A patient calls your front desk on a Monday and says: "I've been a patient here for six years. Why does my statement say new patient?" Your registrar doesn't know. Your biller says the chart supported it. Your provider doesn't remember. And now you have two obligations running in parallel — a billing inquiry and, the moment the patient asks for the underlying records, a 30-day clock under the HIPAA right of access.

This guide covers how practices determine and document a new patient visit CPT code, who owns each step of that workflow, and where the privacy exposure sits — because the same data you use to justify the code selection travels through your clearinghouse, your billing vendor, your scribe tool, and your audit-response folder. If you sign vendor contracts or answer records requests, this is your operational checklist.

Which CPT Codes Are New Patient Office Visits?

The office or other outpatient evaluation and management code set separates new patients from established patients. New patient visits are reported with 99202–99205; established patient visits use 99211–99215. Code 99201 was deleted from the code set effective January 1, 2021.

Since the 2021 revision, level selection for these codes is based on either the level of medical decision making or the total time the reporting practitioner spends on the encounter on the date of service. The code set defines specific time thresholds for each level, and prolonged service is reported separately. Your practice should confirm both the current-year CPT definitions and each payer's policy before building any coding template — thresholds and payer acceptance have changed more than once.

None of this tells you which code fits a given encounter. That determination belongs to the reporting practitioner and your certified coding staff, working from the documentation in front of them. Your job as an administrator is to make sure the inputs to that determination are accurate and the trail is retrievable.

The Three-Year Lookup That Nobody Owns

CPT treats a patient as new when they have not received any professional service from the physician or other qualified health professional — or from another physician or QHP of the exact same specialty and subspecialty who belongs to the same group practice — within the prior three years.

Two operational traps live in that sentence.

Trap one: "same group practice" is a billing fact, not a building

If your organization bills under one tax ID across four locations, a patient seen at your east-side office two years ago is not new at your west-side office when the same specialty is involved. Conversely, a multispecialty group may legitimately register a longtime patient as new when they present to a different specialty. Your scheduler cannot resolve this from memory. It has to come from a documented lookup rule that reflects your actual billing structure and enrolled specialties.

Trap two: what counts as a prior service

Medicare's guidance on this point turns on face-to-face professional services. Interpreting a diagnostic test or reading an image without a face-to-face encounter generally does not make the patient established. CMS publishes its evaluation and management guidance in the MLN Evaluation and Management Services Guide, and commercial payers frequently publish their own variations. Pull both and reconcile them in writing.

A Workflow With Named Owners

Most new-patient miscoding I have seen traced back to an unowned step, not to a coder's judgment. Assign these explicitly:

  1. Scheduler. Runs a duplicate check on name, date of birth, and phone before creating a record. Flags any partial match for registration to resolve — never creates a second chart to move the call along.
  2. Registrar. Executes the documented three-year lookup across all locations under the billing entity, records the result in a structured field, and notes which specialty the prior encounter fell under.
  3. Reporting practitioner. Documents the encounter, including total time or the decision-making elements, on the date of service.
  4. Coder or coding reviewer. Selects the code from documentation and the registration status, and queries the practitioner when the two conflict.
  5. Billing lead. Monitors the new-versus-established ratio by provider monthly and investigates outliers before a payer does.

Write the lookup rule down. When a payer or a patient challenges a new patient visit CPT code eighteen months from now, "our registrar checks" is not a defense. "Our documented procedure, dated and version-controlled, directed the registrar to check X across Y, and here is the field where she recorded the result" is.

A worked administrative example

A patient last visited your group 22 months ago and saw a nurse practitioner working in the same specialty and the same group. Under CPT's definition, that prior face-to-face professional service falls inside the three-year window and inside the same-specialty, same-group boundary — so your registration workflow should return "established" and your coder should be selecting from 99211–99215 rather than the new patient range. The point of the example is not the answer; it is that the answer came from a recorded lookup, not from a guess at the check-in window.

Duplicate Charts Are a Coding Problem and a Privacy Problem

When a scheduler creates a second record for an existing patient, you get two failures at once. The coding failure is obvious — the three-year lookup returns nothing and the visit gets registered as new. The privacy failure is worse: clinical documentation lands in a chart that may later merge with, or be disclosed alongside, the wrong record.

That is how information about one person ends up in another person's release. It is also how you inherit an amendment request under 45 CFR 164.526, which you must act on within 60 days, with one 30-day extension available. A master patient index cleanup project is a compliance activity, not just a revenue-cycle one. Track your duplicate creation rate by user and coach to it.

