A 68-year-old calls your practice on Monday and asks for "a complete physical." She has never been seen by anyone in your group. Your scheduler books 45 minutes, your medical assistant hands her a tablet with a 40-question intake form, and three weeks later your biller is staring at a denial. Somewhere between that phone call and that denial, four separate decisions got made — and at least two of them had privacy consequences nobody documented.

This guide walks administrators and billing staff through the 99387 CPT code description, the operational checks that surround it, and the records-handling exposure that a comprehensive preventive visit creates. It is administrative guidance. Nothing here tells you what to code for a given patient — that determination belongs to your clinicians and your documentation.

What the 99387 CPT Code Description Actually Says

CPT 99387 is defined as an initial comprehensive preventive medicine evaluation and management service for a new patient aged 65 years and older. The descriptor includes an age- and gender-appropriate history, an examination, counseling/anticipatory guidance/risk factor reduction interventions, and the ordering of appropriate laboratory or diagnostic procedures.

Three elements in that descriptor drive everything downstream: initial (new patient, not established), 65 years and older (age at date of service), and comprehensive preventive (not problem-oriented). If any one of those is wrong on the claim, you are looking at a denial, a rebill, or — worse — a refund obligation you find during an audit.

Where 99387 Sits in the Preventive Medicine Family

The preventive medicine E/M codes run in two parallel series. The 99381–99387 range covers new patients, stratified by age band, with 99387 as the oldest band. The 99391–99397 range mirrors it for established patients, with 99397 as the 65-and-over counterpart. Your billing team should treat the new/established fork and the age band as two separate verification steps, because they fail for different reasons.

Three Facts Your Front Desk Has to Nail Before the Visit

1. New-patient status. Under CPT conventions, a patient is new if they have not received a face-to-face professional service from a physician or other qualified health professional of the same specialty and subspecialty in the same group practice within the prior three years. Group mergers, locum coverage, and telehealth visits from two years ago all break this in practice. Build the three-year lookback into your scheduling workflow, not into your biller's memory.

2. Age at the date of service. Not age at scheduling. A patient who turns 65 between booking and the appointment moves age bands. Your registration screen should surface calculated age at DOS, not date of birth alone.

3. Payer rules for routine preventive exams. Commercial plans frequently cover a routine annual exam at no cost share under Affordable Care Act preventive requirements — but the covered service, frequency, and required diagnosis code vary by plan. Traditional Medicare is a different animal entirely, which is the next section.

Medicare and the 99387 CPT Code Description: The Conversation Your Scheduler Owns

Routine physical examinations are statutorily excluded from Medicare coverage. Medicare instead covers the Initial Preventive Physical Examination (the "Welcome to Medicare" visit) and the Annual Wellness Visit, which are billed with HCPCS G-codes and have their own required elements and frequency limits. CMS's Medicare Wellness Visits guidance lays out the element-by-element requirements.

That means a Medicare beneficiary who asks for "a full physical" is asking for something that is operationally distinct from the wellness visit Medicare will pay for. Your scheduler needs a script that surfaces this before the appointment, not at checkout.

The Financial Notice Question

For services excluded from Medicare by statute, an Advance Beneficiary Notice of Noncoverage is not mandatory — but many practices issue one voluntarily so the patient sees the estimated charge in writing and signs for it. If your practice does this, treat the signed notice as part of the designated record set's financial companion and store it where your release-of-information staff can find it, because patients who dispute a balance will ask for it.

Assign one person to own the script and the notice template. In most practices it is the front-office lead; in larger groups it is the revenue cycle manager. Unassigned, it defaults to whoever is at the desk, and that is how you get inconsistent disclosures.

Same-Day Problem Visits and the Documentation Split

Preventive visits routinely surface something that needs its own workup. When a clinician performs a significant, separately identifiable problem-oriented E/M service at the same encounter, CPT provides for reporting that service in addition, with modifier 25 appended to the problem-oriented code.

The administrative rule your billing team should enforce: the note must contain enough separately identifiable content that a reviewer can read the problem-oriented service on its own. Practices that do this well use templates with visually distinct sections and require the clinician to attest which portion supports which code. Practices that do it poorly copy the preventive narrative into both halves and lose the appeal.

Two operational consequences follow. First, the patient may owe a cost share on the problem-oriented portion even when the preventive portion is covered at 100% — tell them at checkout, in writing, and log that you did. Second, split billing raises your audit probability, which means more records leaving your building. That is a privacy workflow, not just a billing one.

