A payer audit letter lands on a Tuesday. It names 25 patients, dates of service spread across nine months, and asks for "all documentation supporting time-based units billed." The clinician who treated most of those patients left your practice in August. This guide is for the administrator or billing lead who has to answer that letter — it covers how timed coding works operationally, who in your practice owns the minute log, what documentation actually survives review, and the privacy and vendor obligations that time data quietly creates.

None of this is clinical guidance. Clinicians decide what service they performed. Your job is to make sure the record shows the minutes, the reconciliation math is reproducible, and the file you send to a payer doesn't over-disclose.

What Timed Coding Means on Your Claims — The Short Answer

Timed coding refers to procedure codes whose billable units depend on documented minutes of service, rather than on the fact that a service occurred at all. Two categories sit side by side on most claims:

  • Time-based (timed) codes — units scale with documented minutes. Common examples include 15-minute therapy and rehabilitation procedures, care-management and remote-monitoring code families with monthly minute thresholds, prolonged service add-ons, and psychotherapy codes defined by time ranges.
  • Service-based (untimed) codes — billed once per encounter regardless of duration.

Because the unit count is arithmetic, timed coding is one of the easiest things for a payer's data analytics to flag and one of the hardest things for a practice to defend retroactively. If the minutes aren't in the record, the units aren't defensible — no matter how appropriate the treatment was.

How Timed Coding Units Are Counted Under Medicare Rules

For outpatient therapy services billed in 15-minute increments, CMS instructs that the total minutes of timed treatment determine how many units may be billed, with a single unit requiring at least 8 minutes of that service. Untimed codes are billed once per day regardless of how long they took, and their minutes are not added into the timed total. The current instructions live in the Medicare Claims Processing Manual; your billing lead should be reading the live version, not a training slide from 2019. Start from the CMS Internet-Only Manuals and pull the chapter that governs the service lines you bill.

Two operational cautions:

Commercial payers may count differently. Some follow CPT's substantial-portion convention rather than Medicare's cumulative method. Your fee schedule matrix should record, per payer, which counting rule applies. If nobody in your practice can name the source document for a given payer's rule, you have a policy gap, not a coding question.

The clinician decides the service; the record decides the units. Your staff never picks a code because it produces a better unit count. They document minutes per distinct service, and code selection follows from documentation and payer rules. Write that sequence into your coding policy verbatim so it exists in writing when an auditor asks how you prevent upcoding pressure.

The Fields That Have to Exist in Every Timed Note

Regardless of specialty, build your template so these fields cannot be skipped:

  1. Start and stop time, or total treatment time for the encounter.
  2. Minutes attributed to each timed service performed, separately.
  3. Which services were one-on-one versus group, where the distinction affects billing.
  4. Identity and credentials of the person delivering each timed service.
  5. Whether any portion was delivered by an assistant or supervised staff member, if your payers require that flag.

A note that says only "45 minutes of treatment" supports almost nothing when the claim carried three different timed procedures. Ambiguity resolves against you on appeal.

Role Assignments: Who Owns the Clock

Timed coding fails at handoffs, so assign each handoff to a named person.

Front desk records actual arrival and departure, not scheduled appointment length. A 2:00 slot that started at 2:19 needs to look like 2:19 in the system.

Treating clinician enters minutes per service before the end of the business day. Your policy should state the closing deadline; 24 hours is common, and anything longer invites reconstruction.

Billing lead runs a pre-submission reconciliation: do documented minutes support the units on the claim? Claims that fail reconciliation go back to the clinician, never forward with an assumption.

Compliance lead samples 10 encounters per clinician per quarter, scores them against the five fields above, and logs the result. That log is what you hand a payer to show the program exists.

A Worked Reconciliation Example

A clinician documents 52 total minutes of timed services: 24 minutes on service A, 18 minutes on service B, 10 minutes on service C, plus one untimed service. The reconciliation question is purely arithmetic — how many total units do 52 timed minutes support under this payer's counting rule, and how are those units allocated across A, B, and C given the per-service minutes documented?

Your billing staff should be able to show that math on a worksheet, with the payer rule cited. If the claim shows four units and the worksheet shows three, someone answered a question the record didn't answer. Keep the worksheet in the billing file; it becomes your audit response draft.

Where Timed Coding Creates HIPAA Exposure

Minute-level data is protected health information with an unusually revealing shape. A time log shows when a patient was in your building, for how long, with whom, and how often. Combined with a schedule export, it reconstructs a behavioral pattern that a chart note alone would not.

