08/27/2026
๐๐ข๐ช๐ก๐๐ข๐๐๐ก๐ ๐๐ก๐ ๐จ๐ก๐๐๐ฅ๐ฃ๐๐ฌ๐ ๐๐ก๐ง ๐๐ฌ ๐๐ก๐ฆ๐จ๐ฅ๐๐ก๐๐ ๐๐ข๐ ๐ฃ๐๐ก๐๐๐ฆ ๐๐๐ฆ๐๐ฅ๐ฉ๐ ๐ฆ๐ฌ๐ฆ๐ง๐๐ ๐๐ ๐ฆ๐๐ฅ๐จ๐ง๐๐ก๐ฌ ๐๐ก๐ ๐ง๐๐๐ฅ๐ ๐๐ฆ ๐ ๐๐๐ฃ๐๐/๐ฃ๐ฅ๐๐ฉ๐๐๐ฌ ๐ค๐จ๐๐ฆ๐ง๐๐ข๐ก ๐ช๐ ๐ฆ๐๐ข๐จ๐๐ ๐๐ ๐๐ฆ๐๐๐ก๐.
Whether the disputed service involves Evaluation & Management (E/M) codes such as 99203โ99205 or 99213โ99215, or psychotherapy codes such as 90832, 90834, or 90837, providers are increasingly confronting payment methodologies that reduce the level of service submitted.
๐ง๐ต๐ฒ๐ฟ๐ฒ ๐ถ๐ ๐ฎ๐ป๐ผ๐๐ต๐ฒ๐ฟ ๐ฝ๐ฎ๐ฟ๐ ๐ผ๐ณ ๐๐ต๐ถ๐ ๐ถ๐๐๐๐ฒ ๐๐ต๐ฎ๐ ๐ฑ๐ฒ๐๐ฒ๐ฟ๐๐ฒ๐ ๐ฎ๐๐๐ฒ๐ป๐๐ถ๐ผ๐ป, What happens to patients' protected health information (PHI) when providers are required to submit clinical records to challenge those reductions?
HIPAA permits certain uses and disclosures of PHI for Treatment, Payment, and Health Care Operations (TPO) without obtaining a separate patient authorization.
๐ง๐ต๐ถ๐ ๐ฑ๐ผ๐ฒ๐ ๐ป๐ผ๐ ๐บ๐ฒ๐ฎ๐ป โ๐ง๐ฃ๐ขโ ๐ฐ๐ฟ๐ฒ๐ฎ๐๐ฒ๐ ๐๐ป๐น๐ถ๐บ๐ถ๐๐ฒ๐ฑ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ ๐ฎ ๐ฝ๐ฎ๐๐ถ๐ฒ๐ป๐'๐ ๐บ๐ฒ๐ฑ๐ถ๐ฐ๐ฎ๐น ๐ฟ๐ฒ๐ฐ๐ผ๐ฟ๐ฑ.
For payment and health care operations, HIPAA's minimum-necessary standard generally applies. Covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose.
See:
45 C.F.R. ยง 164.502(b) โ Minimum Necessary
45 C.F.R. ยง 164.514(d) โ Minimum Necessary Requirements
45 C.F.R. ยง 164.506 โ Treatment, Payment, and Health Care Operations
45 C.F.R. ยงยง 160.202โ160.203 โ HIPAA preemption and more stringent state privacy protections
HIPAA's definition of โpaymentโ is broad. It includes activities associated with claims adjudication, billing, determining coverage, utilization review, medical-necessity review, and related functions.
Therefore, an insurer may legitimately need clinical information to determine whether a submitted service is supported.
๐ง๐ต๐ถ๐ ๐ถ๐ ๐ผ๐ป๐น๐ ๐๐ต๐ฒ ๐ฏ๐ฒ๐ด๐ถ๐ป๐ป๐ถ๐ป๐ด ๐ผ๐ณ ๐๐ต๐ฒ ๐ฎ๐ป๐ฎ๐น๐๐๐ถ๐, ๐ป๐ผ๐ ๐๐ต๐ฒ ๐ฒ๐ป๐ฑ.
๐๐ข๐ก๐ฆ๐๐๐๐ฅ ๐ ๐ฃ๐ฆ๐ฌ๐๐๐๐๐ง๐ฅ๐๐ ๐ต๐ต๐ฎ๐ญ๐ฐ
A provider submits CPT 99214.
The insurer reduces payment to 99213.
The provider disputes the reduction.
