A 29-year-old new patient books an "annual physical" through your website form. Six weeks later, an explanation of benefits arrives showing a $180 patient responsibility, and your front desk gets a phone call that starts with the word "free." Somewhere between the online booking widget, the eligibility check nobody ran, and the office visit code that got added at checkout, your practice created a billing dispute, a records request, and a complaint — all from one appointment.

This guide walks administrators and billing staff through the operational mechanics around CPT code 99385, then makes the privacy, records-handling, and vendor exposure explicit. It is administrative guidance about workflow and documentation, not clinical guidance, and it does not tell you which code fits a given patient encounter. That determination belongs to the rendering provider working from the AMA CPT descriptors, payer policy, and the documented content of the visit.

What CPT Code 99385 Describes — The Short Answer

CPT code 99385 is the preventive medicine evaluation and management code for an initial comprehensive preventive visit for a new patient aged 18 through 39. The AMA CPT descriptor family for preventive medicine services splits along three axes your billing staff has to get right every time:

  • New versus established patient. The 993x5 series covers new patients; the 993x6 series covers established patients. "New" turns on whether the patient received a face-to-face professional service from a provider of the same specialty and subspecialty in your group within the prior three years.
  • Patient age at the date of service. Not age at scheduling, not age at registration. A patient who turns 40 between booking and the visit falls into a different code band.
  • Preventive versus problem-oriented content. Preventive medicine E/M codes are not selected by time or medical decision-making the way office visit codes are.

Your role as an administrator is not to pick the code. It is to make sure the chart, the registration record, and the age and patient-status fields feeding your claim are accurate, and that whoever selects the code has the payer's preventive policy in front of them.

The Eligibility Check Your Front Desk Owes the Patient Before the Visit

Most non-grandfathered commercial plans cover a defined set of preventive services without cost sharing when delivered in network. That coverage is not unlimited, and it does not mean every service rendered on the same day rides along for free. Frequency limits, network status, and the distinction between screening and diagnostic services all bite.

Build a pre-visit script and assign it to a named role — not "the front desk" generically, but a specific position on your staffing grid:

  1. Run electronic eligibility two to three business days before the appointment, not the morning of.
  2. Capture the preventive benefit response, including any frequency limitation, in the practice management record.
  3. Confirm the patient's new-versus-established status against your three-year lookback, and note which provider and specialty you checked.
  4. Deliver a plain-language financial notice: preventive services are typically covered at 100%, and if the visit also addresses a separate problem, a second charge may apply.
  5. Document that the notice was delivered, by whom, and how.

That fifth step is the one practices skip and the one that resolves disputes. When a patient calls angry about a $180 balance, a timestamped note beats a staff member's memory every time.

When a Preventive Visit Also Addresses a Problem

The most common billing friction around cpt code 99385 arises when a patient who came in for a wellness visit raises a separate, significant concern that the provider evaluates and manages during the same encounter. CPT guidance recognizes that a separately identifiable problem-oriented E/M service may be reported in addition to the preventive service, typically with modifier 25 appended to the office visit code.

Payers scrutinize this pairing. Some deny it reflexively. Some apply their own policy layered on top of CPT and the CMS National Correct Coding Initiative edits. Your billing lead should maintain a per-payer matrix showing which plans accept the pairing, which require an appeal, and what the appeal packet needs to contain.

What the documentation has to show

Administratively, the split visit stands or falls on whether the record shows two distinguishable services. Your internal audit checklist should ask whether the note separates preventive content from problem-oriented content, whether the problem work is documented on its own terms rather than folded into the wellness narrative, and whether the diagnosis pointers on the claim line up with that separation. Providers make the coding call; your job is to catch the charts where the documentation cannot support what was billed and route them back before the claim goes out.

The refund and re-bill loop

Set a standing rule: if a preventive-plus-problem claim generates a patient complaint and your audit finds the documentation thin, you correct the claim rather than defend it. Write the threshold, the reviewer, and the turnaround into your billing policy so the decision is not made ad hoc under pressure from an unhappy caller.

Where PHI Actually Leaks in a 99385 Workflow

Trace one preventive visit from booking to payment and count the outside parties who touch protected health information. Most practices are surprised by the number.

The online booking form and website

If your site collects appointment requests, an intake questionnaire, or a "reason for visit" free-text field, that data is PHI the moment it identifies a patient seeking care from you. Any analytics, chat widget, session-replay script, or advertising pixel loaded on those pages can transmit identifiers and page context to a third party. OCR and the FTC have both addressed tracking technologies on health-related web properties, and the exposure is not theoretical — it is a configuration setting on your marketing site that your compliance officer probably has never seen.

