Your cardiology group bills six hospital consults a week. Last Thursday, a payer denied four of them in a single remittance batch, and your biller's note said only "consult not covered." Meanwhile your coder has read-only credentials to the hospital's EHR, pulls the requesting physician's order to support the level, and downloads a PDF to a shared drive nobody has audited since 2023.

The 99254 CPT code sits at the center of that mess. It is a level-four inpatient or observation consultation code, and it carries three operational burdens at once: a documentation standard, a payer-recognition problem, and a records-handling trail that runs through a building your practice does not control. This guide walks the mechanics, then makes the privacy and vendor exposure explicit.

What the 99254 CPT Code Is

CPT 99254 is one of four inpatient or observation consultation codes (99252–99255). It represents a level-four consultation for a hospital inpatient or observation patient, requested by another physician or appropriate source. Level selection is driven either by medical decision making or by total time on the date of the encounter — for 99254, the published time threshold is 60 minutes or more. Consultation codes were restructured in the 2023 CPT cycle, when the separate observation consultation family was folded in and the lowest-level code was deleted.

Two things follow from that description, and both are administrative, not clinical. First, your documentation has to establish that a consultation was requested and that a report went back. Second, level selection is a documentation-driven determination made by the rendering provider and verified by your coding staff against the encounter note — not something your front desk or biller assigns from a superbill checkbox.

The Two Paths to a Level, and Why Your Template Matters

Providers may support the level through medical decision making or through total time. Those are different documentation habits. A time-based path requires the provider to record time actually spent on the date of the encounter, including qualifying non-face-to-face work. An MDM-based path requires the note to reflect the elements the code descriptor contemplates.

Practices that let providers choose freely, without a template that captures either path cleanly, end up with notes that support neither. Pick a house standard for your consult service, build it into the note template, and audit against it quarterly. When your coding team cannot tell which path the provider intended, the level gets downcoded or the claim gets held — and held claims mean more chart movement, more emails, more copies of PHI in more places.

The Request-and-Report Rule Creates a Disclosure Every Single Time

A consultation is defined by a request from another physician or appropriate source, documented in the patient's record, and a written report of findings and recommendations returned to the requester. That report is not optional paperwork. Payers ask for it in audits, and its absence is one of the most common reasons a consultation-level claim collapses on review.

Now the privacy side. That report is a disclosure of protected health information to another covered entity for treatment purposes, which the Privacy Rule permits without authorization. What is not automatic is how you send it. Fax to a shared hospital number, unencrypted email to a physician's personal address, or a portal upload by whoever happens to be at the desk are three different risk profiles.

Write down the transmission method your practice uses for consult reports and make it one method with one documented exception process. Then confirm the fax number or secure address annually. Misdirected consult reports — right document, wrong recipient — are an ordinary, unglamorous source of small breaches, and they almost always trace back to a stale contact record rather than a hacker.

Why Medicare Denials Cluster on Your 99254 Line

Medicare stopped recognizing consultation codes for payment under the Physician Fee Schedule years ago. Practices billing Medicare for a hospital consult generally report the appropriate initial or subsequent inpatient or observation care code instead, per payer instruction. Commercial and Medicaid managed care plans vary: some recognize 99252–99255, some do not, and some recognize them only for specific specialties or place-of-service combinations.

This is a payer-policy question, not a coding-judgment question, and it belongs in a maintained document rather than in your senior biller's head. Build a one-page payer matrix listing each contracted plan, whether it recognizes inpatient consultation codes, and the effective date of the policy you verified. Assign an owner. Review it when contracts renew and when you onboard a new plan.

Check payment policy directly against payer sources and the CMS Physician Fee Schedule materials rather than relying on a coding forum screenshot from three years ago. When your matrix is current, the 99254 CPT code stops generating avoidable denials, and your staff stops circulating chart copies through appeal workflows that never needed to exist.

Hospital EHR Access Is a Privacy Problem Before It Is a Coding Problem

Most groups that bill inpatient consults give coders and billers credentials to the hospital's system so they can pull the requesting order, the note, and the discharge summary. That access is convenient and it is the single largest unmanaged risk in a hospital-based consult workflow.

Your practice and the hospital are typically both covered entities. The hospital is not your business associate, and you are not theirs, so a BAA is usually the wrong instrument. What you need instead is clarity on four points, in writing, with the hospital's HIM or medical staff office:

  • Who holds credentials. Maintain your own roster, separate from the hospital's, and reconcile it monthly.
  • What scope those credentials grant. Coders often receive far broader access than the consult encounters they support.
  • How termination works. When a coder leaves your practice on a Friday, hospital access should die the same day. Put the notification step in your offboarding checklist with a named owner.
  • Who investigates a suspected inappropriate access. The hospital's audit log will show your employee's ID. The hospital will call you.

