A compensation consultant emails your billing manager on a Tuesday: "Please send a line-level productivity extract for all fourteen providers, 24 months, so we can benchmark work RVUs against market." Your billing manager knows how to run that report. In about four minutes she can produce a CSV with 61,000 rows — patient account number, date of service, procedure code, modifier, rendering provider, work RVU, allowed amount.

That file leaves your building as protected health information. Whether that's a permitted disclosure or a reportable one depends on three things you can settle before she clicks export: what the vendor actually needs, whether a Business Associate Agreement is signed, and whether anyone stripped the identifiers. This guide covers what does RVU stand for, how the underlying math works, and where the records-handling and vendor obligations attach.

What Does RVU Stand For? The Short Answer

RVU stands for Relative Value Unit. It is the unit of measure CMS uses in the Resource-Based Relative Value Scale (RBRVS) to express how much relative resource cost a given physician service consumes compared with every other service. RVUs are not dollars. They become dollars only after geographic adjustment and multiplication by an annual conversion factor.

Every service on the Medicare Physician Fee Schedule carries three separate RVU values:

  • Work RVU (wRVU) — physician time, technical skill, mental effort, and stress. This is the component your compensation formula almost certainly uses.
  • Practice Expense RVU (PE RVU) — clinical staff time, supplies, equipment, and overhead. Published in two versions: facility and non-facility.
  • Malpractice RVU (MP RVU) — professional liability insurance cost attributable to the service.

The formula, in one line

Payment = [(wRVU × work GPCI) + (PE RVU × PE GPCI) + (MP RVU × MP GPCI)] × conversion factor.

GPCI is the Geographic Practice Cost Index for your payment locality. The conversion factor is a national dollar multiplier CMS finalizes each fall in the Physician Fee Schedule final rule. Beginning with CY 2026, statute directs two separate conversion factors — one for qualifying alternative payment model participants and one for everyone else — so your fee schedule model needs a field for which one applies to your group. CMS posts the underlying values in the PFS Relative Value Files, and the broader methodology sits on the Physician Fee Schedule page.

Why Your RVU Table Changes Every January (and Sometimes Midyear)

RVU values are not static. CMS revalues individual services through the annual rulemaking cycle, and it periodically applies across-the-board adjustments. The CY 2026 final rule, for example, applied an efficiency adjustment to work RVUs for certain non-time-based services and continued the split between facility and non-facility practice expense.

Operationally, that means one person on your staff owns an annual task with a hard date: download the new Relative Value Files after the final rule publishes, load them into your practice management system and your compensation spreadsheet, and reconcile. Assign it in writing. When it goes unowned, your providers get paid on last year's wRVUs and your payer contracts get modeled against stale conversion factors.

Keep a versioned archive of every RVU file you've loaded. When a physician disputes a Q3 compensation number eighteen months later, you need the exact table that was in effect — not whatever is current.

Where RVU Data Actually Lives in Your Practice

Ask any administrator where RVU data sits and you'll usually hear "the PM system." In practice it lives in at least five places, and each is a separate disclosure surface:

  1. The practice management / EHR database — charge lines with codes, dates, patients, and rendering providers.
  2. The clearinghouse — the 837 claim files that carry the same data outbound.
  3. Someone's spreadsheet — the monthly productivity workbook, usually on a local drive, usually emailed.
  4. A BI or analytics tool — dashboards fed by a nightly extract nobody has reviewed since implementation.
  5. Vendor systems — billing company, coding auditor, benchmarking service, compensation consultant, RCM analytics platform.

Your vendor inventory should list every one of those, with the data elements each receives and the transport method. If you cannot produce that list in ten minutes, that gap is your finding for this quarter — not a hypothetical.

The Export That Turns a Productivity Report Into a PHI Disclosure

Here is the distinction that governs almost every RVU privacy question you'll face:

An aggregated productivity summary — "Dr. Alvarez, 4,812 wRVUs, CY2025" — contains no patient identifiers. Provider identity is not patient PHI. You can email that to a compensation consultant without a BAA, because you aren't disclosing protected health information.

A line-level extract — one row per charge, with account numbers and dates of service — is PHI. Dates of service are identifiers. So are account numbers, medical record numbers, and ZIP codes at full precision. HHS lists all eighteen Safe Harbor identifiers in its de-identification guidance, and dates more specific than year are on that list.

Most RVU disclosure problems happen because someone needed the first thing and sent the second. The consultant asked for wRVUs by provider; the extract shipped with patient columns attached because that's how the canned report runs.

