Your compensation committee wants a work RVU report by provider, by month, split by site, emailed to five people before Friday's meeting. Your billing analyst can build it in about forty minutes. The part nobody assigned to anyone is the question that decides whether that spreadsheet is a routine operations report or a reportable breach: does the file carry patient-level detail, and does every recipient have a legitimate reason to see it?

This guide is for the people who run the practice — administrators, billing managers, privacy officers — not for clinicians choosing codes. It covers how wRVU numbers are produced, the four configuration decisions that make two reports disagree, and the vendor and records-handling obligations that attach the moment the data leaves your billing system.

What a Work RVU Measures — and What It Doesn't

A work RVU is one of three relative value units that Medicare assigns to each CPT/HCPCS code under the Resource-Based Relative Value Scale. The work component is intended to reflect physician time, technical skill, mental effort, and stress associated with performing the service.

The other two components are the practice expense RVU and the malpractice RVU. Medicare payment is calculated by adjusting all three for geographic cost differences and multiplying the total by an annual conversion factor. CMS publishes the underlying values each year in the Physician Fee Schedule relative value files, and you can pull them directly from the CMS Physician Fee Schedule pages.

What a wRVU does not measure:

  • Revenue. It is payer-blind. A commercial visit and a self-pay no-show-fee visit with the same code carry the same wRVU and wildly different collections.
  • Collections risk. Denials, write-offs, and bad debt do not touch the wRVU value unless your report is configured to strip reversed charges.
  • Overhead. Practice expense sits in a separate RVU component.
  • Quality. Nothing in the work component evaluates outcomes.

That last point matters operationally: when a compensation plan uses wRVUs as the sole productivity metric, you have built a volume incentive. Your coding audit program is the control that keeps that incentive honest.

Where Your Work RVU Numbers Actually Come From

Trace the chain before you defend a report to a physician who thinks it undercounts them.

An encounter is documented in the record. A coder or the clinician selects codes and modifiers. Charges post to the practice management system. Your reporting layer joins each posted charge to a relative value table and sums the work component by rendering provider. Somewhere in that chain, a report definition was written — usually years ago, usually by someone who has left.

The Four Decisions That Make Two Reports Disagree

Which RVU file year you apply. CMS revises values annually. If your report pulls the current-year file and applies it retroactively to prior-period charges, a physician's 2025 production will shift when you rerun the same report in 2026. Pick a convention — freeze the file year for the duration of a compensation cycle, or restate annually — and write it into the compensation plan document.

Date of service versus date of posting. A December encounter posted in January lands in different months under each convention. Surgical practices with long charge lags feel this hardest.

Modifier handling. Bilateral procedures, reduced services, co-surgery, assistant-at-surgery, and multiple-procedure situations all carry payment adjustments. Whether your report applies those percentage reductions to the work component is a configuration setting, not a law of nature. Document which convention you use.

Denied and reversed charges. If a charge is voided, does the wRVU credit reverse? Most systems can do it either way. Choose once.

Put those four answers in a one-page methodology memo and attach it to every report you distribute. It eliminates most disputes before they start.

Code Selection Is a Documentation Process, Not a Compensation Lever

Your role as an administrator is not to tell a clinician which code fits a visit. It is to make sure the selection is supported by the documentation in the record, applied consistently, and auditable after the fact.

Practically, that means three standing controls:

  1. A written coding policy naming who selects codes, who reviews them, and how disagreements get resolved.
  2. Periodic chart sampling by someone who does not report to the clinician being reviewed, with a defined sample size and a documented remediation path for findings.
  3. Distribution reviews that flag outlier patterns by provider against internal and specialty peers — as a trigger for review, never as a conclusion.

When wRVUs drive pay, the compliance question an auditor asks is whether the practice noticed the incentive and built a check against it. HHS OIG's compliance program resources are the reference your policy should cite.

Your wRVU Report Is Probably PHI

Here is where most practices get sloppy. A provider-level summary — one row per physician, one column per month — usually contains no patient identifiers and is not PHI. But almost nobody builds that summary from thin air. The analyst exports a detail extract with account numbers, dates of service, and codes, pivots it, and emails the workbook with the detail tab still in it.

That detail extract is protected health information. Dates of service and account numbers are identifiers under the Safe Harbor list. A file that ties a patient account to a procedure code on a specific date is a chart fragment, and it just went to five inboxes.

Using that data internally is permitted. Evaluating practitioner performance, business planning, and general administrative activities all fall within "health care operations" under the Privacy Rule. Permission is not the issue. Scope is.

