A payer audit letter arrives asking for the complete records supporting eleven inpatient admissions your hospitalists billed last spring. Nine of those claims used the 99223 CPT code. You have ten business days, the notes live in a hospital EHR your practice does not own, and your coding contractor is the only person with reliable access.

That is the whole problem in one paragraph. This guide is for the administrator, billing manager, or privacy officer who has to answer that letter — it covers how the 99223 CPT code is selected and documented, who touches the record on the way to the claim, and where the privacy and vendor obligations attach. It is administrative guidance about workflow and documentation, not clinical guidance about which code fits which patient.

What the 99223 CPT Code Covers, and What Decides the Level

The 99223 CPT code is the highest of the three initial hospital inpatient or observation care codes (99221, 99222, 99223), reported once per admission by the physician or qualified health professional performing the initial encounter.

Since the 2023 CPT revisions, level selection rests on one of two paths, chosen by the billing clinician:

  • Medical decision making (MDM) — 99223 corresponds to a high level of MDM under the CPT MDM table.
  • Total time on the date of the encounter — 99223 requires 75 minutes or more; 99222 requires 55 or more; 99221 requires 40 or more.

History and exam must be medically appropriate, but they no longer drive the level. Observation care was folded into this same code family in 2023, so the old separate observation codes are gone — the distinction now shows up in place of service, not code choice.

Your job as an administrator is not to decide which level applies. It is to make sure the record supports whichever path the clinician used, and that the documentation says so plainly.

Time-based selection has a paperwork requirement

If a clinician selects the level by time, the note needs a total time statement for the date of the encounter. "Spent significant time coordinating care" does not survive an audit. A stated number of minutes, tied to the date, does.

Build this into your template review, not into a nagging email. If your group's inpatient note template has no time field, every time-based 99223 depends on the clinician remembering to free-text it.

One Initial Service Per Admission: The Rule Your Billers Argue About Most

Only one initial inpatient or observation service is reportable per admission by the same physician or by another physician of the same specialty in the same group. Everyone else in the group who sees the patient that stay reports subsequent care codes.

Three operational traps follow from that:

  1. Office visit same day as admission. When the same clinician sees the patient in the office and then admits, the work generally rolls into the initial inpatient service rather than being billed twice. Your scrubber should flag same-day office plus initial inpatient claims for the same NPI before they go out.
  2. Split or shared visits. When a physician and an advanced practice provider both contribute to the encounter, CMS requires the claim to reflect who performed the substantive portion, with the FS modifier appended. CMS has revised the substantive-portion definition across multiple rule cycles — check the current-year Physician Fee Schedule final rule and your MAC's guidance rather than relying on a policy your billing team memorized three years ago.
  3. Teaching settings. Resident-involved encounters carry their own attestation and modifier requirements. If your group staffs a teaching hospital, the attestation language belongs in the template, not in the attending's head.

The Documentation Packet Your Coders Need Before They Touch the Claim

Assign this as a named workflow with owners and a clock. A workable version:

  • Day 0–1: Clinician signs the initial encounter note in the hospital EHR. Charge capture entry created with admission date, place of service, and attending NPI.
  • Day 2–3: Coding review. Coder confirms the note identifies the level path — MDM elements or a stated total time — and that the encounter is genuinely the initial service for that admission and specialty.
  • Day 3–5: Query cycle if anything is missing. Queries go through a documented channel with a retention trail, not a text message.
  • Day 5–7: Claim release. Any 99223 held past day 10 gets escalated to the billing manager weekly.

Track your group's distribution across 99221, 99222, and 99223 by clinician, quarterly. You are not looking for a "correct" ratio — you are looking for a clinician whose curve moved sharply without a change in patient mix or setting, which is a documentation-review trigger, not an accusation.

Worked example of a defensible file

A hospitalist admits a patient at 11:40 p.m. The note is signed the following morning. Your coder now has to establish which calendar date the encounter belongs to, because time-based selection is anchored to the date of the encounter. The defensible file contains: the signed note with the encounter date and a stated total time, the charge entry matching that date, and — if the date was corrected — an audit-trail entry showing who changed it and when. That last item is what auditors ask for and what practices most often cannot produce.

Where the 99223 CPT Code Becomes a Privacy Problem, Not Just a Billing Problem

Inpatient E/M billing has a structural feature that office-based billing does not: the record lives somewhere your practice does not control.

