CPT Code 99233: Rounding Documentation and Vendor Risk
Your hospitalist group billed 41 subsequent inpatient visits last Tuesday. Eleven of them went out at the high level. Six weeks later, an additional documentation request lands in the mailroom asking for the complete record on 22 encounters, and the response window is measured in weeks, not months. Somebody in your office now has to pull inpatient notes out of a hospital EHR your practice does not own, package them, and ship them to a contractor.
That is the operational reality behind cpt code 99233. It is the highest level of subsequent hospital inpatient or observation care, it draws attention from payers precisely because it is the top of its family, and every claim carrying it depends on documentation your practice may not physically control. This guide covers the administrative mechanics, then the records-handling and vendor exposure that follows.
What Is CPT Code 99233 and When Do Practices Report It?
CPT code 99233 is the highest-level code in the subsequent hospital inpatient or observation care family (99231–99233), reported per day for an established inpatient or observation encounter. Since the 2023 E/M revisions, level selection for this family rests on either the level of medical decision making or the total time the reporting clinician spends on the date of the encounter. History and exam are performed and documented as clinically appropriate but no longer drive the level.
Whether a given encounter meets that threshold is a clinical determination made by the treating clinician and supported by the note. Your job as an administrator is different: make sure the documentation captures whichever basis was used, make sure the basis is used consistently across the group, and make sure the record can be produced intact on demand.
The two paths your documentation policy has to accommodate
- Medical decision making. The note needs to show the elements the clinician actually weighed — problems addressed, data reviewed and analyzed, risk of management. Copy-forward text that reproduces yesterday's assessment word for word is the single most common weakness auditors flag.
- Total time on the date of the encounter. If the clinician selects on time, the note needs the time, and internal policy should specify how it is recorded. "35–50 minutes" is not a time statement. A specific total, attributable to the reporting clinician, is.
Verify descriptors and time thresholds against your current-year CPT code set rather than against a cheat sheet someone printed in 2023. And confirm your practice actually holds a license for the code set your billers and your clearinghouse are using — CPT is AMA-copyrighted, and unlicensed distribution of code descriptors inside homegrown tools is a contract problem your compliance office owns, not IT's.
Six Handoffs Between the Bedside and the Claim
Map the path a single 99233 encounter takes through your organization. In most independent hospitalist and specialty groups it looks like this:
- The clinician sees the patient and documents in the hospital's EHR, under the hospital's access agreement.
- The clinician records the encounter on a personal or group census tool — a rounding app, a spreadsheet, a printed list, sometimes a photo of a whiteboard.
- That charge capture reaches your billing staff, often by email, shared drive, or a rounding app's export.
- A coder — internal or contracted — reviews the note and finalizes code selection.
- The claim goes to a clearinghouse and then to the payer.
- On denial or audit, someone retrieves the note from the hospital system and transmits it to the payer or its contractor.
Steps 2, 3, and 6 are where practices leak. The census list is protected health information — names, room numbers, admission dates, and frequently a working diagnosis. It is not a scheduling convenience. Treat it with the same controls you apply to the chart.
The rounding list problem
Ask your physicians how they carry the census between the hospital and the billing office. You will hear at least one of: text message thread, personal cloud notes app, photograph of a paper list, or an emailed spreadsheet with no encryption. Each of those is a disclosure to a service provider you have no agreement with.
Write a one-page charge capture policy that names the approved channel, prohibits the others, and specifies destruction of paper lists in a cross-cut shredder at end of shift. Then audit it — walk the physician lounge on a Friday afternoon and count the abandoned rounding sheets. That count is your baseline.
Split and Shared Visits: The Attribution Question Your Payer Will Ask
When a physician and an advanced practice provider both contribute to the same subsequent inpatient encounter in a facility setting, Medicare's split (or shared) visit policy determines whose NPI goes on the claim. CMS has revised the definition of the "substantive portion" more than once since 2022, and your billing lead should confirm the current-year definition in the Physician Fee Schedule final rule before you freeze internal policy. Payment values also change annually — check the CMS Physician Fee Schedule Look-Up Tool rather than an internal fee grid that may be a year stale.
