Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 10, § 10.3

Medicare Enrollment Forms – Information, Processing, and PECOS

activein force · 2026-08-25 – presentas-observed

2.0

(Rev. 13355; Issued: 08-13-25; Effective: 05-05-25; Implementation: 05-05-25)

Sections 10.3, 10.3.1, 10.3.2 and 10.3.3 of this chapter provide guidance and information

regarding the processing of provider enrollment forms. They also include new verification and

operational instructions pertaining to the implementation of PECOS 2.0. Upon the

implementation of PECOS 2.0 (and except as stated otherwise), said instructions in sections 10.3

through 10.3.3 take precedence over all other contrary guidance in this chapter. The contractor

shall not follow the PECOS 2.0 instructions in this chapter prior to the system’s implementation

(or, as applicable, before PECOS 2.0 has been updated to include a certain feature to which the

instruction applies). For more detailed information concerning the contractor’s logistical

navigation of the PECOS 2.0 system, the contractor can consult the PECOS 2.0 “Knowledge

Base” (available within PECOS) and other technical direction.

Section 10.3 discusses the basic processes, capabilities, and policies associated with PECOS 2.0.

The contractor shall adhere to the instructions in 10.3 when processing the applications described

in sections 10.3.1 through 10.3.3.

A. Basic Function

Except as otherwise specified by CMS, PECOS 2.0 automatically processes all web-based

applications upon submission as well as all paper applications after the contractor performs

intake actions (e.g., entering the paper-submitted data into PECOS). (This includes all CMS-

855, CMS-20134, CMS-588, and CMS-460 forms, and irrespective of the type of enrollment

transaction involved (e.g., initial applications, change requests.) In general, PECOS 2.0 will only

halt the automated process: (a) for more complex application situations (e.g., changes of

ownership); or (b) if the contractor must manually perform certain verification activities (e.g.,

review of adverse action documentation). Upon this stoppage:

(i) The application exits the automatic process and requires the contractor to manually intervene.

(ii) PECOS 2.0 creates a list that outlines the verifications/checks performed and when they

occurred.

For web-based applications, providers and suppliers must upload all required documentation,

submit all signatures, and pay an application fee or submit a hardship request before submitting

the application. PECOS requires the application (including the Form CMS-588 and Form CMS-

460) to be 100% complete before the provider/supplier submits it. This reduces the amount of

development the contractor must undertake. In addition, PECOS notifies the contractor of any

change in the status of an application, which helps expedite processing.

(Note that PECOS 2.0 will also conduct certain validations/checks for paper applications after

the contractor completes its data entry of the provider’s or supplier’s application information.)

B. Important Aspects of PECOS 2.0

This subsection (B) discusses various aspects of PECOS 2.0’s capabilities and other concepts

and instructions related thereto. (For purposes of the remainder of section 10.3 and of section

10.3.1, the term “PECOS” means “PECOS 2.0” (although PECOS 2.0 will still occasionally be

used) and the term “PECOS applications” means “web-based applications.”)

1. Verification

Some of the Form CMS-855/20134 application data elements and other enrollment functions that

will be part of PECOS’s verification/operational capabilities are:

(i) Validation of Social Security Numbers (SSN) (though PECOS will not verify employer

identification numbers (EIN) with the IRS)

(ii) Validation of National Provider Identifiers (NPI)

(iii) Performing Delivery Point Verification

(iv) Review of the Death Master File (DMF)

(v) Reviewing for Office of Inspector General (OIG) exclusions per the Medicare Exclusions

Database (MED) (Note that if the System for Award Management (SAM) is not part of PECOS’s

or APS’s verifications, the contractor must perform SAM reviews manually.)

(vi) Checking whether an active reenrollment bar exists. (PECOS maintains the reenrollment bar

list. For each individual or entity added to an application, PECOS will perform a processing

check.))

