A three-provider pediatric practice runs somewhere between 30 and 60 well-child visits a week, and a meaningful share of those land in the early-childhood bracket that CPT code 99392 describes. Each one generates a claim, an immunization registry submission, a screening questionnaire, a portal message, a recall text, and — sooner or later — a daycare form request from a parent who is standing at your front desk with a deadline.

This guide is written for the person who owns that whole chain: the practice administrator, the billing lead, the privacy officer. It covers how the visit gets built operationally, then makes the records-handling and vendor exposure explicit. It is not clinical guidance and it does not tell you which code fits a given encounter. That determination belongs to your providers and coders, working from the documentation in front of them.

What CPT Code 99392 Describes — and Who in Your Practice Decides

CPT code 99392 sits in the preventive medicine services family. The descriptor covers a periodic comprehensive preventive medicine reevaluation for an established patient in early childhood, age 1 through 4 years, including an age-appropriate history and examination, counseling and anticipatory guidance, risk factor reduction, and the ordering of appropriate laboratory and diagnostic procedures.

Its neighbors matter for your edit rules. 99391 covers infants under one year, 99393 late childhood, 99394 adolescents, and the 99381–99385 series covers the same age bands for new patients. Age is measured at the date of service, not the date of billing, which is why a birthday falling between scheduling and check-in is a recurring source of rework in pediatric offices.

Keep the decision with the coder, not the scheduler

Your scheduling template can suggest a visit type. It should never lock a code. Code selection is a documentation-driven determination made after the encounter, based on what was performed and recorded. Build your workflow so the appointment type drives room assignment and time allocation, and the charge capture step happens downstream from the note.

Write that separation into your billing policy in one sentence: scheduling assigns a visit type; the rendering provider and coder assign the code. Auditors and payers both respond well to a practice that can articulate the difference.

Quick Answer: What Is CPT Code 99392 Used For?

CPT code 99392 is the billing code for a routine preventive medicine visit — a well-child check — for an established patient between ages 1 and 4. Practices generally attach it to encounters that include:

  • An age-appropriate comprehensive history and physical examination
  • Anticipatory guidance and counseling documented in the note
  • Ordering of age-appropriate screening or laboratory work
  • An established-patient relationship, meaning a face-to-face service from the practice or same-specialty group within the prior three years

Vaccine products and their administration are reported separately from the preventive visit code. Whether a given encounter supports 99392 is a coding determination made from the documentation — not something the front desk, the payer's prior scheduling notes, or a template default should decide.

The Front-Desk Sequence Behind a Clean 99392 Claim

Map the visit as six operational steps and assign an owner to each. Practices that lose money on preventive visits usually lose it in steps two and six.

  1. Scheduling. Confirm date of birth against the visit type. Flag any child turning 5 before the appointment date.
  2. Eligibility and benefits. Verify preventive benefits and whether the plan applies periodicity limits. Confirm Vaccines for Children eligibility where applicable and record the eligibility category in the chart, not on a sticky note.
  3. Intake. Distribute developmental and behavioral screening instruments. Note which instruments were completed and by whom.
  4. Encounter documentation. The provider records history, exam, guidance, and orders.
  5. Charge capture. Coder reviews the note, selects the preventive code and any separately reportable services, applies modifiers where the documentation supports them.
  6. Post-visit. Immunization registry submission, portal release, recall scheduling, form completion, statement generation.

The modifier 25 conversation, handled administratively

When a child presents for a preventive visit and the provider also addresses a distinct problem, practices commonly report a separate problem-oriented E/M service with modifier 25 appended. Your job as administrator is not to decide when that is appropriate — it is to make sure the documentation supports the decision your coder made.

Concretely: require that the problem-oriented work be documented separately and identifiably from the preventive elements. Audit a sample every quarter. Track your modifier 25 rate by provider and investigate outliers on both ends, because a provider who never reports one may be leaving documented work unbilled.

The Well-Child Chart Holds More Than One Person's Information

This is the part most billing-focused guides skip. A 99392 encounter routinely captures information about people who are not the patient.

Family and social history describes parents and siblings. Screening instruments administered to a caregiver — including maternal depression screening performed during a child's visit — generate answers about an adult's mental health that live inside a toddler's chart. Social risk screening captures household food security, housing, and interpersonal violence.

When a records request arrives for that child, your release staff will hand over whatever is in the designated record set unless someone has thought about this in advance. Two operational decisions to make now:

  • Decide where caregiver screening results are stored and whether they belong in the child's designated record set or in a separately maintained caregiver record, and document that decision in policy.
  • Train release-of-information staff to route pediatric requests through a review step rather than a bulk export.

