Intensive outpatient and partial hospitalization are where a lot of behavioral health and SUD revenue lives, and where a lot of it quietly leaks. The two levels share a continuum but have separate code families, different hours thresholds, and documentation that has to match what you actually delivered.
Get the mapping wrong and you get denials and audit flags. Get it right and these become some of the most reliable claims you file. Here is how IOP and PHP billing actually works in 2026, and what the record has to show.
The short version
- PHP (ASAM 2.5) and IOP (ASAM 2.1) are separate levels with separate code families and authorization rules.
- PHP is often 20 or more structured hours a week; IOP is generally 9 to 19 hours a week for adults.
- The single most expensive mistake is a mismatch between the level you bill and the hours you deliver and document.
- Attendance, hours, medical necessity, and ASAM level-of-care justification are the documentation that keeps these claims paid.
- Payers update these codes periodically, so confirm current codes with each payer.
PHP vs IOP: same continuum, different rules
Both are structured outpatient programs, but they sit at different intensities:
- Partial hospitalization (PHP) is the most intensive outpatient level, corresponding to ASAM Level 2.5. It typically runs five to seven days a week, six or more hours a day, often 20 or more structured hours per week.
- Intensive outpatient (IOP) corresponds to ASAM Level 2.1, generally 9 to 19 hours per week for adults (six or more hours is often acceptable for children and adolescents).
They have completely separate billing code families and authorization requirements, so they are not interchangeable on a claim.
The codes
| Program | HCPCS | Revenue code (UB-04) |
|---|---|---|
| PHP | H0035; S0201 (per diem) | 0912 (less intensive) or 0913 (intensive) |
| IOP (SUD) | H0015 | 0905 |
| IOP (mental health) | S9480 (per diem) | 0905 |
Per-diem codes represent one unit per day of programming, and facility-based programs bill institutionally on the UB-04. Payers update these codes periodically and Medicaid programs vary, so confirm the current codes for each of your payers.
The hours rule is the trap
The single most expensive mistake in IOP and PHP billing is a mismatch between the level you bill and the hours you actually deliver. Billing PHP while delivering IOP hours, or the reverse, is a fast denial and a reliable audit flag. Attendance and hours per day and per week have to be documented, and they have to support the level on the claim. This is the number one thing a reviewer checks, and the number one thing programs get wrong when scheduling and billing drift apart.
Documentation that keeps IOP and PHP claims paid
A working checklist:
- ASAM level-of-care justification (2.1 for IOP, 2.5 for PHP) tied to the six dimensions.
- Physician certification and treatment plan as required, especially for PHP.
- Attendance and hours documented per session and per day, matching the level billed.
- Individualized notes, not the same group note copied across patients.
- Medical necessity for the intensity, including why a lower level would be insufficient.
- Reassessment and continued-stay justification for ongoing authorization.
Example attendance snippet (IOP, Level 2.1): Patient attended three sessions this week, three hours each, for nine structured hours, consistent with Level 2.1. Group and individual components documented separately below.
Authorization and continued stays
IOP and PHP almost always run on authorization, and continued stays have to be justified. That means the initial authorization needs a solid ASAM level-of-care assessment, and each continued-stay review needs a fresh dimensional picture that shows what has changed and why the current intensity is still appropriate. Programs that lose IOP and PHP revenue usually lose it at the continued-stay stage, where a copy-forward note that repeats the admission gives the reviewer an easy reason to step the patient down or deny the days.
Setting and payer change the rules
IOP and PHP billing is not uniform; it varies by setting and by payer. Hospital-based programs bill institutionally on the UB-04, while some freestanding programs bill differently, and the codes and revenue codes a commercial plan accepts may not match what a state Medicaid program or Medicare requires. Medicare in particular has specific conditions of participation and certification requirements for partial hospitalization. The safest approach is to build a per-payer map: for each plan you contract with, the accepted codes, the revenue codes, the authorization requirements, and the certification rules, kept current as payers update their policies.
Active treatment and discharge planning
PHP and IOP have to be active treatment, not maintenance or supervision, and the documentation has to show it. Reviewers look for a structured, therapeutic program with measurable goals and evidence of progress, or a clinical reason for continued stay, not simply attendance. Each day's programming should be documented as active clinical work, and the record should show movement toward goals or a justification for why the intensity is still needed. Discharge and step-down planning belong in the record too: a program that documents when and how it will step a patient down to a lower level of care demonstrates exactly the kind of least-restrictive-setting thinking that payers and the ASAM Criteria expect.
Where IOP and PHP revenue leaks
- Level and hours mismatch on the claim.
- Missing physician certification (especially PHP).
- Group notes that are not individualized.
- Attendance and hours not documented.
- Continued stays billed without reassessment.
- Wrong code family (H0015 vs S9480 vs H0035).
Get the setup right
Three things prevent most of the leakage: confirm each payer's required codes and update them when payers do; map your program's actual hours to the correct ASAM level and bill accordingly; and make attendance and medical-necessity documentation a routine part of the daily note, not a month-end scramble. IOP and PHP can be some of the most predictable revenue a behavioral health program has, but only when the level you bill, the hours you deliver, and the record you keep all say the same thing.
How Adentris helps
Adentris reviews IOP and PHP documentation before the claim goes out: whether the ASAM level matches the hours delivered, whether attendance and medical necessity are documented, and whether the required certifications are in place. It flags the mismatch that would become a denial and drafts the correction while the record is still open. To see it on your own charts, book a 30-minute call with our team.
Related reading
- Behavioral health payer audit readiness solutions
- Best behavioral health documentation compliance software
- AI chart review tools for behavioral health
Frequently asked questions
What is the difference between IOP and PHP billing?
They bill at different intensities with separate code families. PHP is ASAM Level 2.5 (often 20 or more structured hours per week; H0035 or S0201; revenue codes 0912 or 0913). IOP is ASAM Level 2.1 (about 9 to 19 hours per week; H0015 for SUD or S9480 for mental health; revenue code 0905). They have separate authorization requirements.
What HCPCS codes are used for IOP?
H0015 for substance use disorder intensive outpatient (often billed to Medicaid) and S9480 for psychiatric intensive outpatient (per diem), typically paired with revenue code 0905 on the UB-04. Payers update codes, so confirm the current ones for each plan.
How many hours per week are IOP and PHP?
IOP is generally 9 to 19 hours per week for adults (six or more is often acceptable for adolescents). PHP is more intensive, often 20 or more structured hours per week across five to seven days. The level billed must match the hours actually delivered.
Why do IOP and PHP claims get denied?
Most often a mismatch between the billed level and the delivered hours, a missing ASAM justification or physician certification, group notes that are not individualized, or continued stays billed without a documented reassessment.
Do IOP and PHP require prior authorization?
Usually yes. Both typically run on authorization, and continued stays require justification. The initial authorization needs a solid ASAM level-of-care assessment, and each continued-stay review needs a fresh dimensional picture showing why the current intensity remains appropriate.