CPT Code 90662: Billing, Records, and Vendor Checks
Your practice orders 600 doses of high-dose influenza vaccine in July, runs four Saturday clinics in October, and by November your billing lead is working a denial queue full of the same rejection. Meanwhile a tablet used at the church-basement clinic has been sitting in someone's trunk for three weeks with 180 patient names cached on it. Both problems trace back to the same workflow. This guide walks the operational path of CPT code 90662 — from purchase order to claim to registry submission to records request — and makes the privacy, records-handling, and vendor obligations explicit at each step. It is written for administrators and billing staff, not clinicians, and it does not tell you which code fits a given patient.
What CPT Code 90662 Represents on a Claim
CPT code 90662 is a vaccine product code. In the AMA's CPT structure, it sits in the 906xx immunization series and its descriptor references an influenza virus vaccine, split virus, preservative free, with enhanced immunogenicity achieved through increased antigen content, administered intramuscularly. That descriptor identifies the biological only.
It does not describe the act of giving the injection. Administration is reported separately using the immunization administration codes, or — for Medicare Part B — the HCPCS administration code CMS designates for influenza vaccine administration. Two lines, two different determinations, two different documentation trails.
Which product code belongs on a claim is a function of the vaccine actually drawn and given, matched against the manufacturer's labeling, the payer's coverage policy, and the CPT descriptor. Your clinical staff document the product; your coding staff map it. Your job as an administrator is to make sure that mapping is reproducible, auditable, and not living in one person's head.
How Practices Determine and Document the Product Code
Build the determination as a chain of evidence, not a judgment call at the keyboard. A defensible chain looks like this:
- Purchase record. Invoice or distributor packing slip identifying the product, NDC, and lot.
- Inventory receipt. Entry into your vaccine inventory module with NDC, lot, expiration, and doses received.
- Order or standing order. The signed protocol or individual order authorizing administration, with the version and effective date recorded.
- Administration record. Date, site, route, dose, lot, expiration, administering staff member, and the Vaccine Information Statement edition date plus the date it was provided — the last two are federal requirements under the National Childhood Vaccine Injury Act, independent of HIPAA.
- Charge capture. The product code and administration code generated from the administration record, with NDC and units carried to the claim where the payer requires it.
When the chain breaks, it almost always breaks between step 4 and step 5 — a nurse documents "flu shot given" in a free-text note during a high-volume clinic, and someone downstream guesses. That guess is how cpt code 90662 ends up on a claim for a dose that was not that product, and how your practice ends up refunding a payer eighteen months later.
Age Edits and Denials Are a Policy Question, Not a Coding Trick
Payers apply automated edits to influenza product codes, and age is a common edit parameter because vaccine labeling and coverage policies are age-specific. When a claim rejects, the correct administrative response is to compare the administration record against the payer's published policy and the product labeling — not to swap the code until something pays. Document the comparison. Recoding to clear an edit, without a corresponding change in the underlying record, is the pattern that turns a billing error into a false claims problem.
Medicare Part B, Roster Billing, and the PHI That Rides Along
Medicare Part B covers seasonal influenza vaccine and its administration as a preventive benefit, and CMS publishes payment allowances for influenza vaccine codes on its seasonal influenza vaccine pricing listing. Practices running mass immunization events frequently use roster billing, which lets you submit a single claim form with a list of beneficiaries rather than an individual claim per patient.
Roster billing is efficient. It is also a paper artifact containing dozens of names, Medicare Beneficiary Identifiers, dates of birth, and a service that reveals a health encounter. That is protected health information sitting on a clipboard.
Treat roster sheets as a controlled record class:
- Number the sheets before the clinic and reconcile the count at the end. Missing sheet, incident report — no exceptions.
- Never let patients sign a shared roster that displays prior signers' identifiers. Use individual intake slips that feed the roster, or a shielded sign-in.
- Transport in a sealed opaque envelope or locked case. Do not leave rosters in a vehicle overnight.
- Scan into the record and destroy the paper on a documented schedule, with the destruction logged.
The breaches OCR posts to its public breach reporting portal are dominated by electronic incidents, but paper and film losses appear consistently, and off-site clinic paperwork is exactly the kind of record that goes missing without anyone noticing for weeks.
Off-Site and Worksite Clinics: Where the Failures Actually Happen
A flu clinic held at a senior center, an employer's cafeteria, or a partner facility moves your intake process outside your access controls. Before the first event of the season, walk the checklist:
- Devices. Full-disk encryption verified, screen lock at two minutes, no local caching of the schedule beyond the event, remote wipe enrolled. If staff use a hotspot, it is your hotspot with a rotating credential — not the host's guest Wi-Fi.
- Physical layout. Registration table positioned so screens and forms are not readable from the queue. A visible-to-all sign-in sheet at a worksite clinic is a disclosure to every coworker in line.
- Staff roles. One named person owns records custody for the event, start to finish. Put the name on the event plan.
- Host relationship. A venue that merely provides space is not a business associate. A partner that handles registration, scheduling, or records on your behalf is, and needs an agreement in place before the event — not after.
