Medicare Annual Wellness Visit CPT: A Practice Guide
Your scheduler blocks 60 wellness visits for May, your medical assistant emails a health risk assessment link to every one of those patients, and a population health vendor pulls your roster to flag who is overdue. Three separate flows of protected health information started before a single patient walked in. If your practice searched medicare annual wellness visit cpt to figure out what to bill, this article covers the part that comes after — the scheduling logic, the documentation trail, the designated record set implications, and the vendor contracts your compliance file needs before the first claim goes out.
This is administrative guidance for administrators, billers, and privacy officers. It does not tell you which code fits a given patient encounter; it tells you how practices build and defend that decision.
Start Here: The Medicare Annual Wellness Visit CPT Codes Are Not CPT Codes
Nearly everyone who searches for the medicare annual wellness visit cpt code is actually looking for HCPCS Level II G codes. Medicare created its own code set for these services because the wellness visit is a Medicare benefit construct, not a standard evaluation and management service.
The relevant family, as defined by CMS, includes G0402 (the Initial Preventive Physical Examination, commonly called the "Welcome to Medicare" visit), G0438 (initial annual wellness visit), and G0439 (subsequent annual wellness visit). Federally qualified health centers bill under their own encounter code structure. CMS publishes the current definitions and coverage conditions in its Medicare Wellness Visits MLN booklet, which your billing lead should re-download every January rather than working from a printout taped inside a cabinet.
Why this matters operationally: if your charge master, your superbill, or your scheduling template labels these encounters as CPT preventive medicine services, front-desk staff will collect a copay that shouldn't be collected, and your patients will call. The wellness visit carries no coinsurance and no deductible when the coverage conditions are met and the claim is submitted as a preventive service.
Quick Answer: What Codes and Rules Govern a Medicare Wellness Visit?
Practices generally work from four operational facts:
- The codes are HCPCS G codes, not CPT codes — G0402 for the initial preventive physical exam, G0438 for the first annual wellness visit, G0439 for each subsequent one.
- The IPPE window is the first 12 months of Part B enrollment. After that window closes, it cannot be billed.
- G0438 is a once-per-lifetime service for a given beneficiary, and it requires that the patient has had Part B for more than 12 months.
- Subsequent visits follow the 11-full-month rule — 11 full months must pass after the month of the last wellness visit or IPPE.
Code selection for any individual encounter is determined by the rendering provider and documented in the chart. Your job on the administrative side is to make sure eligibility was verified, the required elements were captured, and the record supports what was billed.
The Eligibility Math Your Schedulers Get Wrong
The 11-month rule is not an anniversary date
Staff routinely book patients on the exact anniversary of last year's visit and get denied. The rule counts full calendar months after the month of service. A visit performed on March 25, 2025 makes the patient eligible again on March 1, 2026 — not March 25.
Build this into your scheduling template as a hard rule, not a sticky note. One practice manager I worked with put a two-line eligibility script on the scheduler's monitor and cut wellness-visit denials by more than half in a quarter. Nothing sophisticated. Just removing a judgment call from a person handling 90 calls a day.
Verify before you book, not after you bill
Your eligibility check should run through the Medicare provider portal before the appointment is confirmed. Confirm Part B effective date, last wellness visit date, and whether another practice already billed one this year — that last one is the denial nobody sees coming, especially when a health plan or a home-visit vendor performed a wellness assessment the patient forgot about.
Assign this to a named role. "Whoever is at the front desk" is not a role.
The Health Risk Assessment Is a PHI Intake Pipeline, Not a Form
The health risk assessment (HRA) is a required element of the wellness visit, and it is where the privacy exposure lives. It collects self-reported health status, psychosocial risks, behavioral risks, activities of daily living, and often depression screening responses. That is sensitive PHI, collected at volume, frequently outside your EHR.
Trace every path the HRA can travel
Map how the assessment reaches your practice. Most clinics have more paths than they think:
- Paper packet mailed to the patient and returned by post or brought to the visit
- Patient portal questionnaire completed at home
- Third-party digital intake platform that texts a link
- Telephone pre-visit call performed by an outsourced care-coordination team
- Tablet handed to the patient in the waiting room
Each path is a separate risk to document. Mailed paper sits in an unlocked bin. Tablets in the lobby stay logged into the previous patient's form. Texted links get sent to the number on file, which may belong to an adult child. Phone assessments get performed in an open bullpen where the next patient can hear the depression screening questions.
The minimum necessary standard applies to internal uses too. Your billing team does not need the full HRA narrative to submit a claim. Configure role-based access so it doesn't get one.
