Written and maintained by CASRAI Editorial Board
Last updated
Since 1 January 2021 for office and other outpatient visits, and 1 January 2023 for almost every other evaluation and management family, the level of an E/M service is decided by one of two things and nothing else: the level of medical decision making, or the total time on the date of the encounter. History and examination no longer select the level. They are still performed, still documented, still medically necessary — but they are not the measuring instrument any more.
That means the Levels of Medical Decision Making table in the CPT E/M guidelines is the governing text for most visits billed in the United States. This page walks the table as an auditor walks it: what its three columns actually ask, what the “2 out of 3” rule really requires, and where the honest disagreements live.
Verified against the American Medical Association’s CPT Evaluation and Management (E/M) Code and Guideline Changes, effective 1 January 2023 — specifically the E/M Services Guidelines, Table 1 (Levels of Medical Decision Making), and the accompanying definitions of terms — and against the CMS Medicare Learning Network booklet MLN006764, Evaluation and Management Services (May 2026 revision). CPT codes, descriptions and other data are copyright the American Medical Association. This page describes how to select a level; it is not a substitute for the CPT codebook, and payer and MAC policy can add requirements on top.
What the Guidelines Replaced, and What They Did Not
The single most consequential sentence in the revised guidelines is short and easy to miss:
“The extent of history and physical examination is not an element in selection of the level of these E/M service codes.”
The guidelines still require “a medically appropriate history and/or physical examination, when performed,” and they leave the scope of that work to clinical judgement: “The nature and extent of the history and/or physical examination are determined by the treating physician or other qualified health care professional reporting the service.”
So the 1995 and 1997 documentation guidelines’ bullet-counting is gone as a level-selection mechanism. What replaced it is stated plainly:
“Select the appropriate level of E/M services based on the following: 1. The level of the MDM as defined for each service, or 2. The total time for E/M services performed on the date of the encounter.”
The guidelines also head off a common misreading of their purpose: “These guidelines do not establish documentation requirements or standards of care. The main purpose of documentation is to support care of the patient by current and future health care team(s).” The record still has to make the clinical story legible. It just is not scored by organ systems any more.
The Three Elements, and the 2-Out-of-3 Rule
MDM is defined as “establishing diagnoses, assessing the status of a condition, and/or selecting a management option,” and it is built from exactly three elements:
- The number and complexity of problems addressed at the encounter.
- The amount and/or complexity of data to be reviewed and analysed.
- The risk of complications and/or morbidity or mortality of patient management.
Four types of MDM are recognised: straightforward, low, moderate and high. And the combining rule is a single sentence that decides more claims than any other line in the guidelines:
“To qualify for a particular level of MDM, two of the three elements for that level of MDM must be met or exceeded.”
Three things follow from “two of three,” and practices get all three wrong at some point.
The lowest element is discarded, not averaged
You do not average the columns. You find the highest level at which two columns are independently satisfied. A visit that is high on problems, high on risk and minimal on data is a high-MDM visit — the empty data column is simply irrelevant, because two columns already reached high.
“Met or exceeded” runs upward only
An element at a higher level counts toward a lower one. If problems are high and risk is moderate, both elements have at least met moderate, so moderate is supported by two elements; whether high is supported depends on whether risk also reaches high. The phrase never works in reverse.
Two elements must be met by two different columns
Stacking three data points and two prescriptions does not produce “two elements.” The two must come from two of the three named columns.
Column 1: Number and Complexity of Problems Addressed
This column asks what the clinician actually took responsibility for. The guidelines define a problem broadly — “a disease, condition, illness, injury, symptom, sign, finding, complaint, or other matter addressed at the encounter, with or without a diagnosis being established” — and then narrow “addressed” sharply:
“A problem is addressed or managed when it is evaluated or treated at the encounter by the physician or other qualified health care professional reporting the service… Notation in the patient’s medical record that another professional is managing the problem without additional assessment or care coordination documented does not qualify as being addressed or managed… Referral without evaluation… or consideration of treatment does not qualify.”
Two corollaries matter for anyone defending a chart. First, comorbidities do not count merely for existing: they count “unless they are addressed, and their presence increases the amount and/or complexity of data to be reviewed and analyzed or the risk of complications.” Second, symptoms that cluster around one diagnosis are not separate problems — “each symptom is not necessarily a unique condition.”