Minimum Necessary, Applied to Compensation Reporting

The minimum necessary standard requires you to limit access to what the role actually needs. Translate that into a distribution matrix:

  • Compensation committee and board: aggregated wRVU totals by provider and period. No patient-level rows, ever.
  • Department chair or medical director: aggregated totals plus code-mix distributions, no patient identifiers.
  • Coding auditor and billing manager: full detail, because reconciling a disputed number requires the encounter.
  • Individual clinician: their own detail, on request, through a defined channel.

Enforce it structurally. Build the summary in a separate file that the reporting tool generates directly, rather than as a tab in the detail workbook. Restrict the detail export to two named accounts. Turn off the "email report" button for everyone else.

Every Vendor That Touches Work RVU Data Needs a BAA

Walk the chain again and mark each external party. In a typical mid-sized group, wRVU data passes through more hands than the administrator expects:

  • The revenue cycle management or outsourced billing company
  • The clearinghouse processing claims
  • The business intelligence or dashboard vendor hosting your reporting layer
  • The cloud storage or file-sharing service where the workbook lands
  • The compensation consultant modeling next year's plan
  • The coding audit firm sampling your charts
  • Any interim CFO, locum staffing agency, or valuation firm doing diligence

Each of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. HHS explains the boundary in its business associate guidance. The consultant who receives only de-identified aggregates is not a business associate. The consultant who asks for "the raw charge file so we can model it ourselves" absolutely is.

The failure mode is predictable: the billing company has a BAA from 2018, the analytics vendor has one, and the compensation consultant — engaged in March, urgent, partner-recommended — has a signed engagement letter and nothing else. If you are staring at that gap right now, you can generate a signature-ready Business Associate Agreement through a six-step wizard and have a PDF or DOCX in front of the consultant before the first data pull. One-time purchase, no subscription — appropriate for exactly this kind of one-off engagement.

The Vendor Questions Worth Asking Before the First Export

  1. What is the minimum data set you need? Push for provider-level aggregates first.
  2. Where does the data live, and for how long after the engagement ends?
  3. Who at your firm has access, and are subcontractors involved?
  4. How is the file transmitted? Email attachments are the single most common leak point in this workflow.
  5. What is your breach notification timeline to us, and does it match our BAA?

Submitting to Benchmark Surveys Without Handing Over PHI

Specialty compensation surveys want provider-level wRVU totals, compensation, FTE status, and specialty. Provider-level totals with no patient identifiers generally are not PHI — but check the actual file rather than assuming, because survey templates sometimes request encounter counts by service date range or payer detail that pulls identifiers along with it.

If a submission does require identifiable data, either de-identify under Safe Harbor by stripping the eighteen identifier categories or use expert determination. HHS's de-identification guidance covers both paths. Watch small-cell risk: in a two-physician subspecialty in a rural county, "aggregate" and "identifiable" converge faster than people think.

Role Assignments and a 60-Day Cleanup Sequence

Days 1–10. Billing manager documents the current report definition: RVU file year, date convention, modifier handling, reversal treatment. Privacy officer inventories every existing wRVU report and its distribution list.

Days 11–25. Privacy officer maps each report recipient against the distribution matrix above and revokes access that fails minimum necessary. IT or your EHR administrator restricts detail-level exports to named accounts and enables logging on those exports.

Days 26–40. Compliance lead cross-checks the vendor list against signed BAAs. Every gap gets an agreement executed before the next data transfer, not after. While you are in the vendor file, confirm your broader risk analysis and policy set reflect the reporting stack you actually use — automated risk analysis and policy generation shortens that cycle considerably if your documentation is stale.

Days 41–60. Administrator publishes the methodology memo, attaches it to the next compensation report, and briefs the committee on what the numbers do and do not represent. Coding auditor schedules the next sampling cycle.

When a Physician Disputes the Numbers

Expect it during every compensation cycle. The dispute is almost always a configuration disagreement, not a data error — a surgeon comparing date-of-service totals against your date-of-posting report, or a hospitalist whose modifier-adjusted charges dropped below expectation.

Handle it with a defined process. The clinician requests their own detail through the billing manager. The billing manager produces the encounter-level extract, restricted to that clinician's rendered services. The methodology memo explains the convention. Retain the request, the extract scope, and the resolution — HIPAA requires six-year retention of required documentation, and a documented dispute trail is what you hand an auditor who asks whether your compensation data is governed.

One boundary to keep clear for your front desk: a clinician asking for wRVU detail is an internal operations request. A patient asking for their record is a right-of-access request with its own 30-day clock. Different workflows, different owners, different logs.

Start With the Vendor Gap

Of everything above, the item that creates the most exposure for the least effort to fix is the unpapered vendor. Pull your list of everyone who has received a wRVU extract in the past twelve months, match it against your executed agreements, and close the gaps this week. If you find one, build the agreement and export it for signature before the next data request lands in your inbox.