US · guidance
CMS Pub. 100-08, ch. 2, § 2.3
Sources of Data for UPICs
The term Medicare beneficiary identifier (Mbi) is a general term describing a
beneficiary's Medicare identification number. For purposes of this manual, Medicare
beneficiary identifier references both the Health Insurance Claim Number (HICN) and
the Medicare Beneficiary Identifier (MBI) during the new Medicare card transition
period and after for certain business areas that will continue to use the HICN as part of
their processes.
A. Contractors To Which This Section Applies
This section applies to UPICs.
B. General
The UPICs approach for combining claims data (MAC data, Recovery Auditor data from
the Recovery Auditor data warehouse) and other data to create a platform for conducting
complex data analysis shall be documented in their Information Technology Systems
Plan. By combining data from various sources, the UPIC will present an entire picture of
a beneficiary’s claim history regardless of where the claim was processed. The primary
source of this data will be the CMS shared systems data, National Claims History (NCH),
and Integrated Data Repository (IDR). The UPIC shall be responsible for obtaining data
for all beneficiaries for whom the MAC(s) paid the claims.
At a minimum, UPICs are required to store the most recent 36 months’ worth of data
(including Part A, Part B, DME, home health & hospice) for the jurisdiction or zone defined
in their task order.
If the jurisdiction of the MAC(s) is not defined geographically, the UPIC shall obtain a
complete beneficiary claims history for each unique beneficiary for whom the MAC(s)
paid a claim.
EXAMPLE 1: The MAC(s) jurisdiction covers Maryland but includes a hospital chain
with facilities in Montana. The UPIC would request claims history from shared systems,
NCH, or IDR for all claims paid by the MAC(s).
EXAMPLE 2: The MAC(s) jurisdiction covers Maryland, a beneficiary lives in
Pennsylvania, and the beneficiary saw a doctor in Maryland. The UPIC would
request from shared systems, NCH, or IDR for all claims paid by the MAC(s).
The UPICs will not be able to tap data from the Common Working File (CWF).
The UPICs should, at their discretion, if agreement and cooperation of the MAC(s) are
obtained, use data directly from the claims processing system of the MAC(s), and then
supplement the other data using NCH.
In developing this plan, the UPICs shall address the above requirements and, at a
minimum, establish read-only access to the MAC’s shared claims processing system(s)
and access to the Part A, B, and D data available through the NCH for the jurisdictional
area defined in the Task Order. The UPIC shall obtain denial data through the MACs and
document the process for obtaining this data from the MAC(s) in the Joint Operating
Agreement. At a minimum, the denial data shall include data for edits that were requested
and/or recommended by the UPIC.
The UPIC shall have the ability to receive, load, and manipulate CMS data. The data
shall also be maintained in accordance with CMS and Federal privacy laws and
regulations as described in the CMS Data Use Agreement. For planning purposes, the
UPICs should assume that there are 30 claims per Medicare beneficiary identifier (Mbi)
per year, on average. A claim record is about 1000 bytes. To calculate the storage space
necessary, use the following formula:
(#Mbis) X (30 claims) X (#years) X (1000) = #bytes
The CMS contract officer’s representative (COR) and UPIC will need to complete:
• A data use agreement to give permission to receive privacy protected data;
• A Data request form to specify all data required by the UPIC;
• A HDC application for HDC access and/or CMS systems’ access to get access
to the data center and/or to specify which CMS systems the UPIC will access;
• A DESY system application form. (This is provided to the UPIC
post- award).
History
(Rev. 10365; Issued: 10-02-20; Effective: 08-27-20; Implementation: 08-27-20)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
0009395e055e49f646ae578d177ded2e7ec33125197a6430632b29d63e590516
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.