99387 CPT Code: A Practice Admin's Operations Guide
Your front desk books a 71-year-old new patient for an "annual physical." Six weeks later the claim comes back denied, the patient calls the billing line furious about a $312 balance, and nobody can produce a signed notice explaining that Medicare was never going to pay for it. That sequence is the most common failure mode around the 99387 CPT code, and it is entirely preventable at the scheduling desk.
This guide is for the people who own that workflow: practice administrators, billing leads, and privacy officers. It covers what the code describes, how practices document code selection defensibly, and — because a preventive visit generates an unusually rich pile of protected health information — where the vendor and records-handling exposure sits.
What the 99387 CPT Code Describes
CPT 99387 is the preventive medicine evaluation and management code for an initial comprehensive preventive medicine visit for a new patient aged 65 or older. Its established-patient counterpart is 99397. The preventive medicine family is stratified two ways: new versus established, and by patient age band.
Three operational facts your staff should be able to recite:
- Age drives the code, not the payer. The 65-and-older band determines which code in the series applies. Age is verified against the chart, not against what the scheduler typed.
- "New patient" has a definition. Under CPT conventions, a new patient generally has not received a face-to-face professional service from a physician or qualified health professional of the same specialty and subspecialty in the same group practice within the prior three years. Your practice management system should be the source of truth here, not memory.
- It is a comprehensive service, not a problem visit. The preventive codes contemplate an age- and gender-appropriate history, examination, counseling, anticipatory guidance, risk-factor reduction interventions, and ordering of appropriate labs or diagnostics.
Nothing here tells a clinician what to code for a given encounter. Code selection is a clinical documentation decision made by the rendering provider. Your job as an administrator is to build the workflow, the verification steps, and the audit trail around that decision.
Why the 99387 CPT Code Gets Denied by Medicare
Traditional Medicare does not cover routine physical examinations. That exclusion is statutory, not a coverage determination you can appeal on medical necessity grounds. What Medicare does cover on the preventive side are the Initial Preventive Physical Examination (the "Welcome to Medicare" visit) and the Annual Wellness Visit, which are billed with their own HCPCS G-codes and have their own required elements and frequency rules.
So the 65-and-older patient in your waiting room may be eligible for a covered wellness visit, a non-covered comprehensive preventive exam, both on the same day, or a problem-oriented visit instead. Those are different services with different documentation requirements. CMS publishes education on the wellness visit elements through the Medicare Learning Network; that material belongs in your onboarding packet for every new biller.
The eligibility check that must happen before the appointment
Assign this to a named role, not to "whoever answers the phone."
- At scheduling: capture the reason for visit in the patient's own words, verify insurance, and flag anyone 65+ booking a "physical," "checkup," or "annual."
- 48–72 hours before: run eligibility. Determine Part B enrollment date (which drives Welcome-to-Medicare eligibility) and last wellness visit date. Note whether the patient has a Part C plan or a commercial plan, because Part C and commercial preventive benefits differ from traditional Medicare.
- Day of visit: the check-in staffer confirms the flag was resolved. If it was not, the visit proceeds but the encounter is held for billing review rather than dropped automatically.
ABN workflow and who owns it
When your practice expects to deliver a service that Medicare excludes by statute, an Advance Beneficiary Notice of Noncoverage is not strictly required — but issuing one voluntarily is standard practice because it documents that the patient understood the financial exposure before the exam happened. Handing a patient a bill six weeks later with no signed notice is how you end up in a complaint queue.
Practical rules for the front desk:
- The notice is presented and explained before the service, never at checkout.
- The estimated cost must be a real number your billing team stands behind, not a range copied from a template.
- The signed form is scanned into the chart the same day and the paper copy is shredded or secured — not left face-up in a tray behind the desk where the next patient can read a name and a dollar figure.
- Billing applies the appropriate modifier to signal the statutorily excluded status so the denial generates cleanly and can flow to a secondary payer.
That last item is where practices lose money quietly: a denial that never reaches the secondary payer becomes a patient balance that becomes a write-off.
How Practices Document Code Selection Without Guessing
Auditors do not ask your biller why 99387 was submitted. They ask what in the record supports the service that was billed. Build the workflow so the answer is always in the note.
Three things your internal audit should confirm
Age band and patient status are verifiable. The chart should show date of birth and, for new-patient codes, the absence of a qualifying prior encounter within the lookback window. Pull this from the system, not from a staff attestation.
The comprehensive elements are documented, not implied. A note that says "annual exam, all normal" does not support a comprehensive preventive service. Your template should prompt for the counseling and risk-reduction discussion because that is the component most often missing.