Three exposure points show up repeatedly in practice:

Spreadsheets outside the EHR. Clinicians who track minutes in a personal spreadsheet, a notes app, or a paper card in a lab coat have created an unmanaged copy of PHI. Your risk analysis has to account for it, or you have to eliminate it. Pick one, and write down which.

Audit trail integrity. If minutes are entered days later, your EHR's audit log shows an entry timestamp that contradicts the documented service time. Auditors read both. So do plaintiffs' attorneys. Late entries should be labeled as late entries, with the reason.

Over-disclosure in audit responses. The minimum necessary standard applies to disclosures for payment purposes, including payer audits. Sending a complete chart when the request covers three dates of service is the single most common records-handling error in an audit response. HHS's minimum necessary guidance is short; make your records custodian read it before the first response goes out.

Patients Can Request the Billing File Too

The HIPAA right of access covers the designated record set, which includes billing and payment records — not just clinical notes. When a patient disputes units billed and asks for "everything you used to bill my visits," your minute logs and reconciliation worksheets are likely in scope. You generally have 30 days to act, with one 30-day extension available on written notice. Review the OCR right of access guidance and confirm your records custodian knows where timed-coding worksheets live. If they're in a billing vendor's portal rather than your EHR, your fulfillment process has to reach into that portal.

Vendor Implications: Everyone Who Touches Your Minute Data

List every system that captures, stores, transmits, or analyzes time data for billing. In most practices the list is longer than the administrator expects:

  • The EHR or practice management platform holding the note and the minutes
  • An outsourced billing or revenue-cycle company running unit reconciliation
  • A coding audit firm doing pre-bill or post-bill review
  • Dictation or ambient documentation tools that capture start/stop language
  • Check-in kiosks or scheduling apps that timestamp arrival
  • Remote monitoring or digital therapeutic platforms that accumulate monthly minutes
  • Analytics or dashboard tools ingesting claim and encounter data
  • Payer portals — these are covered-entity-to-payer disclosures, not business associate relationships, so treat them separately

Every vendor on the first seven lines is performing a function on your behalf using PHI, which means you need an executed business associate agreement before they receive data — not after the first invoice. Coding audit firms are the ones practices most often miss, because engagement letters get signed by a clinical leader who never loops in compliance.

If you find a gap while reading this, close it this week. You can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export, as a one-time purchase without a subscription — fast enough that "we're still drafting it" stops being an excuse. Then log the executed agreement, the date, and the vendor contact in your vendor register so your next risk analysis can cite it.

Contract Terms Worth Adding for Time Data Specifically

Beyond the required BAA provisions, negotiate these into the underlying service agreement:

  • Return or destruction of minute logs on termination, with written confirmation and a deadline.
  • Audit-support obligation — if a payer audits claims the vendor coded, the vendor produces its worksheets within a fixed number of days.
  • No secondary use of encounter time data for benchmarking or product development without your written authorization.
  • Named subcontractors, with notice before adding new ones. Offshore coding subcontractors are common and frequently undisclosed until you ask.

A Quarterly Timed Coding Self-Audit You Can Actually Run

Ninety minutes per quarter, one owner, documented result:

  1. Pull 10 encounters per clinician with two or more timed units.
  2. Score each against the five required documentation fields. Record pass/fail per field, not an overall impression.
  3. Recalculate units from documented minutes using the payer-specific rule. Compare to what was billed.
  4. Check the EHR audit log for entry lag. Flag anything documented more than 24 hours after service.
  5. Confirm every vendor that touched those encounters appears in your vendor register with a current BAA.
  6. Write a one-page memo: findings, corrective actions, owner, due date. File it with your risk analysis documentation.

Overpayments identified in step 3 trigger a refund analysis, not a filing-cabinet decision. Loop in counsel before you decide the scope of a self-disclosure.

If your broader documentation set is thin — risk analysis, policies, workforce training records — the timed coding memo will sit alone and unsupported. Tools that automate the HIPAA risk analysis and policy set get you a baseline you can maintain, and NIST's SP 800-66r2 is the free reference for what a defensible Security Rule risk analysis looks like.

Start With the Vendor List

Before your next audit letter, do two things. Reconcile one week of timed claims against documented minutes so you know your real error rate. Then confirm that every vendor holding that minute data has a current, signed agreement on file — and generate the missing BAAs the same day you find the gap. Time data is the easiest thing in your practice to flag and the hardest to reconstruct. Paper it now.