Internal medicine E/M coding and MDM leveling: 99202–99215.
The classic internal medicine visit — three or four chronic conditions, all being actively managed at once, plus whatever brought the patient in that day — is exactly the case the current E/M guidelines were built around, and it's also where coders most reliably leave a level on the table. This guide is the full MDM leveling mechanics for that visit: how problem complexity actually counts stable versus exacerbating conditions, what the data and risk elements require, the time-based pathway as a standalone alternative to MDM, and the prolonged-services codes that pick up where the level-5 range ends.
Key takeaways
- Overall MDM level is set by two of three elements, not the problem list alone. A visit can reach high MDM on data and risk even when problem complexity itself only clears moderate — coders who stop at counting diagnoses miss this constantly.
- Time and MDM are alternative pathways, not additive. Fully satisfying either one independently justifies the code — a short visit with high-complexity MDM and a long visit with straightforward MDM can both land on the same level, for different reasons.
- 99417 and G2212 trigger at different total-time thresholds on different payers. 99417 keys off the level-5 code's minimum time plus 15 minutes; G2212 keys off the maximum plus 15 minutes — a 14-to-20-minute gap that decides whether a claim is billable at all.
- The default-to-99214 trap costs real revenue. Three or more stable chronic conditions plus a new problem, paired with data or risk elements that independently reach high, routinely supports 99215 — and gets billed a level down anyway.
Time or MDM: two independent pathways, not two hoops to clear
Established-patient office visits (99212–99215) and new-patient visits (99202–99205) are billed on either total time or medical decision making — fully satisfying either pathway alone justifies the code. You don't need both, and you don't average them. A visit that clearly documents high-complexity MDM supports 99215 even at 25 minutes; a visit that runs long on straightforward medical decision making can still support a higher level purely on time. Pick whichever pathway the documentation actually supports and code to that one.
| Established patient | Time range | New patient | Time range |
|---|---|---|---|
99212 | 10–19 min | 99202 | 15–29 min |
99213 | 20–29 min | 99203 | 30–44 min |
99214 | 30–39 min | 99204 | 45–59 min |
99215 | 40–54 min | 99205 | 60–74 min |
Time-based billing only works if the total is actually documented as a number, not implied by a long note. If a coder can't point to a stated duration (or a start and stop time) that falls inside the code's range, the visit has to be leveled on MDM instead, whatever the note's length suggests about how long the visit probably took.
Problem complexity: counting stable versus exacerbating chronic illness
This is the element multi-chronic-condition visits hinge on, and it's the one coders count most mechanically — which is exactly why it's the most commonly miscounted. The distinction that actually matters isn't how many chronic diagnoses appear on the assessment, it's the status of each one on the day of the visit.
| Level | What qualifies |
|---|---|
| Straightforward (99202/99212) | One self-limited or minor problem |
| Low (99203/99213) | Two or more self-limited/minor problems, or one stable chronic illness, or one acute uncomplicated illness or injury |
| Moderate (99204/99214) | Two or more stable chronic illnesses, or one chronic illness with exacerbation/progression/treatment side effects, or one undiagnosed new problem with uncertain prognosis, or one acute illness with systemic symptoms |
| High (99205/99215) | One or more chronic illnesses with severe exacerbation, progression, or treatment side effects, or an acute or chronic illness/injury that poses a threat to life or bodily function |
Three well-controlled, stable chronic conditions — hypertension at goal, diabetes with a stable A1c, treated hyperlipidemia — is moderate complexity by problem count alone, and stops there on the problem-complexity axis no matter how many additional stable diagnoses get listed. What pushes a visit to high on this axis specifically is severity of change, not volume: one of those conditions genuinely decompensating — an A1c that jumped two points, a GFR that dropped a CKD stage, blood pressure no longer controlled on the current regimen — or a new acute finding that threatens life or bodily function. Adding a fourth or fifth stable diagnosis to the list doesn't do it; documenting that one of them stopped being stable does.