(vii) Inclusion of high-risk screening list and all other CMS generated lists (e.g., overpayments,

affiliations, Medicaid terminations)

(viii) Facilitation and verification of application fee payment

(ix) Ordering site visit and fingerprinting

(x) Reviewing licensure status via APS. (Note that the contractor may rely on APS licensure

verification in limited scenarios, including revalidation and some changes of information. See

subsection (B)(8) below for more information on licensure.) However, the contractor must still

manually check for certifications, such as for non-physician practitioners.

(xi) Criminal background (e.g., the contractor need not click into APS)

(xii) Complete automated processing of revalidation applications that do not include any changed

information and the application is e-signed

(xiii) Excluding CMS Certification Numbers (CCNs) for certified providers/suppliers, generation

and management of provider transaction access numbers (PTANs) as needed. (PECOS can

allocate locality information as well as determine how many PTANs are required for the

enrollment situation in question and the associated effective date(s). The contractor can make

edits as warranted and consistent with CMS policy. The contractor shall ensure that: (1) any

PECOS-established effective date for a PECOS-issued PTAN is consistent with CMS regulations

and policy; and (2) all PECOS-generated PTANs were issued consistent with CMS policy.

Except as otherwise specified in current or future CMS guidance, the contractor must manually

handle all other validation and processing activities not referenced in (i) through (xiii) above. As

previously indicated, and after performing validations, PECOS will identify for the contractor

those data elements requiring manual intervention because the data element (e.g., EIN, certain

adverse actions, legal business name, certifications) is not one that PECOS checks. Moreover,

automatic processing only occurs with applications for which PECOS has not identified errors

(e.g., additional screening needed, unverified addresses, etc.). If errors exist and/or the

application cannot otherwise be automatically processed further, PECOS reverts to manual

processing and notifies the contractor thereof.

If the contractor manually corrects a data element that PECOS could not validate, PECOS

attempts to reverify said data; the contractor need not manually perform this task.

All required data verification checks must be documented in PECOS (though some of these will

be automatically recorded in PECOS if the system itself verifies the particular data element).

2. Documentation

a. Basic Principle

As a general rule (and for both web and paper applications), the provider/supplier need not

submit documentation unless either of the following instances applies:

i. All other means the contractor is authorized to use (per this chapter) for validating the

information have been exhausted (e.g., licensure web sites, state board web sites, APS, etc.)

AND the supplier has not previously submitted said documentation in PECOS 1.0 or 2.0 (e.g., as

part of a prior revalidation); OR

ii. The provider/supplier is furnishing or changing data for which this chapter specifically and

unequivocally requires the submission of documentation to validate (e.g., adverse legal action

documentation per section 10.6.6) AND the supplier has not previously submitted said

documentation in PECOS 1.0 or 2.0.

The above principle applies to all application types and transactions and notwithstanding any

other instruction to the contrary in this chapter.

Note that documents that have been uploaded into PECOS 1.0 will be migrated to PECOS 2.0.

b. Operational Procedures When Documentation Is Required

i. PECOS Applications – As mentioned earlier, providers/suppliers must upload required

documentation before submitting the application. However, because PECOS cannot “read”

documents or verify their exact contents, the contractor shall manually review and confirm the

type and contents of the submitted document. Once this confirmation occurs, the contractor need

not reverify the document when subsequent applications are submitted unless information

relative to that document has changed.

Except as stated in subsection (2)(a) above, a provider/supplier submitting a web application

need not upload required documentation if it has previously submitted that document. The

provider/supplier will be able to see the document in question in its PECOS record and select and

apply that document to its current application.

ii. Paper Applications - The provider/supplier shall mail, fax, or e-mail such documentation

(e.g., organizational charts per Section 5 of the Form CMS-855A) with its application. The

contractor shall upload received documentation into PECOS when processing the application;

each document, however, must be separately uploaded (e.g., the Form CMS-855 CHOW

application must be uploaded separately from the sales agreement). For paper applications

(including initial enrollments), if the provider failed to submit required documentation, the

contractor shall review the provider/supplier’s enrollment record to see if the provider/supplier

previously submitted the document with a prior application. If it was previously submitted, the

contractor shall apply the document to the current application without developing for it with the

provider/supplier. If it was not previously submitted, the contractor shall develop for it.

iii. Documentation Classification

When documentation is uploaded into PECOS by the provider/supplier (PECOS applications) or

the contractor (paper applications), the contractor shall ensure that, as applicable:

• Each document is uploaded in the application section with which it is most closely associated

(e.g., criminal conviction documentation in the final adverse action section; IDTF technician

certifications in the IDTF section).