The insurer requires the provider to submit the psychiatric encounter note to challenge the determination.
The encounter note may contain information about:
โข childhood sexual trauma;
โข domestic violence;
โข suicidal thoughts;
โข hallucinations or delusions;
โข substance use;
โข sexual history;
โข marital problems;
โข family conflicts;
โข abuse;
โข pregnancy;
โข employment problems;
โข legal issues;
โข previous psychiatric hospitalizations;
โข highly sensitive social history;
โข information concerning spouses, children, or other third parties; and
โข psychotherapy-related discussions.
Some of that information may be relevant to the service under review.
๐ฆ๐ผ๐บ๐ฒ ๐บ๐ฎ๐ ๐ต๐ฎ๐๐ฒ ๐น๐ถ๐๐๐น๐ฒ ๐ผ๐ฟ ๐ป๐ผ๐๐ต๐ถ๐ป๐ด ๐๐ผ ๐ฑ๐ผ ๐๐ถ๐๐ต ๐๐ต๐ฒ๐๐ต๐ฒ๐ฟ ๐๐ต๐ฒ ๐ฒ๐ป๐ฐ๐ผ๐๐ป๐๐ฒ๐ฟ ๐๐ฎ๐๐ถ๐๐ณ๐ถ๐ฒ๐ ๐๐ต๐ฒ ๐ฐ๐ผ๐ฑ๐ถ๐ป๐ด ๐ฟ๐ฒ๐พ๐๐ถ๐ฟ๐ฒ๐บ๐ฒ๐ป๐๐ ๐ณ๐ผ๐ฟ ๐ต๐ต๐ฎ๐ญ๐ฐ.
A legitimate payment purpose does not automatically make every clinical detail equally necessary to accomplish that purpose.
๐ง๐ต๐ถ๐ ๐ฑ๐ถ๐๐๐ถ๐ป๐ฐ๐๐ถ๐ผ๐ป ๐ฏ๐ฒ๐ฐ๐ผ๐บ๐ฒ๐ ๐ฝ๐ฎ๐ฟ๐๐ถ๐ฐ๐๐น๐ฎ๐ฟ๐น๐ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐ ๐๐ต๐ฒ๐ป ๐ฑ๐ผ๐๐ป๐ฐ๐ผ๐ฑ๐ถ๐ป๐ด ๐ถ๐ ๐ฝ๐ฒ๐ฟ๐ณ๐ผ๐ฟ๐บ๐ฒ๐ฑ ๐๐๐๐๐ฒ๐บ๐ฎ๐๐ถ๐ฐ๐ฎ๐น๐น๐ ๐ผ๐ฟ ๐๐ต๐ฟ๐ผ๐๐ด๐ต ๐ฎ๐๐๐ผ๐บ๐ฎ๐๐ฒ๐ฑ ๐ฝ๐ฎ๐๐บ๐ฒ๐ป๐-๐ถ๐ป๐๐ฒ๐ด๐ฟ๐ถ๐๐ ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐๐ฒ๐.
๐๐ข๐ก๐ฆ๐๐๐๐ฅ ๐ง๐๐๐ฆ ๐ช๐ข๐ฅ๐๐๐๐ข๐ช
Provider submits 99214 โ payer reduces it to 99213 without reviewing the clinical note โ provider challenges the reduction โ payer requires the encounter note โ provider transmits highly sensitive psychiatric PHI โ payer reviews the record and decides whether to restore payment.
This raises questions extending far beyond whether the insurer is a HIPAA covered entity:
Why was this particular record necessary?
What PHI was actually necessary to resolve the coding dispute?
Could less PHI accomplish the same coding-validation purpose?
Was the records request generated pursuant to a routine or automated protocol?
What minimum-necessary analysis applies to that protocol?
Who receives and accesses the recordsโthe health plan, a payment-integrity vendor, an AI/algorithm vendor, or another contractor?
How long are the records retained?
What happens to the information after the coding review is completed?
Can the information subsequently be used for another purpose?
๐ง๐ต๐ผ๐๐ฒ ๐ฎ๐ฟ๐ฒ ๐น๐ฒ๐ด๐ถ๐๐ถ๐บ๐ฎ๐๐ฒ ๐ฝ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐ฎ๐ป๐ฑ ๐ฐ๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ ๐พ๐๐ฒ๐๐๐ถ๐ผ๐ป๐.
