Your scheduler blocked forty appointments for April and labeled them "AWV." Twelve of those patients will fill out a health risk assessment on a tablet supplied by a vendor you have never met. Four will screen positive for food insecurity, and someone at your front desk will have to decide whether faxing that to a community pantry is a permitted disclosure. Two will call in June asking for a copy of "the plan the doctor printed out," and your 30-day clock starts the moment they ask.

That is the real shape of a medicare wellness program: a modest amount of clinical activity wrapped in an unusually heavy layer of data collection, third-party tooling, and records obligations. This guide is written for the administrator, biller, or privacy officer who has to make the workflow run without generating a breach report or a failed audit. It covers eligibility mechanics, documentation, vendor contracting, and the disclosure decisions your staff will face every week.

What a Medicare Wellness Visit Is — and What It Isn't

A Medicare wellness visit is a preventive benefit under Part B built around a health risk assessment, a review of history and risk factors, routine measurements, cognitive screening, and a written personalized prevention plan with a schedule of recommended screenings. It is not a head-to-toe physical exam. Medicare does not cover a routine annual physical, and the wellness benefit does not become one because the patient calls it that.

Three distinct visit types sit under the umbrella, and CMS defines each separately: the Initial Preventive Physical Examination available in the first 12 months of Part B enrollment, the initial annual wellness visit available after that first year, and subsequent annual wellness visits. Each has its own HCPCS code family and its own frequency limits. Your billing staff determine which applies by checking enrollment dates and prior utilization — not by asking the patient what they had last year.

CMS publishes the element-by-element requirements in its Medicare Wellness Visits educational tool. Print it. Give it to whoever builds your visit template.

The Eligibility Check Your Scheduler Runs Before the Appointment

Frequency denials are the single most common financial failure in a medicare wellness program, and they are almost always preventable at scheduling.

Build the check into the booking script. Before the appointment is confirmed, someone verifies the patient's Part B effective date and the date of any prior wellness visit through your Medicare Administrative Contractor's provider portal or the eligibility transaction in your practice management system. A visit performed one day short of the frequency window denies in full, and the patient — who was told the service carries no coinsurance — receives a bill.

Assign the check to a named role, not a department

"Front desk verifies eligibility" is not a control. Name the person, name the backup, and log the verification date in the appointment note. When the denial arrives eight weeks later, you need to know who checked and what the portal returned.

Many practices issue a voluntary Advance Beneficiary Notice when a patient insists on proceeding outside the frequency window. Voluntary ABNs do not shift liability the way mandatory ones do, but they document that the patient was told. Decide your policy in writing so the front desk is not improvising.

When additional work happens in the same encounter

Providers frequently address an unrelated problem during a wellness visit. Whether that supports a separately reportable evaluation and management service is a documentation question your coding staff evaluate against payer rules and the medical record — the note has to stand on its own for the problem-oriented work. What administrators need to control is the patient conversation: the wellness portion carries no cost sharing, the separately billed portion generally does. Script that disclosure at check-in, not at checkout.

The Health Risk Assessment Is Where Your Privacy Exposure Lives

The HRA is a required element, and it is also the densest concentration of sensitive data your practice collects outside of a behavioral health note. Depression screening, alcohol use, fall history, cognitive function, functional ability, home safety, caregiver status. In a single form.

Most practices no longer collect it on paper. They use a portal questionnaire, a texted pre-visit link, a lobby tablet, or a standalone HRA platform that pushes a PDF into the chart. Every one of those paths involves a vendor creating, receiving, maintaining, or transmitting protected health information on your behalf. Every one of those vendors is a business associate under 45 CFR 160.103.

Three vendor categories that get missed

  • Pre-visit texting and reminder platforms that carry the HRA link and the patient's name and appointment type.
  • Tablet and kiosk providers where the device caches responses locally before sync — ask where the cache lives and how it is wiped between patients.
  • Turnkey wellness-visit staffing companies that supply a remote nurse or health coach to conduct the visit by video. They touch the entire record, and they are frequently onboarded by a physician-owner without the privacy officer ever seeing the contract.

