Your practice placed 41 tuberculin skin tests last month. Nineteen were new hires at a nursing home you contract with, eleven were your own staff, and the rest were patients who needed documentation for school or a clinical rotation. Every one of those tests generated two encounters, a result that someone outside the exam room wanted, and a question your billing team answered by searching "cpt code ppd test" and hoping the first result matched your payer's policy.

That's the problem. The tuberculin skin test is operationally trivial and administratively messy. This guide covers how the encounter actually runs, how practices decide and document code selection, and — the part nobody writes about — where the privacy and vendor exposure sits.

Which CPT Code Applies to a PPD Test?

CPT 86580 carries the descriptor "Skin test; tuberculosis, intradermal." It describes the placement of the intradermal antigen. The blood-based interferon-gamma release assays sit elsewhere in the code set — 86480 and 86481 — and are typically performed by a reference lab rather than in your treatment room. The subsequent visit at which a qualified staff member reads the result is a separate encounter, and whether it is separately reportable (often discussed in the context of 99211) depends on your payer's policy, your documentation, and applicable edits. Your practice determines code selection from the CPT descriptors, the payer's published policy, and what the record actually supports — not from a search result.

Write that determination down. A one-page internal coding policy that names the code, cites the payer bulletin, and identifies who approved it is the difference between a defensible pattern and a habit.

The Two-Visit Structure Creates Two Records, Not One

Placement happens on day one. The read happens on a defined interval afterward, per the product labeling and your medical director's standing protocol. If the patient doesn't return inside the window, the test is not readable and the sequence restarts.

Who owns each step at your front desk

Assign these explicitly, by role, in writing:

  • Scheduler: books the placement and the read at the same time. Never one without the other.
  • Clinical staff: documents lot number, expiration, site, and administering initials at placement.
  • Reader: documents the measurement, the date and time of the read, and their credential.
  • Front desk: confirms, before the patient leaves, who is authorized to receive the result and in what form.
  • Billing: holds the claim until both encounters are documented, so the read visit isn't billed against an undocumented placement.

That last item is where most small-practice denials originate. A read with no documented placement in the chart is an audit finding waiting to happen.

Self-pay and the Good Faith Estimate

Occupational and school-requirement screening is frequently not a covered benefit. When the patient is uninsured or chooses not to use their coverage, the No Surprises Act's good faith estimate requirement applies. Build the estimate into the scheduling script for the placement visit and cover both encounters plus any reflex testing, so the patient isn't surprised by a second charge for the read. Post the cash price where the front desk can quote it without asking a manager.

The 48-to-72-Hour Reminder Is a Vendor Problem

Every practice that runs skin tests sends reminders, because a missed read wastes the antigen and the patient's time. Those reminders travel through a texting platform, an appointment reminder module, or a patient engagement tool. Each of those is a business associate.

The message content matters less than people assume — "Reminder: return to the clinic tomorrow for your test read" is still protected health information, because it links an identified individual to the fact that they received care from you. The vendor transmitting it creates, receives, maintains, or transmits PHI on your behalf. That triggers the business associate relationship under 45 CFR Part 164, and the contract has to exist before the first message goes out.

Pull your vendor list and check three categories specifically: SMS reminder platforms, the reference lab interface if you send blood-based testing out, and any occupational health portal where employer clients retrieve results. If you're missing paper on any of them, you can generate a signature-ready business associate agreement through a six-step wizard and have it in the vendor's inbox the same afternoon — PDF and DOCX, one-time purchase, no subscription. That's a faster path than waiting for a vendor's legal team to send you their template three weeks from now.

Also confirm what the patient consented to. OCR's guidance on the individual right of access is clear that patients may request unencrypted email or text delivery after being warned of the risk. Document the warning and the choice in the chart. Don't let a staff member decide case by case.

When You Test Your Own Staff, You Are Wearing Two Hats

This is the single most misunderstood scenario in the entire skin-test workflow, and it comes up every time someone in your office searches "cpt code ppd test" for an employee health encounter.

HIPAA's definition of protected health information excludes employment records held by a covered entity in its role as employer. That exclusion does not mean the information is unprotected — it means a different body of law governs it. When your practice tests its own medical assistant, two records get created:

  1. The clinical record, generated by the treating provider in the EHR, which is PHI subject to the Privacy Rule like any other patient encounter.
  2. The employment record, the credentialing or personnel file entry showing the employee satisfied a screening requirement, which is not PHI in your employer capacity — but is subject to the Americans with Disabilities Act's confidentiality requirements and your state's employment law.