Your hospitalists document in a facility EHR under credentials the facility issued. Your coders pull those notes, often by exporting PDFs into your practice management system or a shared drive. At that moment, hospital-generated PHI becomes PHI your practice holds, safeguards, retains, and eventually has to produce or destroy.

Ask three questions and write down the answers:

  • Who at your practice has facility EHR credentials, and when were they last reconciled? Terminated coders and departed clinicians frequently keep hospital access for months because the facility never hears from you. Add "notify facility credentialing/HIM" to your offboarding checklist with a 24-hour deadline.
  • Where do exported notes land? If the answer is a personal downloads folder or an unmanaged shared drive, you have an unencrypted PHI repository nobody has inventoried.
  • What does your agreement with the facility actually say? Hospital-physician arrangements vary. Some position the group as a business associate for certain functions; others do not. Read the document instead of assuming.

Your coding contractor is a business associate — get the paperwork right

Outsourced coders, offshore abstraction vendors, audit-defense consultants, clearinghouses, and the RCM firm that scrubs your claims all create, receive, maintain, or transmit PHI on your behalf. Each one needs a signed business associate agreement before the first record moves, and HHS is explicit about what those agreements must contain.

The failure mode is almost never a missing BAA with the big RCM vendor. It is the small ones: the independent coder you brought on for a backlog, the consultant who reviewed your E/M distribution, the transcription service one clinician uses. If you are chasing signatures across a vendor list, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you need three agreements this week and none next quarter.

Also confirm that any vendor using CPT codes in a product or deliverable holds the appropriate AMA CPT license. CPT is copyrighted; your vendor's licensing gap can become your contract problem.

Answering a Payer Audit Without Over-Disclosing

Disclosures to a health plan for payment purposes are permitted under HIPAA. That permission is not unlimited — the minimum necessary standard still applies to what you send.

A records request for nine admissions is not an invitation to export the entire longitudinal chart for nine patients. Build a standard response packet and stick to it:

  • The signed initial encounter note for the dates at issue
  • Supporting documents the note references for the same dates
  • The relevant orders and the physician attestation, where applicable
  • A cover log identifying each document by patient identifier, date of service, and claim number

Log every audit response in your disclosure tracking. Payment-purpose disclosures are not accountable disclosures under the accounting-of-disclosures rule, but you will want the internal record when the second request arrives eight months later and nobody remembers what went out the first time.

Send it through a channel you can attest to. Fax to a number confirmed by callback, a portal the payer controls, or encrypted transfer. Not an unencrypted email attachment because the auditor's contact was in Outlook.

When the Patient Asks for the Note and the Bill

The designated record set includes billing records. A patient who asks your practice for the documentation behind a high-level inpatient charge is exercising the HIPAA right of access, and your 30-day clock runs from the request — not from the day your coder gets around to it.

Two wrinkles specific to inpatient work. First, your practice must produce what your practice holds; the facility's chart is the facility's obligation. Say so plainly in writing and give the patient the HIM department's contact rather than a shrug. Second, if your billing system holds only a claim summary and the clinical note sits in the hospital EHR, decide in advance whether your standard response includes the retrieved note. Inconsistent handling across staff is where access complaints originate.

A Quarterly Routine That Keeps This Boring

Put four items on a recurring calendar and assign each a name:

  1. E/M distribution review — level mix by clinician, with documentation spot-checks on the outliers. Billing manager owns it.
  2. Facility access reconciliation — active credential list versus current roster. Practice administrator owns it.
  3. Vendor and BAA inventory — every entity that touched PHI this quarter, agreement status, effective date. Privacy officer owns it.
  4. Template audit — does the inpatient note template still capture total time, attestation language, and the current modifier requirements? Compliance lead owns it.

The 99223 CPT code draws scrutiny because it sits at the top of its family, and federal and commercial auditors have returned to high-level E/M billing repeatedly. Scrutiny is manageable. Scrutiny plus an unmapped vendor list and no access log is not.

Do This Next

Pull your vendor list this week and mark every entity that has touched an inpatient record in the last twelve months. For any without a current signed agreement, build the BAA and get it executed before the next audit letter forces the conversation. If the gap is broader than paperwork — risk analysis, policies, the full document set — automate the compliance documentation rather than rebuilding it from a template someone downloaded in 2019.