Also decide where downloaded documents live. "The billing shared drive" is not an answer if nobody can say who has permissions to it. Apply the minimum necessary standard to what your coders pull, not just to what you send out.

The Vendor List Behind One Consult Claim

Trace a single 99254 encounter through your systems and count the third parties that touch PHI along the way. A typical hospital-based specialty group finds five or six:

  1. The practice management or billing platform where the claim is built
  2. An outsourced billing or RCM company, if you use one
  3. A transcription or ambient documentation vendor
  4. A clearinghouse
  5. A secure fax or messaging service used to return the consult report
  6. A coding audit consultant who reviews level selection quarterly

Every one of those is a business associate, and every one needs a current Business Associate Agreement on file before it receives PHI. The two that get missed most often are the coding audit consultant — because the engagement feels like professional advice rather than data processing — and the fax service, because it was set up by the office manager who left in 2022.

If you find a gap while reading this, close it the same week. You can produce a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, as a one-time purchase, which is faster than routing a request through outside counsel for a vendor you need live on Monday. HHS also publishes sample business associate agreement provisions if you want to see the required elements before you draft.

Records Requests When the Encounter Happened in Someone Else's Building

A patient calls your office six weeks after a hospital stay and asks for "everything from my consult." Your staff needs a scripted answer, because the honest one is nuanced.

Your practice must provide what is in your designated record set: the consultation note your physician authored, the report you sent, your billing records for the encounter. Hospital-generated records that you pulled and retained may also fall inside your designated record set if you maintain them and use them for decisions about that patient. Records that live only in the hospital's system, which your coder viewed but never retained, are the hospital's to produce.

The right of access generally requires action within 30 days, with one 30-day extension available if you notify the patient in writing with a reason. Train your front desk to (a) log the request with a date stamp, (b) never refuse it, and (c) hand it to the privacy officer rather than guessing at scope. A well-meaning "you'll have to call the hospital for that" is how access complaints start.

Fee Rules Your Front Desk Should Not Improvise

If you charge for copies, the fee must be reasonable and cost-based within the limits HHS describes. Search and retrieval time is not chargeable. Put your fee schedule on paper, hand the same sheet to every requester, and stop letting individual staff quote numbers from memory.

Payer Audits: Send the Consult, Not the Chart

When a payer requests documentation on a 99254 claim, disclosure for payment purposes is permitted. The failure mode is over-disclosure. Staff under deadline pressure export the full chart because it is one click, and now years of unrelated history sit in a payer's review queue.

Define an audit response packet for consult claims: the requesting order or documented request, the consultation note for the date of service, the report sent to the requester, and the claim detail. Nothing else unless the payer names it. Log what you sent, to whom, on what date, and under which request ID. That log is your defense when someone later asks why a document left the building.

A 90-Day Cleanup Sequence for a Consult Service

Days 1–15. Build the payer matrix for inpatient consultation code recognition. Name an owner and a review date.

Days 16–30. Inventory hospital EHR credentials held by your staff. Reconcile against your current roster. Terminate anything orphaned and add the notification step to offboarding.

Days 31–45. List every vendor that touches consult PHI. Confirm an executed, current BAA for each. Execute the missing ones.

Days 46–60. Audit twenty consult notes against your documentation standard. Report downcoding risk and missing consult reports to the physicians by name, privately.

Days 61–75. Verify every consult-report transmission destination. Fax numbers, portal addresses, direct addresses.

Days 76–90. Update your risk analysis to reflect hospital system access and the download locations you found. If your documentation set has drifted, automated risk analysis and policy generation will get you back to a defensible baseline faster than rebuilding spreadsheets.

The Short Version for Your Next Staff Meeting

The 99254 CPT code is a documentation problem, a payer-policy problem, and a data-custody problem wearing one number. Providers own level selection and the report back to the requester. Your coders own verification and minimum-necessary discipline when pulling from hospital systems. You own the payer matrix, the credential roster, the vendor agreements, and the records-request script.

Start with the vendor list, because it is the one item where a gap is both easy to find and cheap to fix. Pull your contracts this week, and generate the Business Associate Agreements you are missing before your next consult claim moves through a vendor you never papered.