What Is RVU? A Practice Admin's Guide to the Numbers
It is the fifth business day of the month. Your CFO wants work RVUs by provider for January, your billing company emails a spreadsheet, and the spreadsheet has 4,200 rows — each one a patient name, date of service, procedure code, and rendering provider. That file lands in three inboxes and a shared drive before anyone asks whether it needed patient names at all.
That is the operational problem underneath the question what is RVU. The unit itself is simple arithmetic. The workflow that produces it moves protected health information through your billing vendor, your analytics tool, your compensation consultant, and a folder on somebody's laptop. This guide covers the mechanics accurately, then makes the records-handling and vendor implications explicit.
What Is an RVU? The Short Answer
An RVU — relative value unit — is the measure Medicare uses to express how much resource a given service consumes relative to every other service. It is a weight, not a dollar amount. Multiply the weight by a dollar conversion factor and you get a payment.
Every service on the Medicare Physician Fee Schedule carries three separate RVU components:
- Work RVU (wRVU) — clinician time, technical skill, mental effort, and stress. This is the component almost every physician compensation model keys on.
- Practice Expense RVU (PE RVU) — staff time, supplies, equipment, rent. Published in facility and non-facility versions, because your overhead differs when the hospital supplies the room.
- Malpractice RVU (MP RVU) — professional liability insurance cost attributable to that service.
Each component is adjusted by a Geographic Practice Cost Index (GPCI) for the locality where the service happened. The adjusted components are summed and multiplied by the annual conversion factor. That is the allowed amount before modifiers, sequestration, and payer-specific contract terms.
The formula, written out
[(wRVU × work GPCI) + (PE RVU × PE GPCI) + (MP RVU × MP GPCI)] × conversion factor = Medicare allowed amount.
CMS publishes the RVU values, the GPCIs, and the conversion factor every year in the Physician Fee Schedule final rule and the accompanying Physician Fee Schedule files on cms.gov. Download the current year's national RVU file yourself rather than trusting a vendor's cached copy — the values move annually, and beginning with the 2026 rule there are separate conversion factors depending on whether a clinician qualifies as an advanced alternative payment model participant. Your finance team needs to know which one applies before it models anything.
Work RVUs Are What Your Compensation Model Actually Uses
When a physician contract says "$52 per RVU," it almost always means per work RVU, not total RVU. The distinction is not cosmetic. Total RVUs for an in-office procedure can run several times the work component because the practice expense piece carries the supplies and staff. Pay a rate designed for wRVUs against total RVUs and you have just tripled somebody's compensation.
Worked example. Assume a clinician performs 140 encounters in a month. Suppose the codes billed carry an average of 1.6 work RVUs each. That is 224 wRVUs. At a contracted rate of $52 per wRVU, the productivity component of compensation for the month is $11,648 — independent of what any payer actually paid, and independent of whether the claim was collected.
That last point causes more disputes than any other. wRVU-based compensation is a volume and intensity measure. It does not care about your denial rate, your payer mix, or your days in A/R. Your comp plan should state explicitly whether wRVU credit is granted on charge entry, on claim submission, or on payment posting, because those three dates produce three different monthly numbers and three different arguments.
Who Assigns the Numbers, and What Your Staff Actually Decides
Practices do not set RVU values. CMS sets them, informed by recommendations from a specialty society committee that surveys physicians on time and intensity. You take the published values as given.
What happens inside your practice is code selection, and that is a documentation-driven process, not an RVU-driven one. The clinician documents the encounter. A certified coder — internal or at your billing vendor — reads the documentation and selects codes supported by what is written. RVU values attach afterward, as a consequence of the code.
Reverse that order and you have a compliance problem, not a productivity strategy. If your practice runs an RVU-per-encounter dashboard by provider, keep it away from the coding queue. Coders should never see a productivity target while they are assigning codes. Document that separation in your coding policy, name the person responsible for it, and re-affirm it in annual training. Auditors ask.
How practices document code selection
Build a written coding policy that identifies: which code set editions you use, who performs code assignment, what the escalation path is when documentation does not support a submitted code, how often you audit a sample of encounters per provider, and who reviews the audit results. Keep audit findings and the corrective actions taken. That file is the difference between an isolated error and a pattern.
The Monthly RVU Report Workflow, With Roles Attached
Here is a workable cadence. Adjust the dates, keep the role assignments.
- Days 1–3: Billing lead closes the prior month's charge entry and confirms no unposted encounters remain.
