A patient walks into your urgent care at 4:40 p.m. on a Friday, gets a nasal swab, and 15 minutes later your medical assistant reads two pink lines on a cassette. That single test generates a CLIA log entry, a chart note, a claim line, a possible state public health report, and a portal release decision — five records, four different retention rules, and at least two vendors touching protected health information. The 87811 CPT code description is where the billing side of that chain starts, and it is the part most administrators get asked about first.

This guide is for the person who owns that chain: the practice administrator, the billing lead, the privacy officer. It covers what the code descriptor says, how practices document code selection without practicing medicine, and where the privacy, records-handling, and vendor obligations attach.

The 87811 CPT Code Description, Word for Word

CPT 87811 reads: "Infectious agent antigen detection by immunoassay with direct optical (ie, visual) observation; severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2) (Coronavirus disease [COVID-19])."

Three elements do the work in that sentence. Antigen detection — it describes an antigen assay, not a molecular one. Immunoassay with direct optical observation — the result is read visually rather than produced by an instrument that runs a multi-step analytic process. SARS-CoV-2 — the target organism is named, so the code is organism-specific rather than a general antigen code.

That is the full descriptor. The 87811 CPT code description does not tell you which specimen type was collected, which brand of test was used, whether the test is CLIA-waived, or whether a given payer covers it. Those facts live in your test log, your CLIA certificate file, and your payer policy binder — and every one of them can be audited separately.

How 87811 Sits Next to Its Neighbors

Your billing staff will encounter several adjacent codes, and the distinctions are technical, not clinical:

  • 87426 describes SARS-CoV-2 antigen detection by immunoassay using a multiple-step method — a different technique than direct visual observation.
  • 87428 describes an antigen immunoassay, multiple-step method, targeting SARS-CoV-2 together with influenza A and B.
  • 87635 sits in the molecular (amplified probe) family, not the antigen family.
  • 87804 is the influenza antigen code with direct optical observation.

Which code applies in any given encounter depends on the test actually performed and its documented methodology. Your job is not to decide that from the chart note — it is to make sure the record contains enough detail that the correct determination is possible and defensible. That means the device name, the methodology, the specimen type, the result, and the operator are all captured somewhere retrievable.

Who Decides the Code, and What You Document

Code selection belongs to the ordering and performing side of the encounter, informed by the test manufacturer's instructions for use, the CPT descriptor, and payer policy. Billing staff verify and submit; they do not reverse-engineer methodology from a result line.

Build the documentation trail so that no one has to guess:

  1. Device-to-code crosswalk. Maintain a single-page internal reference listing each point-of-care test your practice stocks, its methodology as stated in the instructions for use, its CLIA categorization, and the code your coding policy maps to it. Date it. Re-review it whenever you change suppliers.
  2. Operator identification. CLIA expects you to know who performed the test. Your log should name the person, not the department.
  3. Lot and expiration capture. Auditors and quality reviews both ask.
  4. Payer policy snapshot. Save the coverage policy version you relied on. When a payer changes cost-sharing rules mid-year, you want the dated document.

One reminder for front-desk scripting: the federal requirement that health plans cover COVID-19 diagnostic testing without cost sharing ended with the public health emergency in 2023. Patients still expect free tests. Your financial policy and your good-faith estimate process should reflect current plan terms, not 2021 habits.

CLIA Waiver, the QW Modifier, and Your Certificate File

Most practices running visual-read antigen tests operate under a CLIA Certificate of Waiver. That certificate governs which tests you may legally perform in-house, and it is the first document a surveyor asks for. Keep the current certificate, the effective dates, the listed director, and your site address in one folder with your coding crosswalk.

Many payers require the QW modifier to signal that a test was performed under a waiver, and CMS maintains the authoritative list of waived tests and modifier instructions. Verify the current requirement against CMS's CLIA program materials rather than a cheat sheet someone printed years ago. Modifier requirements and waived-test listings change.

If your practice performs a test outside the scope of its certificate, the exposure is not just a denied claim. It is a licensure and survey problem, and it will surface in the same file review that examines your privacy practices.

The Five Records One Rapid Test Creates

This is where the coding conversation becomes a privacy conversation. A single 87811-coded encounter typically produces:

  • The CLIA test log — often paper, often at the point of care, containing patient name, date, test, and result. This is PHI sitting on a counter.
  • The chart entry — part of the designated record set, subject to the patient's right of access and right to request amendment.
  • The claim — PHI disclosed to a payer under payment, plus whatever your clearinghouse retains.
  • The analyzer or app record — if you use a connected reader, a scanning app, or cloud middleware, a copy of the result and identifiers may live with that vendor.
  • The public health report — where state law still requires it.

