Skip to main content
v2026.11,610 entries · CC-BY 4.0

Risk of Complications and Morbidity: The MDM Column With No Numbers

Column 3 scores the risk of your management, not the risk of the condition. What “prescription drug management” really requires, how the minor/major/elective/emergency surgery ladder works, the narrow definition of intensive toxicity monitoring, and why decisions to forego treatment count.

Ask about Risk of Complications and Morbidity: The MDM Column With No Numbers

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

The third column of the MDM table contains no thresholds, no counts and no lists you can tick. It asks a single question — how risky is the management you chose — and then answers it with a handful of examples explicitly labelled “Examples only.”

Clinicians tend to find this the most comfortable column and coders the least. Both reactions are half right. It is the column where clinical judgement genuinely governs, and it is also the column where an unexamined habit (“there’s a prescription, so it’s moderate”) can carry a whole practice’s coding pattern in a direction that will not survive a records request.

Verified against the American Medical Association’s CPT Evaluation and Management (E/M) Code and Guideline Changes, effective 1 January 2023 — the E/M Services Guidelines section “Risk of Complications and/or Morbidity or Mortality of Patient Management,” Table 1, and the definitions of terms — together with the AMA’s published E/M revisions FAQ guidance, and CMS Medicare Learning Network booklet MLN006764, Evaluation and Management Services (May 2026 revision). CPT codes, descriptions and other data are copyright the American Medical Association.

What This Column Is Measuring

The guidelines open the section with the distinction that governs everything after it:

“One element used in selecting the level of service is the risk of complications and/or morbidity or mortality of patient management at an encounter. This is distinct from the risk of the condition itself.

The problems column already measured how dangerous the illness is. This column measures how dangerous your response to it is. The guidelines reinforce the split from the other side, in the problems section: “While condition risk and management risk may often correlate, the risk from the condition is distinct from the risk of the management.”

The practical consequence is that the two columns can and often should diverge. A patient with a genuinely life-threatening condition managed with observation and reassurance is high in column 1 and lower in column 3. A patient with a benign, non-urgent condition for whom you schedule major elective surgery is the reverse. When a note’s column 1 and column 3 always match, that is usually a sign the same clinical fact is being counted twice rather than two questions being asked.

Risk, defined

“Risk: The probability and/or consequences of an event. The assessment of the level of risk is affected by the nature of the event under consideration. For example, a low probability of death may be high risk, whereas a high chance of a minor, self-limited adverse effect of treatment may be low risk.”

Probability and severity are multiplied, not averaged, and severity dominates. A one-in-a-thousand chance of death is high risk. A near-certain chance of transient nausea is not.

Why there are no numbers

“Definitions of risk are based upon the usual behavior and thought processes of a physician or other qualified health care professional in the same specialty. Trained clinicians apply common language usage meanings to terms such as high, medium, low, or minimal risk and do not require quantification for these definitions (though quantification may be provided when evidence-based medicine has established probabilities).”

The benchmark is your own specialty’s ordinary usage. This is a deliberate refusal to build a scoring grid, and it cuts both ways: it protects clinical judgement, and it means a claimed level has to be legible to a peer reviewer in the same specialty from the note alone.

Roads not taken are management

“For the purpose of MDM, level of risk is based upon consequences of the problem(s) addressed at the encounter when appropriately treated. Risk also includes MDM related to the need to initiate or forego further testing, treatment, and/or hospitalization.”

The word “forego” carries real weight. A documented decision not to hospitalise, not to operate or not to escalate is risk-bearing management. The MDM overview section illustrates this directly: “a decision about hospitalization includes consideration of alternative levels of care,” with examples including “a psychiatric patient with a sufficient degree of support in the outpatient setting” and “the decision to not hospitalize a patient with advanced dementia with an acute condition that would generally warrant inpatient care, but for whom the goal is palliative treatment.”

Shared decision making is defined alongside it as “eliciting patient and/or family preferences, patient and/or family education, and explaining risks and benefits of management options.” Options considered and rejected after such a discussion are part of the management being scored — and they are the most commonly omitted defensible element in the entire table.

The boundary of your own accountability

“The risk of patient management criteria applies to the patient management decisions made by the reporting physician or other qualified health care professional as part of the reported encounter.”

You are scored on the decisions you made. A surgeon’s high-risk operation does not raise the risk column for the internist who referred the patient, unless that internist made her own risk-bearing decisions.