Where the real level often comes from: data and risk, not problem count
This is the part of the trap most guides skip. Overall MDM level is set by whichever two of the three elements — problem complexity, data reviewed and analyzed, and risk — reach the highest level together. A visit can land on high MDM with only moderate problem complexity, if data and risk both independently clear the high bar.
Data reviewed and analyzed is scored across three categories: reviewing prior external notes, tests, or orders and factoring in an independent historian's input (category 1); independently interpreting a test performed by another provider, not just reading their report (category 2); and discussing management or test interpretation directly with an external physician, other qualified health professional, or appropriate source (category 3). Moderate-complexity data generally requires meeting a threshold across several category-1 elements, or hitting category 2 or category 3 once on its own. High-complexity data typically requires a combination that reaches a higher threshold across category 1, or category 3 discussion paired with independent interpretation. For a multi-chronic-condition IM visit, reviewing recent labs, an outside cardiology note, and discussing an abnormal result with the ordering specialist by phone is a realistic route to high-complexity data — and it's routinely under-documented, because the phone discussion never makes it into the note as a discrete, dated entry with the other party named.
| Level | What qualifies |
|---|---|
| Moderate | Prescription drug management (starting, stopping, or adjusting a medication); decision regarding minor surgery with identified patient or procedure risk factors; social determinants of health significantly limiting diagnosis or treatment |
| High | Drug therapy requiring intensive monitoring for toxicity; decision regarding hospitalization; decision regarding parenteral controlled substances; decision not to resuscitate or to de-escalate care given a poor prognosis |
Adjusting insulin, titrating an anticoagulant, or starting a medication that needs lab monitoring for toxicity — methotrexate, lithium, an ACE inhibitor and diuretic combination in a patient with reduced renal function — genuinely reaches high risk. But only if the note documents the monitoring plan explicitly: what's being monitored, and when. A prescription listed in the plan without the monitoring rationale reads as moderate risk, not high, even when the clinical reality was high risk the whole time.
A 62-year-old established patient with stable hypertension, stable type 2 diabetes, and stable hyperlipidemia comes in for a scheduled follow-up and reports two weeks of dysuria and urinary frequency. Problem complexity: three stable chronic conditions plus a new problem with systemic-symptom features — moderate on this axis alone. A coder who stops there defaults to 99214. But the same visit includes reviewing a recent BMP and A1c, plus a phone discussion with the patient's nephrologist about a borderline creatinine trend (high-complexity data), and starting nitrofurantoin while adjusting the ACE inhibitor dose pending the creatinine recheck — a monitoring decision that reaches high risk once the note states the plan. Two of the three MDM elements — data and risk — are now at high, which makes the overall visit high MDM and supports 99215, regardless of what problem complexity alone would suggest. Run a monthly sample of your practice's 99214s against the actual note text for a documented specialist discussion, an intensive-monitoring drug, or a hospitalization decision; that sample reliably finds 99215-supportable visits billed a level down.
Prolonged services: 99417 versus G2212
Once a visit runs past the level-5 time range, the add-on code depends entirely on which payer you're billing, and mixing the two up is a clean, avoidable denial. Both add units of extra time to 99205 or 99215 billed on total time — neither applies if the visit is leveled on MDM instead of time.
