A payer audit letter lands in your practice's mailbox on a Tuesday. It names your hospitalist group, covers dates of service from fourteen months ago, and asks for 40 charts — nearly all of them claims billed with CPT code 99232, the mid-level subsequent hospital inpatient or observation visit. You did not write the notes. Your practice does not host the medical record. Your billing vendor keyed the charges from a system the hospital owns.

This guide is for the administrator or compliance lead who has to answer that letter. It covers how subsequent-visit levels get determined and documented, who touches the chart between rounds and remittance, and where the vendor and records-request exposure sits.

What CPT Code 99232 Represents on the Claim

Since the 2023 CPT revisions to evaluation and management services, hospital inpatient and observation care share a single family of codes. Initial visits run 99221–99223. Subsequent visits run 99231–99233. CPT code 99232 is the middle of those three subsequent-visit levels.

Level selection under the current framework rests on one of two bases: the level of medical decision making, or the total time the reporting practitioner spends on the encounter on the date of service. The code descriptor for 99232 pairs a moderate level of medical decision making with 35 minutes of total time as the typical threshold. Which basis applies to any given encounter is a determination the treating practitioner makes and records — not something your coding staff decides after the fact.

That distinction matters operationally. Your job is to make sure the documentation says clearly which basis was used, and that the record supports it. If the practitioner selected on time, the note needs a total-time statement tied to the date of service. If the practitioner selected on medical decision making, the note needs to reflect the problems addressed, the data reviewed, and the risk considered.

Time vs. MDM: Force the Note to Declare Its Basis

Mixed documentation is the most common finding in the audits I have watched practices lose. A note contains a vague "30–40 minutes" range and a thin assessment, and neither basis stands on its own.

Build a template requirement instead of a training slogan. Ask your practitioners to include a discrete total-time attestation with start-and-stop or an aggregate figure for the calendar date, or an assessment-and-plan section structured to show the decision-making elements. One or the other, explicitly. Your coders should be able to identify the basis in under fifteen seconds without inference.

CMS publishes its evaluation and management payment policy and the annual code-level changes through the Physician Fee Schedule. Assign one person on staff to read the current-year final rule sections that touch inpatient E/M and split/shared billing, and to circulate a one-page summary to the practitioners each January.

What Documentation Supports CPT Code 99232?

Practices that survive audits of this code consistently have five things in the record for each date of service billed:

  • A dated, signed note attributable to the practitioner named on the claim, matching the date of service on the claim line.
  • An explicit basis for the level — either a total-time statement for that calendar date or documentation of the medical decision making elements the practitioner considered.
  • Evidence of the interval since the prior encounter: what changed, what was reviewed, what the plan is now.
  • Attribution for shared work, if a physician and an advanced practice provider both contributed, including any required modifier on the claim.
  • A charge-capture trail showing who entered the code, when, and from what source document.

Nothing on that list requires a clinical judgment from your administrative team. All five are verifiable in a chart review your compliance lead can run in an afternoon.

The Rounding-to-Claim Workflow, and Who Touches the Chart

Map this before your next audit, not during it. For a typical hospitalist or specialty consult group, the path looks like this:

  1. Rounds. The practitioner documents in the hospital's electronic record under credentials the hospital issued.
  2. Charge capture. The practitioner marks a level on a rounding list, mobile charge app, or worksheet — often before the note is finalized.
  3. Coding review. A coder, in-house or contracted, opens the hospital chart remotely and reconciles the marked level against the documentation.
  4. Charge entry. The code lands in your practice management system, with the rendering provider, place of service, and any split/shared modifier attached.
  5. Scrubbing and submission. A clearinghouse validates and routes the claim.
  6. Denials and appeals. Someone pulls chart excerpts and sends them to a payer, sometimes through a portal, sometimes by fax, sometimes by mail.

Count the entities in that chain. A hospital, your practice, a coding contractor, a billing company, a clearinghouse, possibly an audit-defense consultant, possibly a documentation or scribe vendor. Every step after step one moves protected health information across an organizational boundary.

Remote Coder Access and the Two-Covered-Entity Problem

Here is the trap specific to inpatient billing. Your coder reviews notes inside the hospital's system using hospital-issued credentials. The hospital treats that access as a courtesy to a credentialed practitioner's group. Your practice treats it as ordinary revenue-cycle work.