The Four Rows

Level Table wording
Straightforward Minimal risk of morbidity from additional diagnostic testing or treatment
Low Low risk of morbidity from additional diagnostic testing or treatment
Moderate Moderate risk of morbidity from additional diagnostic testing or treatment
High High risk of morbidity from additional diagnostic testing or treatment

The rows are, deliberately, almost tautological. All the content sits in the examples attached to the moderate and high rows — and the table calls them “Examples only.” They illustrate what a level looks like. They are not a definition of it, they are not exhaustive, and satisfying one is not a guarantee.

The Moderate Examples

The table lists four.

Prescription drug management

The most-cited three words in E/M coding, and the least examined. The guidelines do not define the phrase further, which means the ordinary-usage rule applies: management, not the existence of a prescription. Starting, stopping, changing, titrating, or making a documented decision to continue a medication after weighing it is management. A medication list carried forward with no decision recorded is not, and a reviewer reading a note that shows no decision will not find management in it.

The safest discipline is to record the decision rather than the drug: “continuing lisinopril at current dose; BP at target, renal function stable” is management. An unannotated med list is not.

Decision regarding minor surgery with identified patient or procedure risk factors

Note the qualifier. A minor surgery decision reaches moderate when there are identified risk factors. Without them it does not sit here.

Decision regarding elective major surgery without identified patient or procedure risk factors

The mirror image: major surgery, elective, no identified risk factors.

The guidelines refuse to define minor and major by any billing construct: “The classification of surgery into minor or major is based on the common meaning of such terms when used by trained clinicians, similar to the use of the term ‘risk.’ These terms are not defined by a surgical package classification.” A procedure’s global period does not decide whether it is major here. The AMA’s FAQ guidance adds that clinicians should explicitly document the “major” or “minor” characterisation rather than leaving it to be inferred.

Elective versus emergency is about timing relative to the patient’s condition: “An elective procedure is typically planned in advance (eg, scheduled for weeks later), while an emergent procedure is typically performed immediately or with minimal delay to allow for patient stabilization. Both elective and emergent procedures may be minor or major procedures.” And risk factors “are those that are relevant to the patient and procedure. Evidence-based risk calculators may be used, but are not required.”

Where the decision for surgery is itself the billable E/M service in a global-period context, the modifier question is separate from the MDM one — see modifier 57, and modifier 25 for minor procedures performed the same day.

Diagnosis or treatment significantly limited by social determinants of health

Defined as “economic and social conditions that influence the health of people and communities. Examples may include food or housing insecurity.” The operative word in the table entry is significantly limited. The determinant must be shown to have constrained the diagnosis or treatment — a plan altered because the patient cannot refrigerate insulin, or cannot afford the first-line agent, or has no fixed address for follow-up. Recording a Z-code without showing the constraint on management does not reach this example.

The High Examples

Drug therapy requiring intensive monitoring for toxicity

This is the most tightly defined term in the risk section, and it excludes far more than it includes:

“A drug that requires intensive monitoring is a therapeutic agent that has the potential to cause serious morbidity or death. The monitoring is performed for assessment of these adverse effects and not primarily for assessment of therapeutic efficacy… Long-term intensive monitoring is not performed less than quarterly. The monitoring may be performed with a laboratory test, a physiologic test, or imaging. Monitoring by history or examination does not qualify.

Four gates: serious morbidity or death potential; monitoring aimed at toxicity rather than efficacy; at least quarterly if long-term; and by test or imaging, never by history or examination. The guidelines then give both a qualifying and two disqualifying examples: monitoring for cytopenia between cycles of an antineoplastic agent qualifies; monitoring glucose during insulin therapy does not, “as the primary reason is the therapeutic effect (unless severe hypoglycemia is a current, significant concern)”; and annual electrolytes and renal function for a patient on a diuretic does not, “as the frequency does not meet the threshold.”

Decision regarding elective major surgery with identified patient or procedure risk factors

Decision regarding emergency major surgery

The surgery ladder is worth seeing whole, because the qualifiers are what move it:

Decision Risk-factor qualifier Level
Minor surgery With identified patient or procedure risk factors Moderate
Elective major surgery Without identified risk factors Moderate
Elective major surgery With identified patient or procedure risk factors High
Emergency major surgery High

The AMA’s FAQ guidance makes one further point that matters here: the inherent risks of a surgical procedure do not automatically make every surgery high risk. The reporting physician determines risk on the specific patient’s factors and circumstances.

