96110 CPT Code: A Practice Admin's Privacy Playbook
A four-provider pediatric practice runs roughly 40 well-child visits a week. At the 9-, 18-, 24-, and 30-month visits, the front desk hands a caregiver a tablet with two or three standardized questionnaires. That is up to 60 screening instruments a week, each one scored, filed, and — if the documentation holds up — reported under the 96110 CPT code. It is also 60 new records a week, most of them created by a vendor's software before the child is roomed.
This guide is for the administrator, biller, or privacy officer who owns that workflow. It covers what the code describes, what documentation your payers and auditors expect, and — the part most practices skip — which vendors just became business associates and how those screening results behave when a parent, a school, or an attorney asks for the chart.
What the 96110 CPT Code Describes, in Plain Operational Terms
CPT 96110 is defined as developmental screening (for example, a developmental milestone survey or a speech and language delay screen), with scoring and documentation, per standardized instrument. Three operational facts follow from that definition:
- It requires a standardized instrument. An informal question at the door is not a screening. The tool has to be a recognized, scored instrument, and the chart has to name it.
- It is reported per instrument. If two distinct standardized screens are administered and scored at one encounter, the unit count reflects that — subject to payer policy.
- Scoring and documentation are inside the code. The work being described is administration, scoring, and documentation of the result, not an extended evaluation.
Adjacent codes exist for adjacent activities — brief emotional/behavioral assessment and patient- or caregiver-focused health risk assessments each have their own codes and their own payer rules. Which code applies to a given encounter is a determination your clinicians and credentialed coders make against the documentation and the payer's policy. Your job as administrator is to make sure the documentation exists, is retrievable, and is consistent.
The Documentation Elements a Payer Audit Will Ask For
When a payer requests records behind a 96110 line item, the reviewer is looking for a short, boring list. Build your template so all of it lands in the chart automatically.
- The name and version of the standardized instrument used.
- The date administered and, where your policy requires it, who administered it.
- The completed responses or the scored result, stored in or attached to the medical record.
- Interpretation by the clinician and the action taken — repeat, refer, monitor, discuss.
- Any language or format accommodation, since instruments administered in translation are still standardized instruments and the version matters.
Where practices actually lose the audit
Not on medical necessity. On retrievability. The questionnaire was completed in a third-party screening portal, the score synced to the EHR as a one-line flowsheet value, and the actual completed instrument lives in the vendor's cloud. Six months later, the records clerk exports the chart and the underlying instrument is not in it.
Fix this at contract time, not at audit time. Ask every screening vendor two questions: does the completed, scored instrument write back into our record as a retrievable document, and can we export it in bulk if we terminate?
Modifier and payer-policy tracking
Many payers require a modifier on the associated evaluation and management or preventive medicine service when a screening code is reported the same day. Some Medicaid programs pay separately under EPSDT; some commercial plans bundle. Some cap units per date of service.
Keep a one-page payer grid — plan, separately payable yes/no, unit limits, modifier convention, effective date — and assign an owner who refreshes it quarterly against published payer policy. Denials on the 96110 CPT code are usually policy mismatches, not clinical disputes, and a grid resolves most of them before they leave the practice.
Every Screening Instrument Is Also a Vendor Relationship
Trace one 18-month screening from start to finish and count the outside parties touching identifiable data:
- The pre-visit messaging vendor that texts or emails the caregiver a questionnaire link, including the child's name and appointment date.
- The screening platform that hosts the instrument, collects responses, scores them, and stores the result.
- The tablet or kiosk management service, if a separate vendor provisions and locks down the devices.
- The EHR or integration layer that receives the score.
Each of those creates, receives, maintains, or transmits protected health information on your behalf. Each needs a signed business associate agreement on file before go-live — not after the first screen is administered. Add the translation service if instruments are delivered in languages other than English, and any analytics or session-replay tooling embedded in a patient-facing intake page.
That last one deserves attention. OCR has published guidance on online tracking technologies and how third-party trackers on health-related web properties can move identifiable information to advertising and analytics companies. Portions of that guidance were narrowed by litigation in 2024, but the underlying exposure did not go away: if your intake page loads a marketing pixel while a caregiver answers developmental questions, you have a disclosure question to answer and probably a contract you never signed.
If your vendor list is longer than your BAA folder — and for most practices adding digital screening, it is — close the gap before your next screening go-live. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX, one-time purchase, no subscription. That is a same-afternoon fix for a screening platform that has been live for eight months without paper.
What to ask the screening vendor before signing
- Where is the data stored, and is it encrypted at rest and in transit?