Any same-day problem service is separately supported. If a patient presents for a preventive visit and the provider also addresses a new or worsening problem requiring additional work, practices commonly bill a separate problem-oriented E/M with modifier 25 appended. Payers scrutinize this pairing. The defensible version has two distinguishable pieces of documentation — the preventive service and the problem evaluation — not one blended paragraph. Whether the additional work rises to a separately reportable service is the provider's determination.
Run a quarterly sample. Ten charts per provider, scored against a written rubric, with results returned to the provider in writing. Keep the rubric and the results; an auditor who sees a functioning internal review program treats you differently than one who sees nothing.
Where a Preventive Visit Creates Privacy Exposure
A comprehensive preventive encounter for an older adult produces some of the most sensitive data your practice holds: cognitive screening results, depression screening, fall risk, alcohol and substance use, advance directive status, functional decline, sexual health. It lands in intake forms, screening instruments, the note, the claim, and the patient statement.
Intake forms and health risk assessments
Most practices push a lengthy health risk assessment to the patient before the visit. Ask three questions about yours:
- Where does it live? If the form is delivered through a portal or a third-party intake tool, that tool holds PHI and is a business associate.
- Who can see the completed form? Front-desk staff often have full access to intake responses they have no operational need to read. Minimum necessary applies internally, not just to outside disclosures.
- What happens to the paper? Clipboard forms completed in a waiting room and stacked at the desk are a recurring finding in self-audits. Move them behind the counter or go digital.
The vendor list behind a single preventive claim
Trace one 99387 claim end to end and count the outside parties touching it. A typical independent practice will find: the EHR host, the clearinghouse, the outsourced billing company, the eligibility verification service, the patient statement print-and-mail vendor, the appointment reminder platform, a documentation or transcription assistant, the shredding company, and — if you ran an internal audit — the coding consultant who reviewed the charts.
Every one of those is a business associate. Clearinghouses are named as business associates in the regulation itself; the narrow conduit exception does not rescue them. HHS explains the scope and required elements in its business associate guidance.
If you just realized a vendor on that list has no executed agreement — the coding consultant and the reminder platform are the usual gaps — close it this week. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for countersignature. It is a one-time purchase, not a subscription, which matters when you need three agreements and not a platform.
Recall Campaigns Are Operations, Not Marketing — If You Build Them That Way
Preventive visits drive recall outreach: "You're due for your annual." Under the Privacy Rule, communications about treatment and case management generally fall outside the marketing definition, so appointment reminders and care-gap outreach for your own patients typically do not require authorization.
The line moves when a third party pays you to include their product in that message, or when the outreach promotes a service beyond the patient's own care. Two operational controls:
- Content review. One named person approves recall message templates before they go out. No co-branded content without a privacy officer sign-off.
- Channel consent. Capture and record the patient's preferred contact method and any restriction they request. If a patient asks that you not leave voicemails at a shared household number, that restriction has to be honored by the reminder platform, not just noted in the chart.
When the Patient Asks for the Preventive Visit Record
Preventive exams generate records requests — for long-term care admission, disability paperwork, life insurance underwriting, or family caregivers. Two different pathways, two different rules.
A patient requesting their own record triggers the right of access: you have 30 days to produce it, with one 30-day extension available if you notify the patient in writing of the delay and the reason. Fees are limited to a reasonable, cost-based amount. HHS maintains detailed right of access guidance, and access failures have been a sustained OCR enforcement priority.
A third party requesting the record — an insurer, an attorney, an adult child — is a disclosure, not an access request. That requires a valid authorization or another permitted basis, and your release-of-information staff need a checklist that distinguishes the two. Mislabeling a third-party request as a patient request is how records go to the wrong person.
A 30-Day Cleanup Checklist
- Week 1: Pull every claim in the last 12 months for the preventive medicine code series in the 65+ band. Sort by denial reason. Identify how many lacked a signed advance notice.
- Week 2: Write the pre-visit eligibility script and assign it to a named role with a backup. Add the 65+ scheduling flag to your practice management system.
- Week 3: Inventory every vendor touching a preventive encounter. Match each against your executed agreements. Note expiration dates and subcontractor language.
- Week 4: Audit ten charts per provider against a written rubric. Deliver results in writing. Update the intake form storage and disposal process based on what you find at the front desk.
None of this is glamorous. All of it shows up in the denial rate and in what an investigator finds if a complaint lands.
Close the Vendor Gap First
The billing fixes around the 99387 CPT code pay for themselves in a quarter. The privacy gaps are the ones that sit unnoticed until a vendor has an incident and you discover there was never a signed agreement defining who notifies whom.
Start with the vendor inventory. If you find missing agreements, build and export a compliant BAA in a few minutes rather than editing a decade-old template. If your broader documentation set — risk analysis, policies, workforce training records — is equally overdue, automated HIPAA risk analysis and policy generation covers the full document package. Either way, do the inventory before the next preventive season, not after.