Five to ten minutes. That is the entire window described by CPT 98016, the brief communication technology-based service code your billing staff has probably seen appearing on encounter forms since it took effect in 2025. It is a small code with an outsized operational footprint: it touches your scheduling rules, your consent script, your documentation template, and — the part most practices miss — your vendor list.

This guide is for the people who run the practice. If you sign the platform contracts, answer the records requests, or explain to a physician why a claim was denied, the mechanics below are yours to own. Coding decisions belong to the billing provider; your job is to build the workflow that makes those decisions documentable and defensible.

What CPT 98016 Describes and What It Replaced

CPT 98016 is defined as a brief communication technology-based service — a virtual check-in — furnished by a physician or other qualified health professional who can report evaluation and management services, provided to an established patient, involving 5–10 minutes of medical discussion. The code carries two timing exclusions: the service cannot originate from a related E/M service within the previous seven days, and it cannot lead to an E/M service or procedure within the next 24 hours or the soonest available appointment.

Functionally, it stepped into the role HCPCS G2012 played for Medicare. When the CPT 2025 code set introduced the 98000-series telemedicine codes, CMS did not adopt all of them for Medicare payment, but it did recognize 98016 as the successor to the older virtual check-in code. Commercial payer adoption has been uneven, which is why your payer matrix matters more than any national write-up.

One structural point worth internalizing: virtual check-ins have historically been treated as communication technology-based services rather than Medicare telehealth services. That distinction has practical consequences for originating-site and geographic restrictions, and it means 98016 has not risen and fallen with the short-term telehealth extensions Congress has passed in recent years. Confirm current status with your MAC before you build policy on it — this area has moved repeatedly since 2024.

Verify before you bill

Do not let a blog post — including this one — be your source of truth on payment. Pull the current year's Physician Fee Schedule and your MAC's local guidance. HHS also maintains plain-language billing and reimbursement resources for telehealth providers that your billing lead should bookmark and re-check each January.

The Three Timing Rules Your Schedulers Have to Enforce

Most denials tied to virtual check-in codes are not coding errors. They are scheduling errors that nobody caught until the remittance came back.

The seven-day lookback

Before the check-in is documented, someone has to confirm the patient did not have a related E/M service in the prior seven days. In a two-provider practice, that is a glance at the chart. In a twelve-provider multi-site group with a shared call rotation, it is a real query.

Build it into the intake macro. Your front desk or triage nurse should record the date of the last related encounter in the same note where the check-in is captured, so the biller is not reconstructing it from memory three weeks later.

The 24-hour lookahead

If the discussion results in an appointment within 24 hours — or at the soonest available slot — the check-in generally is not separately reportable. This is the rule that catches practices with same-week availability, because scheduling the follow-up is the natural instinct of a good staff member.

The operational fix is a hold. Do not release the charge until the scheduling outcome is known. Many practices park these on a 48-hour review queue and let the billing lead clear them.

The 5-to-10-minute discussion

Time is an element of the code descriptor, so time belongs in the note. Start and stop times, or a stated total of medical discussion time, documented by the person who furnished the service. A note that says "brief phone call" supports nothing.

Can CPT 98016 Be Billed for an Audio-Only Phone Call?

Yes — the code describes communication technology-based services and is not limited to video. A telephone conversation, a secure patient-portal exchange, or a store-and-forward image review can all fall within the descriptor, provided the encounter meets the established-patient requirement, the 5–10 minute discussion element, the seven-day lookback, and the 24-hour lookahead. What changes with audio-only is not the code's availability but your privacy posture: OCR's guidance on audio-only telehealth still requires reasonable safeguards, verification of the patient's identity, and a business associate agreement with any vendor whose technology handles the protected health information. The determination that a particular encounter meets the descriptor is made and documented by the billing provider, not by front-desk staff.

Virtual check-ins carry patient cost-sharing. Medicare has long expected verbal consent for these services to be obtained and documented, and while consent may be captured annually rather than per encounter under current guidance, the safest operational default is to capture it and log the date.

Write a five-line script and put it on the scheduling screen. It should say what the service is, that a charge applies, that coinsurance or a deductible may apply, and ask for agreement. Then log who obtained it and when.

Your documentation set for each CPT 98016 encounter should include, at minimum:

  • Patient identity verification method (especially for audio-only)
  • Date and time, with duration of medical discussion
  • Date of the most recent related E/M encounter
  • Consent capture with date and staff initials
  • Modality used and the specific platform
  • Clinical substance of the discussion and the disposition

That last field — modality and platform — is the one auditors and privacy officers both want, and it is the one templates usually omit.

