Inpatient CPT Codes: A Practice Admin's Workflow Guide
It's Monday. Your hospitalist rounded on fourteen patients over the weekend at two facilities, and the only record your billing team has is a photographed census sheet with initials, room numbers, and handwritten codes in the margin. Nobody has pulled the actual notes yet. That single photo is a claim-integrity problem, a documentation problem, and a HIPAA problem at the same time — and it is how inpatient CPT codes get mishandled in small and mid-sized practices every week.
This guide is for the administrator, biller, or privacy officer who owns that handoff. It covers which inpatient code families your staff will encounter, how the documentation chain should actually run from bedside to claim, and where the privacy and vendor exposure sits once hospital-generated records land in your systems. It is administrative guidance on process and documentation, not clinical guidance on code selection.
Which inpatient CPT codes apply to a hospital stay?
Inpatient and observation evaluation and management services are reported from a small set of code families. Since the 2023 CPT revisions, observation care no longer has separate codes — observation and inpatient hospital care were consolidated into the same ranges. The families your billers will see most:
- 99221–99223 — initial hospital inpatient or observation care, per day
- 99231–99233 — subsequent hospital inpatient or observation care, per day
- 99234–99236 — inpatient or observation care including admission and discharge on the same date
- 99238–99239 — hospital inpatient or observation discharge day management
- 99252–99255 — inpatient or observation consultations
- 99291–99292 — critical care services
- Prolonged-service add-ons, which differ between CPT and Medicare's own HCPCS add-on
Level selection within a family is driven by either medical decision making or total time on the date of the encounter, per the current E/M guidelines. Your practice does not decide which code is "right" for a patient — the rendering clinician does, based on documentation. Your job is to make sure the documentation exists, is dated, is attributable to a specific clinician, and reaches the claim intact. Verify descriptors against the current-year CPT code set your practice licenses; they change.
The documentation chain from bedside to claim
Most inpatient billing failures are handoff failures, not coding failures. Map the chain and assign a name to each link.
Link one: the encounter list
Someone has to know who was seen. In practices without an interface to the hospital system, this is a rounding list — and rounding lists are where PHI leaks. Define an approved format (a report generated inside the hospital EHR or your practice system), an approved transport method, and an approved retention period. Photos on personal phones, text-message threads, and emailed spreadsheets should all be explicitly prohibited in writing, not just discouraged in a meeting.
Link two: the note
Your biller cannot code from a census sheet. Establish a standing rule: no inpatient claim goes out without the corresponding signed note attached or accessible in the system of record. If your clinicians document inside the hospital's EHR, decide now whether your practice pulls a copy into your own chart or works from view-only hospital access. Both are defensible. Only one of them creates a second copy of the record you are now responsible for.
Link three: date and time reconciliation
Several inpatient code families turn on dates and durations — admission and discharge on the same calendar date, discharge day management, and time-based services. Your billers should be reconciling encounter dates against the facility's admission and discharge dates before submission, and flagging mismatches back to the clinician rather than guessing. Build the query into your workflow with a target turnaround, typically 48 hours.
Link four: the 72-hour capture window
Set an internal deadline — many practices use 72 hours from the date of service — for notes to be signed and released to billing. Track compliance by clinician and report it monthly. Late documentation is the single largest driver of unbillable inpatient work and of after-the-fact code assignment that cannot be supported on audit.
Split/shared services and teaching settings: who signs, who bills
When a physician and an advanced practice provider both contribute to the same inpatient encounter on the same date, Medicare treats it as a split (or shared) visit and requires that the practitioner who performed the substantive portion report the service. CMS has revisited the definition of "substantive portion" repeatedly through successive Physician Fee Schedule rules, so confirm the current-year policy in the CMS Physician Fee Schedule guidance rather than relying on a training deck from two years ago.
Operationally, you need three things: a documentation template that identifies each contributor and what they did, a modifier convention your billers apply consistently, and an attestation practice that does not simply copy the other clinician's words. In teaching settings, resident documentation carries its own attestation requirements. Assign one person — usually the compliance lead or billing manager — to own the template language and to re-verify it every January.
The privacy exposure inpatient billing creates
Inpatient work pulls PHI out of your controlled environment and into hospitals, home offices, and vendor queues. Four exposures show up in almost every practice audit.
