Bindinglaw

US · guidance

CMS Pub. 100-04, ch. 24, § 30.1

EDI Enrollment

activein force · 2026-08-25 – presentas-observed

A/B MACs and CEDI are required to furnish new providers that request Medicare claim

privileges information on EDI. A/B MACs and CEDI are required to assess the

capability of entities to submit data electronically, establish their qualifications (see test

requirements in §50), and enroll and assign submitter EDI identification numbers to those

approved to use EDI. All providers are required to submit their claims electronically, per

ASCA, unless they qualify for a waiver (see section 90 below).

The EDI enrollment process for the Medicare beneficiary inquiry system HETS (HIPAA

Eligibility Transaction System (HETS 270/271)) is currently a separate process.

Information on the EDI enrollment process for HETS can be found on the CMS

HETSHelp website (http://www.cms.gov/HETSHelp/).

A provider must obtain an NPI and furnish that NPI to their A/B MAC and CEDI prior to

completion of an initial EDI Enrollment Agreement and issuance of an initial EDI

number and password by that contractor. The A/B MACs and CEDI are required to

verify that NPI is active in the Provider Enrollment, Chain and Ownership System

(PECOS). If the A/B MAC or CEDI is not able to verify the NPI as active in PECOS, the

EDI Enrollment Agreement is denied and the provider is encouraged to contact the A/B

MAC provider enrollment department (for Medicare Part A and Part B providers) or the

National Supplier Clearinghouse (for DME suppliers) to resolve the issue. Once the NPI

is properly verified, the provider can reapply the EDI Enrollment Agreement.

A provider’s EDI number and password serve as a provider’s electronic signature and the

provider would be liable if any entity with which the provider improperly shared the ID

and password performed an illegal action while using that ID and password. A

provider’s EDI access number and password are not part of the capital property of the

provider’s operation, and may not be given to a new owner of the provider’s operation.

A new owner must obtain their own EDI access number and password. When leaving the

Medicare Program, a provider must notify their MAC to deactivate the EDI number.

If providers elect to submit/receive transactions electronically using a third party such as

a billing agent or a clearinghouse, the A/B MACs or CEDI must notify those providers

that they are required to have an agreement signed by that third party. The third party

must agree to meet the same Medicare security and privacy requirements that apply to the

provider in regard to viewing or use of Medicare beneficiary data. (These agreements are

not to be submitted to Medicare, but are to be retained by the providers.) The providers

must also be informed that they are not permitted to share their personal EDI access

number and password with any billing agent or clearinghouse. Providers must also not

share their personal EDI access number to anyone on their own staff who does not need

to see the data for completion of a valid electronic claim, to process a remittance advice

for a claim, to verify beneficiary eligibility, or to determine the status of a claim. No

other non-staff individuals or entities may be permitted to use a provider’s EDI number

and password to access Medicare systems. Clearinghouse and other third party

representatives must obtain and use their own unique EDI access number and password

from those A/B MACs or CEDI to whom they will send or receive EDI transactions. For

a complete reference to security requirements see section 40.1.2.2 below and refer to the

Appendix A CMSR High Impact Level Data document (sections IA-2 and SA-9) located

on the CMS website https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/CIO-Directives-and-Policies/CIO-IT-Policy-Library-

Items/STANDARD-ARS-Acceptable-Risk-Safeguards.html.

History

(Rev.: 4388; Issued: 09-06-19; Effective: 10-07-19; Implementation: 10-07-19)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
dcb1cdc985003d254b4de490463499fbcb92758b4af24cc2f182c2cc3c80834c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-04, ch. 24, § 30.1 — EDI Enrollment · binding.law