Time Based Billing: A Practice Admin's Operations Guide
A payer sends your practice a records request for 18 encounters, all from the same three providers, all coded at higher levels than the group's average. The letter asks for "documentation supporting total time, including start and stop times where applicable." You have 30 days. Two of those providers use a documentation assistant, one uses an ambient recording tool, and none of them consistently wrote down a number.
That is the operational reality of time based billing: the minutes drive the code, but the record drives the audit. This guide covers how administrators and billing staff capture, verify, and store time documentation — and the privacy, records-handling, and vendor obligations that come attached, because every timestamp you generate is protected health information sitting in a system somebody else probably maintains.
Why Time Based Billing Creates a Documentation Problem, Not a Coding Problem
Since the 2021 office and outpatient E/M revisions and the 2023 extension to the remaining E/M categories, practitioners may select a code level using either medical decision making or total time on the date of the encounter. CMS maintains its guidance on these visits on the Evaluation and Management Visits page. Separately, whole families of services have always been measured in minutes: psychotherapy, critical care, care management with cumulative monthly minutes, prolonged service add-ons, and therapy codes with unit thresholds.
Your practice does not decide which method is correct for a given encounter — the treating clinician does, applying CPT guidelines and payer policy to what actually happened. Your job is narrower and harder: make sure that when the clinician chooses time, the chart contains a number that a reviewer can verify, and make sure that number came from somewhere legitimate.
When time based billing fails an audit, it usually fails for one of four administrative reasons. The chart says "prolonged visit" with no minutes. The minutes are identical across 40 encounters. Clinical staff time got folded into practitioner time. Or the attestation appears in a template that fires automatically whether or not anyone read it.
What Counts as Time in Time Based Billing?
For office and outpatient E/M services, CPT counts the practitioner's total time personally spent on the date of the encounter — face-to-face and non-face-to-face — including chart review before the visit, the visit itself, ordering tests or medications, counseling, documenting in the record, and care coordination performed that day. Time spent on services reported separately does not count, and time spent by clinical staff generally does not count toward the practitioner's total.
Other code families set their own rules. Many time-based CPT codes follow the convention that a unit of time is met when the midpoint has passed, unless the code descriptor or guidelines say otherwise. Medicare's therapy timed codes use their own unit thresholds. Care management codes accumulate minutes across a calendar month rather than a single date.
The administrative takeaway: never let a single house rule govern all time-based codes. Your billing team should maintain a one-page reference per code family, citing the current CPT guidance and the specific payer policy, reviewed at least annually and after each fee schedule cycle.
Building the Minute-Capture Workflow: Who Does What
The clinician records the number, not the biller
Only the person who performed the work can attest to the time. Your workflow should make that the easiest path available: a discrete time field in the encounter note, not free text buried in a paragraph. Discrete fields are also reportable, which matters later when you audit yourself.
Write the standard down. Something like: "When code selection is based on time, the note states total practitioner time on the date of service as a specific number of minutes, and identifies the activities included." Vague ranges and "greater than" phrasing invite reviewer questions.
Billing staff verify presence, not accuracy
Your coders can confirm that a number exists, that it is internally consistent with the note, and that it does not conflict with the appointment record. They cannot invent it, adjust it upward, or ask a clinician to "see if it was really 45." Draw that line explicitly in your coding policy, because a query that suggests an answer is the single most damaging document a payer can find.
The administrator owns the pattern review
Once a month, pull time-based encounters by provider and look for signatures of a broken process: clustering just above a threshold, minutes that never vary, totals that exceed the provider's scheduled hours for the day. You are not second-guessing clinical judgment. You are finding template defects and training gaps before an outside reviewer does.
Front desk and scheduling contribute the corroborating trail
Check-in and check-out timestamps, telehealth session logs, and interpreter service records do not replace the clinician's attestation, but they will be the first thing a reviewer compares it against. If your schedule shows a 15-minute slot and the note claims 55 minutes of practitioner time, someone will ask. Sometimes the answer is legitimate — non-face-to-face work counts — and your note should say so.
A Worked Example of the Paper Trail
A provider sees an established patient with three managed conditions. Before the visit she reviews outside records for 9 minutes. The visit runs 26 minutes. Afterward she places orders, documents, and calls a specialist's office, spending another 12 minutes the same day. Total practitioner time on the date of service: 47 minutes.
What your chart needs is the number and the composition: total minutes, on the date of service, with the included activities named. What your chart must not contain is a coder's reconstruction, a rounded-up estimate, or an auto-populated phrase that appears on every note that provider signs.
