Fifty-eight days after your specialist walked up to bed 412 on a Saturday morning, the denial lands: "consultation services not covered under this plan." The note is fine. The physician did the work. The problem is that whoever built the charge did not check which payer bucket the patient fell into before selecting the cpt code for inpatient consult services, and now you are inside a 90-day appeal window with a note that lives in a hospital EHR your billing staff cannot reach.

This guide is for the person who owns that mess — the practice administrator, the billing lead, the compliance officer who signs the vendor contracts. It covers how practices determine and document code selection for hospital consultations, then makes the records-handling and vendor exposure explicit, because inpatient consults generate PHI in a system you do not control.

What Is the CPT Code for Inpatient Consult?

CPT maintains a family of inpatient or observation consultation codes in the 99252–99255 range. Code 99251 was deleted in the 2023 CPT revision, the same cycle that merged observation and inpatient care into a single set of hospital inpatient and observation care codes (99221–99223 for initial care, 99231–99233 for subsequent care, 99234–99236 for same-day admit and discharge).

Three operational facts your staff needs on a card:

  • Level selection for the 99252–99255 family is driven by the level of medical decision making or by total time spent on the date of the encounter — the physician chooses the basis, and your documentation policy should require them to say which.
  • Medicare does not pay consultation codes. CMS eliminated payment for CPT consultation codes effective January 1, 2010. For Medicare patients, physicians report the appropriate hospital inpatient or observation care code instead.
  • Commercial and Medicaid coverage varies. Some plans recognize 99252–99255; some mirror Medicare; some pay them at a different relativity. This is a payer-grid question, not a clinical one.

Nobody outside the treating physician selects the code. Your job is to make sure the right rule set, the right documentation, and the right payer policy are in front of that physician before the charge is finalized.

Your Payer Grid Is the Real Answer, Not a Single Code

Ask your billing lead to produce a one-page grid: every payer you bill, and for each one, whether consultation codes are recognized. If that page does not exist, your denial rate on hospital work is higher than it needs to be and you probably cannot explain why.

For Medicare, the operative guidance sits in the Medicare Claims Processing Manual, Chapter 12, which covers physician services and the reporting conventions for initial hospital care — including the long-standing instruction that the admitting physician of record identifies the admission with the AI modifier while other physicians performing an initial evaluation report initial hospital care codes without it. Verify current specifics with your MAC before you rewrite a charge template; local edits change.

Build the grid, date it, name an owner, and re-verify it every time a payer publishes a policy bulletin. Put the review on the same quarterly calendar as your fee schedule load.

Request, Reason, Report: The Three Artifacts Your Coders Need

Payers that still recognize consultation codes generally expect the record to show that another provider or appropriate source requested the opinion, the reason for the request, and that the consultant sent a report back. In a hospital, all three of those artifacts are scattered across systems.

The request

The request may arrive as a phone call to your answering service, a hospital paging system message, a secure text, or an order entered by the attending. A phone call is not a record. Your policy should require that the consulting physician or a designated staff member document the requesting provider's name, the date and time, and the stated reason — in the hospital chart and in your own system.

The reason

"Cardiology consult" is not a reason. Coders reviewing the charge need the clinical question that was asked. That language comes from the physician, not from your billing team, and your team should never supply it.

The report

If the consultant documents in the hospital's EHR and the attending reads it there, many payers treat that as the report. Some do not, and want evidence of communication back to the requester. Document your standing interpretation per payer so a coder is not guessing at 4:45 p.m. on a Friday.

Role Assignments That Keep an Inpatient Consult Claim Clean

Denials on hospital work almost always trace to an unassigned handoff. Write these down and put names next to them.

The consulting physician

Selects the code. States the basis for level selection — medical decision making or total time. Documents the request source and reason. Signs and dates within your policy window, not the hospital's.

The hospital-rounds coordinator or scheduler

Captures the encounter on the daily census log the same day: patient identifiers, facility, date of service, requesting provider, place of service. This log is PHI. It lives in your system, not on a shared spreadsheet in a personal cloud drive.

The coder or coding vendor

Confirms the payer recognizes consultation codes before the charge drops. Confirms place of service. Queries the physician when documentation does not support the reported basis — and never edits clinical language.

The AR follow-up staffer

Owns the appeal calendar. Knows which payers require the consult request documentation attached at first submission versus on appeal.

