At 8:40 on a Tuesday, your front desk registers a walk-in as a new patient. Three weeks later the claim comes back downcoded, because that same patient saw your group's nurse practitioner at the satellite office fourteen months ago — under a different location, same tax ID, same specialty. The new patient CPT code your team selected was never supportable, and now you are looking at a refund, a corrected claim, and a patient who wants to know why the bill changed.

This guide is for the administrator, biller, or privacy officer who owns that workflow. It covers how practices determine new versus established status, where multi-site and multi-TIN groups get it wrong, and — the part most billing articles skip — what the lookup itself does to your PHI footprint, your vendor list, and your records-request obligations.

What Makes a Patient "New" Under the Three-Year Rule

Under CPT's definition, a patient is new if they have not received any professional services from the physician or qualified health care professional — or from another physician or QHP of the exact same specialty and subspecialty in the same group practice — within the past three years. If they have, they are established.

Three elements have to line up before your team can register someone as new:

  • Time. More than three years since the last face-to-face professional service.
  • Specialty and subspecialty. Exact match, not "close enough." A cardiologist and an electrophysiologist in the same group are not automatically the same for this test.
  • Group practice. Generally tracked by billing entity, not by street address. Two offices under one tax ID are one group.

The office and outpatient E/M families split accordingly: 99202–99205 for new patients, 99211–99215 for established. Preventive medicine services split the same way, with separate new and established ranges. Some code families — emergency department services, for example — make no new/established distinction at all, which is why a blanket registration rule fails.

CMS has long held that interpreting a diagnostic test without a face-to-face encounter does not, by itself, make the patient established. If your radiologist read an outside film in 2024 and never saw the patient, that read generally does not consume the three-year window. Confirm the current language in the CMS Evaluation and Management Services Guide before you write it into policy.

The same-specialty test is where multi-site groups break

A single-specialty practice with one location rarely gets this wrong. A twelve-provider group with primary care, behavioral health, and a part-time podiatrist gets it wrong constantly.

Build a specialty map. One page, one row per rendering provider: legal name, NPI, enrolled specialty and subspecialty taxonomy, tax ID, locations worked. Post it where registration staff can see it. Update it the day a provider is credentialed, not at the next quarterly meeting.

Acquisitions, locums, and the mid-year tax ID change

When you acquire a practice, its patients do not reset to new. If the acquired providers now bill under your tax ID and share a specialty with your existing providers, prior encounters in the acquired chart count. Your migration project plan needs a line item for encounter history, not just demographics and problem lists.

Locum tenens and covering providers follow the billing arrangement. When services are billed under the regular provider's identifiers, the regular provider's history governs the new/established determination. Document which arrangement applies for each coverage period so a payer audit two years out does not depend on someone's memory.

Where the New Patient CPT Code Decision Actually Gets Made

On paper, the provider selects the code. In practice, the registration screen makes the decision at 8:40 a.m. and the provider inherits it. That is a workflow problem you own.

Assign the roles explicitly:

  1. Scheduler: runs the duplicate-record search using name, date of birth, and at least one secondary identifier before creating a chart.
  2. Front desk: confirms encounter history within the group across all locations and flags anything inside three years.
  3. Rendering provider: selects the level of service based on medical decision making or total time on the date of the encounter, per current CPT guidelines.
  4. Coder or biller: reconciles the registration flag against the encounter history before the claim drops, and holds anything that conflicts.

Note the division in step three. Since the 2021 office/outpatient E/M revisions, history and exam are performed as medically appropriate but do not drive level selection. That determination is clinical and belongs to the provider. Your job is the surrounding documentation workflow: making sure time is recorded when time is the basis, making sure the encounter note supports whatever was billed, and making sure nobody's smart phrase auto-populates a level.

The Lookup Itself Is a PHI Event

Checking whether a person has been seen in your group requires querying your records using identifiers they just handed you at a counter. That is a use of protected health information for payment and treatment purposes, which HIPAA permits — but permission is not the same as absence of risk.

Three exposures show up in real practices:

Search results leak affiliations. A front-desk search in a multi-specialty group can surface that the patient was seen by your affiliated behavioral health provider or your infusion clinic. Role-based access should limit what registration staff see to what registration staff need: encounter dates, rendering provider, specialty. Not diagnoses, not notes, not medication lists.