What You May Send Back to the Employer
Worksite clinics generate a predictable request: the HR director wants a list of who got vaccinated. Absent a valid patient authorization, that list is PHI about identifiable individuals and the employer is not entitled to it in its capacity as an employer. Aggregate counts with no identifiers are a different matter.
Decide this before the event, put it in the written agreement with the employer, and brief your staff. The worst version of this conversation happens at 4:45 p.m. on clinic day with an HR manager standing over your nurse.
Registry Submissions Are Permitted — Your Interface Still Needs Governance
Reporting immunizations to a state or local Immunization Information System is a disclosure for public health activities, permitted under the Privacy Rule without patient authorization when made to a public health authority authorized to collect the information. HHS explains the scope in its guidance on disclosures for public health activities. State law layers on top and controls consent, opt-out, and query rights — check yours annually, because these statutes change.
"Permitted" is not the same as "unmanaged." Your registry interface deserves the same treatment as any other data flow:
- Document the interface in your data flow inventory: source system, transport, endpoint, message format, frequency, and the fields transmitted.
- Confirm transport encryption and credential ownership. Know who holds the registry account credentials and what happens when that person leaves.
- Monitor rejections. A silently failing HL7 feed means immunization records are incomplete for months, which surfaces later as a records-request problem.
- Verify the minimum necessary content. If your feed is pushing fields the registry does not require, trim it.
If you have never inventoried these flows, that inventory is a required component of the risk analysis every covered entity owes under the Security Rule. Practices that would rather not build the documentation from a blank page can generate a risk analysis and the supporting policy set with HIPAA.app, then spend the saved time on the parts that need a human — interviewing your staff about what actually happens at the registration table.
Recall Texts, Vaccine Manufacturers, and the Marketing Line
Every fall, someone proposes a text campaign to bring patients in for flu shots. Two separate rules apply.
First, HIPAA. Communications to a patient about health-related products and services generally fall outside the definition of marketing when they concern treatment or care coordination — but that changes if your practice receives financial remuneration from a third party whose product is being promoted. If a manufacturer or distributor is subsidizing the campaign, the analysis shifts and authorization may be required. Get that arrangement in writing and review it before the campaign runs, not after.
Second, telecom rules. Automated texting is governed by consent requirements that have nothing to do with HIPAA. Keep your opt-in and opt-out records and honor revocations same-day.
Operationally: your texting vendor is a business associate. So is the population-health tool generating the recall list. If either lacks a signed agreement, the campaign does not launch.
"Send Me My Immunization Record" Starts the 30-Day Clock
Patients, employers acting with authorization, schools, and long-term care facilities all request immunization histories. When the patient makes the request, it is a right-of-access request and the standard 30-day timeline applies, with a single 30-day extension available if you notify the patient in writing with a reason. HHS maintains detailed guidance on the individual right of access, including the narrow limits on what you may charge.
Two front-desk failure modes to train out:
- Treating an immunization record request as informal and handing it off without logging it. Log every request with date received, requester, format requested, and date fulfilled. Your log is the only evidence you met the deadline.
- Fulfilling a third-party request — an employer, a school — on a patient's verbal say-so. That path needs a valid authorization or a legal basis. Route it to the privacy officer.
The Vendor List Behind a Single 90662 Claim
Trace one dose through your systems and count the outside parties that touch identifiable data:
- Practice management and EHR vendor, plus any hosting provider
- Vaccine inventory or cold-chain monitoring platform, if it stores patient-level administration data
- Clearinghouse submitting the claim
- Billing service or outsourced coding contractor
- Registry interface middleware, if you use a third-party engine
- Patient communication and reminder vendor
- Document storage, scanning, or shredding vendor handling roster sheets
- Any staffing agency supplying nurses for off-site events
Each of those needs a current business associate agreement with breach-notification timelines, subcontractor flow-down, and return-or-destruction terms at termination. If your seasonal staffing agency or a new reminder vendor is missing one, a signature-ready business associate agreement is a one-evening fix — considerably cheaper than explaining the gap during an investigation.
A Six-Week Pre-Season Checklist
Week 1: Reconcile last season's vaccine inventory against claims submitted. Investigate variances greater than a handful of doses.
Week 2: Review payer coverage policies for influenza product codes and update your charge master mapping. Document who reviewed and when.
Week 3: Confirm BAAs for every vendor on the list above. Chase the missing ones.
Week 4: Test the registry interface end to end with a sample record. Confirm acknowledgments return clean.
Week 5: Run the off-site clinic device and paper-handling drill. Name the records custodian for each scheduled event.
Week 6: Brief front desk on records requests, roster handling, and the employer-disclosure script. Fifteen minutes, documented as training.
The billing accuracy of cpt code 90662 and the privacy integrity of your immunization program are the same project. Both depend on one thing: the administration record being complete and correct at the moment the dose is given, and every downstream system reading from it rather than reconstructing it.
If your risk analysis, policies, and vendor documentation are older than your last flu season, rebuild them before this one starts. Produce your risk analysis and full compliance document set, then use the checklist above to pressure-test it against what your staff actually do on a Saturday morning in October.