G0402 CPT Code Description: Practice Operations Guide
A patient turns 65 in April, enrolls in Part B effective May 1, and your scheduler books a “Welcome to Medicare” visit for the following February. That single scheduling decision determines whether the encounter falls inside the eligibility window or outside it — and whether your billing team spends the next quarter fighting a denial. The g0402 cpt code description is where that timeline is defined, and it is also where a surprising amount of privacy exposure begins.
This guide is for administrators, billing leads, and privacy officers. It covers what the code actually describes, how practices verify eligibility, what sensitive data the visit collects, and which vendors end up holding that data. It is administrative guidance on workflow and documentation, not clinical direction on what any individual patient needs.
What the G0402 CPT Code Description Actually Says
G0402 describes an initial preventive physical examination (IPPE) — a face-to-face visit furnished to a new Medicare beneficiary, limited to the first 12 months of Part B enrollment. It is a once-per-lifetime benefit. Two companion codes, G0403 through G0405, describe the optional screening electrocardiogram components that may be furnished as part of the same benefit.
Three operational facts follow from that description:
- It is time-boxed. Eligibility runs from the Part B effective date, not the patient's birthday and not the date of your first appointment.
- It is non-repeatable. A patient who received an IPPE at a prior practice cannot receive another one from you.
- It is a preventive benefit, not a problem-oriented visit. Cost-sharing treatment for the visit itself differs from cost-sharing on the optional screening EKG components, and both differ from any medically necessary services performed on the same day. Verify current cost-sharing rules against CMS guidance before your front desk quotes a dollar figure to anyone.
Why It Is HCPCS, Not CPT
People search for the “g0402 cpt code description” because that is how the code gets talked about at the front desk. Technically, G-codes live in HCPCS Level II — the code set CMS maintains for items and services not described in the CPT manual. Your practice management system probably files them in the same field, which is why the distinction rarely surfaces until an auditor asks. CMS publishes the code set and its updates on its HCPCS overview page, and your coding staff should be pulling descriptors from there or from the current-year file rather than from a vendor cheat sheet that was accurate three years ago.
The 12-Month Window Your Scheduler Has to Verify
Eligibility verification for this benefit is a front-office job, not a back-office cleanup task. Build it into the scheduling script.
Your scheduler needs two data points before the appointment is confirmed: the Part B effective date, and whether an IPPE has already been furnished. Both are available through Medicare eligibility transactions — HETS, your clearinghouse's eligibility tool, or the MAC provider portal. Assign a named role to run the check and a specific place in the chart or practice management system to record the result.
Here is the privacy wrinkle nobody plans for. Staff routinely paste eligibility screenshots into the chart, into a shared spreadsheet, or into a scheduling note. Those screenshots contain the Medicare Beneficiary Identifier and coverage history. A spreadsheet of MBIs sitting on a shared drive with open permissions is a breach waiting for a laptop to walk out the door. Decide now where eligibility evidence lives, who can see it, and how long you keep it.
The Data This Visit Collects Changes Your Privacy Posture
The IPPE is unusually data-dense compared with a routine office visit. Depending on how your clinicians structure it, the encounter can generate documentation covering medical and social history, current medications and supplements, height, weight, BMI and blood pressure, vision screening, functional ability and home safety, cognitive assessment, depression risk screening, substance use and alcohol screening, review of opioid prescriptions and prescription drug monitoring program data, end-of-life planning discussion, and a written schedule of recommended preventive screenings furnished to the patient.
Read that list again as a privacy officer rather than as a biller. In one encounter you have created records touching mental health, substance use, cognitive decline, home living conditions, and advance care wishes. That is the highest-sensitivity cluster most primary care practices produce, and it is being generated at volume by whatever intake tool your team uses.
Screening Instruments and Intake Tools Are a Data Flow, Not a Form
If patients complete depression or substance use screeners on a tablet, in a portal, or through a text-message link before the visit, that data crossed at least one vendor boundary before your clinician saw it. Map it:
- Who hosts the intake form and where does the submission sit before it lands in the chart?
- Does the tool retain a copy after import? For how long?
- Do scores flow to a population-health or care-gap analytics platform?
- Does anyone at the vendor have production access to responses for support purposes?
If your answer to any of those is “I'd have to ask,” that is the gap. And if the review of opioid prescriptions pulls in records that originated from a federally assisted substance use disorder treatment program, additional restrictions under 42 CFR Part 2 may attach to that information. The 2024 rule changes brought Part 2 closer to HIPAA on several points, but “closer” is not “identical” — your policies should say what your staff does when Part 2–protected information arrives in a chart.
