Your cardiology group billed 22 hospital consults last month. Six claims came back denied, two were downcoded on payer review, and one consult report never reached the hospitalist who requested it — your physician dictated it into the hospital's system and nobody at your office kept a copy. All three of those problems belong to the same workflow, and if you administer a practice that sends physicians into hospitals, inpatient consultation cpt billing is where your revenue cycle, your records-request process, and your vendor list collide.

This guide is written for the administrator, biller, or privacy officer who owns that workflow. It covers what the code family actually requires operationally, then makes the privacy and vendor consequences explicit: who holds the record, who needs a Business Associate Agreement, and what happens when a patient asks your practice for the consult note.

The Two Rule Changes That Broke Most Legacy Consult Workflows

Two things happened that a lot of internal cheat sheets never caught up with.

First, Medicare stopped paying separately for consultation codes effective January 1, 2010. Under Medicare, a physician who sees a hospitalized patient at another physician's request reports the appropriate initial or subsequent hospital inpatient/observation care code instead of a consultation code. The Medicare Claims Processing Manual, Chapter 12, spells out the instruction — worth having your coding lead read it directly rather than relying on a summary. You can pull it from CMS's published manual.

Second, CPT restructured the evaluation and management section for 2023. The lowest-level inpatient consultation code was deleted, history and exam no longer drive level selection (they must simply be medically appropriate), and level is selected by either medical decision making or total time on the date of the encounter. Any internal grid your billers built before 2023 is wrong.

The operational takeaway: an inpatient consultation cpt code is payer-dependent, not universal. Some commercial plans, Medicaid programs, workers' compensation carriers, and liability payers still recognize the consultation family. Medicare and plans that follow Medicare rules do not. Your billing team needs a payer matrix, refreshed at least annually and whenever a contract renews.

Build the payer matrix as a living document

  • One row per contracted payer and product line, including Medicare managed-care products, which often mirror Medicare's rules.
  • Columns: recognizes consultation codes yes/no, effective date of the policy you verified, link or PDF of the policy, name of the person who verified it, verification date.
  • Store the payer policy PDF, not just the link. Payer portals rewrite URLs constantly, and in an appeal you need the version that was in force on the date of service.

What Documentation Supports an Inpatient Consultation CPT Code?

For payers that still recognize the family, four elements have to be visible in the chart before the claim goes out. This is the checklist your coders should apply — it is administrative screening, not a clinical judgment about which level fits a given patient:

  1. A request. Documentation that another physician or qualified provider asked for the opinion, including who asked.
  2. A reason. The specific question or problem prompting the request, in the requesting provider's words or reasonably attributed to them.
  3. Rendered service. The consulting physician's own documented evaluation and recommendations.
  4. A report back. Written communication of findings and recommendations to the requesting provider, with evidence it was actually sent.

Level selection is a separate step and belongs to the treating physician, supported by coding staff: the physician documents medical decision making or total time on the date of the encounter, and the coder confirms the documentation matches the level billed under the current CPT descriptors. If it does not, the coder queries — never upcodes, never downcodes silently. Log every query and its resolution.

The Consult Intake Log Your Staff Will Actually Maintain

The single highest-yield fix in most groups is a consult intake log, and the reason is denial defense. When a payer asks you to prove the request element, you should not be hunting through a hospital chart six months later.

Keep it small enough that a rounding physician or scheduler will fill it in from a phone: date and time of request, requesting provider name and pager or callback, facility and unit, patient identifier, stated reason for the request, consulting physician assigned, date report transmitted, method of transmission.

Assign it explicitly. In most groups the hospital-rounding coordinator or the physician's assigned medical assistant owns the log, the billing lead audits ten entries a month, and the privacy officer reviews the transmission column quarterly. Unowned logs die in six weeks.

One caution: that log is protected health information. It lives in your systems, it goes in your asset inventory, and it is subject to the same access controls, encryption, and retention rules as anything else. A shared spreadsheet on a personal cloud drive is a finding waiting to happen.

Who Owns the Note When Your Physician Rounds in Someone Else's Hospital

This is the question that trips up independent specialty groups. Your physician documents the consult in the hospital's electronic record under credentials the hospital issued. Does your practice hold that record?

Usually both entities hold something. The hospital maintains its chart. Your practice, as a separate covered entity, maintains whatever it pulls into its own system for billing and continuity — the copy of the note, the intake log entry, the claim, the report you transmitted. That copy is part of your designated record set, and a patient can request it from you.

The hospital is not your business associate in this arrangement, and you are not the hospital's. Two covered entities sharing PHI for treatment do not need a BAA between them; they may, depending on structure, be participants in an organized health care arrangement with a joint notice. What you do need is documented clarity: who releases what, where your copy lives, and how long you keep it.

Access lifecycle for hospital-issued credentials

Every physician and scribe with hospital EHR access is an access point you are responsible for governing on your side. Maintain a roster of who holds credentials at which facility. When a physician leaves, resigns privileges, or changes service lines, notify the facility's medical staff office in writing the same week and keep the confirmation. Never allow shared logins, and never let an advanced practice provider document under a physician's credentials because the facility's setup is inconvenient.

