Time-Based Medical Billing: Documentation and Privacy
A payer records request lands in your fax queue on a Tuesday. It names 42 dates of service across three clinicians, and it asks for one thing above all others: the documentation supporting the total time reported on each claim. You have 30 days. Your billing manager pulls the notes, and eight of them say some version of "35 minutes spent with patient." No start time, no stop time, no breakdown of what filled those minutes.
That is the operational risk of time based medical billing, and it is administrative before it is anything else. This guide covers how practices capture, document, and defend time-based claims — and, because minute-level records are unusually revealing, what those records mean for your privacy program, your release-of-information workflow, and your vendor list.
What Time Based Medical Billing Means On Your Side Of The Desk
Time based medical billing is any claim where the reported service level is determined by documented minutes rather than by the complexity of the work performed. Code descriptors published by the AMA and payment rules published by CMS define the time ranges; your documentation has to demonstrate that the time actually occurred and what it consisted of.
Three families of service dominate the volume in most practices:
- Office and outpatient evaluation and management visits, where clinicians may select a level based on total time spent on the date of the encounter instead of medical decision making.
- Timed procedural and therapeutic units — physical therapy, occupational therapy, speech therapy — where units are calculated from treatment minutes under payer-specific rules.
- Discrete timed services such as psychotherapy, critical care, care management, and prolonged services, where the descriptor itself is built around a duration.
Your job as an administrator is not to decide which code fits a clinical scenario. Your job is to build the workflow that produces a defensible time record, route it to coding, and keep the resulting data from leaking. CMS publishes the current framework for E/M visits in its MLN Evaluation and Management Services Guide, which your coding lead should be re-reading each time the fee schedule cycle updates.
The Three Time-Capture Workflows Your Staff Actually Run
Office visits: total time on the date of service
When a clinician selects a visit level by time, the countable minutes typically include face-to-face and non-face-to-face work performed by the billing clinician on the calendar date of the encounter — chart review before the visit, the visit itself, ordering, documentation, and counseling. Staff time generally does not count.
The operational failure point is memory. A clinician who reconstructs total time at 7 p.m. from six visits earlier that day produces an estimate, and estimates cluster suspiciously around threshold numbers. Payer analytics notice clustering. Build the capture into the visit, not into the end of the day.
Timed treatment units in therapy departments
Therapy billing runs on treatment minutes. Medicare's substantiation rule for timed units — the one everyone calls the 8-minute rule — requires a minimum quantity of direct treatment minutes before a unit may be billed, and commercial payers frequently apply their own variants. That means your therapy department needs start and stop times per intervention, not a single daily total.
If your therapists document on paper flow sheets and a front-desk staffer keys the minutes into the practice management system, you have a transcription step. Transcription steps produce errors, and errors in timed units produce overpayment findings. Audit that handoff monthly.
Telehealth and asynchronous work
Video platforms produce their own session timestamps, which is convenient right up until the platform log disagrees with the clinician's note. Decide in advance which record governs, document that decision in policy, and make sure your staff know that a connection log is not a treatment log — a call that connects at 9:02 and drops at 9:04 before reconnecting is one encounter, not two.
Who Writes The Number Down, And When
Assign these roles explicitly. Ambiguity here is how practices end up with unsupported claims.
- Clinician: records total time or start/stop times in the note, in the same session as the clinical documentation. Attests to the activities that comprised the time.
- Scribe or documentation assistant, if used: may enter time as dictated but never originates it. The clinician signs.
- Coding staff: maps documented time to the applicable descriptor and payer rule. Does not add, round, or infer minutes.
- Billing manager: runs a pre-submission edit that flags claims where a time-based code was reported without a time statement in the note.
- Compliance lead: samples 10 to 20 time-based claims per clinician per quarter and reviews for internal consistency — overlapping encounters, totals exceeding a plausible workday, identical durations across a full schedule.
That fifth item is where most practices find their problems before a payer does. Two encounters documented as 9:00–9:40 and 9:30–10:05 on the same clinician's schedule is not a coding question. It is a data-integrity question, and it will be read as a billing-integrity question by whoever reviews it later.
What The Audit Trail Proves — And What It Exposes
Here is the part that belongs to your privacy officer rather than your billing manager. Every EHR generates access and modification logs, and those logs are the strongest corroboration you have for time based medical billing. They are also a detailed record of who looked at which chart, when, and for how long.
The HIPAA Security Rule requires audit controls and regular review of system activity. When a payer or an investigator asks you to substantiate time, your audit log is what turns "the note says 40 minutes" into "the record shows the chart was open and edited across that window." Practices that have never validated that their audit logging is enabled, retained, and exportable discover the gap at exactly the wrong moment.
