Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 2, § 2.3

Sources of Data for UPICs

activein force · 2026-08-25 – presentas-observed

The term Medicare beneficiary identifier (Mbi) is a general term describing a

beneficiary's Medicare identification number. For purposes of this manual, Medicare

beneficiary identifier references both the Health Insurance Claim Number (HICN) and

the Medicare Beneficiary Identifier (MBI) during the new Medicare card transition

period and after for certain business areas that will continue to use the HICN as part of

their processes.

A. Contractors To Which This Section Applies

This section applies to UPICs.

B. General

The UPICs approach for combining claims data (MAC data, Recovery Auditor data from

the Recovery Auditor data warehouse) and other data to create a platform for conducting

complex data analysis shall be documented in their Information Technology Systems

Plan. By combining data from various sources, the UPIC will present an entire picture of

a beneficiary’s claim history regardless of where the claim was processed. The primary

source of this data will be the CMS shared systems data, National Claims History (NCH),

and Integrated Data Repository (IDR). The UPIC shall be responsible for obtaining data

for all beneficiaries for whom the MAC(s) paid the claims.

At a minimum, UPICs are required to store the most recent 36 months’ worth of data

(including Part A, Part B, DME, home health & hospice) for the jurisdiction or zone defined

in their task order.

If the jurisdiction of the MAC(s) is not defined geographically, the UPIC shall obtain a

complete beneficiary claims history for each unique beneficiary for whom the MAC(s)

paid a claim.

EXAMPLE 1: The MAC(s) jurisdiction covers Maryland but includes a hospital chain

with facilities in Montana. The UPIC would request claims history from shared systems,

NCH, or IDR for all claims paid by the MAC(s).

EXAMPLE 2: The MAC(s) jurisdiction covers Maryland, a beneficiary lives in

Pennsylvania, and the beneficiary saw a doctor in Maryland. The UPIC would

request from shared systems, NCH, or IDR for all claims paid by the MAC(s).

The UPICs will not be able to tap data from the Common Working File (CWF).

The UPICs should, at their discretion, if agreement and cooperation of the MAC(s) are

obtained, use data directly from the claims processing system of the MAC(s), and then

supplement the other data using NCH.

In developing this plan, the UPICs shall address the above requirements and, at a

minimum, establish read-only access to the MAC’s shared claims processing system(s)

and access to the Part A, B, and D data available through the NCH for the jurisdictional

area defined in the Task Order. The UPIC shall obtain denial data through the MACs and

document the process for obtaining this data from the MAC(s) in the Joint Operating

Agreement. At a minimum, the denial data shall include data for edits that were requested

and/or recommended by the UPIC.

The UPIC shall have the ability to receive, load, and manipulate CMS data. The data

shall also be maintained in accordance with CMS and Federal privacy laws and

regulations as described in the CMS Data Use Agreement. For planning purposes, the

UPICs should assume that there are 30 claims per Medicare beneficiary identifier (Mbi)

per year, on average. A claim record is about 1000 bytes. To calculate the storage space

necessary, use the following formula:

(#Mbis) X (30 claims) X (#years) X (1000) = #bytes

The CMS contract officer’s representative (COR) and UPIC will need to complete:

• A data use agreement to give permission to receive privacy protected data;

• A Data request form to specify all data required by the UPIC;

• A HDC application for HDC access and/or CMS systems’ access to get access

to the data center and/or to specify which CMS systems the UPIC will access;

• A DESY system application form. (This is provided to the UPIC

post- award).

History

(Rev. 10365; Issued: 10-02-20; Effective: 08-27-20; Implementation: 08-27-20)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
0009395e055e49f646ae578d177ded2e7ec33125197a6430632b29d63e590516
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.