Whether 47 minutes supports one code level or a base code plus a prolonged services add-on is a coding determination made against current CPT guidance and the payer's policy — documented in your practice's coding reference, applied by the clinician and reviewed by qualified coding staff. Your operational contribution is ensuring the 47 is real, sourced, and retrievable three years from now.
The Privacy Exposure Hiding in Your Timestamps
Time documentation multiplies the number of systems holding identifiable information about a patient's care. The encounter note holds the attestation. The EHR audit log holds who opened the chart and when. The telehealth platform holds session duration. The ambient documentation tool holds an audio recording or transcript. The billing clearinghouse holds the claim. The time-tracking or productivity dashboard your group bought last year may hold provider-level minute data tied to encounter IDs.
All of that is PHI when it identifies a patient or can reasonably be used to. Three consequences follow.
Minimum necessary applies to audit responses. When a payer requests documentation supporting time, send the encounters requested and the elements requested. Do not ship the entire chart, the full audit log, or unrelated dates because it is easier to export. HHS guidance on the minimum necessary requirement expects you to limit disclosures to what the purpose requires; payment-related disclosures are permitted, but that permission is not a license to over-share.
Time attestations are part of the designated record set. If a patient requests their record, the note containing the minutes goes with it. So does a scribe-produced note that became the clinical record. Your release-of-information staff should know that "billing time documentation" is not automatically excludable, and that the right of access generally requires a response within 30 days.
Provider-level minute analytics still contain patient data. A dashboard showing "average time per encounter" is usually built on encounter-level records. Treat it as a PHI system, put it in your asset inventory, and confirm who at the vendor can see the underlying rows.
Vendor Implications: Every Tool That Touches the Minutes Needs a BAA
Run the list of who creates, receives, maintains, or transmits your time documentation. In most practices it includes the EHR host, the billing company or clearinghouse, the telehealth platform, any transcription or ambient documentation service, the virtual scribe staffing agency, the coding audit consultant, and the analytics vendor generating the productivity reports.
With very limited exceptions, each of those is a business associate and needs an executed agreement before it touches PHI. HHS explains the scope in its business associate guidance. Two failure modes recur in practices that lean on time based billing:
- The scribe gap. An employed scribe is workforce and needs training and access controls, not a BAA. A contracted or offshore scribe service is a business associate and needs both a signed agreement and documented safeguards. Practices routinely mix these up.
- The pilot gap. A clinician trials an ambient documentation product on real encounters for six weeks while procurement "gets around to paperwork." That is unpermitted disclosure for six weeks, and the recordings may still exist.
If you are staring at a vendor list with more tools than signed agreements — the normal situation, not the shameful one — you can produce a signature-ready contract quickly using a six-step Business Associate Agreement generator that exports to PDF and DOCX as a one-time purchase, no subscription. Get the ambient documentation tool, the scribe agency, and the analytics dashboard papered first; those are the three that see the most and are contracted the least formally.
Then push past the signature. Ask each vendor how long it retains audio, transcripts, and audit logs; whether subcontractors process the data; and how it would notify you of a breach and within what timeframe. Record the answers in your vendor file. A BAA that nobody has read since signing does not help you during an incident.
A 60-Day Cleanup Plan You Can Actually Run
- Days 1–10. Inventory every system holding time documentation, including spreadsheets and dashboards. Name an owner for each.
- Days 11–20. Match the inventory against executed BAAs. Flag gaps. Prioritize anything capturing audio or storing transcripts.
- Days 21–30. Pull 20 time-based encounters per provider. Score each for a discrete minute total, named activities, and absence of auto-populated attestation language.
- Days 31–45. Fix templates. Remove any default time text that fires without user input. Add the discrete field if it isn't there.
- Days 46–60. Train in one 30-minute session with real de-identified examples from your own charts, and write the standard into your coding policy with a named reviewer and a review date.
Document the whole exercise. If your risk analysis and policy set are still living in scattered documents, generating a consolidated HIPAA risk analysis and policy package gives you one place to record the systems, the vendors, and the safeguards you just catalogued — which is exactly what an investigator asks for first.
Where Practices Get Caught
Payer auditors look for unsupported minutes. Regulators look for unsupported vendors. Time based billing puts you in front of both, because the same minute that justifies a code also creates a record that somebody outside your walls is storing.
Handle it as one workflow with two outputs: a defensible number in the chart, and a signed, current agreement covering every system that number passes through. If your vendor coverage is the weaker half — and for most practices it is — build the missing Business Associate Agreements this week and close the gap before the next records request arrives.