Shoulder Impingement Syndrome Billing: Who Sees the PHI
A denial lands on a Tuesday morning. The payer wants "records supporting medical necessity" for a shoulder impingement syndrome claim from March. Your biller opens the chart, exports everything the system will hand her, and faxes sixty-eight pages: imaging reports, therapy notes, a two-year-old dermatology consult, the full active problem list, and a medication history.
The claim gets paid. You also made a disclosure you cannot claw back, and you have no record of what went out. This article is for the administrator, biller, or privacy officer who owns that workflow. It maps which data elements leave your building on an orthopedic claim, which outside organizations touch them, and what your BAA, minimum-necessary, logging, and right-of-access obligations look like at each hop. No clinical guidance here — code selection and documentation adequacy belong to your coders and clinicians.
What Actually Leaves Your Building on a Shoulder Impingement Syndrome Claim
Musculoskeletal shoulder complaints are among the highest-volume presentations in primary care and orthopedics, and they routinely involve a referral chain: an initial visit, imaging at an outside facility, a specialist consult, physical therapy, sometimes an outpatient procedure. Each of those steps generates a separate claim, and each claim is a disclosure of protected health information to a payer and everyone in between.
A single professional claim carries more identifiers than most staff realize. On the standard electronic transaction your clearinghouse submits, you are sending:
- Patient name, date of birth, sex, full address, and member ID
- Subscriber information when the patient is a dependent — which is a second person's PHI riding on the same file
- Diagnosis codes, including the ICD-10-CM M75.4- family used for impingement of the shoulder, with laterality
- Procedure codes, modifiers, units, and place-of-service codes
- Date of service, rendering provider NPI, referring provider NPI, and facility identifiers
- Prior authorization numbers and, on appeals, whatever attachments you sent
The identifiers hiding in a "clean" claim
Your staff think of a clean claim as a billing artifact. Treat it as a records disclosure instead. A claim with a laterality-specific impingement code, a date of service, and a home address tells a reader that this named person had a specific shoulder problem on a specific day and saw a specific specialist. That is exactly the kind of inference HIPAA exists to control.
The practical consequence: claim files sitting in a shared network folder, an unencrypted email to a billing contractor, or an exported CSV on a biller's laptop are all PHI repositories. They belong in your risk analysis and your asset inventory alongside the EHR. CMS maintains an overview of the HIPAA Administrative Simplification transaction standards that govern the format of those files.
Every Hop Between Your Front Desk and the Payer
Sit down and list the organizations that touch one orthopedic episode from your practice. For most groups the list runs longer than the vendor list the privacy officer maintains. A typical chain:
- Front desk / registration — captures insurance, runs eligibility through a verification tool
- Scribe or transcription service — hears or reads the entire encounter
- Outside imaging center — receives the order and referring provider information, returns a report
- Coding contractor — reads the full note to assign codes
- Billing company or RCM vendor — holds a standing login to your EHR
- Clearinghouse — receives and reformats every claim file
- Payer and its subcontracted utilization review firm
- Physical therapy practice, DME supplier, or ASC — separate covered entities, separate claims, shared patient
- Denial-management or analytics platform — often ingests the entire remittance and claim history
- Lockbox, statement printer, and patient-payment processor
Items 2, 4, 5, 6, 9, and 10 are business associates. So is any analytics or AI-assisted coding tool that reads your notes. The imaging center, the PT practice, and the payer are not — those are provider-to-provider or provider-to-payer disclosures for treatment and payment, permitted without a BAA. Staff mix these up constantly, and the error runs both directions: they demand a BAA from a referring surgeon who doesn't need one, and they let a new denial-analytics vendor start ingesting data on a handshake.
If your vendor list has grown faster than your paperwork — and after two years of new billing and documentation tooling, it almost certainly has — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which matters when you need three agreements this month and none next month. Get the agreement executed before the vendor's first data pull, not during your next audit.
Is an ICD-10 Diagnosis Code PHI?
Yes, when it travels with anything that identifies the patient. A diagnosis code by itself is not protected — the code set is public. The moment that code is attached to a name, member ID, date of birth, address, account number, date of service, or any of the other identifiers listed in the Privacy Rule's de-identification standard, the whole record is PHI and every disclosure rule applies.
This is why a billing spreadsheet with columns for patient name and diagnosis code is a breach risk identical to a clinical note, and why "it was just billing data" has never been a defense. It is also why an internal report showing volume of shoulder impingement syndrome encounters by month, with no patient identifiers and no small-cell counts that could re-identify someone, is generally safe to email around the practice.
