Don't attach the entire chart. Don't attach the last three progress notes because it was faster than summarizing. If the reviewer needs more, they'll ask, and then you have a documented request driving a second, narrower disclosure.

Same discipline applies to post-payment review and appeals. When a payer requests records to support billed units, send the documentation that supports units and interpretation — not every scanned intake form in the file. Log what you sent, to whom, and on what date. That log is your defense if the patient later asks for an accounting of disclosures.

A neuropsychological testing claim discloses, at minimum: patient identifiers, dates of service, diagnosis codes, procedure codes with time units, the rendering and billing provider identities, and place of service. On review or appeal, the payer can also obtain the supporting record — start and stop times, the list of instruments administered, who administered them, raw and derived scores, and the interpretive report. Disclosures to the payer are permitted for payment without patient authorization, but they are limited by minimum necessary. Disclosures to a school, employer, attorney, or disability carrier are not payment disclosures and generally require a signed, HIPAA-compliant authorization specifying the records released.

The Non-Treatment Requests Are Where Practices Get Hurt

Testing reports have legal and educational value, which means they get requested by people who are not your patient and not your payer.

Attorneys and litigation

An attorney's letter is not an authorization. Neither is a subpoena, standing alone, sufficient under the Privacy Rule without the satisfactory assurances or court order the rule requires. Route these to a single person. Front-desk staff should have one instruction: nothing about a testing record goes out on a lawyer's letterhead without the privacy officer signing off.

Schools and disability determinations

A parent asking you to send a report to a school district is asking for a disclosure that needs authorization — and once it arrives at the district, FERPA and state education law govern it, not you. Say that plainly in writing when the authorization is signed. It reduces the number of angry calls three months later.

Forensic and independent evaluations

When the retaining party is an attorney, court, or employer rather than the patient's health plan, the relationship, the record ownership, and the disclosure rules differ from a treatment evaluation. Decide in advance — in your policies, not mid-engagement — which of your service lines are treatment and which are not, and keep the records in separately governed files.

The 30-Day Clock and the Report Everyone Wants a Copy Of

When the patient or their personal representative requests the record, you have 30 days, with one 30-day extension available if you notify them in writing of the reason and the new date. You may charge a reasonable, cost-based fee. Review HHS's right of access guidance if it's been a while — OCR has enforced this provision persistently, and the fact patterns are almost always mundane delay, not malice.

Testing raises one specific question your policy should answer before it's asked: what happens when a patient requests raw scores, protocols, or completed test forms. The Privacy Rule's grounds for denying access are enumerated and narrow, and psychotherapy notes are the recognized exception rather than a general category for anything clinically sensitive. Test-publisher copyright and test-security concerns are real business issues — they are not, on their own, a listed ground for denial. The rule does allow you to provide a summary instead of the full record if the individual agrees in advance to the summary and any associated fee.

Write your position down, with counsel, and train the person who opens the mail. "We'll have to ask the doctor" is how a 30-day clock becomes a complaint.

A One-Week Inventory Project

Give this to whoever owns vendor management:

  1. Pull one testing episode from three months ago and trace every system and organization the record touched. Name them.
  2. Match each name to a document — countersigned BAA, authorization, or a written note explaining the permitted-disclosure basis (treatment, payment, operations).
  3. Flag the electronic scoring and test-delivery accounts. Check who opened them and whether identifiable data lives on the vendor's side.
  4. Confirm the clearinghouse and billing company agreements are current and reflect the entity you actually contract with today, not the one you signed with in 2019.
  5. Standardize the prior-auth packet so minimum necessary is a template decision, not a daily judgment call.
  6. Log payer record productions in one place with date, recipient, and scope.

Two things make this worth the week. First, vendor and email incidents dominate what gets reported to OCR — you can see the pattern yourself on the HHS breach portal. Second, HHS's proposed overhaul of the Security Rule, published for comment in January 2025, leans hard on asset inventories and mapped data flows. Whatever its final shape, a practice that already knows where its testing records go is not scrambling.

Close the Gaps You Just Found

You'll finish the inventory with a short list of vendors handling neuropsychological testing data under no signed agreement. Handle that list this month: generate the agreements you're missing, get them countersigned, and file them where your next auditor can find them. If the same exercise exposed thin policies or a risk analysis you haven't refreshed since the last hardware change, automated risk analysis and policy generation will get that documentation current faster than a committee will. Neither product is a government credential — no such thing exists — but both produce the paperwork you're actually expected to have on hand.