Remote consult documentation and dictation from home mean laptops, phones, and home networks are in scope for your risk analysis. If your last risk analysis predates the current rounding arrangement, it is stale. Practices that would rather not rebuild that document by hand each year can automate the risk analysis and the supporting policy set and keep the output versioned as staffing changes.

The Consult Report Is a Treatment Disclosure — Route It Like One

Sending findings back to the requesting provider is a disclosure for treatment purposes under the Privacy Rule. It does not require patient authorization, and the minimum necessary standard does not apply to disclosures to a provider for treatment — see HHS's guidance on the minimum necessary requirement.

Permitted is not the same as safely executed. The failure mode is almost always transmission: the fax that goes to a stale number, the report emailed unencrypted to a referring office's general inbox, the portal message sent to a similarly named provider.

  • Verify the destination number or secure address at the time of the request and record it in the intake log — not from a directory last updated in 2021.
  • Use confirmation pages or transmission receipts and retain them with the encounter. They are your proof of the report element and your evidence in a misdirection investigation.
  • Write a standing procedure for misdirected reports: retrieve, document, assess for breach under the four-factor risk assessment, escalate to the privacy officer within 24 hours.
  • Do not attach records unrelated to the consultation question. The minimum necessary exception covers treatment disclosures; it does not make careless bundling defensible to a complaining patient.

Vendors That Touch Inpatient Consultation CPT Data

Walk the data path for one consult and count the outside parties. In a typical specialty group, the list includes an outsourced billing or coding company, a transcription or ambient documentation service, a clearinghouse, a fax or secure-messaging provider, a denial-management or audit-support consultant, and whoever hosts your practice management system and backups.

Each of those creates, receives, maintains, or transmits PHI on your behalf. Each needs an executed Business Associate Agreement on file before the first record moves, plus subcontractor flow-down language. HHS publishes sample BAA provisions as a floor, not a finished contract.

Three gaps show up over and over in specialty groups that bill hospital consults:

  • The coding contractor hired mid-year to clear a backlog, onboarded by a physician rather than the administrator, with no BAA and no access review.
  • The dictation or AI scribe tool a physician adopted independently. If it captures patient encounters, it is a business associate, and shadow IT does not get an exemption.
  • Consultants who receive chart samples during a payer audit response. Sample charts are still PHI.

Set a hard rule: no PHI moves to a new party until a signed agreement is in the file. When a vendor cannot produce paper quickly, generating a signature-ready Business Associate Agreement yourself is faster than waiting on their legal queue, and it keeps your terms as the starting point.

The 30-Day Clock When a Patient Asks Your Practice for the Consult Note

A patient who was seen in the hospital calls your office and wants the specialist's consult note. Your front desk cannot deflect to the hospital. If your practice holds a copy in its designated record set, you must respond.

The Privacy Rule gives you 30 calendar days from the request, with one 30-day extension that requires written notice explaining the delay and the new date. Fees are limited to a reasonable, cost-based amount. OCR's Right of Access Initiative has produced dozens of settlements since 2019, and nearly all involved a small practice that simply took too long. HHS's individual right of access guidance is the reference to give your front desk.

Front-desk script and routing

Train staff to log the request the moment it arrives — date stamped, in one place, whether it came by phone, portal, email, or in person. Confirm identity using your standard method, confirm the delivery format the patient wants, and hand it to the designated records custodian the same business day. Track the due date on a shared calendar, not in someone's memory.

Tell patients plainly what you hold: your practice's consult note copy, reports, and billing records. If they want the complete hospital chart, give them the facility's release contact. Being specific prevents both the complaint and the duplicate work.

Audit Response: Hand Over the Encounter, Not the Enterprise

When a payer or contractor requests records supporting a consultation claim, produce the encounter documentation, the request evidence, the transmitted report, and the transmission receipt. Send them by a secure, documented method with a cover log of exactly which patients and dates you released.

Keep your accounting-of-disclosures practices intact and remember the separation in retention rules: HIPAA's six-year documentation requirement covers your policies, BAAs, risk analyses, and training records. Medical record retention itself is governed by state law and payer contracts, which frequently run longer. Write both numbers into one retention policy so nobody has to guess.

A 60-Day Cleanup Sequence

  1. Days 1–10: Rebuild the payer matrix for consultation-code recognition. Archive the policy PDFs.
  2. Days 11–20: Retire pre-2023 E/M level grids. Confirm coders are working from current CPT descriptors.
  3. Days 21–30: Stand up the consult intake log with a named owner and a monthly audit sample.
  4. Days 31–40: Inventory hospital credentials by physician and facility. Close out every departed provider in writing.
  5. Days 41–50: Reconcile the vendor list against executed BAAs. Chase the gaps, including anything a physician adopted independently.
  6. Days 51–60: Refresh the risk analysis to reflect remote documentation, then retrain the front desk on the 30-day access clock.

Clean inpatient consultation cpt workflows pay for themselves twice — fewer denials, and a much shorter list of surprises when a records request or an audit letter lands. If your risk analysis, policies, and BAAs are the pieces you keep deferring, generate the full compliance document set and spend your time on the workflow instead of the paperwork.