Loading...

National Correct Coding Initiative Edits (NCCI)

Published: August 9, 2016 by Experian Health

Back in 1996, the Centers for Medicare and Medicaid Services (CMS) developed the National Correct Coding Initiative (NCCI) to promote correct coding and prevent inappropriate payment of Medicare Part B claims. As this is an automated prepayment review by CMS, the NCCI edits reduce payment error by identifying coding errors made by providers. In 2009, 7.8 % of Medicare dollars did not comply with one of more Medicare coverage, coding, billing or payment rules, translating into $24.1 billion dollars in Medicare overpayments and underpayments annually.

The NCCI edits define when two HCPCS/CPT® procedure codes may not be reported together except under special circumstances. The Centers for Medicare & Medicaid Services (CMS) based the NCCI coding policies on current coding conventions, coding guidelines, national and local Medicare policies (NCDs and LCDs), and standard medical and surgical practice. Coding polices and guidelines require that procedures are reported with the most comprehensive CPT® code that describes the services performed. For example, a coder should not report a Basic Metabolic Panel (BMP, CPT® 80047) with a Comprehensive Metabolic Panel  CMP,CPT® code 80053) as all the analytes in CPT® 80047 BMP are a subset of the Comprehensive Metabolic Panel and would have been already performed as part of that procedure.

As a claim is processed by the Medicare contractor, the system tests every pair of procedure codes to determine if they comply with the NCCI edit policy. This means every code pair reported for the same date of service for the same beneficiary by the same provider is reviewed against the NCCI-edit tables. If a pair of codes on the claim  matches (“hits”) a pair in the NCCI edit table, the “Column Two” code of the edit pair is denied for payment. Using the CMP/BMP example above, in the NCCI edit tables, CPT® 80047 is the “Column Two” code and would have payment denied.

NCCI-associated modifiers are used to indicate the special circumstances such as when the procedures are performed at different anatomic sites, a separate procedure or repeat clinical diagnostic laboratory test. If an edit allows use of NCCI-associated modifiers, the two procedure codes may be reported together. NCCI-associated modifiers may not be used to bypass an edit unless the criteria for use of the modifier are met.

Each active NCCI edit has a modifier indicator of 0 or 1. A modifier indicator of “0” indicates that an edit can never be bypassed even if a modifier is used. In other words, the Column 2 code of the edit will be denied. A modifier indicator of “1” indicates that an edit may be bypassed with an appropriate modifier appended to the Column 1 and/or Column 2 code.

The NCCI-associated modifiers are: E1, E2, E3, E4, FA, F1, F2, F3, F4, F5, F6, F7, F8, F9, LC, LD, RC, LT, RT, TA, T1, T2, T3, T4, T5, T6, T7, T8, T9, 25, 27, 58, 59, 78, 79, and 91. In January 1, 2013, additional modifiers were added to the list of NCCI-associated modifiers that will allow an edit to be bypassed when the modifier is used correctly (i.e., edits with modifier indicator of “1”). These were LM (left main coronary artery), RI (ramus intermedius), 24 (unrelated evaluation and management service by the same physician during a postoperative period), and 57 (decision for surgery).

Effective Jan 15, 2015, new more specific modifiers  become effective (see also Compliance Matters, Sept 2014) supplementing Modifier -59 (Distinct Procedural Service).

XE Separate Encounter: A Service That Is Distinct Because It Occurred During A Separate Encounter

XS Separate Structure: A Service That Is Distinct Because It Was Performed On A Separate Organ/Structure

XP Separate Practitioner: A Service That Is Distinct Because It Was Performed By A Different Practitioner

XU Unusual Non-Overlapping Service: The Use Of A Service That Is Distinct Because It Does Not Overlap Usual Components Of The Main Service

These modifiers, collectively referred to as –X{EPSU} modifiers, define specific subsets of the -59 modifier. CMS will not stop recognizing the -59 modifier but notes that CPT instructions state that the -59 modifier should not be used when a more descriptive modifier is available. CMS will continue to recognize the -59 modifier in many instances but may selectively require a more specific – X{EPSU} modifier for billing certain codes at high risk for incorrect billing.

Services denied based on NCCI edits may not be billed to Medicare beneficiaries, nor can a provider use an “Advanced Beneficiary Notice” (ABN) to seek payment from the patient since these denials are based on incorrect coding rather than medical necessity or a benefit exclusion.

Hospitals, like physicians and other providers, must follow national correct coding policies. Though the NCCI edits were initially developed for processing professional claims, the NCCI edits are incorporated into the Outpatient Code Editor (OCE) used for processing outpatient hospital service claims, outpatient physical therapy and speech-language pathology services, skilled nursing facilities (SNFs), comprehensive outpatient rehabilitation facilities (CORFs), and home health agencies (HHAs). These are commonly referred to as the NCCI “Hospital” Version of CCI edits.

Review the NCCI manual on CMS here: http://www.cms.gov/Medicare/Coding/NationalCorrectCodInitEd/index.html?redirect=/nationalcorrectcodinited/

Related Posts

Hospitals must prepare for Medicaid reforms under the One Big Beautiful Bill Act, raising uncompensated care costs and compliance demands.