Substance use disorder records carry a separate rulebook. If any part of your organization operates a federally assisted SUD program subject to 42 CFR Part 2, those records do not flow freely into your general registration view. Confirm with counsel how your system segments them before you build a cross-specialty encounter search.

Verbal confirmation happens in the lobby. "Have you seen Dr. Reyes in psychiatry in the last three years?" asked at a counter with four people behind the patient is a disclosure risk you can design away. Move the question to the intake form or the check-in tablet.

If you cannot describe where those lookups happen, who can run them, and what they return, that gap belongs in your risk analysis. The Security Rule requires an accurate and thorough assessment of risks to electronic PHI, and registration workflows are ePHI workflows. Practices that need to produce a defensible assessment without a six-week consulting engagement can generate a documented HIPAA risk analysis and the supporting policy set and then map the findings to the intake and billing processes described here.

When the Code Was Wrong: Refunds, Records, and Amendment Requests

Say the reconciliation step catches it in week three. The patient was established; a new patient CPT code was billed and paid. Now three separate clocks run.

The overpayment clock

For Medicare and Medicaid, an identified overpayment must be reported and returned within 60 days of identification. "Identification" starts when you have — or should have, through reasonable diligence — determined the overpayment exists and quantified it. Document the identification date. Document the return. Keep both with the claim.

The records clock

Billing records sit inside the designated record set. When the patient asks for their chart or their billing history, your practice generally has 30 days to act, with one 30-day extension available if you notify the patient in writing of the delay and the reason. HHS's right of access guidance is worth re-reading before your next records-request cycle, because fee limits and format obligations are where practices get caught.

The amendment clock

If the patient submits a written request to amend information in the designated record set — including a disputed billing entry — you have 60 days to act, with one 30-day extension on written notice. A corrected claim is not the same thing as an answered amendment request. Log both. Denials require a written explanation and a path for the patient to file a statement of disagreement.

Assign an owner to each clock. In most practices, the billing manager owns the overpayment timeline and the privacy officer owns the access and amendment timelines. Write down which is which.

The Vendor List Behind One Line on a Claim

Follow that single new-patient encounter outward and count the third parties that touch it.

  • Your EHR host and its infrastructure subcontractors
  • The clearinghouse running your 270/271 eligibility checks — often the first outside party to receive the patient's identifiers
  • An outsourced billing company or coding contractor
  • Any ambient documentation or transcription tool used in the room
  • Your patient-communication vendor sending the appointment reminder and the balance notice
  • An external coding audit firm reviewing E/M level distribution

Every one of those is a business associate, and every one needs a signed agreement covering the specific services performed. HHS's business associate guidance sets out what the contract must address. The common failure is not a missing agreement — it is a five-year-old agreement that never got updated when the vendor added an AI feature, a new subcontractor, or offshore staffing.

Two questions for every vendor on that list this quarter. First: does the executed BAA describe what the vendor does today? Second: does the vendor receive more data than the service requires? A coding auditor reviewing E/M distribution rarely needs full clinical notes with identifiers attached. Minimum necessary applies to disclosures to business associates.

If you find an agreement that is missing, expired, or scoped to services the vendor no longer performs, you can produce a signature-ready Business Associate Agreement and get it out for signature the same week rather than waiting on the vendor's legal queue.

A 30-Day Cleanup Plan

Week 1. Build the provider specialty map. Pull a report of new patient CPT code volume by rendering provider for the last twelve months. Outliers are not proof of error, but they tell you where to look.

Week 2. Sample twenty registrations flagged as new. Verify each against encounter history across every location and tax ID in the group. Record the error rate. Fix what needs fixing under your overpayment procedure.

Week 3. Review who can run encounter-history searches and what those searches display. Tighten role-based access. Move any lobby-audible questions to written or tablet intake.

Week 4. Reconcile the vendor list against executed BAAs. Update your risk analysis to reflect the registration and eligibility workflows. Retrain the front desk on the three-year rule using your own miscoded examples, not generic slides.

None of this requires a new system. It requires someone to own the reconciliation step and someone to own the clocks.

Start With What You Can Document

The new/established determination looks like a billing question and behaves like a privacy question. It depends on record lookups, cross-entity data sharing, and a vendor chain most practices have never fully mapped.

Before your next payer audit or records request, get the underlying documentation in order — build the risk analysis and policy set that ties your intake workflow, your access controls, and your vendor agreements together. Then run the 30-day plan against it.