US · guidance
CMS Pub. 100-04, ch. 24, § 30.1
EDI Enrollment
A/B MACs and CEDI are required to furnish new providers that request Medicare claim
privileges information on EDI. A/B MACs and CEDI are required to assess the
capability of entities to submit data electronically, establish their qualifications (see test
requirements in §50), and enroll and assign submitter EDI identification numbers to those
approved to use EDI. All providers are required to submit their claims electronically, per
ASCA, unless they qualify for a waiver (see section 90 below).
The EDI enrollment process for the Medicare beneficiary inquiry system HETS (HIPAA
Eligibility Transaction System (HETS 270/271)) is currently a separate process.
Information on the EDI enrollment process for HETS can be found on the CMS
HETSHelp website (http://www.cms.gov/HETSHelp/).
A provider must obtain an NPI and furnish that NPI to their A/B MAC and CEDI prior to
completion of an initial EDI Enrollment Agreement and issuance of an initial EDI
number and password by that contractor. The A/B MACs and CEDI are required to
verify that NPI is active in the Provider Enrollment, Chain and Ownership System
(PECOS). If the A/B MAC or CEDI is not able to verify the NPI as active in PECOS, the
EDI Enrollment Agreement is denied and the provider is encouraged to contact the A/B
MAC provider enrollment department (for Medicare Part A and Part B providers) or the
National Supplier Clearinghouse (for DME suppliers) to resolve the issue. Once the NPI
is properly verified, the provider can reapply the EDI Enrollment Agreement.
A provider’s EDI number and password serve as a provider’s electronic signature and the
provider would be liable if any entity with which the provider improperly shared the ID
and password performed an illegal action while using that ID and password. A
provider’s EDI access number and password are not part of the capital property of the
provider’s operation, and may not be given to a new owner of the provider’s operation.
A new owner must obtain their own EDI access number and password. When leaving the
Medicare Program, a provider must notify their MAC to deactivate the EDI number.
If providers elect to submit/receive transactions electronically using a third party such as
a billing agent or a clearinghouse, the A/B MACs or CEDI must notify those providers
that they are required to have an agreement signed by that third party. The third party
must agree to meet the same Medicare security and privacy requirements that apply to the
provider in regard to viewing or use of Medicare beneficiary data. (These agreements are
not to be submitted to Medicare, but are to be retained by the providers.) The providers
must also be informed that they are not permitted to share their personal EDI access
number and password with any billing agent or clearinghouse. Providers must also not
share their personal EDI access number to anyone on their own staff who does not need
to see the data for completion of a valid electronic claim, to process a remittance advice
for a claim, to verify beneficiary eligibility, or to determine the status of a claim. No
other non-staff individuals or entities may be permitted to use a provider’s EDI number
and password to access Medicare systems. Clearinghouse and other third party
representatives must obtain and use their own unique EDI access number and password
from those A/B MACs or CEDI to whom they will send or receive EDI transactions. For
a complete reference to security requirements see section 40.1.2.2 below and refer to the
Appendix A CMSR High Impact Level Data document (sections IA-2 and SA-9) located
on the CMS website https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/CIO-Directives-and-Policies/CIO-IT-Policy-Library-
Items/STANDARD-ARS-Acceptable-Risk-Safeguards.html.
History
(Rev.: 4388; Issued: 09-06-19; Effective: 10-07-19; Implementation: 10-07-19)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
dcb1cdc985003d254b4de490463499fbcb92758b4af24cc2f182c2cc3c80834c
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.