• If the provider/supplier submits one file containing different document types (e.g., a CP-575,

an ownership chart), each document type within said file is separated and uploaded in its

appropriate application section (per the prior bullet).

If the provider/supplier does not submit its documents consistent with the practices in the two

above bullets, the contractor shall remedy the issue itself without requesting the

provider/supplier to do so.

Note that each page within a multi-page document need not be separately and individually

uploaded in its own file. The document and all of the pages therein can be uploaded as a single,

combined file.

3. Correspondence and Coordination – PECOS Applications Only

a. General Concept

Except as otherwise permitted or specified in sections 10.3.1 through 10.3.3, the contractor shall

send written enrollment-related correspondence to the provider/supplier via PECOS (hereafter

sometimes referenced as the PECOS Communication Vehicle (PCV)). This includes most types

of provider-contractor correspondence, such as emails, revalidation requests, development

requests, approval letters, etc. PECOS will store all such correspondence. Certain written

communications, however, cannot be made through the PCV at this point; in such situations, the

contractor shall: (1) follow current procedures for sending/receiving such communications; and

(2) manually upload a copy of the written correspondence to the related application in PECOS.

Note that the “PCV” is not a separate system or module but is simply a term to describe

PECOS’s automated processes for sending correspondence, automatically e-mailing letters

and/or generating letters for mailing, etc. It is not an interface the contractor will go to review

incoming correspondence.

b. Telephonic Communications

It is emphasized that nothing in sections 10.3 through 10.3.3 precludes the use of telephonic

communication/development (including for web applications) with the provider/supplier if it is

otherwise permitted under these sections. However, the contractor shall document such

telephonic communications in PECOS’ Application Timeline with the same data elements as

those required under section 10.6.19(L) of this chapter.

4. Party Relationships

a. Consolidated Applications and National Entity Profiles

In PECOS 2.0, individuals and organizations will have National Entity Profiles (hereafter

“Profile(s)” or “National Profile(s)”) that are unique by legal name, tax identification number,

and ownership. (This is similar to the associate profile in legacy PECOS, the difference being

that an entity’s ownership information and other data unique to that organization is shared at the

National Profile level in PECOS 2.0.) A party’s National Profile will show Medicare enrollment

record(s) for each of their provider/supplier types (e.g., ABC, Inc. will have one National Profile

that includes 3 separate Medicare enrollment records: one for its clinic/group, one for its durable

medical equipment (DME) enrollment, and one for its IDTF enrollment). All such records will

be grouped by provider/supplier type due to differences in data collection and/or processing

requirements.

Under PECOS 2.0, a provider/supplier can submit one “consolidated application” per

provider/supplier type; said application will be split such that it results in the submission of one

application to each contractor jurisdiction per provider/supplier type group. Consider the

following examples:

EXAMPLE A: A group practice exists in Nebraska, Iowa, and Missouri, all of which are in the

same contractor jurisdiction. Here: (1) only one application is submitted to the contractor as

opposed to three (one for each state); and (2) for inventory purposes, this will constitute only one

application (not three). (Note that the contractor need only send one determination letter

(approval, denial, etc.) to the group practice even though three states are involved. This is

because only one application was submitted.)

EXAMPLE B: A group practice exists in Ohio, Pennsylvania, and West Virginia, each of which

are in separate contractor jurisdictions. Here, the group may submit a consolidated application

for all three enrollments, which PECOS would then split into three separate applications because

there are three separate contractor jurisdictions. (In this example, the fact that there are three

separate states involved is largely irrelevant for application submission purposes. The central

consideration is the number of contractor jurisdictions.)