Decision regarding hospitalisation or escalation of hospital-level care

Including, as above, the documented decision against it. Note the setting sensitivity the guidelines flag: the decision to hospitalise applies to outpatient or nursing facility encounters, whereas escalation of hospital level of care applies to an already-admitted patient. Whether an admission is inpatient or observation is a separate determination — see the two-midnight rule.

Decision not to resuscitate or to de-escalate care because of poor prognosis

Explicitly high. Goals-of-care conversations that change the plan are among the highest-risk management decisions in medicine and are routinely under-coded because they involve doing less rather than more.

Parenteral controlled substances

Listed without qualification.

Worked Examples

The prescription that is not moderate

An established patient attends for a repeat prescription of a topical emollient for mild eczema, currently well controlled. The note reads “eczema stable, refill issued.” A prescription exists, so the habit says moderate.

Test it against the definition: what is the risk of morbidity from this treatment? Minimal. There is no titration, no toxicity consideration, no alternative weighed. Nothing in the note shows management as opposed to issuance. This is a low or straightforward risk column, and if the practice’s coding pattern treats every refill as moderate, that pattern is what a probe review will find.

The decision to do nothing that is high

An 88-year-old nursing-home resident with advanced dementia develops fever and a productive cough. The clinician examines her, discusses options with her daughter and the care home, documents that hospital admission would ordinarily be warranted, records that the agreed goal of care is comfort, and elects oral antibiotics in place with a plan for symptom management and no transfer.

Nothing dramatic was done, and the risk column is high on two independent grounds. There was a decision regarding hospitalisation — the guidelines’ own example is almost this case — and there was de-escalation of care because of prognosis. What makes it defensible is that the note records the alternative considered, who was involved, and why it was declined. Had it read “chest infection, amoxicillin started,” the same clinical event would have documented as a moderate visit at best.

Two columns, two answers

A 30-year-old presents with sudden severe headache. The differential documented includes subarachnoid haemorrhage. CT is normal, the history is reassuring on review, and after a documented discussion of the risks and benefits of lumbar puncture the patient and clinician agree to defer it with a safety-net plan and same-day review if anything changes.

Column 1 is high: a symptom significantly probable of posing a threat to life, with evaluation consistent with that severity. Column 3 is where judgement bites — the management was a documented decision to forego further testing after shared decision making, which the definition expressly brings into the risk column. The level you defend depends on how squarely the note shows that weighing. The two columns are answering different questions about the same encounter, which is exactly what they are supposed to do.

Frequently Asked Questions

Does over-the-counter medication count as prescription drug management?

The example says “prescription drug management.” Recommending an over-the-counter product is not, on the face of the wording, prescription drug management — though a documented decision about a drug interaction or a contraindication involving it may bear on risk in its own right. Do not build a coding pattern on the ambiguity.

Is a decision to order a high-risk test scored here?

Yes. The row wording is “risk of morbidity from additional diagnostic testing or treatment.” Diagnostic risk counts, which is why a decision to proceed to, or to defer, an invasive study belongs in this column even though the study itself may also be a data element.

Can one clinical fact score in both column 1 and column 3?

A single fact should be tested separately against two different questions. The severity of the illness informs column 1; the risk of what you did about it informs column 3. If the note contains only “severe pneumonia” with no management detail, it has supplied an answer to the first question and not the second.

Do I need a risk calculator?

No. The guidelines say evidence-based risk calculators “may be used, but are not required.” Using one and documenting the output is strong evidence; not using one is not a deficiency.

Does the risk column ever decide the level alone?

No. Two of the three MDM elements must be met or exceeded — see the MDM table overview. A high risk column with low problems and minimal data does not produce a high visit.

What if time reflects the encounter better than risk does?

Then use time. Level selection is MDM or total time on the date of the encounter, whichever reflects the encounter most accurately, and lengthy shared decision making is precisely the situation where time often does. See what counts toward total time.

How should risk be documented?

Name the management decision, name the alternatives weighed, and state why the chosen option was chosen. Three clauses. They are also, not coincidentally, what a peer reviewer in your specialty needs in order to agree that your risk assessment was reasonable — which is the standard the guidelines actually set.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.