If the coder is your employee, the access is your practice's workforce access, and your policies, sanctions, and termination procedures govern it. If the coder works for an outside firm, that firm is your business associate — and the hospital may reasonably expect a separate written arrangement before extending credentials. Keep a roster of every named individual with hospital access on your behalf, who employs them, and the date access was last verified. When someone leaves, you notify the hospital the same day you disable your own systems.

Apply minimum necessary discipline to the access level itself. A coder validating a subsequent-visit level needs the progress notes, orders, and results for the relevant dates. Wholesale access to unrelated departments' records is a finding waiting to happen. HHS guidance on the minimum necessary requirement applies to role-based access design, not just to individual disclosures.

Split/Shared Visits: Attribution Is a Compliance Control

When a physician and an advanced practice provider both contribute to the same inpatient encounter on the same date, the claim must reflect who performed the substantive portion, and CMS requires a modifier identifying the visit as split or shared. CMS has revisited the definition of "substantive portion" across multiple rule cycles, so confirm the current-year definition rather than relying on a memo your practice wrote three years ago.

Operationally, the failure mode is not fraud. It is two notes, two time statements, and no one designated as the reporting practitioner. Your charge-capture tool should force a single selection before the charge can be released. If it cannot, your coder needs a written escalation path and a documented turnaround expectation — 48 hours is workable, a week is not.

Where the Vendor Exposure Actually Sits

Every entity that keys, scrubs, reviews, transmits, stores, or defends a 99232 claim on your behalf is handling protected health information for you. That means a signed business associate agreement before the first chart moves, not after the first audit.

Run your vendor list against this set and find the gaps:

  • Billing and revenue-cycle management companies
  • Contract coding firms and individual contract coders
  • Clearinghouses and claim-scrubbing platforms
  • Charge-capture and rounding-list applications
  • Transcription, scribe, and ambient documentation services
  • Audit-defense and appeals consultants
  • Document storage, shredding, and courier services
  • IT support with access to systems holding claim data

The gap I find most often is the appeals consultant retained under a professional-services letter with no privacy terms at all. The second most common is a coding contractor who signed a BAA with the hospital but never with the practice that pays them.

If you are staring at three or four unpapered relationships, you can generate a signature-ready business associate agreement through a six-step wizard and have PDF and DOCX versions in hand the same afternoon — one-time purchase, no subscription. Compare the output against the HHS sample business associate agreement provisions so you know what each clause is doing.

Records Requests When the Encounter Happened Inside a Hospital

A patient calls your office asking for "everything from my hospital stay." Your practice's designated record set includes the notes your practitioners authored and the billing records your practice maintains — not the hospital's full chart. Say that clearly, provide what you hold, and tell the patient in writing where to direct the rest.

The clock is 30 days from receipt, with one 30-day extension permitted if you notify the patient in writing of the reason and the new date. Fees must be reasonable and cost-based. HHS's right of access guidance is the reference to keep on your intranet, because right-of-access complaints remain a steady share of OCR enforcement activity.

Practical detail: patients requesting records after an inpatient stay frequently want the itemized charges as much as the clinical note. Billing records are part of the designated record set. Train the front desk to route these to one named person rather than answering ad hoc.

Responding to the 40-Chart Audit Request

Disclosures to a health plan or its contractor for payment purposes are permitted without patient authorization, and they do not require an accounting-of-disclosures entry. That does not make them casual.

Send only the dates of service the request names. Log what you sent, to whom, on what date, and by what transport method. Use the payer's secure portal when one exists; if you must send electronically outside a portal, encrypt. If a consultant assembles the response, confirm the BAA is in place before you hand over a single chart.

A Quarterly Check You Can Actually Run

  1. Pull 15 recent claims billed at each subsequent-visit level, including CPT code 99232, and confirm the note declares its basis — time or medical decision making.
  2. Verify the rendering practitioner on each claim matches the note author, and that split/shared encounters carry the required modifier.
  3. Reconcile your list of hospital-system users acting on your behalf against current employment and contract status.
  4. Confirm a signed, current BAA exists for every vendor in the claim path, including appeals consultants and courier services.
  5. Time one right-of-access request end to end and record where the days went.

Document the results with a date and a signature. An audit response is far easier when you can show a pattern of self-review rather than a scramble.

Next Step

Start with the vendor list, because it is the shortest task with the largest exposure. If a coding contractor, appeals consultant, or charge-capture app is touching your inpatient claims without a signed agreement, build and export the BAA this week. If your broader policy set and risk analysis are also overdue, automated HIPAA risk analysis and policy generation will get the documentation on paper faster than a committee will.