87426 CPT Description: Practice Ops and Privacy Guide
Your front desk runs eighteen rapid antigen tests in a bad week, the analyzer syncs results to a manufacturer's cloud dashboard, and nobody in your office has read the terms of that dashboard since 2021. That is the practical problem behind the 87426 CPT description: a single lab code that touches your CLIA certificate, your claim edits, your vendor list, and your designated record set all at once. This guide is for the administrator, biller, or privacy officer who owns those four things. It covers what the code describes, how practices document code selection defensibly, and which privacy obligations attach the moment a result leaves the cartridge reader.
What the 87426 CPT Description Actually Says
CPT 87426 reads: Infectious agent antigen detection by immunoassay technique, qualitative or semiquantitative, multiple-step method; severe acute respiratory syndrome coronavirus (eg, SARS-CoV, SARS-CoV-2) [COVID-19].
Break that into the four elements your billers care about. Antigen detection — not nucleic acid amplification, not antibody. Immunoassay technique — the methodology family. Qualitative or semiquantitative — a positive/negative or graded read, not a numeric titer. Multiple-step method — the procedural characteristic that separates this code from the visually read, single-step antigen codes in the 878xx range.
That last element is the one that generates the most internal disagreement. The 87426 CPT description turns on how the assay is performed, not on how sick the patient is and not on which brand of kit sits in your supply closet. Your clinical staff determine the test performed; your coding staff match the performed test's methodology to the code descriptor and the manufacturer's package insert. Those are two different jobs and should stay that way.
Codes That Sit Next to It in the Same Family
Administrators should know the neighbors exist, without treating this as a decision tree:
- Direct optical (visual) observation antigen codes for SARS-CoV-2 — a different procedural characteristic.
- Multiplex antigen codes covering SARS-CoV-2 together with influenza A/B in a single immunoassay.
- Amplified probe / NAAT codes, which are a separate technology family entirely.
- Influenza and RSV antigen codes, used when a respiratory panel is run as discrete tests.
Build a one-page crosswalk that maps each test kit your practice stocks to the descriptor language in its package insert and the code your coding lead selected. Date it. Re-review it whenever purchasing switches vendors, because a supply substitution is a coding event, not just a procurement event.
Featured Answer: Who Can Bill 87426 and What Has to Be True First
Three conditions must be documented before a practice submits a claim using this code:
- A valid CLIA certificate covering the complexity of the test performed. Waived tests require at minimum a Certificate of Waiver; moderate-complexity performance requires the corresponding certificate and personnel qualifications.
- An order and a documented result in the chart. The order source, collection time, result, lot number, and the identity of the person who performed the test belong in the record.
- Code selection tied to the methodology performed, supported by the manufacturer's instructions for use and your internal crosswalk — not to the payer's fee schedule.
The QW modifier is the administrative flag many payers require when a waived test is performed under a Certificate of Waiver. CMS maintains the list of tests granted waived status; your billing lead should check that list against your kit's catalog number rather than assuming. Payer policies vary on whether the modifier is required, optional, or rejected, so your claim scrubber rules need to be payer-specific.
The CLIA Layer Most Practices Underbuild
A Certificate of Waiver is not a coding footnote. It is a federal enrollment that carries recordkeeping duties, and inspectors do sample waived sites. Keep the certificate number, effective dates, and the name of the certificate holder in the same binder as your coding crosswalk, and set a renewal reminder ninety days out.
Your waived-testing log should capture kit lot, expiration date, control results, room temperature where required, operator initials, and patient identifier. Retention follows your state's lab record rules and your payer contracts, whichever is longer. CMS publishes the governing framework under the Clinical Laboratory Improvement Amendments program, and your state agency may layer additional requirements on top.
Assign the Roles in Writing
- Clinical lead: owns competency documentation for every person who touches a cartridge.
- Practice administrator: owns the CLIA certificate lifecycle and the analyzer inventory.
- Billing lead: owns the code crosswalk, modifier logic, and payer-policy monitoring.
- Privacy officer: owns the vendor list, the BAAs, and the result-delivery workflow.
When one person holds all four hats — common in a five-provider practice — write the hats down anyway. The audit question is never "who did it," it is "who was supposed to."
Where the 87426 CPT Description Becomes a Privacy Problem
Here is the part that gets skipped. A rapid antigen result is protected health information from the second it is associated with a patient identifier. The 87426 CPT description says nothing about privacy — but every operational step that produces a claim under it creates a disclosure pathway.
Map yours. In most practices it looks like this:
- Front desk registers the patient and creates the encounter.
- MA collects the specimen and runs it on a connected reader.
- The reader transmits result plus patient identifier to a manufacturer-hosted dashboard or middleware layer.
- Middleware pushes a discrete result into the EHR via an interface.
- The result is released to the patient portal, or texted, or read over the phone.
- The charge drops to your billing system and out through a clearinghouse.
- If applicable, the result flows to a state or local public health reporting endpoint.