The Hospital Chart Is Not Your Designated Record Set

Here is where the billing question becomes a privacy question. Your physician documented in the hospital's EHR. Six weeks later, the patient calls your front desk and asks for the consult note.

Under the HIPAA Privacy Rule, the patient has a right of access to PHI in the designated record set that you maintain. If your practice keeps a copy of the consult note — pulled into your system, faxed back, or exported for billing — that copy is in your designated record set and the access request attaches to it. You cannot redirect the patient to the hospital and close the ticket.

The clock is 30 days from the request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. HHS's right of access guidance is the document to hand your front-desk lead, and OCR has spent years enforcing this specific obligation against small and mid-size practices. Fees must be reasonable and cost-based; "we charge $50 for hospital records" is not a policy, it is a finding waiting to happen.

Two things to settle in writing before the next request arrives:

  1. Do you retain a copy of hospital consult documentation? If yes, it is in scope. If no — if your physicians document only in the facility EHR and you bill from a census log — say so in your access procedure and train staff on the exact redirect language.
  2. Who fulfills the request when the note is only in the hospital system? Name the person. Give them the hospital HIM contact.

Hospital EHR Credentials, Audit Logs, and the Day Someone Leaves

Your physicians hold credentials in a system you do not administer. That is a standing risk with three moving parts.

First, access scope. Hospital EHRs frequently grant broader visibility than your physician needs. The minimum necessary standard still governs what your workforce may look at. "The system let me" is not a defense during an investigation into chart snooping.

Second, audit trails. The hospital holds the access logs. If a patient complains that your physician viewed a record without cause, you will be reconstructing events from someone else's system on their timeline. Know now who to call and what the request process is.

Third — and this is the one practices miss — offboarding. When a physician or NP leaves your group, your internal termination checklist covers your EHR, your email, your VPN. It usually does not cover the six hospital systems where they hold active credentials. Add a line item per facility, with a named contact and a confirmation email retained in the personnel file.

Vendor Implications: Everyone Who Touches the Consult Charge

Trace one inpatient consult charge end to end and count the outside entities that touch PHI: the answering service that took the consult request, the transcription or ambient documentation vendor that produced the note draft, the outsourced coding company that assigned the level, the billing company that submitted it, the clearinghouse that routed it, the document-storage platform where you archive the census log.

Each of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. Each requires a signed Business Associate Agreement in place before the first record moves. HHS's business associate guidance is unambiguous about that ordering, and "we've worked with them for years" does not substitute for a document.

The gap I see most often in hospital-facing practices: the coding vendor onboarded during a staffing crunch, and nobody ever papered it. If you are looking at a vendor on your list with no executed agreement, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you need three of them this week and not a platform commitment.

While you are in the file, check two clauses specifically: breach notification timing to you (not just to HHS), and whether the vendor may use subcontractors offshore. Offshore coding is common and lawful under HIPAA with proper agreements in place; some of your commercial payer contracts restrict it anyway. Read both documents together.

A Worked Example: Denial to Resolution in 21 Days

Day 1 — Denial posts: consultation code not covered. AR staffer checks the payer grid and finds the plan follows Medicare's convention.

Day 2 — AR flags the charge to the coding lead, not to the physician. Coding lead confirms documentation content supports an initial hospital care level under the payer's rules and issues a physician query on the reporting basis.

Day 5 — Physician responds, confirms basis, re-attests. Coder rebills under the correct family per that payer's policy. Nobody rewrote clinical language; the physician made the selection.

Day 6 — Compliance officer notes that the consult note was retrieved from the hospital portal by a billing contractor. Confirms the contractor's BAA is executed and covers portal-based retrieval. It is. Ticket closed with a note in the file.

Day 21 — Payment posts. Payer grid updated with the bulletin reference and the date it was verified.

Four roles, one calendar, zero improvisation. That is the whole system.

Put This on Your Quarterly Calendar

Reconfirm the payer grid. Reconfirm which facilities your clinicians hold credentials at, and reconcile that list against your active roster. Pull your vendor inventory and confirm every entity touching consult documentation has a current signed BAA. Re-read your access procedure and ask your front desk what they actually say when a patient requests a hospital consult note — the answer is often not what the policy says.

If the vendor inventory is where you are stuck, start there: build the missing Business Associate Agreements in an afternoon, then move on to the risk analysis and policy set at hipaa.app. The coding side of an inpatient consult is a payer-policy problem you can solve with a grid. The privacy side is a documentation problem, and documentation problems only get more expensive the longer you leave them.