PHQ-9 CPT Code: Billing, Records, and Vendor Duties
Your front desk hands a tablet to roughly 40 patients a week and asks them to complete a nine-item depression questionnaire before rooming. Every one of those completed forms becomes a billable event, a chart entry, an audit exhibit, and a piece of protected health information sitting inside a vendor's database. Most practices get the first part right and the last three wrong.
This guide covers how practices determine and document the PHQ 9 CPT code they report, what a payer or contractor actually asks for when the claim is reviewed, and the records-handling and vendor obligations that attach the moment you digitize the instrument. It is written for administrators, billing leads, and privacy officers — not for clinicians and not for patients.
Which PHQ 9 CPT Code Applies — and Who Decides
There is no code named "PHQ-9." Practices select from a small set of codes based on how the instrument was used, who ordered it, the payer, and the documentation that exists. The codes most commonly evaluated:
- CPT 96127 — brief emotional/behavioral assessment with scoring and documentation, per standardized instrument.
- HCPCS G0444 — annual depression screening, a Medicare-specific code. CMS has revised its descriptor and its interaction with the annual wellness visit over the years; confirm the current descriptor and payment status before you build it into a fee schedule.
- CPT 96160 / 96161 — administration of a patient-focused or caregiver-focused health risk assessment instrument, which some payers treat as the correct home for certain screening tools.
Code selection is a clinical-documentation decision made by the rendering provider and validated by your coding staff against payer policy. Your job as an administrator is to make sure the decision is documented, consistent, and reproducible — not to pick the code by default in the EHR template and hope it holds.
The featured-snippet answer: how practices report a PHQ-9
A PHQ-9 is typically reported using CPT 96127 (brief emotional/behavioral assessment, per standardized instrument) for commercial payers, or HCPCS G0444 for Medicare annual depression screening, depending on payer policy and the context of the encounter. The instrument itself has no dedicated code. Practices confirm unit limits, frequency limits, and modifier requirements — commonly modifier 25 on a same-day evaluation and management service — in the specific payer's policy before billing, and retain the scored instrument, the date, and the provider's review in the medical record.
Where the units and modifiers go wrong
96127 is reported per standardized instrument, which means a patient who completes a depression screen and an anxiety screen at the same visit generates two units of the same code. Payers set their own annual and per-visit unit caps, and some require a distinct-service modifier when multiple units appear on one line. Others deny 96127 outright when it appears without an E/M or preventive service.
Build a one-page payer grid: payer, accepted code, unit limit, frequency limit, modifier requirement, whether preventive cost-sharing applies. Assign one billing staffer to review it quarterly against payer bulletins. Pull the national relative value and status indicator data from the CMS Physician Fee Schedule Look-Up Tool so your fee schedule is not running on last year's numbers.
What an Auditor Asks For, and What Your Chart Needs to Produce
When a payer reviews a screening claim, the request is narrow and predictable. Your chart needs to produce five things without anyone hunting through scanned attachments:
- The name of the standardized instrument used.
- The date it was administered and the individual responses or the scored total, as your documentation policy requires.
- Evidence a qualified provider reviewed and interpreted the result.
- What the result changed — follow-up, referral, repeat interval, or documented no action indicated.
- Linkage to the encounter and the diagnosis code reported.
The failure mode is almost always number three. A tablet captures the score, the score lands in a flowsheet, and nothing in the note demonstrates provider review. That claim gets recouped, and if the pattern is broad enough, it gets extrapolated.
Assign the roles now, not during the audit
Front desk or medical assistant: administers, confirms completion, flags incomplete instruments. Provider: reviews, interprets, documents the action taken. Coder: selects and validates the PHQ 9 CPT code against the payer grid. Privacy officer: owns where the instrument lives, who can see it, and how it leaves the building. Write those four lines into your screening policy and date them.
PHQ-9 Results Are Not Psychotherapy Notes
This trips up practices constantly. HIPAA's psychotherapy notes exception is narrow: it covers a mental health professional's notes documenting or analyzing a private counseling session, maintained separately from the rest of the record. It explicitly excludes test results, diagnosis, symptoms, functional status, treatment plan, and progress to date.
