Gardasil CPT Code: Billing, Records, and Vendor Rules
A 14-year-old comes in for a second HPV dose. Your medical assistant documents it, your biller drops the gardasil cpt code onto the claim, the state immunization registry picks it up through your interface that night, and eleven days later the patient's mother calls the front desk asking what the explanation of benefits is for. That single dose just touched four systems, two vendors, and at least one state law about minor consent — and none of that is visible from the encounter note.
This guide is for the person who owns that chain: the practice administrator, the billing lead, the privacy officer. It covers how the code actually posts, where the data goes afterward, and which of those hops needs a business associate agreement, a consent record, or a workflow change. It is administrative guidance. Code selection for any specific patient encounter belongs to your clinicians and your certified coder, working from the documentation in the chart.
What the Gardasil CPT Code Covers on a Claim
CPT 90651 is the product code for the 9-valent human papillomavirus vaccine (types 6, 11, 16, 18, 31, 33, 45, 52, 58), for intramuscular use, covering the 2- or 3-dose schedule. It identifies the biological only.
The act of giving the injection is reported separately with an administration code. Which administration family applies depends on the patient's age and whether the documentation supports counseling by a physician or other qualified health professional:
- 90460 — immunization administration through age 18, first or only component, when face-to-face counseling by a physician or QHP is documented; 90461 is the add-on for each additional component.
- 90471 — immunization administration, single vaccine; 90472 is the add-on for each additional vaccine administered at the same visit.
You will also still see legacy HPV product codes on old claims and stale fee schedules. If your charge master has not been reviewed since those products left U.S. distribution, that is a cleanup task, not a coding question — pull the report and retire the inactive lines.
The NDC field is not optional in most Medicaid programs
Many state Medicaid programs and managed-care plans require the 11-digit National Drug Code, unit of measure, and quantity alongside the CPT product code. The NDC is lot-specific to the package, not to the CPT code, so a supply change can break claims quietly. Assign one person to reconcile NDC crosswalks whenever your vaccine supplier ships a different package configuration.
How your practice should document code selection
Write down the rule, not the answer. Your policy should state who selects the administration code, what documentation element they rely on (age at date of service, the counseling note, the components administered), and where that determination is recorded. When a payer audits, the defensible position is a repeatable process tied to the chart — not a biller's memory of what usually gets paid.
Quick Answer: Which Codes Are Involved in an HPV Vaccine Claim?
The gardasil cpt code for the 9-valent HPV vaccine product is 90651. It is reported with a separate immunization administration code — 90460 (with 90461 for additional components) for patients through age 18 when counseling by a physician or qualified health professional is documented, or 90471 (with 90472 for additional vaccines) otherwise. Many payers additionally require the NDC, unit of measure, and quantity. Vaccines supplied through the Vaccines for Children program are billed for administration only, following your state program's modifier and reporting rules.
Three Places the Code Lands After the Claim Goes Out
Billing staff think of the code as ending at the clearinghouse. It doesn't.
Your state immunization information system. Most states require or strongly encourage reporting of administered doses. Your EHR pushes an HL7 message containing the patient's name, date of birth, address, vaccine, lot, and date administered.
Your VFC inventory and eligibility records. If you are a VFC provider, every publicly supplied dose ties to an eligibility screening record for that visit. That record identifies the child's insurance status — Medicaid-enrolled, uninsured, underinsured, American Indian/Alaska Native — and it lives outside the claim.
Your recall and reminder queue. A first dose generates a follow-up obligation. Somewhere in your stack, a list of adolescents due for a second HPV dose is being built, and something is going to send them a message.
Each of those three is a distinct privacy surface with a distinct rule set. Treat them separately.
The Adolescent Consent Problem Your Billing Workflow Creates
HPV vaccination is overwhelmingly an adolescent service, which puts it directly on top of the messiest part of HIPAA: personal representatives. Under 45 CFR 164.502(g), a parent is generally the personal representative of a minor child — except where state law gives the minor the right to consent to the service, or where the parent has agreed to a confidential relationship between the minor and the clinician.
Several states allow minors to consent to vaccines that prevent sexually transmitted infection, in some cases at a specified age. If your state does, your release-of-information workflow must be able to recognize that a Gardasil dose in the chart may not be disclosable to a parent on request. That is a front-desk and records-clerk problem, not a legal-department problem, because the request arrives at the front desk.
What to build before the next request
- Get a written statement of your state's minor-consent rule for this service class from counsel or your state medical association, dated, in your policy binder.
- Flag the chart at the point of service, not at the point of request. If a minor consented independently, the clinical note and the demographic record should both carry the flag.
- Train records staff to stop and escalate when a parent requests records for a patient aged 12 and older. One extra day of review beats an unauthorized disclosure.
- Decide what your patient portal proxy access does at age thresholds. Most portals let you configure adolescent proxy limits. If yours is set to full parental access through age 17, you have made a policy decision by default.
The EOB is the leak you did not plan
Filing a claim under a parent's policy sends an EOB to the subscriber. HIPAA gives patients the right to request confidential communications and, under 164.522(a)(1)(vi), the right to restrict disclosure to a health plan for items or services paid out of pocket in full. That restriction only works if it is captured before the claim leaves your clearinghouse. Once the 837 transmits, you cannot recall it.