That is seven hops. Each hop involving an outside organization that creates, receives, maintains, or transmits PHI on your behalf requires a business associate agreement. Count how many you have signed. In most walkthroughs I have run, the answer is fewer than the number of hops.
The Connected Analyzer Is the Usual Gap
Practices reliably have BAAs with their EHR vendor and clearinghouse. They reliably do not have one with the diagnostic manufacturer whose cloud portal stores every result the reader has produced since installation. The device was bought through supply procurement, the portal login was set up by a rep, and no one routed it through the privacy officer.
If a vendor's platform holds identifiable results, that vendor is a business associate. If you are missing that paper, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription — then send it to the manufacturer's contracting contact with your device serial numbers attached. Do this before your next risk analysis, not after.
De-identified Dashboards Are Not Automatically Safe
Several manufacturers offer analytics dashboards that aggregate positivity rates across sites. Ask, in writing, whether the aggregation happens before or after identifiers are stripped, and whether de-identification meets the Safe Harbor or expert determination standard. "We only show trends" is a marketing statement, not a contractual one. If the underlying store holds identifiers, the BAA governs it regardless of what the dashboard displays.
Public Health Reporting Without Over-Disclosing
HIPAA permits disclosure to public health authorities authorized to collect the information, without patient authorization. The pandemic-era federal laboratory reporting mandate tied to the public health emergency is no longer in force, but state and local reporting requirements did not all disappear with it. Confirm what your state health department currently requires for SARS-CoV-2 antigen results and document the answer with a date and a source.
Two operational cautions. First, apply minimum necessary to the data elements you transmit — send the fields the reporting specification asks for, not a full chart dump. Second, if an HIE or reporting intermediary sits between you and the health department, that intermediary is a business associate even though the ultimate disclosure is a permitted public health disclosure. The permission covers the destination, not the middleman.
Result Delivery: Texting, Portals, and the Complaint You Will Get
Antigen results are fast, which tempts staff into fast delivery channels. A patient may request results by unencrypted text or email, and you may honor that request after warning them of the risk and documenting both the warning and the request. What you cannot do is make unencrypted texting your default because it is convenient at the front desk.
Write the script. Put it on the registration form as a checkbox with a date. Train the MAs that a verbal "just text it to me" gets logged in the chart, not acted on from memory. And keep the delivery preference at the patient level in your practice management system so a temp at the desk does not guess.
The Records Request That Arrives Three Months Later
Antigen results are part of the designated record set. When a patient — or an employer with a valid authorization, or an attorney — requests them, the HIPAA right of access clock applies: thirty days, with one thirty-day extension and written notice. HHS guidance on the individual right of access is the authority your staff should be trained against, and it is the enforcement area OCR has pursued most consistently.
Practical trap: if the result lives only on the manufacturer's cloud dashboard and never made it into the EHR as a discrete value, your records clerk cannot produce it from your system. Test this. Ask your clerk to retrieve a specific antigen result from six months ago using only the EHR. If they have to log into a vendor portal, your interface is incomplete and your access workflow is fragile.
Billing Hygiene That Survives a Payer Audit
Coverage for SARS-CoV-2 testing changed substantially after the public health emergency ended, and it now varies by payer, plan, and indication. Employment screening, travel clearance, and return-to-work testing are frequently non-covered. Build the financial conversation into intake rather than into collections.
- Medicare non-covered scenarios: use your ABN process and retain the signed form with the encounter.
- Commercial plans: verify benefits by indication, not just by code, and keep the reference number.
- Self-pay: publish the cash price and honor it consistently; inconsistent pricing draws attention from more than one regulator.
- Duplicate-charge risk: if a rapid antigen and a send-out molecular test are both performed, confirm your charge capture is not auto-dropping both from one order.
Marketing language matters too. If your website advertises testing, the claims you make about accuracy and turnaround are subject to the FTC's health privacy and advertising expectations — and any tracking pixel on that page is a separate disclosure issue your privacy officer should have already reviewed.
A 45-Minute Internal Review You Can Run This Week
- Pull your CLIA certificate. Confirm type, number, expiration, and holder name.
- List every antigen test kit in inventory with catalog number and package insert on file.
- Ask your billing lead to show the crosswalk mapping each kit to a code and modifier rule, with a revision date.
- Walk to the analyzer. Note the manufacturer, model, and whether it is network-connected.
- Search your BAA folder for that manufacturer. If absent, start the agreement today.
- Have a records clerk retrieve one antigen result from the EHR alone.
- Confirm your current state reporting requirement in writing, with a date.
Every item that fails becomes a finding in your next risk analysis. If your risk analysis, policies, and supporting document set are still living in a spreadsheet someone built in 2022, automating the compliance document set is a faster path than rebuilding it by hand each year.
The 87426 CPT description is a lab descriptor. The obligations it drags behind it are yours — the certificate, the log, the interface, the BAA, and the thirty-day clock. Close the vendor gap first, because it is the one that shows up in a breach notification rather than a claim denial. Draft the missing business associate agreement and get it in front of your analyzer vendor this week.