87637 CPT Code Description: Billing and Privacy Ops
A patient walks into your urgent care in mid-March with a fever. Your MA collects one nasal swab, runs it on the point-of-care analyzer in the back room, and forty minutes later you have three answers from one specimen. That single swab now generates one claim line, one result release, one probable public health report, and contact with at least four outside vendors. The 87637 CPT code description covers the test itself — but the operational and privacy exposure starts the moment the specimen is labeled.
This guide is for the person who owns the claim, the requisition, and the vendor list: practice administrators, billing leads, and privacy officers. It covers what 87637 describes, how practices document code selection, and where the records-handling risk actually sits.
What Is the 87637 CPT Code Description?
CPT 87637 describes infectious agent detection by nucleic acid (DNA or RNA) for SARS-CoV-2, influenza virus types A and B, and respiratory syncytial virus, performed by multiplex amplified probe technique. In plain administrative terms: one molecular test, one specimen, three targets (four if you count flu A and B separately), reported as a single code rather than as separate single-target codes.
It took effect January 1, 2021, alongside its two-target sibling 87636 (SARS-CoV-2 and influenza A/B, molecular). It is a laboratory code priced through the Clinical Laboratory Fee Schedule, with no separately reportable professional interpretation component. Most payers expect it once per specimen, per date of service.
How 87636, 87637, and 87428 Sit Differently on Your Fee Schedule
Your billing staff should be able to state the difference between these three without opening a book, because mis-mapping them in the charge master is the most common source of downstream denials on respiratory panels.
- 87636 — molecular multiplex, SARS-CoV-2 plus influenza A and B.
- 87637 — molecular multiplex, SARS-CoV-2 plus influenza A and B plus RSV.
- 87428 — antigen immunoassay multiplex, SARS-CoV-2 plus influenza A and B. A different methodology entirely.
The distinction is methodology and target count, not clinical judgment. Your job as an administrator is to make sure each analyzer and each send-out test in your catalog is mapped to the code that matches the manufacturer's stated method and target list — and that the mapping is documented, dated, and re-verified when a device or reference lab changes.
How Practices Determine and Document Code Selection
Code selection for a multiplex panel is a documentation exercise, not a guess. Here is the workflow that survives an audit.
- Source document. Pull the manufacturer's package insert or the reference lab's test directory entry. It states the method (amplified probe, multiplex) and the exact organisms detected.
- Charge master entry. Your billing lead maps that specific test name and catalog number to one CPT code, with a note citing the source document and the date reviewed.
- Order-to-charge match. The order in the chart, the requisition, and the charge must all name the same test. If a provider orders "respiratory panel" and your system auto-drops a code, someone needs to own the audit that confirms the drop is correct.
- Result record. The report retained in the chart should show every target reported, which substantiates the multiplex code you billed.
- Annual re-verification. Devices get replaced. Reference labs change platforms. Put a calendar item on your compliance lead in Q4 to re-walk the mapping.
Note what is not on that list: any judgment about whether a three-target panel was appropriate for a given patient. That is the ordering clinician's decision, documented in the chart. Your role is to bill what was ordered and performed, and to escalate through your compliance channel if the pattern of ordering looks like it needs clinical review.
The QW Modifier and Your CLIA Certificate Scope
Two separate questions, and staff conflate them constantly.
First: does your site hold a CLIA certificate that authorizes the complexity of the test being run? A Certificate of Waiver covers only tests granted waived status. A Certificate of Provider-Performed Microscopy does not extend to molecular assays. If you are running a moderate-complexity multiplex platform, you need the certificate that matches.
Second: does the payer require the QW modifier on the claim? For Medicare, tests granted waived status and performed under a Certificate of Waiver generally require QW appended, and CMS publishes updates to the list of waived tests through its transmittals and MLN articles. Some specific point-of-care multiplex molecular devices appear on that list; others do not. Your billing lead should check the current CMS list against the exact device you own — not against the code in general — and re-check it when CMS issues quarterly updates.
Payment sits on the Clinical Laboratory Fee Schedule. Rather than repeating a rate that may have changed, pull the current year's file directly from the CMS fee schedule page and load it into your expected-reimbursement table. Commercial rates will differ; check contracts.
One Specimen, One Code: Where Unbundling Claims Start
The recurring billing error on multiplex respiratory testing is reporting the panel code plus individual single-target codes for the same specimen. Two different staff members, two different charge entries, one specimen — and now you have a duplicate-billing pattern that shows up in a payer audit.
Controls that work:
- Build a hard edit in your practice management system that flags a panel code and a component code on the same date of service for the same patient.
- Run a monthly report of respiratory testing claims by code combination. Five minutes of review catches a mis-built order set before it becomes ninety days of rework.
- Check payer-specific policy and current NCCI edit files before adding a modifier to override a bundling edit. "The system let us" is not a defense.