Practical consequence: your practice manager cannot browse the EHR to check whether staff are current on screening. That's an access-for-employment-purposes lookup against a clinical record, and your audit log will show it. Instead, the treating provider or employee health designee transmits a compliance attestation — screened, date, cleared or referred — into the personnel file. The clinical detail stays in the clinical record.

Put that separation into your access control policy and into the annual training deck. Then go look at your EHR role matrix and confirm your office manager's account doesn't have blanket clinical read access it doesn't need. HHS publishes the full text of the Privacy Rule and related guidance if you need to cite chapter and verse to a skeptical partner.

Employer-Paid Testing Is a Disclosure, Not a Business Associate Relationship

A nursing home sends you 19 new hires. The nursing home pays. The nursing home wants the results.

The nursing home is not your business associate for this. It is not performing a function on your behalf — it is a third party requesting PHI about individuals you treated. Absent a narrow exception, you need a valid HIPAA authorization signed by each individual before you release results to their employer.

Build the authorization into intake, not into the follow-up call

Have the individual sign the authorization at the placement visit, while they're standing at your desk. Chasing signatures after a positive result is how practices end up disclosing without paper. The authorization should name the specific employer, specify "tuberculosis screening results and clearance status" rather than "medical records," carry an expiration, and include the revocation language the rule requires.

There is a limited workplace medical surveillance exception at 45 CFR 164.512(b)(1)(v) for employer-arranged evaluations conducted to meet OSHA or comparable state requirements — but it comes with its own written notice obligation to the individual and it does not cover every occupational screening arrangement. Have counsel confirm before you rely on it, and document which basis you're using for each employer contract.

Delivery method for employer results

Do not fax clearance letters to a shared HR fax that sits in an open hallway. Do not email spreadsheets of names and results without encryption. If you're running volume for one employer, agree on a single named recipient, a secure delivery channel, and a monthly reconciliation. Misdirected disclosures are a routine entry on the OCR breach reporting portal, and batched occupational screening results are exactly the kind of file that gets sent to the wrong person.

Positive Results and the Public Health Exception

Tuberculosis is a reportable condition in every state. Reporting to a public health authority authorized by law to receive it is a permitted disclosure without authorization — that's 45 CFR 164.512(b), and it does not require you to obtain the patient's agreement first.

Operationally, three things need to be true before you need this:

  • Your policy names who reports, with a backup for vacations.
  • You know your state's reporting window and reporting portal, in writing, not in someone's memory.
  • The disclosure gets logged in your accounting of disclosures. Public health reporting is not treatment, payment, or operations, so it is accountable if the patient later requests the accounting.

That last point trips up practices constantly. Most EHRs do not log public health reports automatically. Keep a simple log.

The 30-Day Clock When Someone Asks for Their Result

A student needs documentation for a clinical rotation next Monday. A patient wants their record to take to a new employer. Both are right-of-access requests under 45 CFR 164.524, and the clock is 30 days with one 30-day extension available if you notify the individual in writing.

Nobody should wait 30 days for a one-line skin test result. Set an internal service standard of two business days for single-result requests and route them to a named person. Fees are limited to a reasonable, cost-based amount — labor for copying, supplies, postage — and you may not charge for search and retrieval. HHS's right of access guidance spells out the permitted fee components in detail; print it and give it to whoever handles records requests.

One distinction to train on: a patient directing you to send their own record to a third party is a right-of-access request with different mechanics than a third party requesting the record with an authorization. Your staff needs to recognize which one is in front of them.

Coding Governance: Who Actually Decides

Back to the coding side, because "cpt code ppd test" is a question your billing staff will keep asking as payer policies change.

Name one person who owns the code-selection policy — usually a certified coder or the billing manager. That person reviews payer bulletins quarterly, checks applicable edits including the CMS National Correct Coding Initiative edit files, and updates the internal cheat sheet with a version date. Providers document; the coder assigns; the policy governs. Ad hoc decisions at the front desk are how patterns form that you can't explain two years later.

Run a quarterly ten-chart audit on this specific service line. Check that placement and read are both documented, that lot and site are recorded, that the diagnosis coding matches what the encounter note supports, and that any employer disclosure has a signed authorization attached. Ten charts takes forty minutes and surfaces the same three problems every time.

Your Next Two Hours

Pull the vendor list. Confirm a signed agreement exists for every platform touching reminder messages, lab interfaces, and employer result portals — and close the gaps with a signature-ready BAA before the next batch of new hires walks in. Then check whether your broader documentation set — risk analysis, access control policy, disclosure log — reflects the two-hat problem in employee testing. If it doesn't, automating the risk analysis and policy set is a shorter project than rebuilding it from a template after an OCR inquiry.

The test itself takes ninety seconds. Everything around it is where your exposure lives.