87636 CPT Code Description: Practice Operations Guide
It's 4:40 on a Friday in late March. Your medical assistant runs a combination respiratory panel on the analyzer behind the nurses' station, the result posts fourteen minutes later, and by Monday that single cartridge has generated a claim line, an EHR lab entry, a patient-portal notification, a state public health transmission, and a log entry in a device manufacturer's cloud portal. The 87636 CPT code description is what ties the billing side of that chain together — and the rest of the chain is a privacy problem your practice owns.
This guide is for the administrator, biller, or privacy officer who has to make all five of those downstream events defensible. It covers what the code descriptor actually says, how practices decide whether an assay maps to it, the modifier question that drives most denials, and which vendors along the results path require a Business Associate Agreement.
What Is the 87636 CPT Code Description?
CPT 87636 is defined as infectious agent detection by nucleic acid (DNA or RNA), for severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2, the virus that causes COVID-19) and influenza virus types A and B, using a multiplex amplified probe technique. In administrative terms: one molecular test, one specimen, three targets reported together.
Two neighbors matter for your fee schedule build. 87635 describes SARS-CoV-2 alone by amplified probe technique. 87637 describes the same multiplex concept with respiratory syncytial virus added to the SARS-CoV-2 and influenza A/B targets. Antigen-based testing sits in an entirely different family of codes and is not interchangeable with the nucleic-acid descriptors.
Your coding staff does not choose among these based on what the visit felt like. They choose based on the assay actually performed, the targets the assay reports, and the method the manufacturer's package insert documents. That mapping is a written policy decision, not a per-encounter judgment call.
How Practices Actually Document the Mapping
Build a one-page assay crosswalk and keep it under version control. For each analyzer and cartridge in the building, record: manufacturer, assay name, targets reported, method (amplified probe, multiplex or single), CLIA complexity category, the code your policy assigns, and the effective date. Have the lab director or supervising clinician sign it.
When a manufacturer changes a cartridge configuration or you swap platforms, the crosswalk gets a new row and a new effective date — it does not get overwritten. Auditors ask what you were billing in a specific month, and an overwritten spreadsheet cannot answer that.
Note also that some named commercial assays are described by Proprietary Laboratory Analyses codes rather than the general descriptors. Your crosswalk is where that gets caught, before a year of claims goes out under the wrong line.
The Modifier QW Question That Drives Most Denials
If your practice holds a CLIA certificate of waiver or a certificate of compliance and runs waived-complexity testing, claims for many waived tests must carry modifier QW. Whether a specific multiplex respiratory assay requires it depends on that assay's waived status, not on the code number in the abstract.
CMS maintains the authoritative list of tests granted waived status under CLIA, and it updates on a rolling basis. Assign one person — usually the billing lead — to check it quarterly against your crosswalk and initial the check. Start from the CMS Clinical Laboratory Improvement Amendments resources.
Two more operational items belong in the same quarterly review:
- Certificate scope. Your CLIA certificate type has to cover the complexity of every assay on the crosswalk. A platform upgrade can quietly push you past your certificate.
- Unbundling edits. A multiplex assay reported under a combined descriptor is one line. Confirm your practice management system cannot fire the single-target codes alongside it, and confirm payer policy and NCCI edits before appealing a bundling denial.
Also verify the ordering provider's name, NPI, and the diagnosis coding are captured at the point of order rather than reconstructed at the point of claim. Reconstruction is where documentation audits find their easiest findings.
Everyone Who Touches the Result Between Cartridge and Clearinghouse
Draw this before you argue about it. For a single in-office multiplex respiratory test, the typical path runs:
- Front desk registers the patient and captures insurance — PHI created.
- Clinical staff orders the test in the EHR; the order carries patient identifiers.
- The analyzer runs the specimen. Many modern analyzers hold patient identifiers locally and sync to a manufacturer-hosted portal.
- A middleware or interface vendor moves the result into the chart.
- The result posts to the patient portal, often automatically.
- A reportable-condition message goes to the state or local public health authority.
- The charge drops to billing; the claim moves through a clearinghouse to the payer.
- Denials route to an outsourced follow-up team, if you use one.
That is eight handoffs and, in most practices, four to six separate organizations holding identifiable data. Your Notice of Privacy Practices, your security risk analysis, and your vendor inventory all need to reflect the same eight steps. If your risk analysis was written before you brought molecular point-of-care testing in-house, it is out of date.
Which of Those Vendors Needs a BAA — and Which Doesn't
This is where practices get it backward in both directions. Work through it deliberately.
