CPT Code 99221: Practice Operations and Privacy Guide
At 6:40 a.m. your hospitalist opens a census list on a personal phone, photographs three face sheets, and texts them to the billing coordinator so the day's initial hospital visits get charged before Friday's close. That workflow produces revenue. It also moves patient names, account numbers, insurance IDs, and room assignments across at least four systems your practice does not own.
If your group bills CPT code 99221 or its higher-level siblings, you are running a data pipeline between a hospital and your practice every single morning. This guide walks the operational mechanics of initial hospital care billing for administrators and billing staff, then makes the records-handling, vendor, and privacy consequences explicit. It is administrative guidance on how practices determine and document code selection — not clinical guidance, and not a statement that any code fits any particular patient encounter.
What CPT Code 99221 Covers, in Plain Operational Terms
CPT code 99221 is the lowest of three codes in the initial hospital inpatient or observation care family (99221, 99222, 99223). One provider, one patient, one initial service per admission. Key operational facts your billing staff work from:
- Since the 2023 CPT revisions, separate observation care codes were deleted and observation services folded into the 99221–99223 family.
- Level selection rests on either the level of medical decision making or total time spent on the date of the encounter, plus a medically appropriate history and exam. CPT associates 40 minutes with 99221; confirm thresholds against the current CPT edition your coders use.
- Subsequent hospital care uses 99231–99233. Discharge day management uses 99238–99239. Same-day admission and discharge has its own family.
- Medicare directs the admitting practitioner of record to append modifier AI to distinguish the admitting service from consultants billing the same code family.
- Medicare does not pay the inpatient consultation codes, so consulting specialists typically report from the initial hospital care family without modifier AI.
Your practice does not choose a level. The rendering provider documents; your coders verify that the documentation supports what was selected, and your compliance lead makes sure the verification is written down.
The Documentation Chain Behind Every 99221 Charge
The note lives in a system you do not control
Here is the structural problem administrators underestimate. The note supporting a 99221 charge is written in the hospital's electronic record under a facility access agreement. Your practice bills off it, gets audited on it, and defends it in an appeal — but the hospital is the custodian.
Write down, per facility, who in your organization has read access, how that access is provisioned and terminated, and how your billers obtain a copy of a note when a payer requests documentation. If a coder leaves your practice on a Friday, someone must confirm the hospital deactivated that login. Facility credentialing offices do not always do it automatically, and orphaned hospital credentials belonging to your former employees are your exposure as much as the hospital's.
Time versus medical decision making, documented consistently
When level selection rests on time, the note needs the total time on the date of the encounter. When it rests on medical decision making, the note needs enough detail for a reviewer to follow the elements. Your role is to standardize the attestation language your providers use, not to tell them which basis to pick.
Build a one-page internal reference for your rounding providers covering: how time statements should be phrased, what modifier AI signals, and how split or shared visits get attributed. CMS has revised the definition of the "substantive portion" of a split or shared visit across successive Physician Fee Schedule rules, so check the current-year policy in the CMS Physician Fee Schedule materials rather than relying on a memo written three years ago.
One initial service, one admission
Only one initial hospital care service per admission per provider group and specialty. Duplicate initial charges are one of the most common denials in hospitalist billing, and they usually trace to a handoff — the admitting physician charges, the partner who rounds the next morning charges an initial code again. Fix that with a charge-capture rule, not a memo.
The Census List Is PHI Before It Is a Charge
Your practice and the hospital are separate covered entities. Every census extract, face sheet, and insurance verification that crosses from the facility to your billing team is a disclosure of protected health information. Treatment and payment disclosures are permitted, so the disclosure itself is rarely the problem. How it travels is.
Inventory the actual routes. In most rounding practices, they include some combination of: a printed census carried in a bag, a spreadsheet emailed each morning, a shared network folder, screenshots in a group text, and a charge-capture app. At least two of those probably are not in your security risk analysis.
Minimum necessary applies to payment-related uses and disclosures. A biller who needs account numbers and dates of service does not need a full problem list. When you request documentation from a facility for an appeal, ask for the encounter, not the record.
The three-question census audit
- Who receives the daily census, in what format, and where does the file rest after it is used?
- How long do those files live — on the laptop, in the mailbox, in the shared drive — and who deletes them?
- If the biller's laptop went missing tonight, how many patients' identifiers would be on it?
If you cannot answer question three within an hour, that is your finding for the quarter.
Charge Capture on Personal Phones: Your Highest-Volume Gap
Rounding providers capture charges on mobile devices. That is reality, and banning it produces workarounds rather than compliance. What you can control is the configuration.
For every device used to capture 99221-level charges, confirm: screen lock and passcode enforcement, encryption at rest, whether the charge-capture app stores PHI locally or only in transit, remote wipe capability, and whether photos of face sheets land in a personal cloud photo library that syncs to a home computer. That last one catches practices constantly — a physician photographs a patient label, and the image replicates to a family iPad by dinnertime.
