PPD CPT Code: Billing, Records, and Vendor Handoffs
Your medical assistant places fourteen PPDs on a Monday morning — six new hires from the surgery center down the street, four of your own staff, and four patients whose schools or nursing programs demanded documentation. By Wednesday afternoon, all fourteen need a reader. By Friday, three different sets of rules govern where those results live and who is allowed to see them.
This guide covers the administrative mechanics behind the ppd cpt code — how practices determine and document code selection, how the return-visit workflow gets tracked, and where the privacy exposure actually sits. It is written for administrators, billers, and privacy officers, not for clinicians and not for patients. Nothing here tells you what to bill for a given clinical situation; it tells you how to build the process that produces a defensible claim and a clean record.
What the PPD CPT Code Covers — and What Your Coder Still Has to Decide
The tuberculin skin test has a dedicated CPT descriptor: 86580, "Skin test; tuberculosis, intradermal." That descriptor covers the intradermal placement of purified protein derivative. Interferon-gamma release assays — the blood-draw alternative — sit in a different family (the 86480/86481 range), and they are laboratory codes with an entirely different specimen and vendor path.
Knowing the descriptor is not the same as knowing what to submit. Your coding staff determine code selection from three inputs, in this order:
- The documentation in the chart — what was ordered, what was administered, who administered it, and what was read.
- The current-year CPT manual, because descriptors and guidelines change and last year's charge master is not authoritative.
- The payer's published policy, including coverage determinations, diagnosis linkage requirements, and any edits that apply. CMS publishes fee and coverage information through the Physician Fee Schedule Search tool; commercial payers publish their own medical policy libraries.
Screening for employment or school admission is frequently a non-covered, patient-responsibility service under commercial and government plans. Your front desk needs to know that before the syringe comes out, because the financial conversation after a denial is the one that generates complaints.
The featured question: is the read billed separately?
Short answer: the code for the skin test is generally understood to include both placement and the subsequent reading, which is why most payer policies do not expect a second charge simply for measuring induration at 48–72 hours. Practices that report an additional evaluation and management service for the return visit must be able to point to documentation of a separately identifiable service, and must confirm the payer's stated policy in writing. Your compliance lead — not your MA — owns that determination, and it belongs in a written charge-capture policy rather than in tribal knowledge at the front desk.
The 48-to-72-Hour Window Is a Recall Workflow, Not a Clinical Footnote
Every PPD placed creates a scheduled obligation two to three days later. Miss it and the test is void, the patient re-tests, and someone eats the cost. That makes the read window a tracking system requirement, and tracking systems are where PHI leaks.
Build the workflow explicitly:
- At placement: the return appointment is scheduled before the patient leaves the room. Not "come back Wednesday" — an actual slot with a confirmation.
- At 24 hours: automated reminder goes out. If that reminder travels by SMS or email through a third party, that third party is a business associate handling PHI.
- At 72 hours: the no-show report runs. Unread tests get flagged, documented as invalid, and routed for re-scheduling.
- Weekly: a reconciliation report matches placements to reads. Unmatched lines are your audit exposure.
Text-message reminders are the most-overlooked vendor relationship in this workflow. "Reminder: return to the clinic tomorrow to have your TB test read" identifies the patient, the provider, and the service. That is PHI moving through a vendor's servers. If that vendor is not on your business associate list with a signed agreement, you have a gap that shows up immediately in any OCR investigation or vendor audit.
Documentation elements your chart audit should check
Pull ten TB testing encounters at random each quarter and confirm the record contains: the order and ordering provider; the product name, lot number, and expiration date; the administration site and route; the date and time of placement; the date and time of the read; the measurement recorded in millimeters of induration; and the identity and credentials of the person who performed the read. Missing lot numbers and missing reader identity are the two failures that most often turn a routine payer request into a refund.
Your Own Staff's PPDs Are Employment Records — Not PHI
This is the distinction that trips up practices that test their own employees. HIPAA's definition of protected health information at 45 CFR 160.103 excludes employment records held by a covered entity in its role as employer. When your clinic tests its own medical assistant as a condition of employment, that result is an employment record governed by OSHA and the ADA — not a HIPAA record.
That exclusion does not make the record less sensitive. It makes it differently regulated:
- ADA: employee medical information is kept in a file separate from the general personnel file, with restricted access. A supervisor who can open the shared HR drive should not be able to see TB screening results.
- OSHA: employee medical and exposure records are subject to long retention obligations — many employers apply the duration-of-employment-plus-30-years framework from the access-to-records standard. Confirm the applicable retention with counsel and write it into your retention schedule.
- Work-relatedness: a conversion following a workplace exposure raises recordkeeping questions on the OSHA 300 log. Your safety officer, not your biller, answers those.