๐ง๐๐๐ฆ ๐๐๐๐ข๐ ๐๐ฆ ๐ ๐ฆ๐๐๐๐ ๐๐ฆ๐ฆ๐จ๐
Consider a hypothetical example: If 100 behavioral-health clinicians each have 1,000 claims subjected to systematic coding reductions annually, and clinical documentation must be submitted to challenge those reductions, that could result in as many as 100,000 clinical records becoming part of payment disputes.
Without those disputes, the insurer ordinarily receives claims data, not necessarily the underlying narrative psychiatric documentation for every encounter.
This raises a question I believe regulators should examine; Can a health plan systematically create payment disputes and then rely upon the HIPAA payment exception to obtain the sensitive PHI providers must disclose to reverse those insurer-initiated reductions?
More specifically, Does a routine and recurring records-request process associated with systematic or automated downcoding satisfy HIPAA's minimum-necessary requirements?
๐ง๐ต๐ถ๐ ๐ถ๐ ๐ฎ ๐พ๐๐ฒ๐๐๐ถ๐ผ๐ป ๐๐ผ๐ฟ๐๐ต ๐ฝ๐๐๐๐ถ๐ป๐ด ๐ฏ๐ฒ๐ณ๐ผ๐ฟ๐ฒ ๐๐ต๐ฒ ๐จ.๐ฆ. ๐๐ฒ๐ฝ๐ฎ๐ฟ๐๐บ๐ฒ๐ป๐ ๐ผ๐ณ ๐๐ฒ๐ฎ๐น๐๐ต ๐ฎ๐ป๐ฑ ๐๐๐บ๐ฎ๐ป ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ ๐ข๐ณ๐ณ๐ถ๐ฐ๐ฒ ๐ณ๐ผ๐ฟ ๐๐ถ๐๐ถ๐น ๐ฅ๐ถ๐ด๐ต๐๐ (๐ข๐๐ฅ).
Letโs think about what the insurer already has.
A professional claim already provides significant information, including:
โข CPT/HCPCS codes;
โข ICD-10-CM diagnoses;
โข provider identity;
โข provider specialty;
โข patient identity;
โข date of service;
โข place of service;
โข modifiers;
โข charges; and
โข other reported services.
If an insurer makes the initial determination that โ99214 should be paid as 99213โ without reviewing the underlying encounter documentation, another question naturally follows.
What information was sufficient to justify reducing the provider-selected code in the first place?
And then, Why is the patient's psychiatric encounter note required to restore the payment when that record was not required to reduce it?
๐ง๐ต๐ถ๐ ๐ฑ๐ผ๐ฒ๐ ๐ป๐ผ๐, ๐ฏ๐ ๐ถ๐๐๐ฒ๐น๐ณ, ๐ฒ๐๐๐ฎ๐ฏ๐น๐ถ๐๐ต ๐ฎ ๐๐๐ฃ๐๐ ๐๐ถ๐ผ๐น๐ฎ๐๐ถ๐ผ๐ป. ๐๐ ๐ฑ๐ผ๐ฒ๐ ๐ฒ๐๐๐ฎ๐ฏ๐น๐ถ๐๐ต ๐ฎ ๐พ๐๐ฒ๐๐๐ถ๐ผ๐ป ๐๐ผ๐ฟ๐๐ต ๐ฎ๐ป๐๐๐ฒ๐ฟ๐ถ๐ป๐ด.
Psychiatric records deserve particular attention.
A psychiatric encounter note is not comparable to a simple laboratory result. Psychiatric and psychotherapy documentation can contain some of the most sensitive information maintained anywhere in a patient's medical record.
Meanwhile, the coding dispute may concern something far narrower.
For an E/M service, for example, the issue may be whether the encounter satisfies the AMA CPT requirements for moderate medical decision making. Prescription drug management may contribute to moderate risk, while the problems addressed and/or data may establish the remaining MDM requirements.
This raises another important question, Does an insurer actually need every clinical detail contained in the psychiatric encounter note to validate 99214, or could a more limited coding-validation record accomplish the legitimate payment purpose?
For psychotherapy, the relevant coding question may concern the documented psychotherapy time and whether the service supports 90832, 90834, or 90837.
Again, What PHI is actually necessary to resolve that question?
๐ช๐ต๐ฎ๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป๐ ๐๐ผ ๐๐ต๐ฒ ๐ฟ๐ฒ๐ฐ๐ผ๐ฟ๐ฑ ๐ฎ๐ณ๐๐ฒ๐ฟ๐๐ฎ๐ฟ๐ฑ?