Two operational consequences follow. First, decide your retention period for audit logs and write it down — six years is the common floor because it matches HIPAA documentation retention, and payer look-back windows can be long. Second, treat log exports as PHI. An audit log export naming patients, clinicians, and timestamps is protected health information, and it moves by email far too often.
Minimum necessary applies to time data
When a payer requests substantiation for 42 dates of service, they get 42 dates of service. Not the full chart. Not a log covering every patient the clinician touched that month. HHS guidance on the minimum necessary standard applies squarely to payment-related disclosures, and a bulk log export that sweeps in uninvolved patients is a disclosure you did not need to make.
Give your release-of-information staff a written procedure for filtering log exports by patient and date range. If your system cannot filter, that is a vendor requirement to raise at renewal.
Every Vendor That Touches Your Time Data Needs A Signed BAA
Walk the path a single time-based claim takes through your practice and list every organization that handles it. A representative list:
- Your EHR and practice management host
- Any scribe service, including remote or AI-assisted documentation vendors
- Transcription and dictation providers
- Your billing company or outsourced coding partner
- The clearinghouse that submits the claim
- Telehealth platforms that generate session timestamps
- Audit-defense consultants and external coding auditors
- Any analytics or dashboard tool that ingests encounter-level time data
Each of those creates, receives, maintains, or transmits PHI on your behalf, which makes each a business associate under the definitions HHS lays out in its business associate guidance. The last two items are the ones practices routinely miss. An external auditor reviewing your time documentation is looking at patient records; the engagement letter is not a substitute for an agreement.
If a vendor on that list has no executed agreement — or has one signed in 2017 that nobody has re-read — you can produce a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. It is a one-time purchase, which matters when you are closing a gap on eleven vendors at once rather than budgeting for another subscription.
What to add to the agreement for time-data vendors
Beyond the required terms, ask for three things specific to this data class: a commitment that audit logs are retained for a defined period and exportable in a usable format; notification timelines that let you meet your own breach obligations; and a written statement of where processing occurs, including any subcontractors. Vendors that cannot answer the log-export question are telling you something about your future audit defense.
Records Requests: The 30-Day Clock Does Not Pause For Billing Questions
Patients ask for time documentation more often than administrators expect, usually when a bill surprises them. Under the HIPAA right of access, a patient may request the records in your designated record set, and your practice generally has 30 days to act, with one 30-day extension available if you notify the patient in writing. HHS keeps its right of access guidance current, and OCR has enforced this provision consistently.
Billing records maintained by or for your practice that are used to make decisions about the patient are part of the designated record set. Train your front desk to route these requests to the ROI workflow immediately rather than parking them with billing for a coverage explanation. The clock starts on receipt, not on resolution of the billing dispute.
A Worked Example: The Internal Time Review
Say you run a nine-clinician multispecialty group. Your compliance lead pulls 15 time-based claims per clinician for Q1. The review checklist:
- Does the note contain a time statement, and is it specific rather than a template default?
- Do documented activities match what the payer's rules allow to be counted?
- Do any two encounters for the same clinician overlap in wall-clock time?
- Does daily documented time exceed a plausible clinical day?
- Does the EHR audit log corroborate chart activity during the stated window?
- Was the claim submitted with the time-based code the documentation supports, per coding staff's mapping?
Findings go to the clinician as education, not as accusation — most time documentation problems are habit problems. Findings that show a pattern go to your governing body with a remediation plan and a re-review date. Document the review itself; the existence of a functioning review process is evidence of a compliance program, and its absence is evidence of the opposite.
The Ninety-Day Build
Days 1–30: Inventory every code your practice bills on time. Confirm your EHR templates prompt for start/stop or total time rather than allowing free text. Verify audit logging is enabled and exportable, and confirm the retention setting.
Days 31–60: Complete the vendor walk described above and close every missing or stale agreement. Write the minimum-necessary procedure for log exports and train ROI staff on it.
Days 61–90: Run your first sampled review. Add a pre-submission claim edit for missing time statements. Update your risk analysis to reflect where time and audit-log data lives, including any new documentation vendor. If your risk analysis and policy set have not been refreshed since your last system change, automating the risk analysis and document set is faster than rebuilding it in a spreadsheet.
Start With The Agreement You Are Missing
Time based medical billing puts unusually granular data into unusually many hands — scribes, coders, billers, clearinghouses, auditors. Before your next payer request arrives, pull your vendor list and check which of those relationships is running without a current agreement. If you find one, generate a signature-ready BAA and get it executed this week. It is the cheapest gap on your list to close, and the one an investigator asks about first.