Published: December 9, 2025 by Experian Health

With the Appropriate Use Criteria program slated to go into effect in 2023, healthcare providers shoud implement new alerts for prior authorizations.

Published: October 24, 2022 by Experian Health

Healthcare data breaches are nothing new, but their size and frequency are increasing: CVS Health lost over a billion search records when a third party accidentally made an online database publicly accessible in March 2021. A ransomware data breach at prescription management vendor CaptureRx affected over a million patients at 17 healthcare providers in February 2021. More than 3.47 million individuals and at least 10 healthcare organizations were affected by a massive data breach at file transfer company Accellion, which spanned multiple global industries in December 2020.   Further illustrating the risks to healthcare organizations, Scripps Health in San Diego was hit with two class-action lawsuits that assert that the organization should have done more to protect patient data. If upheld, it will set a precedent for healthcare organizations to be held legally responsible for failing to protect data – to the tune of $1000 per patient. The direct monetary cost of fines and lawsuits, however, may ultimately be a secondary concern as damaged reputation is often a more difficult setback to overcome. Patients increasingly approach healthcare as “consumers” and a breach – or a poorly managed breach situation – might prompt them to look elsewhere for care. “Incidents happen every day. However, the real threat lies in how quickly and efficiently an organization can respond. This is what customers will remember. You need to be able to make prompt updates to your website, scale up call center capacity, and have answers ready when consumers need them.” The growing frequency and scale of health information breaches means it’s no longer sufficient to say, “we’re careful with our health data – this won’t happen to us.” Medical identities are extremely valuable, which makes them an attractive target to cybercriminals. In addition, the sudden increase in virtual care and remote working during the pandemic has created new vulnerabilities in data security.   A recent FBI alert that a major ransomware group is targeting the healthcare sector with phishing attacks is a cl reminder that healthcare organizations can’t relax when it comes to cybersecurity. It’s a case of “when, not if” a healthcare organization will have to deal with a breach. Prevention is the goal, but preparation is the smart strategy.   Shifting from data breach prevention to preparedness   During the pandemic, the volume of data being shared within and between healthcare organizations sky-rocketed, as providers offered more virtual care services and workforces became more distributed. While these innovations meant access to healthcare and work could continue safely, the shift to cloud-based data sharing and storage, means the data perimeter is much broader and tougher to secure – if there remains a perimeter at all. Data must be secured at the device- and employee-level now.   While prevention is better than cure, the hard truth for healthcare cybersecurity teams is that they’re increasingly likely to have to deal with a breach. Unfortunately, many organizations don’t have the technology, resources, or time to prevent breaches all the time, at every access point.   Chris Wild, vice president at Experian Health, says:   “We’re seeing an increased frequency of cyber threats across the whole industry. Hardly a week goes by that we don’t hear of a health system under attack from hackers or ransomware. The statistics show us there’s a health data breach nearly every single day, so it’s just a matter of time before it impacts any one provider, pharmacy, payer or physician group.”   Instead of focusing solely on prevention, healthcare organizations need a strategy to prepare for what happens when a breach occurs. If they don’t, they risk a long, public struggle to contain the breach, resulting in brand damage, patient loss, and financial consequences in the form of fines and lost revenue.   Building a data breach response plan   Recovering from a data breach requires a speedy and thorough response. With a plan in place, action can be taken as soon as the dreaded call comes in. Knowing exactly what needs to be done to meet HIPAA notification requirements, helps reassure consumers and regulators alike that every effort is being made to contain the breach. Not only will this help minimize fines, but it will also mitigate against the reputational damage caused by the security breach.   A breach is bad enough but compounding the negative impact of exposed data by failing to provide sufficient support to worried consumers is even worse. Wild says: “Incidents happen every day. However, the real threat lies in how quickly and efficiently an organization can respond. This is what customers will remember. You need to be able to make prompt updates to your website, scale up call center capacity, and have answers ready when consumers need them.”   A robust response plan calls for C-suite engagement, clear success metrics, and regular pressure-testing. Above all, it must be flexible to adapt to whatever size and type of breach occurs.   The best support for the worst-case scenario A data breach response plan isn’t going to prevent the breach itself, but it can help a healthcare organization take the right steps in the aftermath. Having serviced thousands of data breaches over the last 17 years, Experian Health’s Reserved Response™ program is based on real world experience and has evolved as the threats and consequences have increased. In a recent survey, clients using Reserved Response reported 15% fewer data security incidents than those who did not. Furthermore, any incidents that did occur tended to be smaller in scale.   Because the risk and impact of data breaches is trending upwards, this year Experian Health has introduced a new Reserved Response Hub. This digital, self-service tool helps to prepare and test a data breach plan, including: the new and improved 2021 Data Breach Response Guide downloadable readiness reading materials tried and tested notification templates a pre-breach incident checklist access to Experian’s full Reserved Response service, which provides support before or after a breach to ensure regulatory compliance and support for those impacted.   Reserved Response can help healthcare organizations put together a data breach preparedness plan in as little as three days.  

Published: June 25, 2021 by Experian Health

Subscribe to our blog

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to the Experian Health blog

Get the latest industry news and updates!
Subscribe