| Code | Payer | Threshold rule | Total minutes for 99205 | Total minutes for 99215 |
|---|---|---|---|---|
99417 | Commercial payers following CPT time rules | Level-5 code's minimum time + 15 min for the first unit | 75 min | 55 min |
G2212 | Medicare | Level-5 code's maximum time + 15 min for the first unit | 89 min | 69 min |
The gap between the two thresholds is 14 to 20 minutes, which is exactly the range where a practice bills the wrong code on the wrong payer: a Medicare claim at 80 minutes for a 99205-level visit clears the 99417 threshold (75 minutes) but falls short of G2212's 89-minute Medicare threshold, so a 99417 unit appended to that Medicare claim denies as an invalid code for the payer, while a G2212 unit appended to it denies as not meeting the time requirement. Neither is a documentation problem — both are a payer-mapping problem, fixable by tying the prolonged-services code to the payer at the scrubber level rather than leaving it to the coder's memory per claim. ⚠️ These specific minute thresholds are the industry-standard figures reported consistently across coding references and match CPT's and CMS's own published structure for the two codes, but this build could not open CMS's MLN or Physician Fee Schedule text directly to re-confirm the exact G2212 minute values against the primary source (CMS.gov returned access errors to automated retrieval); verify the current threshold in the CMS PFS Look-Up Tool or your MAC's E/M billing guidance before building it into a scrubber rule.
- Check data and risk independently of problem count before defaulting to 99214 on a multi-chronic-condition visit.
- Document the monitoring plan explicitly whenever a medication decision is meant to support high risk.
- State total time as a number (or start/stop times) whenever billing on the time pathway.
- Map 99417 to commercial payers and G2212 to Medicare at the scrubber level, not per claim.
- Don't stop at counting stable chronic diagnoses — that axis caps at moderate on its own.
- Don't bill 99417 on a Medicare claim or G2212 on a commercial claim; the codes aren't interchangeable across payers.
- Don't average the time and MDM pathways — pick whichever one the documentation fully supports.
- Don't leave a specialist phone discussion undocumented; it's the difference between moderate and high data.
Think your internal medicine visits are underleveled?
We'll audit a sample of your recent 99214s against the actual note text for high-complexity data and risk your coders may be missing, and show what's recoverable.
Frequently asked questions
Why does MDM sometimes support 99215 when the problem list looks like a routine 99214?
Because overall MDM level is set by whichever two of the three elements — problem complexity, data reviewed, and risk — reach the highest level together, not by problem count alone. Three or more stable chronic conditions plus a new problem typically lands problem complexity at moderate on its own. But if the visit also includes high-complexity data (reviewing outside records and discussing a result with a specialist) and high-complexity risk (starting a drug that needs intensive toxicity monitoring, or a hospitalization decision), those two elements now sit at high, which makes the overall visit high MDM regardless of what the problem-complexity axis alone would suggest. Coders who stop at counting diagnoses miss this every time.
Can medical decision making alone justify 99215 without meeting the time threshold?
Yes. Established-patient office visits are billed on either total time or MDM, and fully satisfying either pathway independently supports the code — you don't need both. A 25-minute visit that clearly documents high-complexity MDM (severe exacerbation, high-complexity data, and high risk, with at least two of the three elements reaching that level) supports 99215 on MDM alone, even though the visit ran well under the 40-to-54-minute time range for that code. The reverse is also true: a longer visit with straightforward MDM can still support a higher code purely on total time.
When do we bill CPT 99417 versus HCPCS G2212 for a prolonged office visit?
Bill 99417 on commercial claims that follow CPT's own time rules and G2212 on Medicare claims — never both on the same claim, and never 99417 on a Medicare claim. CPT ties 99417 to the minimum time of the level-5 code (60 minutes for 99205, 40 minutes for 99215) plus 15 minutes before the first unit is reportable. Medicare's G2212 is stricter, requiring total time to reach the maximum of the level-5 range (74 minutes for 99205, 54 minutes for 99215) plus 15 minutes — 89 total minutes for 99205, 69 total minutes for 99215 — before the first unit is billable.
Verify before billing. CPT is a registered trademark of the American Medical Association; codes here are paraphrased, not reproduced from the CPT Professional edition. CPT, HCPCS and ICD-10 codes, coverage policy, and bundling edits change, including annual code-set updates. This page reflects standard industry practice and is provided for general education — it is not a substitute for your own compliance review, your current payer contracts, or the current-year code sets. Confirm requirements against your specific payer mix before submitting claims.