Working upward, the table’s problem tiers are: minimal (one self-limited or minor problem); low (two or more self-limited or minor problems, or one stable chronic illness, or one acute uncomplicated illness or injury, or one stable acute illness, or one acute uncomplicated illness or injury requiring hospital inpatient or observation level care); moderate (one or more chronic illnesses with exacerbation, progression or side effects of treatment; or two or more stable chronic illnesses; or one undiagnosed new problem with uncertain prognosis; or one acute illness with systemic symptoms; or one acute complicated injury); and high (one or more chronic illnesses with severe exacerbation, progression or side effects of treatment; or one acute or chronic illness or injury that poses a threat to life or bodily function).
The definitions behind those labels are where the level is genuinely won or lost — particularly the counter-intuitive definition of “stable.” The problems column has its own guide, because these definitions do not behave the way clinicians expect.
Column 2: Amount and/or Complexity of Data to Be Reviewed and Analysed
This is the column auditors find miscounted most often, because it is the only one with arithmetic in it. The data element is divided into three categories:
- Category 1 — Tests, documents, orders, or independent historian(s). Each unique test, order or document is counted to meet a threshold number.
- Category 2 — Independent interpretation of tests not separately reported.
- Category 3 — Discussion of management or test interpretation with an external physician, other qualified health care professional, or appropriate source, not separately reported.
The thresholds are asymmetric, and reading them off the table precisely matters:
| Level | Data label | What must be satisfied |
|---|---|---|
| Straightforward | Minimal or none | — |
| Low | Limited | At least 1 of 2 categories: either any combination of 2 Category 1 elements, or assessment requiring an independent historian |
| Moderate | Moderate | At least 1 of 3 categories: either any combination of 3 elements from Category 1 (including independent historian), or Category 2, or Category 3 |
| High | Extensive | At least 2 of 3 categories, on the same structure as moderate |
Note the structural quirk at the low level: the independent historian is broken out as its own Category 2 there, whereas at moderate and high it folds into Category 1 and independent interpretation becomes Category 2. The category numbers are not stable across rows. Counting a “Category 2” at low as though it meant independent interpretation is a real and recurring error.
The counting rules that generate the disputes — what “unique” means, when a panel is one test, why a separately reported interpretation cannot also be a data point — are set out in the data column guide.
Column 3: Risk of Complications and/or Morbidity or Mortality of Patient Management
The risk column is the one with no arithmetic at all, and the guidelines are explicit that this is deliberate:
“Definitions of risk are based upon the usual behavior and thought processes of a physician or other qualified health care professional in the same specialty. Trained clinicians apply common language usage meanings to terms such as high, medium, low, or minimal risk and do not require quantification for these definitions.”
Two distinctions carry most of the weight. First, this column is about the risk of management, not the risk of the condition: “This is distinct from the risk of the condition itself.” The guidelines add, in the problems section, that “the risk from the condition is distinct from the risk of the management.” Second, the entries in the table are labelled “Examples only” — prescription drug management, decisions about minor or major surgery, drug therapy requiring intensive monitoring for toxicity, decisions about hospitalisation, decisions not to resuscitate. They are illustrations of a level, not a checklist that defines it.
Risk also expressly includes roads not taken: “Risk also includes MDM related to the need to initiate or forego further testing, treatment, and/or hospitalization.” A documented decision against hospitalising a patient is risk-bearing management. The risk column guide takes the examples apart individually.
A Worked Encounter, Mapped Column by Column
A 68-year-old established patient presents with two weeks of worsening exertional dyspnoea. She has type 2 diabetes and hypertension, both at goal. The clinician takes a history, examines her, reviews an echocardiogram report from a cardiologist in a different practice, reviews a chest radiograph performed the previous week at a hospital outpatient department, orders a BNP and a basic metabolic panel, and telephones the cardiologist to agree a plan. A new diuretic is started.
Column 1. The dyspnoea is an undiagnosed new problem with uncertain prognosis — a problem in the differential that “represents a condition likely to result in a high risk of morbidity without treatment.” That alone is moderate. The diabetes and hypertension are at goal and are not addressed in a way that adds data or risk, so under the comorbidity rule they do not lift the column further. Moderate.
Column 2. Category 1 elements: the echocardiogram report from the cardiologist is a prior external note from one unique source; the chest radiograph from the hospital is a result from a different unique source; the BNP is a unique test ordered; the basic metabolic panel is a single test, because “a clinical laboratory panel… is a single test.” That is four Category 1 elements, comfortably past the three needed for moderate. Separately, the telephone call to the cardiologist is a Category 3 discussion, provided it was a genuine interactive exchange and is not separately reported. Two of the three categories are therefore satisfied. High.
