99221 CPT Code Description: A Practice Admin's Guide
Your hospitalist group posted 63 initial inpatient encounters last month. Forty-one of them were billed at the lowest of the three initial-care levels, and your revenue cycle vendor just flagged the pattern for review. Before anyone touches a claim, you need to know exactly what the 99221 CPT code description covers, what documentation supports level selection, and — the part most practices skip — how many outside parties touched protected health information to get that claim out the door.
This guide is written for administrators, billing leads, and privacy officers who oversee hospital-based or facility-based professional billing. It covers the operational mechanics of the code, the internal workflow that produces defensible documentation, and the vendor and records-handling obligations that ride along with every inpatient encounter.
Quick Answer: The 99221 CPT Code Description in One Paragraph
CPT 99221 describes initial hospital inpatient or observation care, per day, for the evaluation and management of a patient. It requires a medically appropriate history and/or examination and either straightforward or low-level medical decision making. When level selection is based on total time, the code corresponds to 40 minutes or more of qualifying physician or other qualified health professional time spent on the date of the encounter. It is the first of three initial-care levels — 99222 and 99223 sit above it at higher medical decision making or 55 and 75 minutes respectively. Only one initial service is reported per admission per physician or per group of the same specialty; later days in the same stay fall under the subsequent care codes.
What Changed in 2023 and Why Your Old Templates May Still Be Wrong
The AMA restructured the inpatient E/M family effective January 1, 2023. Observation care codes 99217 through 99220 were deleted and folded into the hospital inpatient and observation care family. That means the initial-care codes now serve both settings, which is why your charge capture screen should not still be offering separate observation options.
The second change matters more for documentation review. History and exam no longer determine the level. They must be medically appropriate and documented, but bullet counting is gone. Level selection now rests on either medical decision making or total time on the date of the encounter.
If your practice is still running an audit tool that scores organ systems and HPI elements against the 1995 or 1997 guidelines for inpatient encounters, you are auditing against retired criteria. CMS maintains a current Evaluation and Management Services Guide through its Medicare Learning Network, and that document — not a vendor cheat sheet from 2019 — should anchor your internal review standard.
The Two Paths, and Why Your Providers Need to Pick One
A provider documents either the elements that support a decision-making level or the total time spent on the date of the encounter. Practices get into trouble when the note gestures at both and supports neither — a thin assessment plus a time statement of "approximately 40 minutes" with no accounting of what filled it.
Time-based selection includes qualifying non-face-to-face work performed on the date of the encounter: chart review, ordering, care coordination, documentation. It excludes time reported separately under other codes and excludes clinical staff time. Your job as an administrator is not to judge whether a given patient warranted a particular level. Your job is to ensure the note contains enough to let a coder or auditor see how the level was reached.
Split or Shared Visits and Teaching Settings
In facility settings, an initial inpatient service may be performed in part by a physician and in part by an NP or PA in the same group. Medicare has specific requirements for how the billing practitioner is identified and how the service is appended with the FS modifier. If your group bills split or shared services, that policy needs to live in writing, with named roles, and be re-checked against your MAC's current guidance every year. Teaching physician attestation requirements are separate and equally auditable.
The Internal Workflow Behind a Single Initial Inpatient Claim
Map this once and post it. Most billing errors and most privacy incidents trace back to an undocumented handoff.
- Day 0 — Census capture. Someone identifies which patients your providers saw. This is usually a hospital-generated census list or a rounding list pulled from the facility EHR.
- Day 0–1 — Note completion. The provider documents. If a scribe, transcription service, or ambient documentation tool is involved, that vendor now holds PHI.
- Day 1–3 — Charge capture. Level selection is either provider-entered or coder-assigned. Your policy should state which, in writing, and by whom.
- Day 2–5 — Coding review. Internal coder or contracted coding firm reconciles the note against the reported level. Queries go back to the provider through a documented channel.
- Day 3–7 — Claim submission. Billing staff or an RCM vendor transmits through a clearinghouse.
- Ongoing — Denial and audit response. Records go out to payers, review contractors, or appeal vendors.
Count the parties in that list. For a typical hospitalist group, four to six separate organizations handle identifiable patient information on one claim. Each one is a business associate relationship, and each one needs a signed agreement on file before the first record moves.
Where PHI Actually Moves — and Where It Leaks
Inpatient professional billing has a distinct privacy profile because your practice is working inside someone else's system. Three exposure points show up repeatedly in incident reviews.
