99233 CPT Description: Admin, Records, and Vendor Rules
Say your hospitalist group rounds at two facilities and bills roughly 400 subsequent inpatient visits a month. A payer sends a records request for 25 of them — every one coded at the top of the subsequent-care family. Your biller forwards the request, your coder pulls charts from two different hospital systems, and an outside consultant reviews the notes over a weekend. Somewhere in that chain, three separate privacy decisions got made by people who never framed them as privacy decisions. This guide walks the 99233 cpt description from the operations side: what the descriptor requires, who touches the record on the way to a clean claim, and where your BAA list and minimum-necessary rules have to hold.
What the 99233 CPT Description Actually Says
CPT 99233 is the highest-level code in the subsequent hospital inpatient or observation care family (99231, 99232, 99233). The descriptor covers subsequent care, per day, for the evaluation and management of a patient, and requires a medically appropriate history and/or examination plus a high level of medical decision making. When total time on the date of the encounter is used for code selection instead, 50 minutes must be met or exceeded.
Two structural points matter for your workflow. First, since the 2023 CPT revisions, inpatient and observation care share one set of codes — the old standalone observation codes were deleted. Second, history and exam no longer drive level selection; they must be medically appropriate, but they are not scored. Level selection runs on medical decision making or time, not both.
The Two Roads to Level Selection
- Medical decision making. Scored across three elements: number and complexity of problems addressed, amount and complexity of data reviewed and analyzed, and risk of complications from management decisions. The high-level threshold requires meeting or exceeding the criteria in two of the three.
- Total time on the date of the encounter. Includes qualifying non-face-to-face work performed by the reporting clinician on that calendar date — record review, ordering, documenting, care coordination. It does not include time billed separately or staff time.
Your job as an administrator is not to decide which road a given encounter should take. Your job is to make sure the documentation supports whichever road the clinician used, that the choice is legible to a reviewer, and that the chart never has to be reconstructed from memory six months later. CMS's Evaluation and Management Services Guide is the reference to keep in your policy binder, and it gets updated — verify you are working from the current edition each year.
How Practices Determine and Document Code Selection
Level assignment is a clinical judgment recorded by the treating clinician. What your operation controls is the scaffolding around it.
Build the note template so that, when time is the basis, the attestation states total time on the date of the encounter and identifies it as such — not "spent significant time with patient." When medical decision making is the basis, the note should make the problems addressed, the data actually reviewed, and the management risk visible without a reviewer inferring them.
Assign an owner to the template itself. In most groups that is the compliance lead working with one physician champion. Templates that drift — a copied-forward attestation, a hard-coded time value, a default risk statement — are the single most common finding when a payer looks at a 99233 cpt description claim pattern.
Split or Shared Visits and Teaching Settings
If a physician and an advanced practice clinician both contribute to the same inpatient encounter, CMS policy governs who reports it and how the substantive portion is established. That policy has been revised more than once in recent rulemaking cycles. Do not run last year's internal guidance; pull the current Physician Fee Schedule final rule language and date-stamp your internal policy each January.
Teaching settings add attestation requirements for attending involvement. Your workflow needs a check that the attending attestation is present before the claim drops, not after a denial.
Who Touches the Inpatient Chart Between Rounds and Remittance
Here is where the privacy work lives. A subsequent inpatient visit generates a note inside the hospital's system, but the professional claim comes from your group. That means protected health information moves — and every movement needs a lawful basis and a documented control.
Map the chain for one encounter. In a typical independent group it looks like this:
- Clinician documents in the hospital EHR under facility-issued credentials.
- The note, or an abstract of it, reaches your group's system — via interface, portal download, secure email, or in some groups a printed face sheet someone carries.
- Your coder or coding vendor reviews the documentation and assigns or validates the level.
- Your billing team or revenue cycle vendor submits the professional claim.
- On denial or audit, someone assembles a records packet and transmits it to the payer.
Steps 1 and 5 are usually fine. The hospital-to-group flow is a permitted disclosure for treatment and payment between covered entities, and payer disclosures are permitted for payment. Steps 2, 3, and 4 are where practices get sloppy — unencrypted attachments, personal accounts, shared logins, a coder's local download folder that nobody has ever inventoried.
Termination Is the Step Everyone Skips
Hospital EHR credentials belong to the hospital, but the offboarding obligation is yours to trigger. When a clinician leaves your group, someone must notify credentialing at every facility that day. Keep a facility-by-facility access roster and reconcile it quarterly. Standing access at a hospital where a former employee no longer rounds is exactly the kind of finding that turns a small incident into a reportable one.