A scored screening instrument is a test result. It sits in the designated record set. That means it is subject to the individual right of access, and your 30-day clock runs on it like anything else. HHS's right of access guidance is the operative reference — and note that you cannot withhold a screening score simply because staff consider it sensitive.
Two complications your policy should address explicitly. First, state mental health confidentiality law is frequently stricter than HIPAA and may impose additional consent requirements before disclosure. Second, adolescent screening raises minor-confidentiality questions — who may access the record, and under what circumstances a parent's proxy portal account should be restricted. HHS maintains a plain-language overview of HIPAA and mental health information that is worth circulating to your front desk before the next records request lands.
Minimum necessary when the payer asks for the form
A records request from a payer supporting a screening claim does not automatically entitle the payer to the entire behavioral health section of the chart. Decide in advance what your standard audit packet contains — the scored instrument, the corresponding note, the claim — and train the release-of-information staffer to send that and nothing else. Blanket "send the chart" responses are how a routine claim review turns into an impermissible disclosure.
Every Digital Screening Tool on Your Intake Tablet Is a Vendor Problem
The instrument itself is freely reproducible — the PHQ family of screeners was placed in the public domain and does not require a license. What is not free of obligation is the software you use to deliver it.
Inventory this honestly. The digital intake platform that pushes forms to a patient's phone before the visit. The kiosk vendor. The SMS reminder service that includes the questionnaire link. The translation service that renders the instrument in Spanish or Vietnamese. The population-health analytics tool that ingests scores to build your quality measure numerators. The billing company that touches the resulting claim. Each of these creates, receives, maintains, or transmits PHI on your behalf. Each needs a business associate agreement executed before the first patient response flows through it.
Practices routinely discover during a risk analysis that the screening module was turned on by a clinical lead months ago and no one in administration ever signed paperwork with the vendor. If that describes even one line on your inventory, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than waiting on a vendor's redlined template that never arrives.
Tracking technology on the page where the form lives
If your screening questionnaire is hosted on a web page, check what analytics and advertising scripts run on that page. OCR's bulletin on online tracking technologies addresses exactly this scenario, and while a federal court vacated a portion of that guidance in 2024 concerning unauthenticated pages, nothing in that ruling touched authenticated environments. A patient logged into your portal completing a depression screen is generating PHI, full stop. A third-party pixel firing on that page is a disclosure you almost certainly did not authorize.
Have your web vendor produce a script inventory for every patient-facing page. Anything you cannot justify, remove. Anything you keep, cover with a BAA or eliminate the identifiers.
A Ninety-Day Cleanup Sequence
Days 1–15. Build the payer grid. Pull twelve months of claims for the screening codes you report and check denial rate by payer. Identify which denials are unit limits, which are missing modifiers, and which are documentation.
Days 16–30. Audit ten charts internally against the five-item documentation list above. If provider review is missing in more than one, the template is the problem, not the provider.
Days 31–60. Complete the vendor inventory for anything touching screening data. Match each entry to an executed, current BAA. Note the ones with no agreement, an expired agreement, or an agreement signed by someone who left in 2023.
Days 61–90. Update your release-of-information procedure for behavioral health content, confirm your state's mental health confidentiality requirements with counsel, and fold the screening workflow into your security risk analysis. If your risk analysis is a spreadsheet last touched two years ago, tools that automate the risk analysis and the supporting policy set will get you to a defensible document faster than another round of internal meetings.
The Short Version
Selecting the right PHQ 9 CPT code is a payer-policy exercise your coding staff owns. Proving the service happened is a documentation exercise your providers own. Keeping the resulting data out of places it does not belong is a vendor-management exercise you own — and it is the one that generates breach notifications rather than recoupments.
Start with the vendor inventory. If any tool in your screening workflow is moving patient data without a signed agreement in your file, put a compliant BAA in place this week and work backward from there.