Every Vendor That Touches a G0402 Encounter
Walk one IPPE encounter end to end and count the third parties. A typical primary care practice finds six to ten:
- Patient reminder and pre-visit intake platform
- Eligibility verification tool or clearinghouse
- EHR host or IT managed service provider
- Ambient documentation or transcription service
- Health risk assessment or quality-reporting vendor
- Referral management or care coordination platform
- Revenue cycle management or outsourced coding partner
- Claims clearinghouse
- Secure messaging or fax service delivering the written screening schedule
- Offsite backup or archive provider
Each one that creates, receives, maintains, or transmits protected health information on your behalf needs a business associate agreement in place before the data moves. HHS publishes sample business associate agreement provisions, but sample text is a starting point, not a finished contract — you still have to name the parties, set breach notification timing, define subcontractor obligations, and specify what happens to your data at termination.
The recurring failure mode in practices is not refusing to sign BAAs. It is signing them for the EHR and the clearinghouse, then never getting around to the intake tool, the transcription service, and the analytics platform someone in the quality department onboarded with a credit card. If your vendor list has holes, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Close the gap this week rather than the week after a vendor incident.
The Records Request You Will Get Fourteen Months Later
IPPE documentation shows up in records requests more often than you would expect, because it is frequently the most comprehensive baseline record in the chart. Long-term care intake, disability determinations, family disputes over capacity, and attorney requests all reach for it.
Your obligations do not change because the encounter was preventive. A patient exercising the right of access is entitled to a copy of the designated record set, generally within 30 days, in the form and format requested if you can readily produce it, at a fee limited to what the rule permits. OCR's individual right of access guidance remains the operative reference, and right-of-access failures have been one of OCR's most consistently enforced areas.
Two practical points for IPPE records specifically:
The written screening schedule counts. If your clinician furnished a personalized preventive services plan to the patient, that document belongs in the record and in your release. Practices that generate it from a template and never save a copy have a documentation problem and a records-production problem simultaneously.
Third-party requests are not access requests. A request from a facility, an attorney, or an adult child requires a valid authorization or another permitted basis. Train the person who opens the mail to route these differently, because the depth of an IPPE record makes over-disclosure expensive.
Amendment Requests Follow the Same Sensitivity Curve
Patients ask to amend depression screening notes, cognitive assessment findings, and social history entries. You have 60 days to act, with one 30-day extension available. Have a written process, a designated decision-maker, and a place to file the request, your response, and any statement of disagreement. Ad hoc handling of amendment requests about mental health documentation is how a privacy complaint gets filed.
Documentation and Code Selection: Who Decides What
Keep this boundary clean in your policies. Code selection rests on the documented service and the treating clinician's judgment about what was medically appropriate. Administrative staff verify eligibility, confirm the documentation supports the elements described in the code descriptor, apply payer edits, and escalate discrepancies. They do not decide clinically what should have happened.
What your compliance program can and should standardize:
- A documentation checklist mirroring the current descriptor elements, maintained by a named owner and reviewed when CMS updates the code set
- A pre-bill review step that flags encounters missing a required element rather than silently downcoding or upcoding them
- A written escalation path from biller to clinician when documentation and code do not match — with the clinician making the final call
- A quarterly sample audit, with results logged, findings assigned, and remediation dated
When your outsourced coding partner changes a code, you need to know who did it, when, and on what basis. That is a BAA and audit-trail question as much as a billing one.
One Encounter, Six Handoffs: A Worked Sequence
Assign every step below to a role, not a person, and put the assignments in writing.
- Scheduler confirms Part B effective date and prior IPPE history; records verification result in the designated field; does not paste the MBI into a note.
- Intake coordinator sends the pre-visit questionnaire through a platform under a current BAA; confirms the patient's chosen communication channel is documented.
- Clinical staff capture vitals, screening results, and functional and safety information into the EHR, not into a scratch document on a workstation desktop.
- Clinician performs and documents the visit, determines and documents the appropriate code, and generates the written screening schedule — with a copy retained in the chart.
- Billing runs pre-bill documentation review, applies payer-specific edits, and escalates mismatches to the clinician.
- Privacy officer spot-checks the audit log monthly for access to IPPE encounters by staff without a treatment, payment, or operations reason.
That last step is the one most practices skip. A visit that documents cognitive status and home living conditions for a longtime community member is exactly the record a curious employee opens. Snooping incidents are internally detected, internally remediable, and internally preventable — but only if someone is looking.
Where the g0402 cpt code description Meets Your Risk Analysis
If your Security Rule risk analysis does not name the intake platform, the transcription service, and the analytics tool that handle IPPE data, it is not describing your practice. The g0402 cpt code description tells you what data the encounter produces; your risk analysis has to account for where that data travels and what safeguards apply at each stop. Practices that need to rebuild that documentation set from scratch can automate the risk analysis and policy set rather than restarting a spreadsheet every renewal cycle.
One concrete next action: pull your vendor inventory, trace a single IPPE encounter from appointment reminder to paid claim, and mark every third party without an executed, current BAA. If that list is not empty, build the agreements you are missing and get them signed before the next visit generates another chart full of screening data.