Your medical assistant runs six respiratory antigen tests before lunch. Two get billed, one gets held for a prior authorization question, and three end up on a claim with a modifier nobody at the front desk can explain. That is the moment the 87426 CPT code stops being a lab issue and becomes your issue.

This guide is written for practice administrators, billing leads, and privacy officers who own the antigen testing workflow end to end. It covers what the code describes, how your practice verifies it can legitimately bill for the testing it performs, and the specific privacy, records-handling, and vendor obligations that follow the specimen from the counter to the clearinghouse. It is administrative guidance, not clinical or coding advice for any particular patient encounter.

What the 87426 CPT Code Describes

In the CPT microbiology section, 87426 is defined as infectious agent antigen detection by immunoassay technique, qualitative or semiquantitative, multiple-step method, for severe acute respiratory syndrome coronavirus (including SARS-CoV-2). The operative phrase for your workflow is multiple-step method.

That phrase describes how the test is performed on the bench, not how sick the patient is and not which brand of kit sits in your supply closet. Multiple-step immunoassays typically involve discrete reagent additions, incubation, and instrument-based reading. Your practice does not choose the code by preference; the method your staff actually performs and documents drives which code your coding team assigns.

Is 87426 the same as 87811?

No. Both codes cover SARS-CoV-2 antigen detection by immunoassay, but they describe different methods. 87426 describes a multiple-step method. 87811 describes a single-step method with direct optical observation, which is the category most familiar point-of-care cassette tests fall into. Practices determine which code applies by comparing the manufacturer's instructions for use and the documented bench procedure against the CPT descriptors, then document that determination in a written coding policy so every biller applies it the same way. Billing both for the same specimen, or defaulting to whichever pays more, is exactly the pattern payer audits are built to find.

The CLIA Question That Comes Before the Billing Question

Before your billing team touches a single claim, someone in your practice needs to answer a narrower question: does your CLIA certificate permit the testing you just performed?

Every FDA-cleared or authorized test is assigned a complexity categorization — waived, moderate, or high. Tests billed under the 87426 CPT code are frequently not waived, which means a practice holding only a Certificate of Waiver cannot lawfully perform them, regardless of how the claim is coded. Verify the categorization for the specific test system you have on the bench, by manufacturer and model, and keep that verification in the same binder as your CLIA certificate.

If your practice is certified for moderate complexity testing, the obligations widen: a designated laboratory director, documented personnel qualifications and competency assessments, proficiency testing enrollment where required, quality control records, and biennial survey readiness. CMS maintains the program overview and certificate information on its Clinical Laboratory Improvement Amendments page. Add state clinical laboratory licensure on top, because several states impose requirements beyond federal CLIA.

The QW modifier trap

The QW modifier signals that a test was performed under a CLIA Certificate of Waiver. It applies only to tests CMS has published on its list of waived tests. If your billing software appends QW by habit because a previous point-of-care code required it, you are asserting a certificate scope you may not have. Have your billing lead pull a report of every claim line carrying QW for the last 12 months and reconcile it against your actual certificate and the CMS waived test list. Budget an hour. It is the cheapest audit you will run this quarter.

How Your Coding Team Documents Code Selection for 87426 Claims

Code selection is a documentation exercise, not a judgment call made at the front desk. Build the sequence into your standard operating procedure:

  1. Order and reason. The ordering provider documents the clinical reason for the test in the chart. Coders derive the diagnosis code from that documentation — never from a dropdown that a scheduler picked at check-in.
  2. Method verification. The bench log or instrument record establishes what method was performed, which supports the CPT code your coder assigns.
  3. Payer policy check. Coverage for respiratory antigen testing varies by payer, plan, and place of service. The federal cost-sharing waivers tied to the COVID-19 public health emergency ended in 2023, so testing is now adjudicated under ordinary plan benefits, deductibles, and medical necessity policies.
  4. Patient financial notice. If a test is likely to be non-covered — screening without a documented indication, for example — your intake staff should follow your written advance notice process before the specimen is collected, not after the denial arrives.
  5. Payment amounts. Medicare pays clinical diagnostic laboratory tests under the Clinical Laboratory Fee Schedule. Pull current rates directly from CMS rather than trusting a spreadsheet a vendor emailed you two years ago.

Write all five steps down. When a payer requests records for a batch of 87426 CPT code claims, the response quality depends entirely on whether these artifacts exist in the chart, not on how confident your coder sounds on the phone.

Map Every Vendor That Touches an Antigen Result

Here is where administrators consistently under-scope. A single in-house antigen test can generate protected health information in six or seven systems, several of which nobody put on the vendor list.