Your risk analysis has to account for all five locations, not just the EHR. A paper test log kept in a bin behind the triage desk for eighteen months is an inventory item, a safeguard question, and a disposal obligation. If your current asset inventory does not list the point-of-care testing area as a location where PHI is created and stored, the inventory is incomplete — and HHS's proposed Security Rule update, published in early 2025 and still pending as of this writing, leans harder on exactly that kind of asset accounting. If maintaining that documentation set manually has become the reason your risk analysis is two years old, tools that generate the risk analysis and policy set from your actual environment shorten the gap considerably.

Public Health Reporting After the Federal Mandate Sunset

The federal laboratory reporting mandate created during the pandemic has been retired. State and local reporting requirements were never uniform and did not all sunset with it. Some jurisdictions still require reporting of positive SARS-CoV-2 results; others have folded it into general respiratory surveillance; others require nothing from waived-testing sites.

Two actions for your privacy officer this quarter. First, confirm in writing with your state health department what your practice is currently required to report, in what format, and to which system. Second, make sure your Notice of Privacy Practices and your workforce training reflect that public health disclosures are permitted without patient authorization under the Privacy Rule's public health provisions. HHS's guidance on disclosures for public health activities is the reference to hand your staff, and the minimum necessary standard still applies to the content of the report.

Document the legal basis for each recurring disclosure stream. When an accounting-of-disclosures request arrives, "we've always sent those" is not an answer.

Employer-Paid and School Testing: Where the Rules Change

If a local employer contracts with your practice to test its workforce, the analysis shifts. Sending results back to the employer is not treatment, payment, or health care operations. Disclosure to an employer generally requires a patient authorization, unless the narrow workplace medical surveillance provision applies and its conditions — including written notice to the individual — are met.

Practices routinely get this wrong by treating a signed employer agreement as consent from the employee. It is not. Before your first billed encounter under any employer testing arrangement:

  • Decide whether results go to the employer at all, or only to the individual.
  • Draft an authorization form specific to that disclosure, with the recipient named.
  • Train the staff who will collect it, so the form is signed before the swab, not after.
  • Separate the billing pathway. Employer-paid encounters are not payer claims, and mixing them creates refund problems.

Vendor List Check: The Reader, the Middleware, the Portal

Visual-read tests look like the lowest-tech thing in your building, which is exactly why they escape vendor review. Ask three questions about every point-of-care testing workflow:

Does anything leave the building electronically? Connected readers, phone-based result scanners, and manufacturer result portals frequently transmit identifiers to a vendor cloud. That vendor is a business associate.

Who touches the claim? Clearinghouses, outsourced billing companies, and coding audit firms all handle PHI tied to the 87811 CPT code description on your claims. Confirm each has a current, signed agreement and that you can produce it in under ten minutes.

Who disposes of the logs? Shredding vendors and records storage companies belong on the list too.

If any of those relationships is running on a handshake or an expired form, close the gap now — a signature-ready business associate agreement is a one-evening fix, and it is far cheaper than explaining the omission during a breach investigation.

Right of Access and Information Blocking on Point-of-Care Results

Test results in the chart are part of the designated record set. When a patient requests them, the Privacy Rule's right of access generally gives you 30 days, with one 30-day extension available if you notify the patient in writing.

Separately, the information blocking rules apply to electronic health information, including results. A blanket practice of holding results for a clinician callback before portal release can create exposure under those rules unless it fits a recognized exception. Review your release-delay settings against the current information blocking guidance and document whichever exception you rely on, by name, in your policy.

A 90-Minute Review You Can Run This Week

  1. Minutes 0–15: Pull the CLIA certificate. Confirm it is current and lists every test you stock.
  2. Minutes 15–35: Build or update the device-to-code crosswalk. Date and initial it.
  3. Minutes 35–50: Walk to the testing area. Photograph where logs sit. Fix anything visible from a waiting-room chair.
  4. Minutes 50–65: List every vendor in the testing and billing path. Match each to a signed agreement.
  5. Minutes 65–80: Email your state health department contact for current reporting requirements. Save the reply.
  6. Minutes 80–90: Check portal release timing and note which exception, if any, your delay relies on.

Everything on that list is discoverable. Auditors, surveyors, and investigators all start with documents, and the practices that come through cleanly are the ones whose paperwork was written before anyone asked.

If your risk analysis, policies, and vendor documentation are scattered across drives and predate your current testing workflow, generate the full compliance document set in one pass and give your next survey something coherent to read.