EXAMPLE C: An organization has a group practice and an IDTF in one contractor jurisdiction.

The entity must submit two applications because the clinic and IDTF are two distinct

provider/supplier types and the enrollments are therefore grouped separately.

(Regarding Example C, note that a physician/practitioner can change a specialty within its broad

supplier type category via PECOS 2.0 (e.g., changing from a nurse practitioner to a physician

assistant). However (and as with the aforementioned group-IDTF scenario), a physician cannot

change an enrollment to that of an NPP, or vice versa, by this means absent a new enrollment.)

National Profile (or “global”) data is only screened when changed. This means that global

information is not rescreened each time the provider/supplier submits an application pertaining to

an enrollment record under/within that National Profile. In a similar vein, though, changes to

National Profile information (e.g., legal business names (LBN), ownership) made on a single

application are applied to all of the provider/supplier’s enrollments. That is, an authorized or

delegated official can make changes to National Profile information for numerous and associated

providers/suppliers at one time, whereas data changes that are specific to a unique enrollment

only apply to that enrollment. An illustration follows:

EXAMPLE D: Suppose 20 separately enrolled IDTFs have four common owners: W, X, Y, and

Z. W sells its 25 percent interest to V. Under PECOS, this change can be reported via a

single/consolidated application submission. Twenty separate submissions are unnecessary. Now

assume that two of these group practices are changing their respective addresses. Here, the

entity must submit an application that indicates the two separate change requests because the

practice location data is unique to each enrollment.

Once the consolidated application has been processed and finalized, PECOS creates/updates all

applicable individual enrollment records as though a single application had been submitted for

each.

Though providers/suppliers may submit consolidated applications that update multiple

enrollments of the same provider/supplier type or grouping, they still remain free to submit

separate/individual applications for each enrollment.

When the provider/supplier is making a National Profile level change and that profile has

multiple enrollments, the provider/supplier must check the box in PECOS confirming that it

understands that this change: (1) is related to the National Profile for (XYY) with (TIN 123); and

(2) will accordingly update all of the provider’s/supplier’s other active Medicare enrollments

within PECOS, regardless of what is shown on this particular application. (This is sometimes

labeled an “indirect enrollment record update” (IERU). With a National Profile level change that

revises an enrollment record, PECOS may notify the provider/supplier (typically the contact

person or the correspondence address) of the IERU.

b. Consolidated Application Exceptions

(i) Providers/suppliers may only submit one type of provider enrollment transaction in a

consolidated application (e.g., the provider cannot submit a consolidated application to reactivate

the billing privileges of three of its enrolled suppliers and to report a CHOW involving two of its

enrolled providers).

(ii) Initial enrollments for certain provider/supplier types (e.g., certified providers) cannot be

submitted via a consolidated application.

(iii) DMEPOS suppliers may be limited in the number of individual enrollments than can be

included in a consolidated application.

(iv) Consolidated applications are only for PECOS applications, not paper applications; that is,

consolidated applications cannot be submitted via paper

c. Associations

Certain types of relationships (excluding ownership and management relationships) between

enrolled persons and organizations in PECOS are labeled “associations.” (This is not to be

confused with the definition of “affiliation” in § 424.502 for purposes of § 424.519.) These

associations/relationships frequently involve: (1) reassignors and reassignees; (2) IDTFs and

supervising physicians; and (3) CAH II relationships. In all cases, both parties in the relationship

must be enrolled for the affiliation to exist. The purpose of the “association” designation is to

give a formal label to certain types of relationships for PECOS purposes.

d. Signatures

i. General Policy - If an application is submitted that will create multiple enrollments or

enrollment records and the signer is authorized to sign all enrollments, the application’s signature

will be automatically applied to the other enrollments.

ii. Authorized Officials

In a consolidated application with multiple enrollments, an authorized official can only sign for

those enrollments for which the individual is on record as an authorized official. To illustrate,

suppose a consolidated application contains enrollments in Pennsylvania and Ohio. Smith is

listed as an authorized official for the Pennsylvania enrollment but not the Ohio enrollment.