Where PHI Travels on a New Patient Claim

Map the actual path. For most practices, a single new patient encounter touches more parties than the administrator assumes:

  • The EHR or practice management host, if cloud-based
  • An outsourced coding or coding-audit firm
  • The billing or full revenue-cycle vendor
  • The clearinghouse that scrubs and transmits the claim
  • Eligibility and insurance-discovery services queried at registration
  • An ambient documentation or transcription tool that captured the visit
  • The patient-statement print-and-mail vendor
  • The collections agency, if the balance ages
  • Whoever hosts your document repository when you assemble an audit response

Every one of those creates, receives, maintains, or transmits protected health information on your behalf. Each requires a business associate agreement before PHI moves, and each subcontractor beneath them requires one too. HHS publishes sample business associate agreement provisions that show the required elements — breach notification timelines, permitted uses, subcontractor flow-down, and return or destruction at termination.

Take twenty minutes and reconcile your vendor list against your signed BAA folder. If the coding consultant you brought on for a documentation audit last quarter isn't in that folder, you have an unpapered disclosure sitting in your file. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription — which is faster than chasing a vendor's outdated template through three rounds of redlines.

The Records Request That Follows the Billing Dispute

When a patient challenges why they were billed as new, they often escalate to a records request. Handle that as a right-of-access matter, not a customer-service matter.

The designated record set includes billing records used to make decisions about the individual. That means the itemized statement, the claim detail, and the encounter documentation are generally in scope. You have 30 days to act, with one 30-day extension if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. OCR's right of access guidance spells out the boundaries, and OCR has brought a long series of enforcement actions specifically on access failures.

Practical instruction for your front desk: a patient asking "send me everything you have on that visit" is a records request the moment it arrives, regardless of whether it came by phone, portal message, or a note handed across the counter. Log it with a date received. The clock does not wait for your form.

Producing Records for a Payer Audit Without Overdisclosing

Payer requests targeting new patient E/M levels are routine. Disclosure for payment purposes is permitted, but the minimum necessary standard still governs what you send.

Build a standing procedure:

  • Read the request and extract exactly which dates of service and which elements are named.
  • Assemble only those encounters. Do not export the full chart because it is one click.
  • Have a second person compare the assembled packet against the request before transmission.
  • Transmit through an encrypted channel and log the disclosure — date, recipient, scope, and requester.
  • Store the packet in a location covered by your access controls and retention schedule, not on a shared drive folder named after the auditor.

That log is what lets you answer, months later, precisely what left your practice. NIST's cybersecurity resource guide for the HIPAA Security Rule is a reasonable reference when you are tightening the transmission and access-control side of this.

Ambient Scribes and the New Patient Encounter

New patient visits are the longest encounters you bill and the ones providers most want help documenting. That makes them the first place ambient AI tools get deployed — and time-based level selection makes the resulting record directly relevant to code justification.

Before that tool records a single visit, get answers in writing: Is a BAA signed? Where is the audio stored and for how long? Is patient data used to train models, and can you opt out contractually? Who at the vendor can access recordings, and is that access logged? Can you retrieve everything associated with one patient if a records request or a subpoena arrives?

If the vendor's answer to any of those is a sales rep's verbal assurance, you don't have an answer. And if a time-based code selection rests on a note generated by a tool whose retention policy you can't describe, your audit response is weaker than your billing report suggests.

A 45-Minute Self-Audit You Can Run This Week

  1. Pull 20 claims from the last quarter carrying a new patient visit CPT code. Confirm a documented three-year lookup exists for each.
  2. Check whether the lookup covered every location under your billing entity.
  3. Count duplicate charts created in the last 90 days, by user.
  4. Compare your live vendor list to signed BAAs and note every gap.
  5. Time your last five right-of-access requests from date received to date fulfilled.
  6. Confirm your payer-audit disclosures from the last year were logged with scope and recipient.

Anything you can't answer from records within 45 minutes is a documentation gap, not a memory gap — and it will read that way to a reviewer.

Close the Vendor Gap First

Coding accuracy on new patient visits is a training and workflow problem you can fix with a written lookup rule and monthly ratio monitoring. The unpapered vendor is the one that turns a billing question into a reportable event. Start there: build the BAAs you're missing for your coding consultant, your statement vendor, and your scribe tool, and if your broader policy set and risk analysis need the same treatment, automate the full compliance document set rather than rebuilding it from a template folder someone left behind.