Business associates
The analyzer manufacturer, if its cloud portal stores or transmits identifiable results. The interface or middleware vendor. Your clearinghouse. Your billing company or outsourced denial-follow-up team. Your IT managed service provider, if it can reach systems holding PHI. Any patient-communication vendor that texts or emails results notifications. Each of these performs a function on your behalf that involves PHI, and each needs a signed agreement on file with a current date and a named contact.
Not business associates
A reference laboratory you send specimens to for treatment purposes is itself a covered entity, and a disclosure to it for treatment does not require a BAA. Neither does a required disclosure to a public health authority. Neither does the payer you bill, which is a covered entity receiving the claim for payment purposes. Chasing agreements you don't need wastes the same hours you should be spending on the ones you're missing.
Where practices get caught: the analyzer vendor. A device sold as a standalone instrument two years ago now ships with a connectivity module and a support technician who can remote into the console. That relationship changed; the paperwork usually didn't. Review HHS guidance on the provisions a BAA must contain before you accept a vendor's one-page addendum.
If your review turns up two or three vendors with no agreement or an agreement signed under an older rule set, you need signature-ready documents this week, not next quarter. A guided Business Associate Agreement generator walks through the six decisions that actually vary between vendors — subcontractor flow-down, breach notification timing, return-or-destruction at termination — and exports PDF and DOCX for signature. One-time purchase, which matters when you need four agreements once rather than a subscription forever.
Public Health Reporting After the PHE Ended
The federal COVID-19 public health emergency ended in May 2023, and the reporting mandates that rode on it ended with it. State and local reporting obligations did not. Influenza and novel coronavirus reporting requirements vary by jurisdiction, and multi-state practices frequently have different obligations per location.
HIPAA permits disclosure to a public health authority authorized by law to collect the information. That permission is not a blanket license — the disclosure has to be to the right authority, in the required format, limited to what the law requires. Document the statutory or regulatory citation for each jurisdiction you report into, and keep it with your disclosure accounting procedures.
The enforcement-discretion notifications HHS issued during the emergency, including the one covering community-based testing sites, have expired. Practices still relying on workflows built under those notifications are operating without the cover they think they have.
You Cannot Sit on a Positive Result
The information blocking rules treat laboratory results as electronic health information subject to access, exchange, and use requirements. A blanket policy that holds all results for 72 hours so a clinician can call first is the exact practice that draws an information blocking complaint.
The permitted exceptions are narrow and require documentation applied case by case — not a global portal setting. If your practice has a delay configured, know which exception you are claiming and have it in writing. The ONC information blocking resources lay out the exception framework.
Run this as a specific test: ask your EHR administrator to show you the current portal release rule for lab results, in the interface, today. Most administrators discover the setting does not match the policy binder.
The Records Request Side
Patients have a right to their completed test reports directly from the practice, and under the CLIA privacy rule amendments, from the performing laboratory as well. Your standard right-of-access clock applies: 30 days, with one 30-day extension available if you notify the patient in writing with a reason. HHS keeps detailed right-of-access guidance that your records staff should have read, not skimmed.
Two operational rules that prevent most access complaints. First, a pending balance never gates a records release. Second, when a request arrives for "my COVID and flu test," the responsive record is the report itself, not a summary letter your front desk typed.
A Worked Denial, Start to Finish
A commercial payer denies a claim carrying the multiplex respiratory line as "not separately payable." Here is the sequence that resolves it without a phone call marathon.
Pull the assay crosswalk row in effect on the date of service. Confirm which descriptor the assay maps to and whether the claim carried the required modifier for your CLIA status. Pull the payer's published lab policy for that date — not the current version. Compare the denial reason to the policy language.
If the payer bundled a multiplex line into a same-day component code, the fix is usually an edit in your practice management system that fired both. If the payer requires the QW modifier and it was absent, that is a corrected claim, not an appeal. If the payer's policy genuinely excludes the service, that is a contract conversation for your next renewal, and you document the decision rather than rebilling monthly.
Track denial reasons for this code family in a monthly report. Three denials from the same payer for the same reason is a configuration problem in your system, not bad luck.
Your Next 30 Days
Do four things. Rebuild the assay crosswalk with signatures and effective dates. Reconcile your vendor inventory against the eight-step results path and close every BAA gap. Verify the portal release setting in the interface. Confirm your state reporting obligations per location with a citation.
If the third item you check is a security risk analysis that predates your point-of-care molecular testing, that document needs a rewrite too — automated risk analysis and policy generation gets you a current document set faster than a consultant's calendar allows. Understanding the 87636 CPT code description is the billing half of this. Controlling where that result travels afterward is the half that shows up in enforcement.