Practically: your registration screen needs a field for a confidential-communications request, your biller needs a hold status that honors it, and someone needs to reconcile the two weekly. If a patient asks to self-pay to keep a dose off the family's EOB, that is a same-day operational decision, not a callback item.
Registry Reporting Is a Public Health Disclosure — the Interface Vendor Is Still a Business Associate
Reporting immunizations to a state IIS is permitted under the public health provisions at 45 CFR 164.512(b). The state health department is a public health authority, not your business associate; you do not need a BAA with them, and you do not need patient authorization to report where state law requires it.
What trips practices up is the middle layer. If a health information exchange, an interface engine hosted by a third party, or your EHR vendor's integration service transmits that HL7 message on your behalf, that entity is creating, receiving, or transmitting PHI for you — and it needs a business associate agreement. "It's just a pipe" is not the conduit exception; the conduit exception is narrow and applies to transmission-only services with transient access.
There is a second, less-known provision worth knowing: 164.512(b)(1)(vi) permits disclosure of proof of immunization to a school where state law requires it, if you obtain and document agreement from the parent, guardian, or the adult or emancipated minor patient. Agreement can be oral, but you must document it. Build a checkbox, log the date and the person who took the agreement, and stop faxing immunization records to schools on assumption.
Also remember that minimum necessary applies to public health disclosures. Sending a complete chart when the registry needs vaccine, date, lot, and demographics is an over-disclosure you cannot walk back.
The Vendor List Behind One Vaccine Dose
Sit down with your vendor inventory and find every party that touches an immunization record. For a typical practice, the list looks like this:
- Billing company or outsourced coder — sees the full claim including the gardasil cpt code, patient demographics, and payer data. BAA required.
- Clearinghouse — BAA required.
- Interface/HIE vendor moving data to the IIS — BAA required.
- Reminder, recall, and patient-messaging vendor — BAA required, plus a content review (below).
- Vaccine inventory or temperature-monitoring platform — BAA required if it holds patient-level administration data; many do. If it only logs fridge temperatures with no PHI, document that determination in writing rather than assuming it.
- Patient portal and proxy-access module — usually covered by the EHR BAA; confirm the module is in scope.
- Answering service or after-hours triage — BAA required.
If any line on that list is missing a signed agreement, close the gap before you do anything else. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than routing a redline through counsel for a texting vendor you onboarded eighteen months ago.
Reminder texts and the marketing rule
A recall message telling a patient a second dose is due is a treatment communication and does not require authorization. It changes character the moment a manufacturer pays for it. Under the marketing definition at 164.501, a communication that encourages use of a product and is subsidized by a third party whose product is being described generally requires patient authorization. If a vaccine manufacturer offers to fund your recall campaign, route it to your privacy officer before your marketing coordinator says yes.
Separately, check the message content itself. "Time for your HPV vaccine" sent to a shared family phone number discloses more than "You have a follow-up visit due — please call us." Sensitivity is a content decision your practice controls.
Records Requests, Retention, and the 30-Day Clock
Immunization records are among the most-requested documents your front desk handles — schools, camps, employers, college health services. They are part of the designated record set, and the HIPAA right of access gives you 30 days to respond, with one 30-day extension if you notify the patient in writing of the reason and the new date.
Two operational rules keep you out of trouble. First, a school or employer request is not a patient access request — it needs an authorization or a specific permission, and the two queues should never merge. Second, your fee for copies must follow the access-fee limits; charging a per-page rate designed for litigation copies to a parent asking for a one-page immunization record is exactly the kind of thing that generates a complaint.
On retention: your VFC provider agreement sets minimums for eligibility screening documentation and inventory records, and your state sets minimums for the medical record. Those numbers are usually different. Write both into your retention schedule with the citation next to each, and make sure your document-destruction vendor's BAA covers the disposal.
A Ninety-Day Cleanup You Can Assign This Week
- Week 1 — Billing lead: pull a 12-month report of all HPV vaccine product and administration codes billed. Identify inactive product codes, missing NDC segments, and VFC doses billed with a product charge in error.
- Week 2 — Privacy officer: confirm the state minor-consent rule in writing and document how it maps to your portal proxy settings.
- Week 4 — Administrator: reconcile the vendor list above against signed BAAs. Note the effective date and the breach-notification timeline in each.
- Week 6 — Front desk supervisor: retrain on the difference between a patient access request and a third-party authorization, using immunization records as the worked example.
- Week 8 — IT or EHR admin: review exactly which data elements your IIS interface transmits. Compare against what the state requires.
- Week 12 — Privacy officer: update the risk analysis to reflect any new vendor, interface, or messaging channel found during the review.
None of this is exotic. The reason it matters is that immunization data flows through more third parties than almost anything else in a primary care or pediatric practice, and the volume of small disclosures makes it easy to normalize a bad habit. Scroll the OCR breach portal and you will see how many incidents originate with a vendor relationship nobody had documented.
Next Step
Start with the vendor list, because it is the only item on this page you can finish in an afternoon. Identify every party that touches an HPV vaccine record, then build the business associate agreements you are missing and get them signed. If your broader documentation set — risk analysis, policies, workforce training records — has drifted since the last time anyone looked, automating the compliance document set will get you back to a defensible baseline faster than rebuilding it in a shared drive.