Patient list export spec for outreach
Hand this spec to whoever pulls reports from your EHR or practice management system. It lists the columns an outreach list needs, the format for each, and which are required or optional. It also says what to leave out. Most outreach needs contact details and visit dates, not diagnoses.
File format
One CSV file, UTF-8, with a header row.
One row per patient. If a patient has several open items (for example two gaps), use one row per patient per item and repeat the patient ID.
Dates as YYYY-MM-DD. Phone numbers as 10 digits, no punctuation.
File name: `[practice]-[program]-[YYYY-MM-DD].csv`
Send it through an approved, encrypted channel, or upload it directly to a HIPAA-covered tool. Never email it as a plain attachment.
Core columns (every outreach list)
| Column | Format | Required? | Notes |
|---|---|---|---|
| patient_id | Text | Required | Your internal ID or MRN, so staff can find the patient. Keep leading zeros. |
| first_name | Text | Required | |
| last_name | Text | Required | |
| dob | YYYY-MM-DD | Required | Used for identity checks on calls. |
| phone_primary | 10 digits | Required | |
| phone_primary_type | mobile, landline, unknown | Required | Texts go to mobile numbers only. |
| phone_primary_source | patient_provided, other | Required | The TCPA free-to-patient exemption covers only patient-provided numbers. |
| phone_secondary | 10 digits | Optional | |
| ok_to_call | yes, no, unknown | Required | From your consent and opt-out records. |
| ok_to_text | yes, no, unknown | Required | Separate from calls. |
| preferred_language | Text | Optional | For example English, Spanish. |
| authorized_contact_name | Text | Optional | A caregiver or family member listed as involved in care. |
| provider_name | Text | Required | The patient's PCP or treating provider, for the script. |
| location | Text | Optional | Clinic site, for multi-site groups. |
| last_visit_date | YYYY-MM-DD | Required | |
| next_appointment_date | YYYY-MM-DD | Optional | Blank if none. Prevents calling patients already booked. |
| insurance_type | Medicare, Medicaid, commercial, self-pay, other | Optional | Only if the program depends on payer. |
Program columns (add only for the program you're running)
| Program | Add these columns | Format |
|---|---|---|
| Annual wellness visit recall | last_awv_date; medicare_part_b_start_date | YYYY-MM-DD |
| Screening or care gap recall | measure_name; gap_status; last_screening_date | Text; open or closed; YYYY-MM-DD |
| No-show recovery | missed_appointment_date | YYYY-MM-DD |
| Post-discharge (TCM) | discharge_date; discharge_facility; discharge_setting | YYYY-MM-DD; Text; inpatient, SNF, observation, other |
| Refill reminder or med sync | medication_name; last_fill_date; days_supply; refills_remaining; sync_date | Text; YYYY-MM-DD; Number; Number; YYYY-MM-DD |
| Comprehensive medication review | mtm_eligible; plan_name | yes or no; Text |
Leave these out
Diagnosis codes, problem lists and clinical notes, unless the program needs a specific one (for example a diabetes flag for an eye exam gap). Then export only that flag, not the full list.
Social Security numbers.
Full insurance member IDs, unless you need to match against a payer file.
Lab values and medication lists beyond what the program uses.
Balances and billing details on clinical outreach lists.
Minimum necessary check:
Every column has a job in this program's script or routing.
Patients who opted out are marked, not silently dropped, so the opt-out carries forward.
Deceased patients and patients who left the practice are removed.
The file goes only into a tool with a signed BAA on the plan you're using.
Compliance notes
- Minimum necessary applies to outreach lists. Covered entities must "make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose" (45 CFR 164.502(b); 164.514(d)).
- The vendor holding the file is a business associate. Anyone who "creates, receives, maintains, or transmits PHI" for you needs a signed BAA (45 CFR 160.103; 164.504(e)).
- Separate call and text consent. TCPA consent and opt-outs apply per number, and AI calls count as artificial-voice calls (FCC 24-17; 47 CFR 64.1200).
- Track phone source. Only patient-provided wireless numbers can use the free-to-patient exemption (47 CFR 64.1200(a)(9)(iv)(A)).
Upload this export to Rivvi's free plan, which includes a HIPAA BAA, and ask it to build the call list; Rivvi works from the file, with no EHR integration required. Get started for free.
These templates are a starting point, not legal advice. Review them with your compliance lead or counsel before use.