Medicare Wellness Exam Requirements: A Practice Guide
Your recall list has 380 Medicare patients on it for the third quarter. Your front desk will call every one of them, a third will complete a health risk assessment before they arrive, and at least four different systems — your scheduling module, your portal, an outbound reminder service, and whatever tool your quality team uses to close care gaps — will touch protected health information in the process. The medicare wellness exam requirements are a billing and documentation problem on the surface. Underneath, they are a records-handling and vendor problem, and that half is the one that lands on your desk when something goes wrong.
This guide is written for practice administrators, billing leads, and privacy officers. It covers how the visit types differ operationally, how eligibility timing is verified, who collects the health risk assessment, and which of the vendors in that chain need a signed business associate agreement before they see a single patient name.
What the Medicare Wellness Exam Requirements Include
CMS defines the annual wellness visit as a set of required elements, not a physical exam. A visit that omits an element is a documentation deficiency, and documentation deficiencies are what auditors pull first. The commonly referenced elements are:
- A health risk assessment completed by or with the patient
- Medical and family history, updated at each visit
- A current list of providers, suppliers, and prescriptions the patient uses
- Routine measurements — height, weight, body mass index, blood pressure, and other measurements deemed appropriate
- Detection of cognitive impairment through direct observation and information from patients, family, or caregivers
- Review of potential depression risk factors and functional ability and safety
- A written screening schedule covering the next five to ten years
- A list of identified risk factors and conditions, with interventions
- Personalized health advice and referrals to health education or preventive counseling
- Advance care planning, at the patient's discretion
Element specifics shift with the annual physician fee schedule. Confirm the current list against the CMS Medicare Wellness Visits education material before you rewrite a template, and put a named owner on that review each January.
Three Visit Types, Three Different Clocks
Practices track three distinct encounters, and mixing them up is the most common revenue and audit issue in this service line.
The Initial Preventive Physical Examination — the "Welcome to Medicare" visit — is available once in a lifetime and only within the first 12 months of Part B enrollment. Miss the window and it is gone permanently.
The initial annual wellness visit is also once in a lifetime, and it cannot occur within 12 months of the IPPE or within the patient's first 12 months of Part B coverage.
Subsequent annual wellness visits recur, but no more often than once every 12 months. Practices generally schedule on an 11-full-months-elapsed convention to avoid a denial when a patient shows up a day early.
Code selection is a documentation-driven determination made by the billing team and the rendering clinician together, based on the patient's coverage history and the elements actually performed and recorded. Your job as an administrator is to make sure the eligibility data reaching that decision is accurate — not to decide which code fits a given encounter.
The Eligibility Check Your Front Desk Runs Before the Recall Call
Verify eligibility before the outreach call, not after the patient is in the chair. The standard workflow is a Medicare eligibility inquiry that returns preventive service history, run against the patient's MBI at the point of scheduling.
Assign this to a specific role. In most practices it belongs to the scheduler or a dedicated eligibility coordinator, with a billing supervisor auditing a sample weekly. Log the date of the last wellness visit in a structured field, not a free-text note, so your recall report can filter on it.
The privacy angle: eligibility inquiries pull coverage and service history into your system, and that data is PHI the moment it lands. If a scheduler is running these from a personal laptop over a home network, you have a security rule problem that has nothing to do with Medicare rules. Confirm your remote-access controls cover schedulers, not only clinical users.
Who Collects the Health Risk Assessment — and Who Else Reads It
The health risk assessment is the element most likely to leave your building. Practices collect it three ways, and each carries a different exposure.
Patient portal or emailed link
Convenient, and it puts the drafting burden on the patient. It also means an HRA containing depression screening responses, fall history, and functional limitations sits in a vendor's environment. If that vendor is not your EHR publisher, it is a separate business associate with a separate agreement obligation.
Paper packet mailed in advance
Low tech, and it fails in predictable ways. Returned mail with a completed HRA inside is a disclosure to whoever picked it up. Track address verification at the point of scheduling and log returned mail as a potential incident for review, not as a scheduling nuisance.
Phone intake by staff
Fastest to control, hardest to staff. If your front desk conducts HRA calls from an open reception area, patients in the waiting room hear cognitive and depression screening questions about someone else. Move those calls to a closed room. Auditors have cited far less.
Whatever method you use, apply the minimum necessary standard to the internal routing. A scheduler does not need the completed depression risk section to book a follow-up.