I want to know:
โข Who actually receives the clinical note, the insurance company or a vendor?
โข Is the note ingested into a payment-integrity platform?
โข How long is it retained?
โข Who can subsequently access it?
โข Is information extracted from the note?
โข Is it incorporated into provider profiling?
โข Is it used in future payment-integrity decisions?
โข Is it incorporated into fraud, waste, and abuse analytics?
โข Is it used to develop, validate, train, or refine automated models or algorithms?
โข Does information obtained from one disputed claim influence future claims?
โข Can a third-party vendor use the information for any secondary purpose?
โข What controls prevent impermissible secondary use or redisclosure?
๐๐๐๐ฆ ๐ถ๐ ๐ฐ๐๐ฟ๐ฟ๐ฒ๐ป๐๐น๐ ๐๐ต๐ฒ ๐ฒ๐
๐ฎ๐บ๐ฝ๐น๐ฒ ๐๐ผ๐ฟ๐๐ต ๐๐ฎ๐๐ฐ๐ต๐ถ๐ป๐ด!
BCBSโs Level of Service Validation program has brought downcoding into the spotlight.
Where a payment methodology reduces submitted levels of service without first reviewing the underlying clinical documentation, but providers must subsequently disclose confidential encounter records to challenge those reductions, the privacy question deserves independent examination.
The issue is not simply whether an individual encounter note can legally be disclosed under HIPAA's payment exception.
The larger question is, Does a routine and recurring records-request protocol generated by a systematic downcoding program comply with the minimum-necessary requirements of 45 C.F.R. ยงยง 164.502(b) and 164.514(d)?
For mental-health records, Do more stringent state mental-health confidentiality laws impose additional limitations on the scope, use, retention, or redisclosure of those records?
๐ง๐ต๐ฒ ๐ค๐๐ฒ๐๐๐ถ๐ผ๐ป ๐ ๐๐ฎ๐ป๐ ๐ข๐๐ฅ ๐๐ผ ๐๐ป๐๐๐ฒ๐ฟ ๐ถ๐ ๐ถ๐ณ ๐๐ต๐ผ๐๐๐ฎ๐ป๐ฑ๐ ๐ผ๐ณ ๐ฝ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ๐ ๐บ๐๐๐ ๐ฟ๐ผ๐๐๐ถ๐ป๐ฒ๐น๐ ๐๐๐ฟ๐ฟ๐ฒ๐ป๐ฑ๐ฒ๐ฟ ๐ต๐ถ๐ด๐ต๐น๐ ๐๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐ฝ๐๐๐ฐ๐ต๐ถ๐ฎ๐๐ฟ๐ถ๐ฐ ๐ฎ๐ป๐ฑ ๐ฝ๐๐๐ฐ๐ต๐ผ๐๐ต๐ฒ๐ฟ๐ฎ๐ฝ๐ ๐ฑ๐ผ๐ฐ๐๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป ๐บ๐ฒ๐ฟ๐ฒ๐น๐ ๐๐ผ ๐ฐ๐ผ๐ป๐๐ฒ๐๐ ๐ฝ๐ฎ๐๐บ๐ฒ๐ป๐ ๐ฟ๐ฒ๐ฑ๐๐ฐ๐๐ถ๐ผ๐ป๐ ๐ถ๐ป๐ถ๐๐ถ๐ฎ๐๐ฒ๐ฑ ๐ฏ๐ ๐ฎ๐ป ๐ถ๐ป๐๐๐ฟ๐ฒ๐ฟ, ๐ถ๐ ๐๐ต๐ฎ๐ ๐ฟ๐ฒ๐ฐ๐ผ๐ฟ๐ฑ๐ ๐ฟ๐ฒ๐พ๐๐ฒ๐๐ ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ๐ฑ ๐๐ผ ๐๐ฎ๐๐ถ๐๐ณ๐ ๐๐๐ฃ๐๐'๐ ๐บ๐ถ๐ป๐ถ๐บ๐๐บ-๐ป๐ฒ๐ฐ๐ฒ๐๐๐ฎ๐ฟ๐ ๐๐๐ฎ๐ป๐ฑ๐ฎ๐ฟ๐ฑ?
