What Vaccines Are Covered by Medicare Part B: Ops Guide
Three vaccine categories get paid under Part B on a routine preventive basis. Everything else your Medicare patients ask for either falls under a narrow injury-and-exposure rule or lands in Part D, where your practice usually cannot bill it at all. If your front desk does not know which bucket a request falls into, you get the same three outcomes every autumn: unpaid claims, patients billed for something they were told was free, and a shelf of expired inventory.
This guide covers what vaccines are covered by Medicare Part B from an administrative standpoint — the coverage buckets, the roster-billing mechanics, the Part D handoff — and then makes explicit the privacy, records, and vendor obligations that ride along with an immunization program. It is written for administrators and billing staff, not for clinicians deciding what a patient needs.
What Vaccines Are Covered by Medicare Part B: The Short Answer
Part B covers vaccines in two distinct ways, and the distinction drives your cost-sharing conversation at the front desk.
Preventive vaccines paid under Part B, with the deductible and coinsurance waived:
- Influenza (seasonal, once per flu season; a second dose in the same season may be payable when medically necessary)
- Pneumococcal
- Hepatitis B, for beneficiaries your clinicians document as intermediate or high risk
- COVID-19
Vaccines Part B covers as treatment, subject to the deductible and coinsurance: vaccines administered because of an injury or direct exposure to a disease or condition — the classic examples being rabies vaccine after an animal bite and tetanus vaccine after a wound. These are billed as treatment, not prevention, and the patient owes their normal cost share.
Everything else runs through Part D: shingles, RSV, Tdap given for routine prevention rather than after a wound, and other adult vaccines recommended by ACIP. Since January 1, 2023, those carry no cost sharing for the beneficiary under their Part D plan — but the payment path is a drug plan, not your Part B claim.
Before each season, have your billing lead reconcile administration codes, diagnosis requirements, and frequency edits against your Medicare Administrative Contractor's current guidance and the CMS Medicare Learning Network booklet on Part B immunization billing. Do not carry last year's crosswalk forward on faith.
The Part D Handoff That Eats Your Front Desk's Morning
A 71-year-old asks for a shingles vaccine at her wellness visit. Coverage exists, cost sharing is zero, and your practice still may have no clean way to get paid for it.
Most physician offices are not enrolled to bill Part D. The realistic options are: refer to a pharmacy, bill the patient and give her a receipt to submit to her plan for reimbursement (a workflow patients hate and often abandon), or contract with a third-party vendor that processes Part D vaccine claims on your behalf in real time.
Pick one, write it down, and train to it. An undocumented policy here produces improvised decisions at the desk, which is how patients get balance-billed for something their plan covers in full.
The vendor decision is also a PHI decision
If you choose the third-party Part D billing route, that vendor receives names, dates of birth, Medicare Beneficiary Identifiers, plan enrollment data, and administration records. That is a business associate relationship, full stop. Get the agreement signed before the first transmission, not after the first claim rejects. If you need a defensible starting point, a signature-ready Business Associate Agreement beats the one-page waiver most small vendors will hand you.
Roster Billing Turns a Spreadsheet Into a PHI Repository
Mass immunizers can use simplified roster billing for influenza and pneumococcal vaccine — and it is efficient precisely because it consolidates many beneficiaries onto one submission. That efficiency is the privacy problem.
Your roster contains beneficiary names, MBIs, dates of birth, sex, dates of service, and the vaccine administered. It is a Designated Record Set contributor and it is electronic PHI the moment someone opens it in a spreadsheet.
Ask these four questions before flu season, and get answers in writing:
- Where does the file live? A named folder on an access-controlled network share or EHR module — not a desktop, not a personal drive, not a USB stick that rides home in someone's bag.
- Who can open it? Role-based access limited to the staff who build, bill, and reconcile it. Your scheduler does not need it.
- How does it reach your billing service? SFTP or a portal upload. Not an email attachment, and never an unencrypted one.
- When does it get purged? Set a retention period consistent with your state's medical-record rules and your six-year HIPAA documentation obligation, and enforce it.
Minimum necessary applies to the columns, too. If your billing vendor does not need a home address or phone number to submit the claim, do not send it.
Eligibility Checks, Clearinghouses, and the Vendors Your Program Adds
An immunization program quietly expands your vendor inventory. Walk the data flow for a single dose and count the third parties that touch identifiable information:
- Eligibility and benefit verification tool (is this patient in Part B, and has the once-per-season edit already fired?)
- Clearinghouse submitting the claim
- Billing service or RCM partner reconciling remittances
- EHR or standalone inventory module recording lot number, site, and route
- State immunization information system, often reached through a health information exchange intermediary
- Patient outreach vendor sending the "flu shots are here" texts
- Print-and-mail house handling recall letters to patients who never respond to texts
Six or seven relationships for one clinical act. Each one either has a current business associate agreement or it is an unaddressed disclosure sitting on your risk register. Temperature-monitoring services for your vaccine refrigerator usually do not receive PHI — verify that, because some bundle patient-facing modules you did not ask for.