Pull a current inventory of every script running on your scheduling and intake pages. If a vendor receives PHI and has no signed Business Associate Agreement, you have a gap to close this quarter, not next year. Practices that need a defensible agreement quickly can produce one with a step-by-step Business Associate Agreement builder and get it in front of the vendor the same week.

Eligibility and clearinghouse traffic

Your pre-visit eligibility check sends member identifiers to a clearinghouse and on to the payer. That flow is standard and permitted, but it still belongs on your vendor inventory with a current BAA, a documented data-retention term, and a breach-notification clause with a deadline you can actually meet. HHS publishes sample business associate agreement provisions that give you a baseline to compare vendor paper against.

Recall lists and reminder campaigns

Preventive visits generate recall workflows: annual reminders, birthday-month outreach, lapsed-patient lists. The list itself is PHI. When your marketing coordinator exports a spreadsheet of patients aged 18 to 39 who have not had a preventive visit in 18 months and uploads it to an email platform, that platform is a business associate — and the export needs to follow your minimum necessary standard, not include the full demographic dump because the export template was easier.

Appointment Reminders Versus Marketing — Know Which One You Are Sending

Treatment communications and appointment reminders sit outside the HIPAA marketing definition and do not require authorization. A message promoting a third party's product or service, or one for which your practice receives payment from a third party, generally does. The line matters operationally because your recall emails often go out through the same platform as your newsletter.

Practical control: require two separate lists in your messaging platform, one for clinical reminders and one for general communications, with different approvers. Log who approved each send. If a preventive-care reminder ever carries a sponsored insert, that send needs authorization review before it leaves the building. Review the HHS guidance on marketing under the Privacy Rule with your practice's actual send calendar in hand — the abstract rule is easy, the applied version is where practices get it wrong.

The Records Request That Follows a Billing Dispute

Billing disputes over preventive visits produce records requests. A patient who believes their wellness visit should have been covered will ask for the chart note, the itemized statement, and sometimes the claim file. Under the HIPAA right of access, you generally have 30 days to act on a request for records in the designated record set, with one 30-day extension available if you notify the individual in writing of the reason and the new date.

OCR has pursued right-of-access enforcement steadily, and the fact pattern is almost always mundane: a request came in through an unmonitored channel, sat, and expired. Assign a single owner, log every request on receipt with a due date, and confirm your fee schedule matches the cost-based limits described in the HHS right of access guidance.

Two practical notes. First, a billing statement is not automatically outside the designated record set — billing records used to make decisions about the individual are generally included. Second, if the patient asks for records to be sent to a personal email address, honor the request after confirming identity and documenting that you advised them of the risks of unencrypted transmission.

Fitting Preventive-Visit Vendors Into Your Risk Analysis

Every element above — booking widget, intake forms, clearinghouse, messaging platform, payment processor, recall spreadsheet on someone's desktop — belongs in your Security Rule risk analysis. The analysis is not a questionnaire you answer once. It identifies where ePHI lives, who touches it, what could go wrong, and what you are doing about it, and it gets revisited when your systems change. NIST's SP 800-66 Revision 2 maps Security Rule requirements to concrete safeguards if you want a structure to work from.

If your last risk analysis predates your current scheduling stack, the document is decorative. Practices that need to rebuild the analysis, the policy set, and the supporting documentation without hiring a consultant for six weeks can generate a complete HIPAA risk analysis and policy document set and then spend their time on the findings instead of on formatting.

A 60-Day Cleanup Plan You Can Assign Today

  • Week 1 — Practice administrator: inventory every vendor that touches scheduling, intake, eligibility, billing, or patient messaging. Flag any without a current signed BAA.
  • Week 2 — Billing lead: build the per-payer matrix for preventive-plus-problem claims, including denial reason codes and appeal requirements.
  • Week 3 — Front-desk supervisor: deploy the pre-visit eligibility script and the financial notice, with a documentation field in the practice management system.
  • Week 4 — Privacy officer: audit the website and patient portal for tracking scripts. Remove or contract for anything transmitting PHI.
  • Week 6 — Privacy officer: separate clinical reminder lists from general communication lists; assign approvers.
  • Week 8 — Practice administrator: refresh the risk analysis to reflect the current vendor inventory, and log a remediation date for each finding.

None of this requires new headcount. It requires naming an owner for each step and putting a date on it. The preventive visit is the highest-volume, lowest-drama appointment on your schedule — which is exactly why the workflow around it drifts and nobody notices until a patient calls.

Start with the vendor inventory this week. When you find the gaps — and you will — generate the risk analysis and policy documentation that turns the list into a defensible record of what you found and what you fixed.