The Security Rule requires your risk analysis to cover electronic PHI wherever your organization creates, receives, maintains, or transmits it. HHS has published guidance on what a compliant risk analysis has to include, and OCR enforcement has repeatedly turned on organizations that scoped the analysis to the main practice system and left mobile workflows, spreadsheets, and satellite processes out of it. A charge-capture app used at three hospitals belongs in scope.
If your current risk analysis is a spreadsheet someone built in a hurry two years ago and never mapped to your actual data flows, rebuild it. Tools that automate HIPAA risk analysis and generate the supporting policy set get you to a documented, defensible baseline faster than reconstructing it by hand — which matters when the request arrives with a 30-day response window attached.
Your Vendor List for Hospital Rounding Revenue
Initial hospital care billing quietly adds vendors that never appear on the front-desk vendor roster. Walk your list and confirm a signed, current business associate agreement for each of these categories:
- Charge capture / rounding app vendors. They hold census data and encounter detail. BAA required.
- Outsourced billing and coding companies. They receive notes and demographics. BAA required, plus a written statement of where their staff are located and whether work is subcontracted offshore.
- External coding auditors. A vendor reviewing your 99221 through 99223 distribution reads full notes. BAA required.
- Clearinghouses and RCM platforms. BAA required.
- Secure messaging and file transfer tools used to move documentation between the hospital and your billers. BAA required unless the vendor is genuinely a conduit, which most are not.
The hospital itself is usually not your business associate — two covered entities exchanging PHI for treatment and payment do not need a BAA between them. What you may need instead is a written data-use understanding covering the census feed: what fields, how transmitted, who is notified when something goes wrong. HHS publishes sample business associate agreement provisions as a baseline, though the sample is a floor and not a finished contract. If you are onboarding a charge-capture vendor this quarter and need an executable agreement quickly, a guided BAA builder that produces a signature-ready document beats routing a template through counsel for a low-risk, standard-terms vendor.
When the Payer Asks for the Chart
Higher-level initial hospital codes attract documentation requests. When an additional documentation request lands, your workflow should be already written:
- Day 0–2: Billing logs the request, identifies the facility of service, and submits the record retrieval request to the hospital's release-of-information process.
- Day 3–10: Coder reviews the retrieved documentation against the submitted code before anything goes out. If the documentation does not support the level billed, you decide about a corrected claim now, not after the audit result.
- Day 10–20: Compliance lead approves the response packet, confirming it contains the requested encounter and not the patient's entire history.
- Transmission: Through the payer's portal or an encrypted channel. Never an unencrypted email attachment, never a fax to an unverified number.
Payment-related disclosures are permitted and are not subject to the accounting-of-disclosures requirement, but you still want an internal log. When a payer later claims it never received records, your log is the only thing standing between you and a takeback.
When the Patient Asks for the Chart
A patient who saw your hospitalist calls your office asking for "my hospital records." Your front desk needs a scripted answer, because the correct one is nuanced.
Your designated record set includes what your practice maintains and uses to make decisions about that individual — typically the billing record and whatever encounter documentation your group holds. The full facility chart belongs to the hospital's designated record set, and that request goes to the hospital's health information management department. Say that clearly and give the patient the hospital's release-of-information phone number rather than a shrug.
For what you do hold, the 30-day clock under the access right starts when the request is received, with one 30-day extension available if you notify the individual in writing with a reason. Fees are limited to a reasonable, cost-based amount. OCR has run a sustained right-of-access enforcement initiative for years, and the settlements overwhelmingly involve small practices that simply took too long. Review the HHS individual right of access guidance with your front desk annually — the mistakes are procedural, not legal.
A 30-Day Cleanup Plan You Can Actually Assign
Week 1 — Billing manager. Map every route the daily census travels. Name the systems, the people, and the retention behavior of each.
Week 2 — Practice administrator. Reconcile the vendor list against signed BAAs. Flag any vendor touching hospital charge data without a current agreement, and note the effective date on each one.
Week 3 — Compliance lead. Confirm mobile device configuration for every provider capturing charges. Test remote wipe on one device. Document the test.
Week 4 — Administrator and compliance lead together. Update the risk analysis to include the rounding workflow, write the ADR response procedure, and put the patient records script in front of the front desk with the hospital HIM number on it.
None of this changes how a provider selects between 99221, 99222, and 99223. All of it changes whether your practice can explain, six months from now, how the data behind those charges moved and who was accountable for it.
If your rounding workflow expanded faster than your documentation did — new facility, new charge-capture app, new outsourced coder — start by generating a current risk analysis and the matching policy set, then work the vendor list against it. A morning's work now is considerably cheaper than reconstructing it under a response deadline.