Where CPT 98016 Creates Privacy Exposure

Every virtual check-in moves PHI across a channel you do not fully control. The enforcement discretion that let practices use non-public-facing consumer video apps during the public health emergency ended in 2023, following a 90-day transition period that closed on August 9 of that year. There is no longer a grace period. If a vendor's technology creates, receives, maintains, or transmits PHI on your behalf, you need a business associate agreement.

The vendors most practices forget

Run your check-in workflow end to end and list every entity that touches the data. In a typical primary care practice, the list is longer than expected:

  1. The video or messaging platform itself
  2. The SMS gateway that sends the appointment link
  3. The answering service or after-hours triage vendor that routes the initial call
  4. The transcription or ambient documentation tool, if clinicians use one
  5. The cloud storage or archive holding recorded sessions or images
  6. Any analytics or call-recording layer bundled into your phone system

Each of those is a business associate unless it qualifies as a mere conduit — and the conduit exception is narrow. It covers entities that transport data without accessing it other than randomly or infrequently, like a telecom carrier or the postal service. A platform that stores session recordings, retains message history, or indexes content for search is not a conduit. HHS's telehealth and HIPAA guidance is the reference to hand your practice manager on this point.

Close the paper gap before the next audit

The pattern OCR sees repeatedly in breach investigations is a practice with a real vendor relationship and no executed agreement. That is not a technical failure; it is an administrative one, and it is entirely preventable in an afternoon. If your virtual check-in workflow added a vendor this year and the contract file is empty, generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase with no subscription, and it closes a gap that costs far more to explain after the fact.

Minimum Necessary in a Ten-Minute Call

Short encounters tempt staff into shortcuts. A front-desk employee gathers symptom detail so the clinician can "be ready." A triage line records the full call. Neither is inherently a violation, but both expand the PHI footprint of a service that is supposed to be brief.

Define what non-clinical staff may collect for a virtual check-in and write it down. Typically: identity verification, callback number, reason for contact in the patient's own words, and consent. Everything else belongs to the clinician.

If your phone system records calls by default, decide deliberately whether virtual check-ins should be recorded, document that decision, and set retention accordingly. Recordings you never listen to are pure liability — they are discoverable, breachable, and subject to the right of access.

Records Requests: The Part Nobody Plans For

A patient who had three virtual check-ins last quarter and requests their designated record set is entitled to what you maintain. If the check-in note lives only in the platform vendor's portal and never synced to the chart, you have a records problem and an interoperability problem at once.

Test it. Pick one patient with a documented CPT 98016 encounter and run a mock request through your normal process. Time it. If the note is not in the chart export, fix the integration — or the manual step that was supposed to cover the integration.

The same test surfaces your accounting-of-disclosures posture and tells you whether the vendor can produce records if you terminate the contract. Termination and data return obligations are BAA terms; verify yours actually say something.

Where 98016 Belongs in Your Risk Analysis

A new communication channel is a change to your information system, which means it belongs in your Security Rule risk analysis. Adding virtual check-ins without updating the analysis is the kind of omission that turns a minor incident into a finding.

NIST's SP 800-66 Revision 2 gives a workable structure for documenting the assets, threats, and safeguards involved. Map the check-in data flow, note where PHI rests versus transits, record your encryption and authentication controls, and identify who at your practice owns each. Practices that would rather not rebuild that documentation by hand can automate the risk analysis and policy set and spend the recovered hours on staff training instead.

Revisit it whenever the modality changes. Adding portal-based photo submission to an existing phone workflow is a new risk, not the same one.

A Monday-Morning Workflow You Can Hand to Staff

  1. Front desk: verify established-patient status and identity; capture reason for contact; read the consent script; log consent date and initials.
  2. Front desk: pull and record the date of the last related E/M encounter into the note template.
  3. Clinician: conduct the discussion on an approved platform only; record start/stop times, modality, and disposition.
  4. Scheduler: if a follow-up visit is booked, flag the encounter and note the appointment date.
  5. Billing lead: hold the charge 48 hours; clear the queue by confirming no qualifying E/M within 24 hours or soonest availability; release or write off.
  6. Privacy officer: quarterly, reconcile the approved-platform list against executed BAAs and against what staff actually used.

That sixth step is the one that saves you. Staff drift toward whatever tool is fastest, and the gap between your approved list and your actual list is where breaches start.

Start With the Vendor Inventory

Before your next billing cycle, list every technology that touched a CPT 98016 encounter in the last 90 days and put an executed agreement next to each name. If any line is blank, build the business associate agreement and get it signed this week. The coding rules will keep changing; the obligation to paper your vendors will not.