A medical assistant gives an RSV dose at 9:15 a.m. By 9:22, that single encounter has written to your EHR, queued a claim to your clearinghouse, decremented a lot in your vaccine inventory module, fired an HL7 message to the state immunization registry, and probably dropped the patient into a recall list. Five systems, one dose, and the rsv vaccine cpt code your staff selected sits at the center of all of it.

This is a practice-operations guide for administrators, billing leads, and privacy officers. It covers how practices determine and document RSV product and administration code selection, where the claims break, and — the part that gets skipped — which vendors and disclosures that workflow quietly creates. It is not clinical guidance and it does not tell you which code fits a particular patient.

Two Codes Per Dose, and Your Denials Usually Come From the Second One

RSV immunization claims are built from a product line and an administration line. Practices that treat this as one decision instead of two generate the bulk of their rework.

The product line

Product codes are specific to the manufacturer's product and formulation. The RSV vaccine product codes sit in the 906xx vaccine series — 90678, 90679, and 90683 each describe a distinct RSV vaccine product. Your coding staff should be mapping the NDC printed on the vial or syringe to the product code the payer recognizes, not selecting from memory.

Nirsevimab is the exception that catches people. It is a monoclonal antibody, not a vaccine, and it carries its own product codes (90380 and 90381, distinguished by dose volume) outside the vaccine series. Practices that assume it codes like a vaccine tend to discover otherwise through a denial batch three weeks later.

The administration line

Vaccine administration is reported separately — the 90471/90472 family for administration without counseling, and the 90460/90461 family for counseling-based administration in patients through age 18. Monoclonal antibody administration uses a different pair entirely: 96380 and 96381.

The mismatch — vaccine-series administration code paired with a monoclonal product code, or vice versa — is one of the more common preventable denials in immunization billing. Build the pairing into your charge template so the front-line user cannot mix families by hand.

Which RSV Vaccine CPT Code Applies? The Short Answer

For a featured-snippet-length answer: RSV vaccine products are reported with product codes in the 906xx series (90678, 90679, 90683), each tied to a specific manufacturer's product; nirsevimab, a monoclonal antibody rather than a vaccine, uses 90380 or 90381 by dose volume. Administration is billed separately — 90471/90472 or 90460/90461 for vaccines, 96380/96381 for the monoclonal. The correct rsv vaccine cpt code for any given encounter is determined by the product administered, the patient's age and payer, and the current-year CPT descriptors — verify against the AMA's current CPT code set and the payer's published immunization policy before you build the charge.

How Your Practice Documents Code Selection (and Why That File Matters)

Code selection is an administrative determination your practice has to be able to reconstruct. Auditors ask how you arrived at a code. "The EHR defaulted to it" is not a defense.

A workable process assigns four steps to named roles:

  • Inventory lead: records NDC, lot, expiration, and funding source (private purchase, VFC, state-supplied) at receipt.
  • Billing lead: maintains the NDC-to-CPT crosswalk and confirms effective dates when new codes or descriptor revisions publish. CPT codes for new immunization products often carry a distinct effective date; billing before that date produces a clean, silent denial.
  • Coding reviewer: signs off on the charge template pairing product and administration codes, plus any modifiers your payers require (preventive-service and state-supplied-product modifiers are the two your staff will hit most).
  • Practice administrator: owns the annual re-verification and the file that shows when each mapping changed and who approved it.

Keep that crosswalk in a controlled document with version history. When a payer recoups eighteen months of administration fees, the version history is what tells you whether the error was yours or theirs.

The Part D Problem: Why the Claim Doesn't Go Where Your Staff Expects

Adult RSV vaccination for Medicare patients generally falls under Part D, not Part B. Your medical claim scrubber will not catch this, because it is not a coding error — it is a benefit-category routing problem.

Under the Inflation Reduction Act, ACIP-recommended adult vaccines covered under Part D carry no cost sharing for the beneficiary. That is good news for patients and an operational headache for practices, because most physician offices are not set up to bill Part D. Practices resolve it in one of three ways: enroll to bill Part D directly, use a billing intermediary that submits pharmacy-benefit claims on your behalf, or refer the patient to a pharmacy partner. CMS's Medicare Part B immunization billing guidance is worth reading precisely to see what is not on the list.

Each of those three paths has a different privacy footprint. Direct enrollment adds a transaction type to your systems. A billing intermediary is a business associate and needs an executed BAA before the first claim. A pharmacy referral is a disclosure for treatment purposes — permitted without authorization — but if you are transmitting patient lists in bulk to a pharmacy partner rather than referring individuals, you have moved past treatment and into territory that needs a documented legal basis.

Supplied-Product Workflows: VFC, State Doses, and the $0 Product Line

When the product came to you free through VFC or a state program, you still report the product code — typically at a nominal or zero charge with the payer-required modifier — and bill only the administration. Practices that omit the product line entirely lose the registry and audit trail that proves the dose was accounted for.