Or
๐๐ฎ๐ โ๐ฝ๐ฎ๐๐บ๐ฒ๐ป๐/๐ต๐ฒ๐ฎ๐น๐๐ต ๐ฐ๐ฎ๐ฟ๐ฒ ๐ผ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐โ ๐ฒ๐ณ๐ณ๐ฒ๐ฐ๐๐ถ๐๐ฒ๐น๐ ๐ฏ๐ฒ๐ฐ๐ผ๐บ๐ฒ ๐ฎ ๐บ๐ฒ๐ฐ๐ต๐ฎ๐ป๐ถ๐๐บ ๐๐ต๐ฟ๐ผ๐๐ด๐ต ๐๐ต๐ถ๐ฐ๐ต ๐ฒ๐ป๐ผ๐ฟ๐บ๐ผ๐๐ ๐๐ผ๐น๐๐บ๐ฒ๐ ๐ผ๐ณ ๐๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐ฐ๐น๐ถ๐ป๐ถ๐ฐ๐ฎ๐น ๐ฑ๐ผ๐ฐ๐๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป ๐ฎ๐ฟ๐ฒ ๐ผ๐ฏ๐๐ฎ๐ถ๐ป๐ฒ๐ฑ ๐ฏ๐ฒ๐ฐ๐ฎ๐๐๐ฒ ๐ฝ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ๐ ๐ต๐ฎ๐๐ฒ ๐ป๐ผ ๐บ๐ฒ๐ฎ๐ป๐ถ๐ป๐ด๐ณ๐๐น ๐๐ฎ๐ ๐๐ผ ๐ฐ๐ต๐ฎ๐น๐น๐ฒ๐ป๐ด๐ฒ ๐๐ต๐ฒ ๐ฝ๐ฎ๐๐บ๐ฒ๐ป๐ ๐ฑ๐ฒ๐๐ฒ๐ฟ๐บ๐ถ๐ป๐ฎ๐๐ถ๐ผ๐ป ๐๐ถ๐๐ต๐ผ๐๐ ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐ถ๐ป๐ด ๐ถ๐?
One final question is if the insurer did not need the patient's clinical record to determine that the provider's code should be reduced, why does it need the patient's clinical record before it will consider restoring that code?
This is not an accusation that every records request violates HIPAA. It is a regulatory question.
And considering the scale of automated and systematic payment-integrity programs, it is one I believe the HHS Office for Civil Rights should examine.
๐ง๐ต๐ถ๐ ๐ถ๐ ๐๐ต๐ฎ๐ ๐ ๐๐ผ๐๐น๐ฑ ๐ฝ๐๐ ๐ฏ๐ฒ๐ณ๐ผ๐ฟ๐ฒ ๐ข๐๐ฅ!
Centralized Case Management Operations
U.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Room 509F HHH Bldg.
Washington, D.C. 20201
Email: [[email protected]](mailto:[email protected])
I respectfully request that the U.S. Department of Health and Human Services Office for Civil Rights (OCR) investigate whether [Health Plan]'s systematic or automated downcoding and associated medical-record-request practices comply with the HIPAA Privacy Rule's minimum-necessary requirements under 45 C.F.R. ยงยง 164.502(b) and 164.514(d).
The health plan routinely reduces claims submitted at higher levels of service, including [identify CPT codes], without first reviewing the underlying clinical documentation, yet requires providers to disclose the corresponding encounter records including highly sensitive mental-health information to challenge those reductions and obtain reconsideration of the originally submitted code.
This process potentially results in large-scale disclosures of PHI that would not otherwise have occurred. I am not alleging that every payment-related request for clinical documentation is prohibited by HIPAA; rather, I am asking OCR to determine whether the health plan's routine and recurring records-request protocol is appropriately limited to the minimum PHI reasonably necessary to accomplish its stated payment purpose.
I further request that OCR examine what information is actually necessary to validate the disputed codes; whether less intrusive documentation could accomplish that purpose; whether these requests are generated automatically; what minimum-necessary policies and criteria govern them; whether the records are received or processed by the health plan or third-party payment-integrity, technology, or algorithmic vendors; how the PHI is accessed, retained, used, and redisclosed after the review; and whether information obtained through these payment disputes is subsequently used for provider profiling, fraud/waste/abuse analytics, future claims determinations, or the development, validation, training, or refinement of automated payment models.
Of particular concern is a process in which the health plan apparently determines that a provider-selected code should be reduced without reviewing the patient's clinical record, but then requires disclosure of that sensitive record before it will consider restoring the code.
I respectfully ask OCR to determine whether such a systematic process complies with HIPAA's minimum-necessary requirements and other applicable Privacy Rule protections.