Apply the minimum necessary standard to disclosures that are not to the patient or their personal representative and not for treatment. A daycare center asking for immunization status does not need the developmental screening results.

Personal Representatives, Custody Paperwork, and Who Gets the Chart

For a patient age 1 through 4, a parent or guardian is almost always the personal representative under the Privacy Rule, and access requests run through them. That simplicity ends the moment custody is contested.

Your front desk should not be adjudicating custody orders at the counter. Build a two-tier process: staff collect the request and any court documentation, and a designated privacy contact reviews before release. Document the reviewer's decision and the basis for it. HHS publishes practical guidance on personal representatives that is worth putting in front of your staff during annual training.

Regardless of who asks, the access clock is the same: you have 30 days to act on a request for records, with one 30-day extension available if you notify the requester in writing with a reason and a date. Right-of-access complaints have been a durable OCR enforcement priority, and pediatric practices are not exempt. If you want to see the pattern in reported incidents, the OCR breach portal is public and searchable.

School, Daycare, and Sports Form Requests

Preventive visits generate paperwork demand. A parent completes a 99392 visit on Tuesday and needs a daycare enrollment form Thursday.

The Privacy Rule includes a specific provision permitting disclosure of proof of immunization to a school where state law requires it prior to admitting the student, provided you obtain and document agreement from the parent or guardian. That agreement can be oral. Document it anyway — name the person who gave it, the date, and who took it. Your form-completion log should capture request date, requester, what was released, and authorization basis.

Set a turnaround standard and staff to it. Three business days is achievable in most practices. Parents who wait two weeks for a daycare form escalate, and escalations become complaints.

The Vendor List Behind a Single Well-Child Visit

Walk one 99392 encounter through your systems and count the third parties that touch protected health information:

Recall and reminder messaging

Well-child visits run on periodicity schedules, which means recall automation. Your texting or email vendor is transmitting patient names, appointment types, and sometimes visit reason. That is a business associate relationship, and the visit-type field is exactly where practices leak more than they intend.

Screening instrument platforms

If caregivers complete developmental or behavioral screening on a tablet or through a link, the platform hosting that instrument is handling PHI — including, as noted above, information about adults. Confirm the agreement covers it.

Clearinghouse, registry, and portal interfaces

The clearinghouse transmitting your claims, the interface engine pushing immunization data to your state registry, the portal releasing after-visit summaries, and the analytics or quality-reporting tool pulling well-child completion rates all sit in scope.

Pull your vendor inventory and check each line against a signed, current agreement. If you find gaps — and most practices do, usually in the messaging and screening-tool categories — you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, as a one-time purchase rather than another subscription. HHS also publishes sample business associate agreement provisions if you want to compare language before you sign anything.

Statements, EOBs, and the Confidential Communications Request

Preventive visits are frequently covered at no cost sharing, which lulls practices into ignoring billing communications. Then a denial hits, a statement generates, and it mails to the policyholder's address — which may not be the household where the child lives.

Patients and their representatives can request that you communicate by alternative means or at alternative locations, and you must accommodate reasonable requests. Give your billing staff a documented path to honor that: a flag in the system, a designated alternative address field, and a rule that suppresses the default statement run for flagged accounts.

For Medicaid-enrolled children, remember that preventive visits fall under EPSDT requirements, which carry their own periodicity and reporting expectations. CMS maintains the program details on its EPSDT page.

A 90-Day Cleanup for Preventive Visit Operations

Days 1–30. Inventory every vendor that touches a well-child encounter. Confirm signed agreements. Pull your visit-type field values and strip anything descriptive from outbound reminders.

Days 31–60. Audit 20 preventive charts against claims. Check age-at-service accuracy, established-versus-new determination, modifier usage, and whether separately reported services are separately documented. Route findings to providers as education, not discipline.

Days 61–90. Rewrite your pediatric release-of-information procedure with the caregiver-screening question answered explicitly. Train front desk on custody escalation. Build the form-completion log if you do not have one.

None of this is glamorous, and none of it shows up on a dashboard. It shows up when a parent files a complaint, a payer requests records, or a texting vendor has an incident and you go looking for the agreement you never signed.

Start With the Agreement Gap

If you do one thing after reading this, reconcile your vendor list against your signed agreements — the messaging platform and the screening tool are the two most commonly missed. When you find the gaps, build the missing BAAs in a single sitting and file them where your next auditor will actually look. If your broader policy set and risk analysis documentation are also overdue, automating the full compliance document set is a reasonable next step once the agreements are in place.