From a records standpoint, split/shared documentation creates a specific obligation: both participants' work must be visible in the note, and the attribution must be defensible from the record alone. If your group uses a modifier to flag these encounters, put the modifier logic in writing and give the same document to your coding vendor. Verbal instructions to an offshore coding team do not survive staff turnover.
When an Audit Letter Arrives: Minimum Necessary Still Applies
A payer audit request feels like an obligation to send everything. It is not. Disclosures for payment purposes are permitted, but the minimum necessary standard still governs how much you send. HHS guidance on the minimum necessary requirement is the reference to hand your records clerk.
Practical version for a 99233 audit: send the encounter notes for the dates at issue, the orders and results the clinician documented reviewing, and the face sheet. Do not send the entire admission, unrelated specialty consults, or behavioral health and substance use records that carry additional protections. Log every disclosure with the date, recipient, and scope.
Three failure modes in the response workflow
- Wrong patient. Bulk exports from a hospital EHR are easy to misfilter. Require a second person to verify patient identifiers against the request list before transmission.
- Unencrypted transmission. If a contractor offers a portal, use the portal. If your only option is email, use the encryption your organization already licenses — and confirm the recipient can actually open it before the deadline.
- No copy retained. Keep an exact copy of what you sent. When the contractor later claims a note was missing, the burden of proof is yours.
The Vendor List Hiding Behind Every Inpatient Claim
Sit down with your accounts payable ledger and mark every party that touches, stores, or transmits PHI in the 99233 workflow. A typical independent hospitalist group finds more than it expected:
- The rounding and charge capture app
- The outsourced coding firm and any subcontractor it uses
- The billing company or RCM vendor
- The clearinghouse
- The transcription or ambient documentation vendor
- The denials and appeals consultant
- The document storage or e-fax provider used for audit responses
- The IT support contractor with remote access to billing workstations
Each of those needs a signed business associate agreement in place before PHI moves, and the agreement needs to address subcontractors, breach notification timing, and return or destruction of data at termination. HHS publishes sample business associate agreement provisions that define the required baseline.
If your review turns up a vendor operating without a current agreement — and it usually turns up two or three — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you need three agreements this quarter and none next quarter.
Hospital access agreements are not BAAs
Here is the distinction that trips up group administrators. When your physicians document in the hospital's EHR under a medical staff or participation agreement, the hospital is a separate covered entity, not your business associate. Your access to that system is governed by the hospital's terms — including its audit logging, its sanctions policy, and its expectations for account sharing.
Two consequences. First, if one of your physicians inappropriately accesses a chart, the hospital's audit log will show it and the hospital will call you. Second, if your group later loses hospital privileges, you may lose access to the source documentation supporting claims you already submitted. Confirm in writing how your group retrieves records post-termination, and how long that access lasts.
A Practical Assignment Sheet
Give these four items owners and dates rather than adding them to a standing agenda:
- Billing lead, 30 days: Document, in writing, how the group selects and documents E/M levels for subsequent inpatient care, including the time-recording convention and the split/shared attribution rule. Circulate to every clinician and to the coding vendor.
- Privacy officer, 30 days: Complete the vendor inventory above. Flag any party with no BAA, an unsigned BAA, or one predating your current subcontractor arrangements.
- Practice manager, 45 days: Replace unapproved charge-capture channels. Kill the text threads. Document the approved channel in the employee handbook and in onboarding.
- Compliance lead, 60 days: Run a ten-chart internal review of high-level subsequent visits. You are checking whether the documentation supports the basis used — not second-guessing clinical judgment. Report findings as a distribution, not as individual discipline, the first time through.
That internal review is also your best defense if the pattern in your 99233 volume ever draws a question. A group that can produce dated self-audits with corrective actions is in a materially different position than one that cannot.
What This Adds Up To
The revenue question around cpt code 99233 is about documentation quality. The compliance question is about who else touched the record on its way from a hospital bedside to a payer's audit contractor. Most practices have the first conversation every year and the second one never.
Start with the vendor inventory — it is the fastest way to find real gaps. When it surfaces agreements you need, build the BAA and get it signed before the next quarter's claims go out. If your broader documentation set needs the same treatment, automated risk analysis and policy generation covers the rest of the file your privacy officer is supposed to be able to produce on request.