Scheduling pages and tracking technologies
If you built a "Schedule Your Medicare Wellness Visit" landing page, check what analytics and advertising scripts run on it. The regulatory ground here has shifted — OCR's guidance on online tracking technologies was partially vacated in federal litigation in 2024, and the enforcement picture for unauthenticated pages remains contested. What has not changed: once a patient logs into your portal to complete an HRA, anything transmitted from that authenticated session to a third party is squarely PHI. Inventory your scripts. Most practices find at least one they didn't authorize.
Same-Day Problem Visits and the Documentation Trail
Patients rarely arrive with nothing on their mind. When a significant, separately identifiable problem is addressed during the same encounter, practices bill the problem-oriented service alongside the wellness visit using the appropriate modifier — and that combination is a known audit target.
Your compliance responsibility is the documentation architecture, not the clinical call. Two things make audits survivable:
- Separable notes. The wellness visit elements and the problem-oriented work should be distinguishable in the record, not blended into one narrative paragraph.
- Required elements checklist. The wellness visit has a defined element list — vital measurements, medical and family history, current provider and supplier list, cognitive impairment detection, depression risk review, functional ability and safety review, a written personalized prevention plan, and a screening schedule. Your template should force each one.
Run an internal sample of ten wellness visit charts per quarter against that element list. Have someone who does not build the templates do the reviewing.
The Vendor Roster Behind a Wellness Visit Program
Count the outside parties touching a single wellness visit at a mid-sized primary care practice: the digital intake vendor, the population-health platform flagging care gaps, the patient-reminder texting service, the transcription tool, the print-and-mail house producing the personalized prevention plan, the billing company submitting the claim, and sometimes a contracted nurse practitioner group running visits in bulk. That is seven business associates for one $150 encounter.
Every one of them needs an executed business associate agreement on file, and "we sent it to their legal team in 2023" is not an executed agreement. HHS publishes sample business associate agreement provisions that establish the floor. If you are chasing signatures across a growing vendor list, generating a signature-ready business associate agreement in one sitting beats another month of email tag.
Three questions to ask any wellness-visit vendor
- What data do you retain after the visit, and for how long? Care-gap platforms often keep full rosters indefinitely. Get the retention and destruction terms in writing.
- Do you use our patients' data for product development or de-identified analytics? This clause hides in the fine print of digital intake contracts.
- Who are your subcontractors? The texting vendor's SMS gateway is a subcontractor. Your BAA should flow down.
If you cannot produce a current BAA, a completed risk analysis, and the policies governing this workflow within a day of a records request, you have a documentation gap rather than a privacy program. Practices that need that whole set built and kept current can automate the HIPAA risk analysis and policy document set instead of rebuilding it in a spreadsheet every renewal cycle.
The Personalized Prevention Plan Lands in Your Designated Record Set
The written personalized prevention plan handed to the patient is part of the medical record. When a patient — or an attorney, or an adult child with a valid authorization — requests the chart, that plan and the underlying HRA responses come with it.
Under the HIPAA right of access, you have 30 days to respond, with one 30-day extension available if you notify the patient in writing. Right-of-access enforcement has been one of OCR's most consistent activities for years, and the settlements skew toward small practices that simply did not respond.
The operational trap: if your HRA lives in a third-party intake platform and never syncs into the EHR, your records clerk will fulfill the request from the EHR alone and omit responsive records. Test this. Pull a wellness visit chart the way a records request would arrive and see whether the HRA responses appear.
A 30-Day Build Plan
Week 1 — Billing lead. Correct the charge master so wellness visit codes are labeled as HCPCS G codes, not CPT preventive services. Confirm no copay prompts fire at check-in for these appointment types.
Week 2 — Scheduling supervisor. Write the eligibility script, embed the 11-full-month rule in the scheduling template, and require a portal eligibility check before confirmation.
Week 3 — Privacy officer. Map every HRA collection path. Inventory the vendors touching each one. Verify executed BAAs and note the gaps with owner names and dates.
Week 4 — Clinical documentation lead and privacy officer together. Audit ten charts against the required element list, test a simulated records request end to end, and confirm the prevention plan is retrievable.
Where This Program Actually Breaks
The failures I see are boring and repeatable. Assessments printed in a batch and left on the printer overnight. A staffing agency running wellness visits under a verbal arrangement with no BAA. A texting vendor added by the marketing coordinator without telling the privacy officer. Prevention plans mailed to the address on file after the patient moved.
None of those show up in a claim denial report. They show up in a complaint, or in a breach notification you have 60 days to send.
Fix the mechanics first — codes, eligibility, templates. Then treat the wellness visit for what it operationally is: a high-volume, vendor-heavy PHI collection program that happens to bill under a G code. If your risk analysis, policies, and vendor agreements are stale, build the current document set before your wellness visit volume scales further. It is far cheaper to do it in March than to reconstruct it during an investigation.