The Vendor List Behind Your Wellness Visit Program
Sit down and write out every outside party that touches a wellness visit. Most practices are surprised by the length. A typical list:
- The HRA form platform, if it is separate from the EHR
- The outbound reminder service sending calls, texts, or emails
- A care-gap or population health tool identifying eligible patients
- A transcription or scribe service documenting the encounter
- The clearinghouse submitting the claim
- Any coding audit firm reviewing wellness visit documentation
- A shredding vendor destroying paper HRAs
- Health plan–contracted vendors requesting charts for risk adjustment or quality reporting
Every one of those that creates, receives, maintains, or transmits PHI on your behalf needs a business associate agreement in place before access begins. HHS publishes sample BAA provisions, but the sample is a starting point — it does not address breach notification timelines, subcontractor flow-down, or return-and-destruction terms in the detail most practices need.
If you are staring at three vendors with no executed agreement and no legal budget this quarter, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, and it gets the unsigned vendors off your list this week rather than next quarter.
The plan-contracted vendor question
Health plans routinely send vendors to request charts tied to wellness visits. Those requests are usually permissible disclosures for payment or health care operations, and a BAA between you and the plan's vendor is generally not what governs them — the plan's own obligations do.
That does not mean you hand over the full chart. Verify the requester's identity and authority, confirm the specific patients and date ranges, log the disclosure, and release only what the request supports. Write that verification step into your records-release procedure and name who performs it.
Documentation That Survives an Audit Without Creating Exposure
Auditors want to see each required element performed and recorded for the date of service. Templates help, but a template that auto-populates unperformed elements is worse than no template. Turn off defaults that assert an element was completed.
Three practical controls:
- A pre-signature checklist the clinical staff member completes, mapping each required element to a location in the note.
- A monthly internal sample — ten charts, reviewed by billing leadership against the current CMS element list, with findings logged.
- Version control on templates, so you can prove which element set was in effect on a given date of service.
The written screening schedule and personalized prevention plan go home with the patient. That is a deliberate disclosure to the patient, which is fine — but confirm the printout carries only that patient's information. Batch-printing plans and handing out the wrong one is a real incident category, and it is entirely preventable with a name-and-DOB verification at handoff.
The 30-Day Clock When a Wellness Visit Record Is Requested
Patients and their designees request wellness visit documentation more often than you would expect — usually to share the screening schedule with a specialist or a family caregiver. Under the HIPAA right of access, you have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
Fees are limited to a reasonable, cost-based amount. You cannot charge for retrieval or for the labor of searching. Review the OCR right of access guidance with whoever handles records requests, and confirm they know that a request to send records to a third party the patient designates is still an access request, not a general authorization.
Practical failure point: HRA responses collected in a third-party form platform sometimes never merge into the chart. If a patient requests "everything from my wellness visit" and the HRA lives only in a vendor portal, your 30-day clock is running against data you do not directly control. Fix the integration or stop using the separate platform.
Assigning the Workflow by Role
A wellness visit program falls apart when nobody owns the seams. A workable division:
- Scheduler: runs eligibility, confirms the 12-month interval, verifies mailing address, books the visit, sends the HRA.
- Clinical support staff: collects measurements, confirms medication and provider lists, completes the pre-signature element checklist.
- Rendering clinician: performs and documents the assessment elements, finalizes the personalized prevention plan.
- Billing lead: determines the appropriate code based on documented elements and coverage history, tracks denials by reason, escalates interval errors back to scheduling.
- Privacy officer: maintains the vendor and BAA inventory, reviews HRA collection methods annually, logs disclosures to plan-contracted requesters.
Put those five lines in your policy manual with names attached. When staff turns over, the seams are where the medicare wellness exam requirements quietly stop being met.
Four Things to Check This Month
First, pull your vendor inventory and flag every entry without an executed BAA and a documented execution date. Second, confirm your HRA collection path stores data somewhere you can produce it within 30 days. Third, verify that eligibility history is captured in a structured field your recall report can read. Fourth, listen to one HRA phone call from the waiting room and decide whether you would want that call to be about you.
Meeting the medicare wellness exam requirements is a documentation discipline. Protecting the information those visits generate is a separate discipline, and it is the one with civil penalties attached.
Next Step
Start with the gap you can close fastest. If your wellness visit program depends on vendors you have never papered, build the business associate agreements and get signatures moving — it is a one-time purchase and takes an afternoon, not a legal engagement. If the broader documentation set behind it is also thin, automated risk analysis and policy generation will get your written program current before your next payer audit or records request forces the issue.