Minimum Necessary When the Inpatient Record Runs 400 Pages
Coding a high-level subsequent visit invites broad chart review — labs, imaging, consults, prior days' notes. That is legitimate for the coder validating data complexity. It is not automatically legitimate for everyone downstream.
The minimum necessary standard applies to your internal uses as well as your external disclosures. HHS's guidance on the minimum necessary requirement expects role-based limits, and "role-based" means your billing clerk does not need the full inpatient record to post a payment.
Three practical controls:
- Scope the audit response, not the whole admission. When a payer requests documentation for a specific date of service, send that date's note plus the specifically requested supporting items. Do not ship the entire admission because it is easier to export.
- Separate coder access from poster access. Different roles, different views, documented in your access control policy.
- Kill the local copies. Coders working from downloaded PDFs create a shadow record set nobody manages. Require review inside the system of record, or inside one designated encrypted repository with retention rules.
The Vendors Sitting on Your 99233 Workflow
Count them honestly. A group billing subsequent inpatient care typically involves an outsourced or contract coder, a revenue cycle management company, a clearinghouse, a transcription or ambient documentation tool, an appeals or audit-defense consultant, and sometimes an analytics vendor benchmarking level distribution across the group.
Every one of those creates, receives, maintains, or transmits PHI on your behalf. Every one is a business associate, and every one needs a signed agreement before the first chart moves. That includes the consultant you engaged for a two-week audit response and the coding contractor working three hours a week from home.
The two agreements most often missing in practice are the independent contract coder and the audit-defense consultant — both engaged fast, under deadline pressure, often by a clinical leader rather than by administration. If you need to close that gap this week rather than next quarter, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase, no subscription. HHS also publishes sample business associate agreement provisions if you are building from scratch with counsel.
Ambient Documentation Tools Deserve a Second Look
If clinicians are using an ambient scribe or dictation tool to draft inpatient notes, ask four questions in writing: where is audio stored, how long is it retained, is it used to train models, and does the BAA address secondary use. Also confirm whether the tool auto-populates time statements. A tool that generates a total-time attestation without clinician verification is a documentation-integrity problem sitting on top of a privacy problem.
When a Patient Asks for the Notes Behind an Inpatient Visit
Patients who were admitted often assume the hospital holds everything. Your group's professional notes for the subsequent visits are part of your designated record set, and a request to you starts your clock — 30 days, with one 30-day extension available if you notify the individual in writing with a reason and a date.
Two failure modes to train out of your front desk. First, redirecting the patient to the hospital and closing the ticket — that is not a response. Second, treating the request as a subpoena and escalating it into legal review for weeks. Review the HHS individual right of access guidance with whoever answers your phones, and log every request with a date received and a date fulfilled.
Fees are limited to a reasonable, cost-based amount. Print-and-mail workflows that quote per-page charges from a 2009 policy are a live risk; access-related complaints have been a durable enforcement theme for OCR, and resolutions in this area are searchable in the OCR portal.
A Monthly Control Loop You Can Actually Run
Assign each item an owner and a date. Thirty minutes a month beats a scramble during an audit.
- Level distribution review. Practice manager pulls subsequent-care level mix by clinician. Outliers get a documentation conversation, never a coding instruction.
- Template integrity spot-check. Compliance lead samples five charts per clinician for copy-forward attestations and hard-coded time values.
- Attestation completeness. Billing lead confirms attending and split/shared attestations are present pre-submission, not post-denial.
- Facility access reconciliation. Credentialing owner compares active hospital EHR accounts against the current roster.
- BAA reconciliation. Compliance lead compares the vendor list from accounts payable against the signed-agreement register. Any vendor touching charts without an agreement stops receiving PHI that day.
- Transmission audit. Confirm no records left the practice by unencrypted email or personal file-sharing account.
- Access request log review. Any request open past day 20 gets an extension letter drafted.
Notice what is absent from that list: any step where an administrator decides a specific code fits a specific patient. Keep that boundary clean. Your control loop measures whether documentation supports the level reported and whether the record moved safely — not whether the clinician's judgment was right.
Where the 99233 CPT Description Meets Your Compliance File
A high-level subsequent inpatient code is a documentation-heavy, vendor-heavy, chart-movement-heavy claim. That combination is why the 99233 cpt description belongs in your compliance documentation, not just your coding cheat sheet. Your risk analysis should name the hospital EHR access pathway, the coding vendor, the RCM vendor, and the ambient documentation tool as specific systems with specific safeguards.
If those artifacts are stale, rebuild the set — you can automate the risk analysis and policy document set rather than editing a template someone downloaded years ago. Then close the vendor gap: pull your AP vendor list this week, mark every party that touches an inpatient chart, and put a signed BAA in place for each one before the next audit letter arrives.