Minimum Necessary Applies to Payment, Not Just Marketing
Back to the sixty-eight-page fax. Disclosures for payment purposes are permitted, but they are still subject to the minimum necessary standard. HHS's guidance on the minimum necessary requirement expects covered entities to have policies and procedures limiting routine disclosures to what is reasonably needed, and to review non-routine requests individually.
"Send everything so it pays" is not a policy. It is the absence of one.
A five-step protocol for a payer records request
- Log it on arrival. Date received, payer, claim number, date of service, exactly what was asked for, and the response deadline. One spreadsheet or ticket queue, owned by one named person.
- Read the request literally. If the payer asked for the office note and the operative report for a specific date of service, that is the scope. It is not an invitation to send the longitudinal chart.
- Assemble to scope, then have a second person check the packet against the request before it goes out. This single step catches most over-disclosures.
- Send through a channel you can prove. Payer portal upload with a confirmation receipt beats fax, which beats email. Retain the confirmation.
- Record what actually went out — page count, document titles, method, sender. When someone asks two years later, you need an answer that is not "probably the whole chart."
Build this into your denial workflow, not next to it. If the protocol lives in a binder and the biller lives in a work queue, the binder loses.
Workers' Compensation and Attorney Requests Break the Normal Pattern
Shoulder complaints generate an unusual volume of non-standard requests: workers' compensation carriers, employer-designated case managers, disability insurers, and plaintiff or defense attorneys. Your staff cannot treat these like ordinary payer requests, because they are not payment disclosures under HIPAA.
Workers' compensation gets its own permission. The Privacy Rule allows disclosure as authorized by and to the extent necessary to comply with state workers' comp laws — HHS keeps a plain-language page on workers' compensation disclosures. What is permitted varies by state, so your privacy officer should have a one-page cheat sheet for your state's rule, not a general HIPAA summary.
Attorney requests, disability carriers, and employers acting outside a comp claim generally require a valid patient authorization. Train the front desk to route every one of these to the privacy officer instead of answering them. And remember that these disclosures — unlike treatment, payment, and operations — are the kind that show up in an accounting of disclosures, which a patient can request going back six years. If you are not logging them, you cannot produce the accounting.
When the Patient Asks for the Billing Record
Patients who dispute a bill for a shoulder impingement syndrome episode frequently ask for the underlying records, and they usually ask the front desk. The designated record set includes billing and payment records, not only clinical documentation. That means the itemized statement, the claim as submitted, and the remittance advice are all in scope.
The clock is 30 days from the request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees must be reasonable and cost-based, limited to labor for copying, supplies, and postage — you cannot bill for search and retrieval time. HHS's right of access guidance is the operative reference, and OCR has enforced this provision more consistently than almost any other.
Two failure modes to design against. First, requests that arrive by phone or at the check-out window and never get logged. Second, records held by your billing company — if the RCM vendor has the claim history and you don't, your 30 days are burning while you wait on their ticket queue. Put a turnaround commitment for access requests in the BAA or the underlying services contract.
Portal Logins Nobody Audits
Prior authorization for imaging and orthopedic procedures runs through payer portals, and those portals hold PHI. Every one of them is an access-control obligation.
Pull your list of payer and vendor portals this month and answer three questions for each: who has credentials, are any shared, and when was the last time you removed someone. Shared logins are the norm in small billing offices and they destroy your ability to attribute an access. When the referral coordinator resigns, portal access almost never makes it onto the offboarding checklist — the EHR does, the badge does, the payer portals don't.
Add a column to your termination checklist listing every external portal by name. Assign the removal to one person with a same-day deadline. The public HHS breach portal is a useful reminder of how ordinary the underlying causes usually are.
A Quarterly Review You Can Assign by Name
Ninety minutes, once a quarter, four owners:
- Privacy officer: reconcile the vendor list against executed BAAs. Any vendor added in the last 90 days without a signed agreement gets escalated the same week.
- Billing manager: sample five payer records requests from the quarter. Was the response logged, scoped, and reviewed by a second person?
- Practice administrator: pull the portal inventory and every termination from the quarter. Confirm removals.
- Front-desk lead: confirm that attorney, employer, and disability requests were routed to the privacy officer rather than answered at the desk.
Write down what you found, including the items you did not fix. Documented awareness of a gap with a remediation date is defensible. A clean sheet that nobody actually reviewed is not.
Start With the Paperwork You Can Finish This Week
The disclosure trail behind an orthopedic episode is long, but the obligations are finite: know your vendors, sign the agreements, scope your responses, log what leaves, and answer patients on time. If your gap is unsigned agreements, build and export the BAAs you're missing and close that item permanently. If the gap is broader — no current risk analysis, stale policies, no documented procedures behind any of the workflows above — a complete compliance document set and risk analysis gives you something to hand an auditor that reflects how your practice actually runs.