Time Based Coding: A Practice Admin's Compliance Guide
A payer audit letter lands on your desk asking for 40 office visit charts. Buried in paragraph three is a second request: system audit logs showing when each note was opened, edited, and signed. That second sentence is the reason time based coding is an operations and privacy problem, not just a billing one. If your practitioners select evaluation and management levels by total time, your defense against a takeback lives partly in your electronic record's metadata — and that metadata sits inside systems your vendors can reach.
This guide is for practice administrators, billing managers, and privacy officers. It covers how time based coding actually works in a clinic workflow, what your documentation has to show, and which records-handling and vendor obligations it triggers. It does not tell you which code fits which patient — that determination belongs to the treating practitioner.
What Counts as Total Time on the Date of the Encounter
Since the 2021 revisions to the office and other outpatient E/M codes — extended in 2023 to most other E/M families — practitioners may select a level based on either medical decision making or total time spent on the date of the encounter. History and exam are no longer scoring elements. Emergency department visit codes remain an exception with no time-based option.
Total time generally includes the reporting practitioner's face-to-face and non-face-to-face work on that calendar date:
- Preparing to see the patient, including reviewing separately obtained records and test results
- Obtaining and reviewing history
- Performing a medically appropriate examination
- Counseling and educating the patient, family, or caregiver
- Ordering medications, tests, or procedures
- Communicating with other health professionals about the patient
- Documenting clinical information in the health record
- Independently interpreting results and communicating them, when not separately reported
- Care coordination, when not separately reported
Excluded: travel time, staff time, time spent on services reported separately, and general teaching not specific to the patient. Time cannot be counted twice. If a procedure is billed separately, the minutes attributable to it come out of the E/M total.
Other timed code families run on different rules entirely. Psychotherapy codes, critical care, and anesthesia each have their own timing conventions and midpoint thresholds. Do not let a single "how we count time" policy paragraph cover all of them.
The one-sentence answer for your front-office training deck
Time based coding means the practitioner selects the visit level using the total time they personally spent on that patient's care on the encounter date, rather than the complexity of medical decision making. The chart must state the total time, and the time must be tied to that specific calendar date.
The Documentation Line Your Auditor Reads First
Auditors do not hunt for a narrative. They look for a discrete, attributable statement of total time. A note that says "extensive counseling provided" supports nothing. A note that states the practitioner's total time on the date of service, in minutes, is the anchor.
Build the attestation into your templates so it cannot be skipped, and make sure it names the practitioner. In multi-provider encounters, an unattributed time statement is the single most common defect that turns a defensible chart into a refund.
Late entries, addenda, and the version history problem
Practitioners finish notes after hours. That is normal and not disqualifying — the requirement is that the time counted was spent on the encounter date, not that the note was signed that day. What creates exposure is silent overwriting.
Your record system should preserve version history and label addenda with the author and timestamp. If a time statement changes from one figure to another with no addendum, an auditor sees an edit and a motive. Write a policy that forbids editing a signed note without an addendum, and confirm your system enforces it rather than trusting the policy alone.
Where Time Based Coding Breaks Down in Real Workflows
Split and shared visits
When a physician and an advanced practice provider both contribute to a facility-setting visit, Medicare requires identifying who performed the substantive portion. CMS has revised and postponed the definition of "substantive portion" more than once across recent rulemaking cycles. Do not write your policy from memory or from a conference slide — pull the definition from the current-year Physician Fee Schedule final rule each January and reissue the internal guidance.
Operationally, this means both clinicians need to record their own time separately. A shared note with one combined figure is unusable. Assign this to your billing lead as a quarterly template review.
Teaching settings
Where residents are involved, only the teaching physician's own qualifying time counts toward time based coding. Resident minutes do not add. If your practice hosts rotators, your template needs a field that separates the two, and your coders need training to reject notes that blur them.
Prolonged services
Prolonged service add-on codes exist for time that exceeds the range of the highest-level code, but CPT's add-on and Medicare's own G-codes use different thresholds and different counting windows. Payers also differ. Maintain a payer-specific grid, owned by one named person, refreshed annually. A single blanket rule applied across all payers is how practices generate self-disclosure obligations.