  • The analyzer itself. Modern bench instruments phone home. If the manufacturer's cloud dashboard stores patient identifiers, result values, or accession numbers, that manufacturer is a business associate and needs a signed agreement.
  • Remote support access. Field service engineers who screen-share into a networked analyzer are reaching PHI. Log the sessions, restrict the accounts, and confirm the agreement covers it.
  • Middleware and interface vendors. Anything translating instrument output into your record system holds PHI in transit and often in a queue.
  • Reference laboratory. When specimens go out because your certificate does not cover the test, the reference lab is typically a separate covered entity — but your courier, requisition portal, and result-delivery channel each need their own analysis.
  • Clearinghouse and billing service. Claim lines carrying diagnosis codes reveal test results by inference. Minimum necessary applies to claims data too.
  • Patient communication tools. Portal, secure messaging, texting platform, automated call service.

Adding a new analyzer or a new cloud dashboard changes your technical environment, which means your Security Rule risk analysis is now out of date. That analysis has to be accurate and current — it is the one document OCR asks for first in nearly every investigation, and "we did one in 2021" is not a defense. If yours has not been refreshed since your testing footprint changed, you can generate an updated risk analysis and matching policy set in far less time than rebuilding it in a spreadsheet. And when a new instrument vendor turns out to be a business associate you never papered, a signature-ready business associate agreement closes the gap the same day rather than the same quarter.

Public Health Reporting Is Permitted — and Accountable

Reportable condition rules are set by your state and local public health authorities, and respiratory pathogen reporting requirements have shifted repeatedly since 2023. Confirm your current obligations with your state health department in writing, and note which tests, which result values, and which turnaround times apply.

On the HIPAA side, disclosures to a public health authority authorized by law to collect the information are permitted without patient authorization. HHS explains the parameters in its guidance on disclosures for public health activities.

Two operational consequences your privacy officer owns. First, public health disclosures are not treatment, payment, or health care operations, so they are generally accountable disclosures — if a patient requests an accounting, these need to appear in it. Second, that means you need a log. If your reporting happens through an automated electronic case reporting interface, confirm the interface produces a retrievable record of what was sent and when, because a patient request six months later will not be satisfied by a vendor's assurance that transmission occurred.

Employer- and School-Sponsored Testing Changes the Rules

If your practice tests employees for a local employer and reports results back to that employer, you have left ordinary clinical billing and entered occupational health. Results going to an employer generally require a valid patient authorization, unless the narrow workplace medical surveillance provision applies — and that provision carries its own written notice requirement to the individual.

Practical safeguards: use a separate authorization form specific to employer disclosure, limit what you send to the minimum the employer is entitled to receive, and make sure your staff cannot accidentally attach a full chart summary to a workplace results roster. Train the front desk on what to say when an HR manager calls asking for a name and a result. "I can't confirm or deny that" is a complete sentence.

Results Delivery, the 30-Day Clock, and the Text-Message Question

A patient who asks for their test results has exercised the right of access, and your practice generally has 30 days to respond, with one 30-day extension available under limited conditions. HHS maintains the detailed individual right of access guidance, including the rules on fees and on providing records in the form and format requested.

Patients may request delivery by unencrypted email or text. You can honor that request, but document that you warned them of the risk and that they chose to proceed anyway. What you cannot do is treat unencrypted channels as your default. The pandemic-era enforcement discretion that once covered certain remote communication technologies expired in 2023; there is no leftover flexibility to lean on in 2026.

One more failure mode worth naming: negative results announced in a crowded waiting room. Reasonable safeguards on incidental disclosure apply to a hallway just as much as to a firewall.

A Two-Week Cleanup for Your 87426 Workflow

  1. Days 1–2 (lab lead): Document the manufacturer, model, and CLIA complexity categorization for every antigen test system in the building. Compare against your certificate.
  2. Days 3–4 (billing lead): Run a 12-month claim report for the 87426 CPT code and its single-step counterpart. Reconcile modifier usage and flag any line that does not match your certificate scope.
  3. Day 5 (compliance officer): Write or update the one-page coding policy that states how method-based code selection is determined and documented.
  4. Days 6–8 (privacy officer): Walk the physical path of a specimen and list every system and person that sees an identifier. Cross-check against your business associate register.
  5. Day 9 (IT or vendor manager): Confirm remote-support accounts on networked analyzers are named, logged, and disabled when not in use.
  6. Days 10–12 (compliance officer): Refresh the Security Rule risk analysis to include the testing systems you just inventoried, and update policies that reference outdated pandemic-era flexibilities.
  7. Day 13 (practice manager): Train the front desk on results release, employer requests, and the accounting-of-disclosures log.
  8. Day 14 (administrator): Sign off, date the file, and calendar the next review.

Two weeks of structured work converts a fuzzy testing workflow into a defensible one. Note also that HHS proposed significant updates to the Security Rule in early 2025; whatever the final shape, the direction of travel is toward more documentation of asset inventories and vendor oversight, not less. Practices that already maintain a current inventory will adapt quickly.

Do This Next

Pull your CLIA certificate and your business associate register, put them side by side with the analyzer list from step one, and see how many gaps appear. If the exercise surfaces a stale risk analysis or missing policies — and it usually does — build the current document set for your practice and get the paperwork caught up to the testing you are already performing and billing.