Smith therefore cannot serve as an authorized official for the latter.

e. Multiple Contractor Involvement

As already referenced, situations will arise where a submitted consolidated application that

changes National Profile information impacts multiple contractors. (To illustrate, a provider that

is enrolled in three contractor jurisdictions (X, Y, Z) might submit a consolidated application to

change its DBA name.) The contractor shall observe that:

(i) Each contractor is responsible for processing the application it receives. It cannot rely on one

of the other affected contractors to process all of the applications. Using our above

illustration, X must process the application it received that is unique to its jurisdiction, Y

must process the application specific to its jurisdiction, and so forth.

(ii) The term “processing” in (i) above includes, but it not limited to, verifying data, developing

for clarifying information, approving/denying the application, etc. Thus, for example,

Contractor X cannot rely exclusively on Contractor Y’s verifications without attempting to

validate the same data concerning the Contractor X application. Nor can Contractor Y use

Contractor X’s development letter to solicit the same data. Each application in this situation

stands alone on its own merits and must be handled separately (e.g., each contractor must: (a)

make its own determination (approval, denial, etc.) regarding the application it is processing;

(b) send its own approval/denial/rejection letter; (c) develop for clarifying data pertaining to

its application; and (d) process its application consistent with applicable timeliness

requirements).

5. Letter Generation

i. Automation

Except as stated in subsection (5)(ii) below and as otherwise stated in this section 10.3, PECOS

generates and sends to the provider/supplier all required letters (e.g., approval letters under

section 10.7 et seq. of this chapter), though the contractor must manually select which letter must

be sent. Note that each letter will have an issue date that signifies both (1) the date of the letter

and (2) the date it is sent. The contractor shall treat this issue date as the “date of letter” and

“date sent” for purposes of establishing applicable effective dates, the conclusion of development

periods, and other timeframes that are based on the letter date or sent date.

ii. Exceptions to Automated Letter Process

There may be isolated instances when the contractor has to produce and/or send letters outside of

PECOS. This could include, for example:

• PECOS can produce most letters requiring certified mail, but the contractor must manually

print and send them

• The letter type is not available in PECOS

(Note that the contractor can always override a particular automated letter creation and

upload/use a different letter.)

For letters the contractor must prepare and/or send outside of PECOS, the contractor shall ensure

that: (1) the letter has an “issue date” consistent with subsection (5)(i) above; and (2) it uploads a

copy of the letter to PECOS. Except for certified letters (which must be mailed via hard-copy),

the contractor may send the letter via mail, e-mail, fax, or the PCV, although the PCV is very

highly preferred if the printed letter can be uploaded into PECOS and sent via this means.

The “date of the letter” is the date on which the letter was created. The “issue date” is the date

on which the letter was sent. For letters that PECOS sends (see subsection (5)(i) above), the

letter and issue dates will be the same. For the letters discussed in subsection (5)(ii), however,

they may be different (i.e., the contractor may send the letter the day after it is created).

iii. Additional Information

• Editing - If the contractor must edit a letter after it has been sent, the contractor shall (a) edit

it outside of PECOS and (b) upload it consistent with the document upload instructions

described in this chapter and other CMS guidance.

• Verbiage Insertion – Any language the contractor must insert into a letter shall be entered

using the language insertion feature in the letter module.

• Outside Letter - If CMS instructs the contractor to submit a letter that is typically not

generated by PECOS (e.g., an educational letter to supplement an approval letter), the

contractor shall create the letter outside of PECOS and upload it to the appropriate location.

• All opt-out letters (e.g., approval, denial) shall be created outside of PECOS.