Apply minimum necessary before you apply encryption

Encryption protects a file in transit. It does not make an over-broad disclosure permissible. The minimum necessary standard requires you to limit what you disclose to what the recipient actually needs for the stated purpose.

Build two standing report templates and lock them down:

  • Template A (no PHI): provider, period, encounter count, wRVU total, wRVU by code category. Approved for benchmarking and compensation vendors.
  • Template B (PHI): full line detail. Released only to vendors with a signed BAA and a documented need — coding auditors, your billing company, your RCM partner.

One more caution for small and rural groups: aggregation is not a magic shield. A single-provider specialty line with three encounters in a rural county can be re-identifiable. Suppress small cell counts in anything leaving the practice.

Which RVU Vendors Need a Business Associate Agreement

Run every vendor that touches RVU data through one question: does this vendor create, receive, maintain, or transmit PHI on our behalf? If yes, you need an executed BAA before the first file moves.

Typically yes:

  • Billing and revenue cycle companies
  • Coding auditors and documentation reviewers
  • Clearinghouses
  • Analytics or dashboard platforms fed by line-level extracts
  • Offshore coding or data-entry partners (and their subcontractors)
  • Any consultant who asks for chart-level detail to validate code selection

Typically no, if and only if the data stays aggregated:

  • Compensation survey and benchmarking services receiving provider-level wRVU totals
  • Actuarial or market-rate consultants working from summary tables

That "if and only if" is where practices get burned. The BAA is cheap insurance; the file that quietly included a date-of-service column is not. When the scope is ambiguous, execute the agreement. If you're staring at a vendor who needs paper before Friday, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, no waiting on outside counsel to open a matter.

Then log it. Vendor name, service, PHI elements, BAA execution date, renewal or review date, subcontractor flag. An unlogged BAA is functionally an unsigned one when an auditor asks.

Coding, Documentation, and the Compensation Formula

RVUs enter your compensation model through code selection, and code selection is a clinical and coding-professional determination — not an administrative one. Your job is the process around it, not the answer.

What administrators own

  • A written code-selection and documentation policy that identifies who assigns codes, who reviews, and how disagreements are resolved.
  • Credentialed coders or a coding vendor performing review against documentation, with findings routed back to providers.
  • A periodic internal audit schedule — sample size, frequency, and who reads the results.
  • Documented education when reviews show pattern issues.
  • Corrected claims workflow when a review finds a code that documentation doesn't support.

Never let a compensation formula sit in a room with no coding oversight. When productivity pay is tied to wRVUs and no one independently reviews code selection against documentation, you have created a financial incentive without a control. That is a compliance exposure regardless of anyone's intent, and it is exactly the pattern reviewers look for.

Keep the audit findings themselves under the same handling rules as any other PHI-bearing record. Coding audit workpapers contain patient-level detail. They should not live in a shared drive folder the whole business office can browse.

Billing Records Are Part of the Designated Record Set

Patients have a right of access to their billing and payment records, not just clinical notes. When a patient requests "everything you have about my visit," your response includes the charge detail — the codes, units, and amounts — that generated the RVU count.

You generally have 30 days to act, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Practical implications:

  • Your access-request procedure must name someone who can pull billing detail, not just chart notes.
  • Fees are limited to a reasonable, cost-based amount. "Whatever our billing vendor charges us for a custom report" is not automatically defensible.
  • If your billing company holds the records, your BAA must obligate them to support access requests within your timeline — not theirs. Check that clause on every renewal.

Five Questions Before You Approve the Next RVU Extract

  1. What is the recipient's stated purpose, in writing? No purpose, no file.
  2. Does the file contain any of the eighteen identifiers? Open it and look at the column headers. Dates of service count.
  3. Is there a signed BAA on file, and does it cover this service line? A BAA for claims submission doesn't automatically cover an analytics module the vendor added last year.
  4. How is the file moving? Secure portal or encrypted transfer — not an email attachment to a personal address.
  5. Who logged the disclosure? Date, recipient, data elements, approver. Ten seconds now, or a reconstruction project later.

Put those five questions on a one-page form and require a signature from the person approving the export. It converts an invisible four-minute action into a documented decision.

Your Next Step

Pull your vendor list this week and mark every entry that receives charge-level data. For each one, confirm an executed BAA covering the current scope of services. Where you find a gap, produce the agreement and get it signed before the next extract leaves your network. If the same review surfaces missing policies or a stale risk analysis, automating the underlying compliance document set is a faster path than rebuilding it in Word.

Now you know what does RVU stand for, how it converts to dollars, and — more usefully — which of your monthly reports is a permitted summary and which one is a disclosure waiting for a signature.