Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 2, § 2.4

Sources of Data for MACs and UPICs

activein force · 2026-08-25 – presentas-observed

A. Contractors To Which This Section Applies

This section applies to MACs and UPICs. The sources of data for CERT and Recovery

Auditors are specified in their SOWs.

B. General

The data sources that MACs and UPICs use will depend upon the issue(s) being

addressed and the availability of existing data. CMS maintains numerous systems

housing Medicare, Parts A, B, and D claims, Beneficiary Entitlement, Enrollment and

Utilization data, Provider reference information. The IDR is the enterprise resource

designed to house and unify the data from disparate systems to enable cross-cutting

reporting and analysis. The IDR has been created with an aim toward reducing data

redundancy, providing flexibility to satisfy changing business needs and serve as the

relational data warehouse for core CMS data. The IDR provides the system platform and

database structures which enable one store of data to meet the various needs of our MAC

and UPIC community. The repository is leveraged by multiple reporting, analytical and

operational production applications.

Systematic data analysis requires MACs and UPICs to have in place the hardware and

software capability to profile providers in aggregate, by provider type, by common

specialties among providers, or individually. Some of the provider information that

should be used includes:

• Types of providers;

• Volume of business;

• Volume (or percentage) of Medicare/Medicaid patients;

• Prevalent types of services;

• Location;

• Relationships to other organizations;

• Types of ownership;

• Previous investigations by the UPIC;

• Size and composition of staff;

• Administrative costs;

• Claims history; and

• Other information needed to explain or clarify the issue(s) in question.

Where possible, the selection of providers should show a representative grouping, in

order to accurately reflect the extent of program losses.

C. Primary Source of Data

Claims data is the primary source of information used to identify and target fraudulent,

wasteful or abusive activities. Sources of claims data are:

• IDR--MACs and UPICs should utilize the reports accessible in the

system platform and database structures. Reports include the

following:

o Claims Summary Information report (CSI) which used to be called

Health Care Information System (HCIS),

o Part B Analytics System Report (PBASR), which show

comparative utilization ratios by code, MAC, and specialty,

o Short Term Alternatives for Therapy Services (STATS) which

shows Outpatient therapy professional and provider claims data,

o IDR Analysis Reports which include analysis reports and IDR volume

and statistics, and

o Focused Medical Review (FMR) which shows Part B claims

utilization and enrollment data.

The MACs and UPICs shall also use national data where available. National data for

services billed by skilled nursing facilities (SNFs) and home health agencies (HHAs) is

available at the CMS Data Center. When made available, contractors can access through

CMS One Program Integrity (see below One PI) or the CMS Enterprise Portal.

• CMS One Program Integrity (One PI) – Serves as a system application, tool

and databases providing access to the CMS IDR;

• Contractor Local Claims Data – Local data should be compiled in a way to

identify which providers or type of service in the contractor’s area may be

driving any unusual utilization patterns;

• CMS Fraud Prevention System(FPS) --When access is available, MACs

should consider periodically reviewing the information and data trends

resulting from national predictive models contained in the FPS;

• CMS PBASR--The Report stores data sets that contain annual timeframes, and

Healthcare Common Procedure Coding System HCPCs/CPT codes that

correspond to provider/supplier disciplines. Each data set displays the allowed

services, allowed charges, and payment amounts by HCPCs/CPT codes and

prominent modifiers. The PBAR is only accessible through the Enterprise

Portal; and

• CMS Claims Summary Information (CSI)—–Files contain Medicare Part A

(i.e., Inpatient, Skilled Nursing Facility, Home Health Agency (Part A & B)

and Hospice) and Medicare Part B (i.e., Outpatient) information based on the

type and State of the institutional provider. The data set names correspond with

the provider type. Brief descriptions of the provider types and the selected

reporting elements (e.g., units of service, billed charges, provider ZIP code,

etc.) are provided. Access is through the One PI portal.

D. Secondary Sources of Data

The MACs and UPICs should consider other sources of data in determining areas for

further analysis. These include:

• OIG and Government Accountability Office (GAO) reports;

• Fraud Alerts;

• Beneficiary, physician and provider complaints;

• Appeals data from QICs, including appeals overturn rate for a particular type

of claim;

• Referrals from the QIO, other contractors, CMS components, Medicaid

fraud control units, Office of the U.S. Attorney, or other federal programs;

• Suggestions provided directly or implicit in various reports and other materials

produced in the course of evaluation and audit activities, (e.g., contractor

evaluations, State assessment, CMS-directed studies, contractor or State audits

of providers);

• Referrals from medical licensing boards;

• Referrals from the CAC;

• Peer Review Reports such as the First -look Analysis Tool for Hospital

Outlier Monitoring (FATHOM) and Program to Evaluate Payment Patterns

Electronic Report (PEPPER), and Comparative Billing Reports;

• Information on new technologies and new or clarified benefits;

• Provider cost reports;

• Provider Statistical and Reimbursement (PS&R) System data;

• Enrollment data;

• Overpayment data;

• Pricing, data analysis, and coding (PDAC) data;

• Referrals from other internal and/or external sources (e.g., MAC audit staff,

audit staff or, MAC quality assurance (QA) staff);

• Medicare Learning Network – which includes MedLearn Matters articles

and Quarterly Provider Compliance Newsletters;

• IBM Cognos support for the Part D and Drug Data Processing System

(DDPS) using the Teradata data repository;

• CMS prepared data, such as a listing of distinct providers or suppliers and/or

bills that require medical review.

While the MAC, Recovery Auditor, and UPIC should investigate reports from the GAO,

congressional committees, Office of Inspector General Office of Audit Services (OIG

OAS), OIG OI, newspaper and magazine articles, as well as local and national television

and radio programs, highlighting areas of possible abuse, these types of leads should not

be used as a main source for leads on fraud, waste or abuse cases.

History

(Rev. 12772; Issued: 08-09-24; Effective: 09-20-24; Implementation: 09-20-24)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
100688865c51dd0dac4a7b1f062f9fa1ffb6c98ea863a3706e5d295a0d3fc48d
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.