When your vendor list, data flows, and physical sites change — and a seasonal immunization program changes all three — your Security Rule risk analysis is out of date. That is the moment to refresh it, and generating an up-to-date HIPAA risk analysis and the supporting policy set is considerably faster than reconstructing last year's assessment from memory in the middle of October.
Flu Reminder Campaigns Cross the Marketing Line When a Manufacturer Pays
A text message telling your established patients that flu vaccine has arrived is a treatment communication. You do not need an authorization to send it.
Change one fact and the analysis flips. If a vaccine manufacturer or distributor pays your practice — or pays the outreach vendor on your behalf — to send communications promoting that company's product, you have received financial remuneration from a third party whose product is being marketed. HHS guidance on marketing under the Privacy Rule is direct about this: that campaign requires a prior written authorization from each patient, and the authorization must disclose the remuneration.
Practical control: route every co-funded or vendor-sponsored outreach offer through your privacy officer before anyone signs. Add a single line to your outreach approval form — "Is any part of this campaign funded by a manufacturer, distributor, or their agent?" — and require an answer. Also confirm your texting workflow honors stop requests, because telephone consumer protection rules apply on top of HIPAA and neither excuses the other.
Registry Reporting Is Permitted — Log It Anyway
Reporting doses to your state immunization information system is a public health disclosure permitted without authorization. You do not need a patient's signature, and you should not build a workflow that pretends you do.
Two operational cautions. First, state law varies on adult registry participation — some jurisdictions require consent or offer an opt-out for adults, and your workflow must reflect your state, not the general federal rule. Second, permitted disclosures under the public health provision are accountable disclosures. If a patient exercises their right to an accounting, you need to produce them.
Confirm your EHR logs registry submissions in a retrievable format rather than firing them into an interface with no audit trail. If it does not, your privacy officer needs a manual log — and needs to know that before the first request arrives, not during it.
Immunization Records Are Access Requests, and the Clock Is 30 Days
Patients ask for immunization records constantly: employers, travel, long-term care admission, a new specialist. Those are right-of-access requests under the Privacy Rule, and the standard applies whether the request covers a 40-page chart or a single line item.
You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. You may charge only a reasonable, cost-based fee, and "we print it at the desk" is not a billing event. Review the HHS individual right of access guidance with whoever staffs your records line, then confirm they can locate a dose administered at an offsite clinic three years ago.
Third-party requests are not access requests
When an employer or a long-term care facility asks directly for vaccine history, that is a disclosure to a third party requiring an authorization — different form, different log entry. Train your front desk to distinguish the two, because the person asking is often insistent and always in a hurry.
Offsite Clinics: Paper, Locked Boxes, and Chain of Custody
Health fairs, senior centers, employer sites, and skilled nursing facilities are where immunization programs and privacy programs collide. The controls you rely on inside the building — badge access, locked file rooms, screen timeouts — do not travel.
Assign these before the van leaves:
- Sign-in sheets: one line per patient, no shared clipboard displaying prior entrants' names and dates of birth.
- Consent and screening forms: collected into a locked container, counted at the site and counted again on return, with a named person signing for the count both times.
- Devices: encrypted, screen-locked, and on a hotspot or cellular connection rather than the venue's guest Wi-Fi.
- Rosters: built from the site forms after return, in the office, on a controlled drive.
- Overheard conversations: position the administration station so screening questions are not audible to the next four people in line. Incidental disclosure has limits, and a queue is not a treatment area.
Document the offsite workflow as a facility in your risk analysis. An OCR investigator asking about physical safeguards will not accept "that was a one-day event."
A Pre-Season Checklist With Names Attached
90 days out — billing lead: reconcile administration and vaccine codes, frequency edits, and diagnosis requirements against current MAC guidance. Document how the practice determines and records code selection, including which staff role confirms it and what documentation supports the risk-based hepatitis B determination.
75 days out — practice administrator: decide and write down the Part D handoff policy. Refer, receipt, or contracted vendor. One answer.
60 days out — privacy officer: inventory every vendor in the immunization data flow. Confirm a current, signed BAA for each. Flag gaps with a due date.
45 days out — privacy officer and IT: refresh the risk analysis to reflect new vendors, new offsite sites, and any new device use. Update policies that changed as a result.
30 days out — front-desk supervisor: train the coverage conversation. Which vaccines run through Part B, which run through the drug plan, what the patient owes for an exposure-related dose, and how to route a records request.
Week of launch — clinical and billing leads together: run three test claims and three test registry submissions. Confirm both produce retrievable audit entries.
Knowing what vaccines are covered by Medicare Part B is the easy half of this. The half that generates complaints, breach reports, and unpaid claims is the plumbing underneath it: who holds the roster, who signed a BAA, who logged the registry disclosure, and who answers the records line in 30 days.
If your risk analysis has not been touched since before you added the outreach vendor and the offsite clinics, start there — you can generate the risk analysis, policies, and supporting compliance documentation in less time than it takes to schedule the meeting where you would otherwise argue about it.