- Do your staff accounts use unique credentials with role-based access, and can we pull an access log?
- Do you use subcontractors — hosting, scoring, translation — and do you flow the BAA terms down to them?
- What is your breach notification timeline to us, in days, in the contract?
- On termination, do we get a complete export, and do you certify deletion?
Screening Results Sit Inside the Designated Record Set
A completed developmental screen used to make decisions about a patient is part of the designated record set. That means the individual — or their personal representative — has a right of access to it, and your practice generally has 30 days to respond, with one 30-day extension available if you notify the requester in writing of the delay and the reason. HHS's right of access guidance spells out the timeline, the fee limits, and the form-and-format obligations.
Practical consequence: if the completed instrument lives only in a vendor portal, your 30-day clock still runs. "The vendor has it" is not a response. Build the export path into your records-request procedure and time it once so you know how long it actually takes.
Who is allowed to ask — the part that trips up front desk staff
For a pediatric patient, the requester is usually a parent acting as personal representative. Usually is not always. Custody orders, foster placement, guardianship changes, and state laws granting minors independent consent for certain categories of care all change who may access what. HHS's guidance on personal representatives defers heavily to state law here.
Write the escalation rule down: front desk verifies identity and relationship, and any request involving separated parents, a custody document, a subpoena, a school district, or an adolescent-completed screen goes to the privacy officer before anything is released. Nobody at the front desk should be interpreting a custody order between patients.
Schools, early intervention, and referral packets
Screening results frequently travel to early intervention programs, developmental specialists, or school districts. Treatment-related disclosures to another provider are one thing; sending records to a school system is often a different analysis, and many practices handle it with a signed authorization as a matter of policy rather than parsing the distinction at the counter. Decide your standing rule, document it, and train to it — inconsistency is what generates complaints.
The Waiting Room Is a Disclosure Surface
Tablets are the weak point. Three controls, none expensive:
- Kiosk mode plus session timeout. The device returns to a blank start screen after submission and after 60 seconds of inactivity. No back button into the prior caregiver's answers.
- Screen privacy filters and seat placement. A caregiver answering questions about a child's speech should not be doing it under the gaze of the next family in line.
- An inventory with a serial number, an assigned owner, and a wipe procedure. A tablet that leaves the building — borrowed for an outreach event, sent for repair — needs a documented remote-wipe capability.
Paper carries its own risk. Clipboards stack up at the front desk, get scanned in batches, and sometimes sit overnight. If your workflow is paper, the completed instruments need a locked bin between collection and scanning, and a documented shredding step after verification.
All of this belongs in your security risk analysis, not in a hallway conversation. If you need a structure for that assessment, NIST SP 800-66 Revision 2 maps HIPAA Security Rule requirements to concrete safeguards and is free. Reviewing the OCR breach portal for incidents at practices your size is a fast way to see which failure modes are actually common.
Assign the Screening Workflow by Role, Not by Habit
Write these five assignments into your policy manual with names attached:
- Front desk: issues the device or form, verifies the correct patient is selected, returns the device to a clean state, and never interprets results.
- Clinical staff: confirms completion, ensures the scored instrument is attached to the correct encounter.
- Clinician: documents interpretation and action taken.
- Billing: applies the payer grid, tracks unit limits and modifier conventions, works denials on the 96110 CPT code as a category rather than one at a time.
- Privacy officer: owns the vendor list, the BAA folder, the records-request escalation path, and the annual review of both.
A 60-Minute Audit You Can Run This Quarter
- Pull ten encounters where a screening code was reported. Confirm the instrument name, date, score, interpretation, and action are all retrievable from the chart without logging into a vendor portal.
- List every system that touched those ten screens. Match each to a signed, current BAA. Note gaps.
- Time one records request end to end, including vendor export, and compare it to the 30-day standard.
- Walk the waiting room at peak hours. Pick up a tablet a caregiver just used and see what you can see.
- Check your retention rule for pediatric records against your state's requirement — most run to the age of majority plus a set number of years, which is longer than practices assume.
The billing side of the 96110 CPT code is a solvable problem: a payer grid, a documentation template, and a denial owner. The privacy side is the one that generates complaints, and it lives in the vendors you added without paperwork.
Start with the contracts. Pull your screening platform, messaging vendor, and integration partner, and build the agreements you're missing — six steps, PDF and DOCX export, one-time purchase. If your risk analysis and policy set are equally overdue, the full compliance document set can be generated alongside them. Then go run the five-step audit above before your next well-child block fills up.