The privacy angle here is eligibility screening. VFC eligibility categories require your front desk to collect and store insurance status and, in some categories, information about the patient's coverage circumstances. That data lives in your practice management system, gets reported to the state program, and is subject to the same access controls as everything else in the chart. It also shows up in VFC compliance site visits, where a reviewer will look at your records. Know in advance what your staff may show and what stays covered.

Every Dose Is a Disclosure: Registry Reporting You Cannot Turn Off

Immunization information system reporting is a public health disclosure. HIPAA permits it — HHS's guidance on disclosures for public health activities lays out the basis at 45 CFR 164.512(b) — and where state law requires reporting, the minimum necessary standard does not restrict what the law requires you to send.

That does not make the interface unmanaged. Three things belong on your privacy officer's list:

Some states require affirmative consent for adult records in the registry; others are opt-out; others mandate reporting outright. Your front desk needs a scripted answer and a documented workflow for the patient who says "don't put that in the state database." If your state allows opt-out, someone has to actually suppress the record — and someone has to verify the suppression held after the next EHR update.

2. The registry interface is usually vendor-mediated

Very few practices send HL7 directly to the state. There is an integration engine, an EHR module, or a middleware vendor in between. That intermediary is handling PHI on your behalf and belongs on your business associate inventory with a signed agreement, not on a handshake that predates your tenure.

3. Registry query is a read operation too

Staff who query the registry to check a patient's history are accessing records held by a third party. Access is logged. Curiosity lookups in a state registry produce the same category of problem as curiosity lookups in your EHR, and they are auditable by the state, not by you.

The Vendor List RSV Billing Quietly Expands

Run the dose through your systems and count the outside parties. A typical immunization workflow now touches a clearinghouse, an inventory and lot-tracking module, a registry interface vendor, a cold-chain temperature monitoring platform with a cloud portal, a patient reminder and recall messaging vendor, an eligibility-verification service, and — for practices routing to Part D — a pharmacy benefit intermediary.

Most of those handle PHI. All of them need a business associate agreement in place before the first record moves, and each new integration changes the data-flow map that your security risk analysis is supposed to describe. If your last risk analysis predates the RSV workflow you built in 2023 or 2024, it no longer describes your practice. Tools that generate a current risk analysis and the supporting policy set exist for exactly this problem — the point is that the assessment reflects the systems you actually run today, not the ones you ran three vaccine seasons ago.

For the vendor you onboarded without paperwork, a signature-ready business associate agreement is a same-afternoon fix. The harder work is the inventory: list every system that touched an immunization record this quarter and mark which ones have executed agreements. Most practices find two or three they forgot.

When a Vaccine Reminder Becomes Marketing

Recall campaigns are where immunization operations run into the marketing rule. A reminder that a patient is due for an immunization, sent by you as part of treatment, does not require authorization. The same message becomes marketing under 45 CFR 164.501 if a third party — a manufacturer, for instance — pays you to send it in exchange for describing their product. Payment plus product promotion equals authorization required.

Ask the question before the campaign, not after: who is funding this outreach, and is any part of the message describing a specific manufacturer's product? Document the answer. Also confirm your messaging vendor's consent handling, because telephone and text consent rules operate independently of HIPAA and carry their own exposure. The HHS/ONC Security Risk Assessment Tool is a reasonable starting point for documenting how these communication channels are secured.

Sensitive Categories: Maternal Immunization Records

RSV immunization administered during pregnancy creates a record that ties a patient to a pregnancy and a date. A federal court vacated most of the 2024 reproductive health privacy rule in 2025, so the attestation regime practices prepared for is largely not in force — but state law has not stood still, and several states impose their own restrictions on disclosing pregnancy-related information.

Practical instruction for your records staff: route any subpoena, third-party request, or unusual disclosure request involving pregnancy-related records to the privacy officer before responding. Do not let a records clerk make that call at the fax machine.

What to Verify Before Next Season

  1. Pull your current NDC-to-CPT crosswalk and confirm every mapping against the current-year CPT descriptors and each major payer's immunization policy.
  2. Test each charge template for correct product-plus-administration pairing, including the monoclonal antibody family.
  3. Confirm your Part D routing path and that any intermediary has an executed BAA.
  4. Document your state's registry consent or opt-out requirement and the exact screen where staff record it.
  5. List every vendor that touched an immunization record last quarter; reconcile against your BAA file.
  6. Confirm your risk analysis reflects the current data flows, including the registry interface and the temperature-monitoring portal.
  7. Review any planned recall campaign for third-party funding before it sends.

The billing side of this work pays for itself in reduced denials. The privacy side pays for itself once, on the day someone asks who had access to a patient's immunization record and you can answer in under an hour. If your documentation set cannot support that answer today, build the risk analysis and policy package before the next immunization season adds another vendor to the list.