HHS is explicit that the agreement must be in place before the vendor handles PHI, and it specifies what the contract has to require — permitted uses, safeguards, subcontractor flow-down, breach reporting, and return or destruction at termination. Review the HHS business associate guidance against what your vendors actually signed. If you find a gap, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, which matters when you are papering five vendors at once rather than buying a platform.

SDOH Screening, Community Referrals, and the Authorization Question

CMS added an optional social determinants of health risk assessment element to the annual wellness visit, with its own HCPCS code, and many practices adopted it because the downstream referrals are the point. Screening a patient for transportation barriers only helps if someone acts on the answer.

Here is the operational trap. A food bank, a housing agency, a rideshare program, and a legal aid clinic are generally not covered entities and generally not your business associates. The treatment disclosure permission that lets you send records to a specialist does not automatically extend to a community-based organization that provides no health care.

Your privacy officer should make a written determination for each referral partner and, in most cases, obtain a patient authorization before sending anything beyond what the patient personally chooses to share. A practical middle path many practices use: give the patient the referral information and let them make the contact, and document that you did. That converts a disclosure decision into a patient decision.

If a referral partner does perform a function on your behalf — care coordination software, a closed-loop referral network — that is a business associate relationship and needs the agreement.

Documentation That Survives an Audit and a Records Request

The written personalized prevention plan is not a byproduct. It is a required deliverable, it goes to the patient, and it becomes part of your designated record set.

That means when a patient asks for it — or asks you to send it to their daughter, their attorney, or a second-opinion physician — you are working under the right of access rules. You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS maintains the operative guidance on the individual right of access, and access failures have been a persistent enforcement theme.

The retrieval problem nobody plans for

If your HRA lives in a vendor portal and only a summary PDF lands in the chart, your records staff cannot produce the full designated record set without logging into a third-party system. Test this. Ask your health information custodian to produce a complete wellness visit record for a real patient and time it. If it takes three systems and two phone calls, fix the integration or change the vendor — the 30-day clock does not pause for architecture.

Build a retention rule too. Medicare record retention expectations and your state's medical record statute rarely match, and the longer period governs. Write the number down in your policy rather than leaving it to whoever manages the archive.

Outreach Campaigns: Where Tracking and Marketing Rules Bite

Wellness visit recall campaigns are standard. A list of Part B patients due for an annual visit gets loaded into a texting platform or a mail vendor, and the campaign runs.

Two things to control. First, communications that encourage a patient to use your own preventive services are treatment or health care operations, not marketing — unless a third party pays you to make the communication and it promotes that third party's product or service. If a plan or a supplier is funding your outreach, route the arrangement through counsel before the first text goes out.

Second, the "Schedule Your Medicare Wellness Visit" landing page on your website. Analytics and advertising tags on pages where patients identify themselves or book appointments have drawn sustained regulatory attention; HHS OCR published guidance on online tracking technologies, portions of which were narrowed by a federal court in 2024, and the FTC has separately pursued health data cases outside HIPAA entirely. Have your marketing contact list every tag on your scheduling pages and confirm what each one transmits. Most administrators discover at least one tag they did not authorize.

A 30-Day Cleanup Plan

  1. Days 1–5. Practice manager lists every system, device, and outside party that touches wellness visit data — including the tablet vendor and the transcription service.
  2. Days 6–12. Privacy officer matches each entry to a signed, current BAA. Flag anything missing, unsigned, or predating your last vendor change.
  3. Days 13–18. Billing lead documents the eligibility verification workflow with named owners and adds the verification field to the appointment template.
  4. Days 19–24. Records custodian runs the retrieval test and writes the SDOH referral disclosure policy.
  5. Days 25–30. Train front desk on the cost-sharing script and the referral policy. Log the training.

None of this requires new headcount. It requires someone to own the list and refuse to let a new vendor onto it without paperwork.

Start With the Vendor List

The medicare wellness benefit will keep pulling third parties into your data flow — assessment tools, remote staffing, referral networks, recall platforms. The compliance work is not the visit. It is the contracting discipline around it.

If you found gaps in step two, draft the missing agreements now rather than at renewal. And if your broader documentation set — risk analysis, policies, workforce training records — has not been refreshed since your last vendor turnover, automating the compliance document set is a reasonable next step once the BAAs are signed.