- Day 4: Billing vendor or internal RCM staff generates the RVU extract. Specify the fields in writing — provider NPI, service date, code, units, wRVU value, and nothing else.
- Day 5: Practice administrator reconciles encounter counts against the schedule to catch missing charges.
- Day 7: Aggregated wRVU totals by provider go to finance and to the compensation committee. Encounter-level detail does not.
- Day 10: Providers receive their individual numbers with a defined window to question them.
- Quarterly: Compliance officer samples the extract logic and confirms the RVU values used match the current CMS file.
Where RVU Data Stops Being Finance and Becomes PHI
A file containing patient names, dates of service, and procedure codes is protected health information. Attaching a wRVU column does not change that. The moment your productivity workflow pulls encounter-level detail, you are moving PHI — and every downstream recipient falls under HIPAA's vendor rules.
Run your RVU pipeline against this list:
- Billing company or RCM vendor — business associate. Needs a BAA.
- Analytics or business intelligence platform holding the extract — business associate, even if the only thing it does is chart totals.
- Compensation consultant reviewing provider productivity — business associate if they receive encounter-level data; not if they receive only aggregate provider totals with no patient-level rows.
- Benchmarking survey you submit to — typically aggregate provider-level counts only. Read the submission template before you assume.
- Accountant or outside CFO — business associate the instant PHI is in the file they receive.
- Contract coders and coding auditors — business associates.
If any name on that list is missing a signed agreement, fix it before the next reporting cycle. HHS publishes sample business associate agreement provisions, which are a starting point rather than a finished contract. When you need a signature-ready document for a new analytics tool or a compensation consultant this week, you can generate a complete Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you are onboarding a single vendor and not building a program.
The de-identification question people get wrong
Stripping the patient name is not de-identification. The Safe Harbor method requires removing all eighteen identifier categories, and full dates of service are one of them. A spreadsheet with dates of service and ZIP codes remains PHI even with names deleted. HHS's de-identification guidance walks through both Safe Harbor and expert determination.
The practical fix is upstream: ask your billing vendor to deliver the productivity extract already aggregated to provider-month totals. Most can. Then the file your finance team handles contains no patient rows at all, and half your exposure disappears without a single new control.
Minimum Necessary Applied to Your Productivity Dashboard
The minimum necessary standard governs internal uses, not just external disclosures. Your practice manager reviewing productivity does not need the same view as your coding auditor investigating a specific claim.
Write role-based access into your dashboard configuration:
- Finance and compensation committee: aggregate totals by provider and period. No patient identifiers.
- Practice administrator: aggregate plus encounter counts for reconciliation. Identifiers only if reconciliation genuinely requires them.
- Coding and compliance staff: full encounter detail, access logged.
- Individual providers: their own detail, not their colleagues'.
Then handle the exports. A dashboard with clean permissions is undone by one "Export to CSV" that lands in a personal downloads folder and gets emailed to a home address. Disable export for roles that do not need it, and cover the rule in training with a specific example rather than a general principle.
RVU Reports, Billing Records, and the 30-Day Access Clock
A patient's right of access reaches the designated record set, and billing and payment records used to make decisions about that patient are part of it. Your practice generally has 30 days to respond, with one 30-day extension available if you notify the patient in writing with a reason.
Internal productivity analytics — a provider's monthly wRVU total, a compensation model spreadsheet — are not part of the designated record set, because they are not used to make decisions about the individual patient. But the underlying claim, the codes submitted, and the payment record are. Train whoever answers records requests to tell the difference, and put it in writing so the answer does not depend on who is at the desk that day.
Six Things to Confirm Before the Next Comp Cycle
- Your RVU file is the current CMS release, and you know which conversion factor applies to each clinician.
- Your comp plan states whether it uses work RVUs or total RVUs, and at what trigger point credit is earned.
- Coders cannot see productivity targets while assigning codes, and that separation is documented.
- Every recipient of encounter-level RVU data has a signed, current BAA on file.
- The finance-facing report contains aggregate totals, not patient rows.
- Your records-request procedure distinguishes billing records from internal productivity analytics.
Answering what is RVU for your leadership team takes five minutes. Making sure the reporting pipeline behind it does not quietly create an unpapered vendor relationship takes an afternoon — and it is the part that shows up in a breach notification.
Start with the vendor list. Pull every party that receives your monthly extract, check for a signed agreement, and produce the missing BAAs before the next reporting cycle closes. If your broader documentation set — risk analysis, policies, workforce training records — has drifted since your last review, automated HIPAA compliance documentation will get it back to current faster than rebuilding it in a word processor.