Your electrophysiology group saw 312 patients last quarter in a clinic suite on the second floor of the hospital's main building. Your charge-capture template defaults to POS 11. Nobody changed it. That is roughly 312 claims with the wrong place of service, each one paid at the non-facility rate for a service delivered in facility space — and a payer with a two-year lookback window. Understanding POS 22 in medical billing is not a coding curiosity; it is the difference between a clean claim and a recoupment letter with interest.

This guide is written for the person who owns the charge master, the credentialing file, and the records request queue. It covers what POS 22 reports, how your staff should determine it, and — the part most billing articles skip entirely — what happens to patient records, notices, and vendor contracts when your clinicians practice inside someone else's building.

What POS 22 in Medical Billing Actually Reports

Place of service codes are a two-digit set maintained by CMS and used on professional claims (CMS-1500 / 837P) to report the physical setting where the face-to-face service occurred. POS 22 carries the descriptor On Campus–Outpatient Hospital. CMS publishes the full descriptor list in its Place of Service Code Set, and that page is the only version your coding staff should be working from.

Two mechanical points your team needs to internalize. First, POS reports location of the encounter, not the employer of the physician, not the tax ID on the claim, and not where the note was written. Second, POS appears only on the professional claim. The hospital's institutional claim (UB-04 / 837I) uses type of bill and revenue codes — there is no POS field on that side. So when a service is delivered in a hospital outpatient department, two claims leave two organizations describing the same encounter in two different vocabularies.

That split is the operational root of nearly every downstream problem in this article.

On Campus vs. Off Campus: POS 22 and POS 19

Before January 1, 2016, POS 22 covered all hospital outpatient settings. CMS then created POS 19 (Off Campus–Outpatient Hospital) and re-descriptored 22 as on-campus. That split exists because payment policy for off-campus provider-based departments diverged from on-campus departments, and the claim needed to carry the distinction.

"Campus" is a regulatory term, not a colloquial one. The provider-based rules at 42 CFR 413.65 define it around the physical area immediately adjacent to the provider's main buildings and other areas generally within 250 yards. Your practice does not make that determination. The hospital does, through its provider-based attestation and its own compliance office.

Action item: get the determination in writing. If your physicians see patients in three hospital-affiliated locations, request a written statement from the hospital's revenue integrity or compliance department identifying, by street address and suite, which locations are on-campus provider-based, which are off-campus provider-based, and which are freestanding. Date it. Re-request it annually and whenever the hospital opens, moves, or reclassifies a site. That memo is your audit defense.

Quick Answer: When Does a Practice Use POS 22?

A practice reports POS 22 when the face-to-face service was furnished in a department of a hospital that is (a) provider-based, meaning the hospital bills a corresponding facility claim, and (b) located on the hospital's main campus as defined by the provider-based regulations. If the department is provider-based but off campus, POS 19 applies. If the location is a freestanding office not billed as a hospital department, POS 22 does not apply regardless of who owns the building. The determining facts are the hospital's provider-based status for that location and the location's campus status — both of which the practice should obtain in writing from the hospital rather than infer from signage, ownership, or badge access.

Why POS 22 Cuts Your Practice Expense Payment

Medicare's physician fee schedule pays two practice expense rates for many codes: facility and non-facility. The non-facility rate is higher because it assumes your practice bore the overhead — the room, the staff, the supplies, the equipment. When the hospital furnishes that overhead and bills for it separately, the professional claim is paid at the facility rate. POS 22 is one of the codes that triggers facility pricing.

So a POS 11 default on a POS 22 encounter overpays the professional claim while the hospital also collects a facility payment for the same visit. That pattern — duplicate overhead reimbursement — is exactly what OIG place-of-service reviews have historically targeted, and it is a well-worn theory in False Claims Act matters. It is also easy for a payer's analytics to find: the professional and institutional claims share a beneficiary, a date, and often a procedure code.

The two-bill problem your front desk absorbs

Patients seen in a provider-based department receive two statements: yours for the professional service, the hospital's for the facility fee. Your front desk will field those calls whether or not the charge is yours. Give them a one-page script that names the hospital's billing line, explains the two-claim structure in plain language, and — this matters for privacy — tells them what they may and may not disclose about the hospital's claim. Your staff should not be reading the hospital's account balance off a shared portal to a caller they have not verified.

Note also that the provider-based rules impose a written beneficiary notice obligation tied to off-campus departments. Confirm with the hospital which of your sites carries that obligation and who delivers the notice, so it is not silently assumed to be your registration staff.

Who Owns the Chart When the Visit Happens in Hospital Space

Here is the question that arrives at your desk three months after the billing is squared away: a patient seen in your POS 22 clinic requests "all my records," and your practice and the hospital are two separate covered entities documenting the same encounter.

Designated record set boundaries

Your obligation under the HIPAA right of access runs to your designated record set — the records you maintain and use to make decisions about the individual, including your billing records. It does not extend to the hospital's registration, nursing, or facility documentation simply because the visit occurred in their suite. But you cannot answer a request by pointing vaguely at the hospital either. HHS guidance on the individual right of access sets the clock at 30 days, with one 30-day extension available if you notify the individual in writing.