Column 3. Starting a diuretic is prescription drug management, which the table lists as a moderate-risk example. There is no decision about surgery, hospitalisation or intensive toxicity monitoring. Moderate.
Two of three at moderate; only one at high. The visit is moderate MDM. Note how the analysis behaves: the data column reaching high does nothing on its own, because a single high column cannot carry a level. And note that had the clinician not documented the substance of the cardiology call, the data column would have fallen to moderate — which would have changed nothing at all, because moderate was already established twice over. That asymmetry is worth internalising: not every documentation gap changes the answer, and knowing which ones do is the difference between a defensible chart and a nervous one.
Where MDM Interacts With the Rest of the Claim
Three interactions catch practices repeatedly.
Separately reported services are removed from MDM. The guidelines state it twice, for interpretation and for discussion: “When the physician or other qualified health care professional is reporting a separate CPT code that includes interpretation and/or report, the interpretation and/or report is not counted toward the MDM.” If you bill the professional component of a study, you cannot also bank it as a data element. This is where the modifier 26 / TC split becomes an MDM question rather than a billing formality.
The same-day procedure question is separate. Whether the E/M is separately identifiable from a procedure performed the same day is decided by the modifier 25 test, not by the MDM table — see the modifier 25 guide, and modifier 57 where a major-surgery decision is involved.
Time is an alternative, not a tiebreaker. You choose MDM or total time for a given encounter, whichever “reflects the encounter most accurately.” You do not use MDM to establish a floor and then add time on top. What counts toward total time is its own body of rules.
Frequently Asked Questions
If history and exam do not count, can I stop documenting them?
No, and the guidelines are careful here. A medically appropriate history and examination are part of the service; what changed is that their extent is not scored for level selection. A note with no clinical narrative fails on medical necessity long before it fails on level.
Who decides whether a chronic illness is “stable” or “exacerbated”?
The treating clinician. The AMA’s own E/M FAQ material is explicit that physicians, not coders, determine whether problems are stable or worsening, and that the documentation should reflect that clinical assessment. A coder can query an ambiguous note; a coder cannot re-diagnose stability.
Does a higher-level diagnosis automatically mean higher MDM?
No, and the reverse trap is more common. The guidelines say “the final diagnosis for a condition does not, in and of itself, determine the complexity or risk,” and add that “presenting symptoms that are likely to represent a highly morbid condition may ‘drive’ MDM even when the ultimate diagnosis is not highly morbid.” Chest pain that turns out to be reflux is scored on the workup the presentation warranted.
Does the MDM table apply to every E/M code?
Almost, but not all. The guidelines note that the concept of level of MDM does not apply to the lowest-level established office visit or the lowest-level emergency department visit, and that certain time-based families such as critical care use time differently. Emergency department levels do not use time at all, because those services “are typically provided on a variable intensity basis.” Always read the category-specific instructions.
Do multiple minor problems ever add up to something higher?
They can, but through the risk column rather than by arithmetic in the problems column. The guidelines state that “multiple problems of a lower severity may, in the aggregate, create higher risk due to interaction.” That has to be documented as an interaction, not asserted as a count.
Is the table the same across settings?
The table is, but its examples are not equally applicable. The guidelines say so directly: the decision to hospitalise applies to outpatient or nursing facility encounters, whereas the decision to escalate hospital level of care applies to a patient already admitted. Read the introductory guidelines for the relevant code family alongside the table — and, for inpatient status questions, the two-midnight rule is a different decision from the MDM one.
What an Auditor Actually Looks For
Reviewers do not read a note looking for the level you billed. They read it looking for two columns that independently reach the level you billed, and they test each one against the definitions rather than against the labels. The practical implications:
- Name the problems and their status. “Diabetes, at goal” and “diabetes, uncontrolled despite maximal oral therapy” sit in different rows of column 1 and are the same number of words.
- Attribute reviewed material to its source. A data element that cannot be traced to a unique external source cannot be counted as one.
- Document the substance of any discussion, and enough to show it was interactive. Sending or receiving a chart note is expressly not a discussion.
- Record management decisions that were considered and rejected. Under the risk definition they count, and they are the single most commonly omitted defensible element.
- If time is the basis, say so and record the total. The guidelines require that the total time on the date of the encounter “should be documented in the medical record when it is used as the basis for code selection.”
Recovery audit contractors and MAC targeted-probe activity both work from these columns; if you are responding to a records request, the RAC audit process guide covers the timelines and appeal levels that sit around the coding question.