- When a repeat test is genuinely performed on a separate specimen, document the specimen collection times. That is the record that supports the second line.
Refunds matter as much as denials. If your monthly review finds overpayments, your compliance policy should specify the timeline and the person responsible for initiating repayment. Discovering an error and sitting on it is a materially worse position than the error itself.
Every 87637 Claim Touches at Least Four Vendors
Trace one panel result from swab to remittance and count the outside parties holding protected health information:
- The analyzer vendor's cloud portal or device middleware, if results sync off-device for QC, connectivity, or remote support.
- Your reference lab or LIS interface vendor, if the specimen is sent out or results flow through an integration layer.
- Your clearinghouse, which transmits the claim with diagnosis and test detail.
- Your billing or RCM service, if denials and appeals are handled outside the practice.
Add a fifth if your patient portal, secure messaging, or automated result-notification tool is a separate product. Every one of these is a business associate, and every one needs an executed agreement on file before it touches the first result — not after.
When you inventory this chain, you will usually find one gap: the analyzer vendor whose field engineer logs in remotely, or the small connectivity tool a prior manager installed. If you need a signature-ready agreement for that vendor this week, you can generate a Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Get it signed before the next remote support session, and log the execution date in your vendor register.
Your vendor register should record, for each entity: what PHI it receives, the BAA execution and expiration dates, whether subcontractors are involved, and who at your practice owns the relationship. If your register is a spreadsheet nobody has opened since 2024, that is your finding, not a hypothetical one.
Public Health Reporting Is Permitted — Log It Anyway
Influenza, RSV, and SARS-CoV-2 reporting obligations vary by state and by facility type. Disclosures to a public health authority authorized to receive them are permitted under the Privacy Rule without patient authorization; HHS maintains guidance on public health disclosures.
Two operational points your staff will get wrong. First, permitted does not mean unlimited — disclose only what the reporting requirement calls for. Second, if the disclosure is not treatment, payment, or health care operations, it may be accountable, and your accounting-of-disclosures process needs to capture it. If your reporting is automated through an interface, confirm the interface logs what it sent and when, and that the logs are retrievable by your privacy officer rather than only by the vendor.
Result Delivery and the 30-Day Access Clock
Patients have a right of access to completed test results, including panel results, under 45 CFR 164.524. Your practice has 30 days to respond to a written request, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Review the HHS right of access guidance with your front desk, not just your privacy officer — the failure almost always happens at intake, when someone tells a patient to "ask the lab."
Practical controls: a single intake point for records requests, a logged received-date, a fee schedule that stays within the cost-based limits, and an identity-verification step for phone and email requests that does not become an obstacle course. If you release results by text or unencrypted email at the patient's request, document the request and the fact that you warned them of the risk.
Tracking Technology on Your "Get Your Results" Page
If your results portal or testing information page carries a third-party analytics or advertising script, someone needs to answer what that script collects and where it goes. OCR's guidance on tracking technologies has been through litigation and revision, and portions addressing unauthenticated pages were vacated by a federal court in 2024 — but the underlying rule has not changed. If a vendor receives identifiable information about a patient's interaction with your authenticated portal, that vendor is a business associate and needs an agreement, or the tracker needs to come off.
Assign this to whoever controls your website. Ask for a list of every script on the portal and the results pages, with a business justification for each. Remove what nobody can justify.
A 14-Day Cleanup Plan for Respiratory Panel Operations
- Days 1–3 (billing lead): Pull the charge master entries for every respiratory test in your catalog. Confirm each maps to one code, sourced from a package insert or lab directory. Document the review date.
- Days 4–5 (billing lead): Check your specific analyzers against the current CMS waived-test list and confirm QW handling per payer. Fix the claim scrubber rules.
- Days 6–8 (compliance lead): Run a 12-month report on panel-plus-component code combinations. Quantify any overpayments and start the refund process on what you find.
- Days 9–11 (privacy officer): Rebuild the vendor register for the specimen-to-remittance chain. Identify every missing or expired BAA and issue agreements.
- Days 12–13 (privacy officer): Walk one real records request end to end. Time it. Confirm the received-date log exists.
- Day 14 (administrator): Sign off, file the documentation, and calendar the next review. If your broader policy set and risk analysis are also overdue, automated HIPAA risk analysis and policy generation will get you a defensible baseline faster than rewriting templates by hand.
The 87637 CPT code description is a paragraph of technical text. The operational obligations attached to it — correct mapping, CLIA scope, modifier accuracy, vendor agreements, reporting logs, and a 30-day access clock — are what your practice is actually accountable for. Start with the vendor register, because that is the gap you are most likely to already have. If a vendor on that list is touching results without a signed agreement, build and export the BAA today and close it before your next audit does it for you.