Your Audit Log Just Became a Billing Exhibit
Once time drives revenue, the audit log becomes corroborating evidence — and it cuts both ways. A log showing a chart open for four minutes next to a note claiming forty is a problem. A log showing sustained activity supports the claim.
You already owe audit controls and information system activity review under the HIPAA Security Rule at 45 CFR 164.312(b) and 164.308(a)(1)(ii)(D). Most practices have logging turned on and nobody reviewing it. Time based coding gives you a business reason to close that gap: designate a reviewer, set a cadence, and document the review. See the HHS overview of the Security Rule requirements for the baseline.
Two cautions. First, audit logs are generally not part of the designated record set, because they are not used to make decisions about the individual — so a patient access request does not automatically compel them. Get that determination in writing from counsel and put it in your access policy rather than deciding it under deadline pressure. Second, exporting logs for a payer or a consultant is a disclosure of PHI-adjacent material that must move encrypted, through a channel you control.
The Vendor List Time Based Coding Creates
Time-based documentation pushes practices toward tooling, and every tool is a new business associate. Walk your list:
- Ambient documentation and AI scribe vendors. These capture full encounter audio. Ask where recordings are stored, how long they are retained, whether audio is deleted after transcription, and whether your data can be used to train models. Get the retention answer in the contract, not the sales deck.
- Human scribe services. Remote scribes touch the live chart. Confirm unique named accounts — never shared logins — so audit logs stay attributable.
- External coding auditors. They receive charts, logs, and sometimes claim data. Scope the minimum necessary set and require return or destruction at engagement end.
- Telehealth platforms. Session duration data supports time attestations. Confirm the platform retains and can produce it, and confirm the BAA covers that data.
- Billing companies and clearinghouses. Already business associates, but re-check subcontractor flow-down language when they add an AI coding module.
Every one of these needs a signed business associate agreement in place before PHI moves, plus a risk analysis entry describing where the data sits. If your BAA folder is a mix of countersigned PDFs and unanswered emails, tools that automate risk analysis and generate the full compliance document set will get you to a defensible baseline faster than another spreadsheet. For a one-off vendor onboarding, a signature-ready business associate agreement closes the gap in an afternoon.
Payer Audits Versus Patient Access: Two Different Clocks
A payer requesting records for a post-payment audit is not a business associate. That disclosure runs as a payment activity under 45 CFR 164.506, and no BAA is required — but minimum necessary still applies. Send the charts requested, for the dates requested. Do not ship an entire longitudinal record because it was easier to export.
A patient requesting their own record runs on a different clock: 30 days, with one 30-day extension if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. OCR has pursued a long-running enforcement initiative on right of access, and the settlements have overwhelmingly involved small practices that simply did not respond. Review the HHS right of access guidance and hand it to whoever opens the mail.
Log both request types in one tracker with a due date column. Your privacy officer should review it weekly. When something does go wrong, the OCR breach portal is a useful reminder of how often the cause is an unencrypted export or a misdirected email — exactly the workflows an audit response creates.
A 90-Day Rollout You Can Actually Staff
Days 1–30 — Inventory. Billing manager pulls the current-year fee schedule rule and builds the payer grid for prolonged services and split/shared. Privacy officer inventories every vendor that touches the note: scribes, ambient tools, coding auditors, telehealth. Flag any without an executed BAA.
Days 31–60 — Template and access controls. Add a mandatory, attributable time attestation field. Verify version history and addenda enforcement. Eliminate shared logins. Confirm audit logging captures note open, edit, and sign events with user identity.
Days 61–90 — Test and train. Run an internal review of 20 time-selected charts. Check for the attestation, correct attribution, and no double-counted procedure minutes. Train practitioners on what is excluded. Train front desk and records staff on the two request clocks. Document the training with attendance and date.
Then set the recurrence: payer grid annually in January, chart sample quarterly, vendor and BAA review annually, audit log review monthly.
What to Do This Week
Pull ten charts where a level was selected by time. If you cannot find an attributable total-time statement in every one, your templates are the problem, not your practitioners. Fix the template first, then the training, then the vendor paperwork.
If that vendor paperwork is the piece you keep deferring, start with a current risk analysis and a complete policy set — generate your HIPAA compliance documentation and work the gaps it surfaces. Time based coding will hold up under audit only if the systems recording that time hold up too.