A Preventive Visit Generates More Sensitive Data Than the Claim Suggests

The claim line says "preventive medicine, new patient, 65+." The chart behind it says something else entirely: substance use screening, depression screening, cognitive assessment, fall risk, sexual history, firearm safety, advance directive status, functional decline, and a family history that implicates people who never consented to anything.

That is the record your release-of-information staff will hand out under a subpoena, an attorney authorization, or a disability determination request. If your team's default is "send the whole chart," the 99387 CPT code description is a good reminder of how much they are actually sending. HHS's minimum necessary guidance applies to disclosures for payment and operations — including responding to a payer audit.

Intake Questionnaires and the Vendors Holding Them

Most practices collect the preventive history through something other than the EHR itself: a tablet kiosk app, a patient-portal form, a texted pre-visit link, or a scanned paper packet processed by a document management service. Each of those is a business associate holding screening responses about depression, alcohol use, and cognition.

Pull your intake stack and answer four questions for each vendor: Do we have a signed BAA? Where is the data stored and for how long? Does the vendor retain responses after they sync to the chart? Can we get a deletion confirmation? HHS publishes sample business associate agreement provisions if you are starting from scratch; if you need a signature-ready document rather than a template to redraft, a guided BAA generator will get you to an executable PDF faster than legal review of a Word file.

Records Requests That Follow a Preventive Claim

Payer audits. When a plan reviews a preventive-plus-problem split, send the encounter note and the specific supporting documents — not the full longitudinal chart. Log what you sent, to whom, and on what date. That log is your defense if the patient later asks for an accounting.

Patient access requests. A patient who gets a surprise cost share on the problem-oriented portion will often request the note to see what was documented. Under the HIPAA Right of Access, you generally have 30 days to respond, with one 30-day extension available on written notice, and your fee is limited to a reasonable, cost-based amount. HHS's right of access guidance is the reference to keep in your ROI binder — enforcement in this area has been persistent and unglamorous.

Amendment requests. Preventive intake forms are self-reported. Patients dispute them. Have a documented amendment workflow with a named decision-maker and a 60-day response clock.

No. The 99387 CPT code description covers an initial comprehensive preventive medicine service for a new patient aged 65 and over, including an age-appropriate history and examination. The Medicare Annual Wellness Visit is a separate benefit billed with HCPCS G-codes, built around a health risk assessment and personalized prevention plan rather than a comprehensive physical exam. Traditional Medicare does not cover routine physical examinations. Practices seeing Medicare beneficiaries determine and document which service was actually performed and bill accordingly.

Vendor Inventory: Everyone Who Touches One Preventive Visit

  • Eligibility/clearinghouse vendor — sees demographics and coverage; BAA required.
  • Intake or kiosk app — sees screening instrument responses; BAA required, retention terms matter.
  • Reference lab interface — sees orders and results.
  • Patient reminder/recall platform — sends "you're due for your annual" messages; BAA required, and message content should not disclose more than necessary.
  • Statement and payment processor — sees balances tied to service dates.
  • ROI or document management service — handles the outbound chart.
  • EHR host or IT managed service provider — has standing access.

Seven vendors, one visit. If your BAA tracker has fewer rows than your vendor list, that gap is the finding an investigator will open with. Your Security Rule risk analysis is supposed to account for every one of these data flows, and HHS's proposed Security Rule update circulated for comment in January 2025 would make that documentation expectation considerably more prescriptive. If your current risk analysis is a spreadsheet from three EHR upgrades ago, automating the risk analysis and policy set will close the gap faster than another quarter of good intentions.

A 60-Day Cleanup Plan

  1. Days 1–10: Audit 25 preventive claims from the last quarter. Check new-patient lookback, age at DOS, and modifier 25 documentation on any split visits.
  2. Days 11–20: Write and test the scheduler script for Medicare beneficiaries requesting a physical. Have two staff read it aloud to you.
  3. Days 21–35: Inventory every vendor that touches intake, reminders, statements, and ROI. Match against signed BAAs. Escalate the mismatches.
  4. Days 36–50: Retrain ROI staff on scoping disclosures for payer audits. Sample five recent releases and measure what was sent versus what was requested.
  5. Days 51–60: Update the risk analysis to reflect the actual vendor list, and document the decisions you made along the way.

The 99387 CPT code description is two sentences long. The operational surface behind it — scheduling logic, financial notices, split documentation, seven vendors, and a chart full of screening data — is what actually determines whether your practice survives an audit or a records complaint.

If the vendor inventory above turned up gaps, start with the documentation layer: generate a current risk analysis and the supporting policy set, then work the BAA list against it. Ninety minutes of structured work now is cheaper than reconstructing three years of vendor relationships under a request for information.