Write the boundary down before you need it. Your access policy should state, by document type, what lives in your designated record set for POS 22 encounters — physician notes, orders you authored, your professional billing records, results you received and relied on — and what belongs to the hospital. Then give your records clerk a warm-handoff script and the hospital's HIM contact, so a misrouted request does not burn 25 days before anyone notices.

OHCA, joint notices, and the arrangement you may already be in

If your physicians and the hospital hold themselves out to patients as participating in a joint arrangement and share protected health information for joint operations, you may be operating in an organized health care arrangement. That status permits a joint notice of privacy practices and allows PHI sharing for the arrangement's joint activities without a business associate agreement between you and the hospital.

Do not assume you are in one. Confirm it in writing, and confirm what notice patients actually receive at registration. A practice that thinks it is covered by the hospital's joint notice, while the hospital thinks the practice distributes its own, produces a patient population that received no compliant notice at all.

The Vendor List POS 22 Creates

Practicing inside hospital space usually means your clinicians touch the hospital's EHR. It rarely means your vendor obligations shrink. Walk your list:

  • Your billing company or RCM vendor. Handling your professional claims for POS 22 encounters is a business associate function. BAA required.
  • Your clearinghouse. Business associate. Required, even though claims are transactional.
  • Your coding audit or documentation-improvement consultant. They read charts. BAA required.
  • Your transcription, dictation, or ambient-scribe vendor. BAA required, and check whether the hospital's IT policy even permits it inside their environment.
  • Your answering service, patient-outreach texting tool, and secure messaging platform. These follow the patient, not the building. BAA required.
  • The hospital itself. Generally not your business associate for treatment or for its own facility billing. But if the hospital performs a function on your behalf — professional coding for your group, credentialing support, IT hosting of your practice data — that specific service may need an agreement.

HHS's overview of business associate obligations is the reference to hand your practice manager. When you find a gap — and on a POS 22 vendor sweep you almost always find at least one — you need a signature-ready document, not a six-week legal cycle. You can generate a Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for signature; it is a one-time purchase rather than a subscription, which makes it practical for the two or three contracts you discover mid-quarter.

A Charge-Capture Workflow That Doesn't Guess at POS

Guessing is what produces the 312-claim problem. Build the determination into the workflow instead.

  1. Scheduling owns the location field. Every appointment type is bound to a specific physical location record, not a free-text room name. No location, no scheduled slot.
  2. Each location record carries a locked POS attribute. Set from the hospital's written provider-based determination. Only two named people — typically the practice administrator and the billing manager — can change it, and changes generate a log entry.
  3. Charge capture inherits POS from the encounter location. Remove the practice-level default. A biller who can type over the POS field will eventually type over it.
  4. Pre-submission edit. Flag any claim where POS conflicts with the location record, or where a facility-setting POS pairs with a non-facility-priced line. Route flags to a single reviewer, not a queue.
  5. Monthly reconciliation. Pull claim counts by POS by rendering provider. A physician whose POS distribution shifts materially month over month is either practicing somewhere new or has a template problem. Both need a phone call.
  6. Quarterly sample audit. Twenty claims per site. Confirm the POS on the claim matches the written determination on file and the documented encounter location in the note.

Assign each step to a named role in writing. "Billing handles it" is not an assignment.

Where This Lands in Your Risk Analysis

A POS 22 arrangement changes your data flows: your clinicians authenticate into a system you do not administer, your billing extract may originate from the hospital's data warehouse, and your workforce accesses PHI on hardware you may not own. Your HIPAA Security Rule risk analysis has to reflect the environment your people actually work in, not the office suite on your lease. If your last risk analysis predates the hospital arrangement, it is stale — and stale risk analysis is one of the most reliably cited findings in OCR resolution agreements.

Document the shared-environment questions explicitly: who provisions and deprovisions your clinicians' hospital accounts, how quickly a termination on your side propagates to their access, who reviews audit logs for your users, and what happens to your professional documentation if the affiliation ends. If you need a structured way to produce and maintain that analysis alongside your policy set, tooling that automates HIPAA risk analysis and the supporting policy documents will get you further than a spreadsheet that one person updates in December.

Six Things to Do Before the End of This Quarter

  • Request written provider-based and campus determinations from the hospital for every location your clinicians use.
  • Audit your location records and lock the POS attribute on each one.
  • Pull 90 days of claims and reconcile POS against those determinations.
  • Write the designated record set boundary for shared-space encounters and give records staff the hospital HIM contact.
  • Confirm in writing which notice of privacy practices patients receive at registration, and whether an OHCA exists.
  • Run the vendor sweep and close the BAA gaps you find.

None of this is glamorous, and none of it takes a full week. What it prevents — a recoupment on 300 claims, a blown 30-day access clock, a breach traced to a vendor with no agreement on file — takes considerably longer to clean up.

If the vendor sweep is the item you keep postponing, start there. Pull the list, mark the gaps, and build the missing Business Associate Agreements in an afternoon rather than carrying them into next quarter's audit.