The two-hat problem: charting your own employees as patients
Small practices routinely test staff by creating a patient chart in the EHR. The moment you do that, you have blended an employment record with a treatment record, and you have handed chart access to every user with a clinical role.
If your practice tests its own workforce, decide deliberately which system of record you're using. If it's the EHR, restrict the chart, run access audits on employee charts monthly, and treat any curiosity-browsing hit as a disciplinary matter with a documented outcome. If it's an occupational health log kept outside the EHR, make sure that log is access-controlled, backed up, and included in your risk analysis inventory.
When an Employer, School, or Staffing Agency Is the Requester
Testing another company's employees changes your posture entirely. Those workers are your patients. The employer is a third party with no automatic right to results.
Two paths exist. The clean one is a written HIPAA authorization signed by the individual, naming the employer, the specific information disclosed, and an expiration. The narrower one is the workplace medical surveillance provision at 45 CFR 164.512(b)(1)(v), which permits disclosure to an employer, in defined circumstances, of findings from an evaluation conducted at the employer's request — but it carries its own written-notice requirement to the individual and is limited to findings related to the workplace medical surveillance or work-related illness or injury.
Practically: pick the authorization path, standardize the form, and have the patient sign it at check-in for the placement visit. Then apply minimum necessary to the outbound letter. The employer needs a statement of the screening outcome and the date. The employer does not need the full encounter note, the patient's other diagnoses, or the medication list your EHR's default "clinical summary" export happily attaches.
Every Vendor That Touches a PPD Program Needs a Signed BAA
Map it out for your own practice and the list is longer than you expect:
- Appointment reminder / SMS platform
- Billing service or revenue cycle vendor
- Clearinghouse
- Occupational health or screening-tracking software
- Document scanning or fax-to-email service handling employer result letters
- Any IT contractor with access to the EHR or the file server holding results
- Cloud storage where scanned consent forms land
Reference labs running IGRA testing are usually a different animal — a clinical laboratory acting as a health care provider for treatment purposes is generally a covered entity in its own right, not your business associate. HHS explains the distinction on its business associates guidance page. Document your reasoning either way, because "we assumed" is not an answer during an audit.
If you found two or three vendors on that list without a current signed agreement — the usual outcome — close the gap this week rather than this quarter. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, as a one-time purchase with no subscription. That is faster than routing a request to outside counsel for a texting vendor you onboarded eighteen months ago.
The 30-Day Clock When a Patient Asks for the Result
Nursing students and new hires ask for copies constantly, and they ask urgently because a start date depends on it. Under the HIPAA right of access, you generally have 30 days to act on a request, with one 30-day extension available if you notify the individual in writing of the reason and the new date. HHS maintains detailed right of access guidance covering timelines, formats, and permissible fees.
For a one-page test result, thirty days is theater. Set an internal service level of two business days and staff to it. Right-of-access enforcement has been one of OCR's most consistently pursued categories, and the underlying facts are almost always mundane — a small request that sat in someone's queue.
Patient-directed transmission to a third party
When a patient asks you to send the result directly to a school or employer, the request must be in writing, signed, and clearly identify the recipient and where to send it. Note that the scope of third-party directives and the fee limits that apply to them were narrowed by federal court decision, so do not assume the patient-rate fee cap extends to every third-party transmission. Have your privacy officer write the current policy down, date it, and re-review it annually.
A Nine-Line Operational Checklist
- Charge master maps TB skin testing to the current-year descriptor; reviewed each January.
- Written charge-capture policy states how the read visit is handled, with payer policy cited.
- Financial responsibility for screening-only visits disclosed and signed before placement.
- Return appointment scheduled at placement, not offered verbally.
- Weekly placement-to-read reconciliation report, reviewed by a named person.
- Standard authorization form used for every employer or school disclosure.
- Outbound results letter limited to the minimum necessary — outcome and date.
- Employee screening records stored separately from patient charts and from personnel files.
- Every vendor touching the workflow appears on the BAA register with an execution date.
Where This Fits in Your Broader Documentation
A TB screening program is a useful stress test. It crosses billing, employee health, occupational health contracting, third-party disclosure, and at least four vendors — which means the gaps it exposes are rarely confined to the ppd cpt code line on a claim. If your vendor register is incomplete here, it is incomplete elsewhere. If your risk analysis never mentioned the screening-tracking spreadsheet on the shared drive, it is missing other systems too.
Start with the agreements, because they are the fastest thing to fix and the first thing anyone asks for. Build your signed BAA set for the reminder platform, the billing vendor, and the tracking software this month, then work outward to the risk analysis and policy set that should have listed them in the first place. The billing side of TB testing is small money. The records side is where the real exposure sits.