The Census List Nobody Owns
A facility census list is a spreadsheet of patient names, dates of birth, room numbers, and admitting diagnoses. It gets emailed, printed, carried, texted, and left in cars. It is the single highest-volume PHI artifact in a hospital-based practice and it usually has no assigned owner, no retention rule, and no disposal step.
Fix it with three decisions: name the role that generates the list, specify the transmission channel, and set a destruction point. HHS guidance on the minimum necessary standard applies directly here — a billing coordinator reconciling charges does not need the full admitting history for every patient on the floor.
Hospital EHR Credentials for Your Billing Staff
Coders often get read access to the facility system to pull notes. That access is governed by the hospital's audit logs, not yours, and the hospital will come to you when an audit shows one of your staff opened a chart for a patient your providers never saw. Maintain your own roster of who holds facility credentials, review it quarterly against your active employee list, and build credential termination into your offboarding checklist. Same-day deactivation, not next-week.
Documentation Tools That Capture More Than the Note
Ambient documentation and transcription tools are now common in rounding workflows. They may capture ambient room audio, meaning conversations about other patients, family members, and staff. Before one goes live, get the answers in writing: what is retained, for how long, whether recordings are used for model training, and where the data sits. Then get it into an executed agreement.
The Vendor Paperwork an Inpatient Billing Operation Needs on File
Pull your vendor list and check for signed, current agreements covering each of these categories:
- Revenue cycle management or billing service
- Clearinghouse
- Coding contractor or outsourced audit firm
- Transcription, scribe service, or ambient documentation vendor
- Denial management and appeals vendor
- Secure messaging or file transfer platform
- Document storage, shredding, and records retrieval services
- IT support with access to systems holding PHI
Two gaps recur. First, agreements signed years ago with a vendor whose scope has since expanded — the billing company that now also runs your patient statements and payment portal. Second, no agreement at all with the small specialty vendor a single department onboarded without telling compliance.
If your review turns up missing paperwork, the fastest clean route is to generate the document properly rather than reusing a decade-old template with the wrong entity name. You can produce a signature-ready Business Associate Agreement through a six-step wizard, exportable as PDF or DOCX, as a one-time purchase — useful when you have four vendors to paper this week and no appetite for a subscription. HHS also publishes sample business associate agreement provisions that show the required elements.
Records Requests for Hospital Encounters: Who Holds the Chart
A patient calls your office asking for records of their inpatient stay. Front desk needs a scripted answer, because the honest one is split: the hospital holds the facility record, and your practice holds the professional record your providers created — progress notes, consults, and the billing record.
Define your designated record set for hospital-based encounters in writing. State whether it includes notes authored in the facility system, and how you retrieve them if it does. Then the 30-day clock under the HIPAA right of access runs against something concrete instead of a debate.
Right-of-access failures have been a steady enforcement theme for years. The fact that the record lives in a hospital system your practice does not control is an operational problem to solve, not a defense.
Audit Response Without Creating a Second Incident
Time-based level selection generates measurable patterns. If a payer requests records on a sample of initial inpatient encounters, your response workflow becomes a PHI transmission event under deadline pressure — the exact conditions that produce misdirected faxes and unencrypted email.
Decide in advance: which staff member assembles the response, which channel transmits it, who verifies the recipient address, and where the log of what was sent lives. Pull requests almost always specify a portal or secure upload. Use it. A fax cover sheet typed at 4:45 p.m. on a Friday is how a records response becomes a breach report.
A 60-Minute Self-Check for Your Inpatient Billing Line
- Confirm your charge capture screen reflects the post-2023 code set with no deleted observation codes.
- Verify your internal audit tool scores medical decision making and total time, not retired history and exam elements.
- Confirm your written policy names who selects the level — provider or coder — and how queries are documented.
- List every organization that touched an inpatient claim in the last 90 days. Match each to a signed agreement.
- Reconcile facility EHR credentials against your current staff roster.
- Write down your census list lifecycle: generated by, transmitted how, destroyed when.
- Test your right-of-access script for an inpatient encounter with your front desk.
Anything that fails becomes a dated remediation item with a named owner. Undated findings do not get fixed.
Start With the Paperwork You Can Close This Week
Understanding the 99221 CPT code description is the coding half. The vendor and records half is where administrators carry the real exposure, and it is also the half you can fix without a single provider conversation. If your vendor file has holes, generate the missing agreements and get them signed before the next audit request lands. If your broader policy set and risk analysis documentation are equally overdue, automated HIPAA risk analysis and policy generation will close that gap faster than another quarter of good intentions.