Census lists and rounding sheets
A printed census sheet with twelve names, ages, room numbers, and admitting diagnoses is a bulk PHI disclosure in paper form. Practices lose these in cars, hospital cafeterias, and scrub pockets. Require shredding at end of shift, prohibit removal from the facility unless the sheet goes directly into a locked bin, and log the requirement in your training records so you can demonstrate it later.
Hospital EHR credentials are not a business associate relationship
When the hospital grants your clinicians access to its EHR for treatment purposes, that is a permitted disclosure between covered entities — not a delegation of the hospital's work to you. But everything your staff downloads, screenshots, prints, or copies into your chart becomes PHI your practice holds and must protect. Your risk analysis should name hospital EHR access as a data flow and describe the controls on the copies your side creates. Access reviews matter here: when a clinician leaves, someone must notify every facility to terminate credentials, and that step belongs on your offboarding checklist with a named owner.
Minimum necessary on the payment side
The minimum necessary standard does not restrict disclosures for treatment, but it does apply to payment and health care operations. That means the packet your billers send to a payer, or the record set you hand to an outside coding auditor, should be scoped to what the request actually requires. HHS's minimum necessary guidance is short and worth circulating to your billing staff verbatim.
Remote coders, scribes, and transcription
Inpatient documentation volume pushes practices toward remote scribes and outsourced coding. Both arrangements route full clinical notes through third parties, often across state or national borders. Ask where the data rests, who has administrative access, whether subcontractors are used, and how audit logs are produced on request. Get the answers in writing before the first note moves.
The vendor list you should be able to produce in ten minutes
If a regulator asked today, could you list every third party that touches your inpatient billing data? Most practices can name the big ones and forget the rest. Work through the chain:
- Billing company or RCM service submitting the claims
- Coding audit or documentation-improvement consultant reviewing note quality
- Clearinghouse handling claim transmission
- Transcription or scribe service producing the notes
- IT support with remote access to billing workstations
- Cloud storage or file-transfer tool used to move records between the hospital and your office
- Shredding and document destruction vendor
- Any AI-assisted coding or note-summarization tool in the workflow
Each of these needs a business associate agreement in place before PHI moves, and each agreement needs terms that actually match the service — breach notification timelines you can meet, subcontractor flow-down, and return or destruction of data at termination. HHS publishes sample business associate agreement provisions, but the samples are a starting point, not a finished contract. If you're onboarding a coding vendor this quarter and don't want to route a one-page favor through outside counsel, you can generate a signature-ready BAA through a six-step wizard and export it as PDF or DOCX — one-time purchase, useful for exactly this kind of mid-year vendor addition.
Records requests when the chart lives at the hospital
A patient who was hospitalized in February emails your office in April asking for "everything from my hospital stay." You have 30 days to act on a request for access to records in your designated record set, with one 30-day extension available on written notice. Your obligation runs to the records you maintain — the notes your clinicians authored and hold, plus billing records — not the facility's full chart.
Train your front desk on the distinction and give them a script: your practice fulfills what it holds, and directs the patient to the hospital's health information management department for the facility record. Do not stall, and do not send the patient away empty-handed because part of the record sits elsewhere. Review the HHS individual right of access guidance annually; access complaints remain one of the most common bases for OCR investigation.
One nuance worth documenting in your policy: disclosures for treatment, payment, and health care operations are excluded from the accounting of disclosures. Your billers do not need to log routine payer submissions. They do need to log the unusual ones — a records release to an attorney, a disclosure under a subpoena, a report required by law.
A quarterly review that catches problems before a payer does
Pull ten inpatient encounters at random each quarter. For each one, confirm: a signed note exists, the author matches the billing provider, the encounter date matches the facility's dates, the place of service is correct, any split/shared attestation is present and specific, and no code was assigned after submission without documentation to support it. Log the results and the corrections.
Separately, review one vendor per quarter. Confirm the BAA is current, the contact for breach notification is a real person who still works there, and the service description still matches what the vendor actually does. Vendors expand scope quietly; agreements rarely follow. You can check the HHS breach portal to see whether a vendor in your chain has reported an incident you were never told about.
Inpatient CPT codes are just the visible end of a workflow that stretches across two organizations, several vendors, and a lot of unlogged paper. Fix the handoffs and the coding gets easier. Leave them loose and you'll be reconstructing a February encounter from a photographed census sheet in September.
Next step: pick the one vendor in your inpatient billing chain whose paperwork you're least sure about, and close the gap this week — draft and export the BAA before the next batch of notes moves. If your broader documentation set is also overdue, automated risk analysis and policy generation will get the rest of the file in order.