6. Site Visits and Application Fees

a. Site Visits (SVs) -

i. General Principle

All SVs are ordered through PECOS, and all SV results (with photos) are entered/uploaded into

said system. The National SV Contractor(s): (i) completes SV requests directly in PECOS; or

(ii) receives the request from PECOS and sends the full SV record back to PECOS from its

system when complete. They either are ordered for and attached to the relevant application or

they occur ad-hoc. However, the contractor must still review the site visit results and indicate

pass/fail, consistent with existing instructions.

PECOS can identify a completed/passed site visit within the previous 12 months so that a new

site visit is unnecessary.

ii. Ordering

• PECOS Applications – PECOS will automatically order a site visit (if one is required) only

in the following situations:

(A) An initial application

(B) Excluding certified providers/suppliers, a change of information or revalidation

application if the provider/supplier is currently in the high or moderate screening level

and the practice location in question has not passed a site visit within the previous 12

months.

Notwithstanding the foregoing, the contractor can manually intervene to postpone or cancel this

site visit if warranted under the circumstances (and consistent with the instructions in this

chapter).

For all other situations not referenced in subsection (ii)(A) and (B) above, the contractor must

manually order the site visit.

• Paper Applications – The contractor must manually order the site visit if one is required.

b. Application Fees

Application fees can be combined if multiple enrollment records are implicated by the

submission (e.g., consolidated application), but each application still requires a separate fee. To

illustrate, suppose an entity is enrolling 5 different IDTFs, and the fee amount is $631 per IDTF.

The provider can submit separate $631 fees or can combine them into a single $3,155 payment.

In the case of hardship waivers, however, 5 separate hardship waivers – one for each enrollment

– must be submitted; they cannot be combined into one waiver request.

In addition:

• If the provider/supplier is submitting an application requiring a fee, PECOS will

automatically indicate the appropriate fee amount.

• For consolidated applications in which multiple fees are required, the provider/supplier can

remove an enrollment record from its submission (e.g., the provider wishes to rescind its

prospective enrollment because the fee amount is excessive), PECOS will correspondingly

reduce the required total fee amount. If the provider/supplier does this after it has paid the

fee, it can request a refund via the instructions in this chapter.

• If the provider/supplier makes an “out of bound” fee payment (that is, a payment outside of

the application submission), the provider/supplier can apply the fee(s) to its application by

entering Pay.gov tracking IDs.

• Providers/suppliers can request hardship waivers directly via PECOS.

• Fee refunds shall continue to be processed consistent with existing instructions.

7. Application Re-Routing and Returns

For web applications incorrectly sent to the contractor, the latter can re-route the application to

the correct contractor via PECOS. For paper applications incorrectly sent to the contractor (and

unless otherwise stated in this chapter or in another CMS directive), the contractor may return

the application per 42 CFR § 424.526 without completing application intake.

PECOS cannot independently determine whether an application should be returned (e.g., initial

Form CMS-855A application submitted more than 180 days prior to the effective date). The

contractor must make this assessment.

8. Licensure

As already mentioned, APS will present to the contractor its review of the provider/supplier’s

licensure status. In some cases, however, the contractor will have to also manually verify the

provider/supplier’s licensure using an original source, such as a state licensing board website. In

this regard, the contractor shall adhere to the following:

• Applications Other Than Initial Enrollments and Reactivations – The contractor need not

review licensure original sources if all three of the following requirements are met: (1) all of

the licensure information on the application (regardless of the data’s materiality) matches that

shown in APS (e.g., same name, active status); (2) the license contains no restrictions or

qualifiers insofar as the contractor can determine from the application and the APS review;

and (3) it is otherwise clear to the contractor that the provider/supplier is appropriately

licensed.

• Applications Other Than Initial Enrollments and Reactivations -- If any of the three criteria

in the previous bullet are not met OR the contractor is in any way uncertain as to whether the

provider/supplier is appropriately licensed, the contractor shall review an original source.

(Note that the data match between APS and that on the application must be 100%, regardless

of the materiality of the data or the extent of the discrepancy. Even if there is a slight

difference in the individual’s name, an original source must be reviewed.)

• Initial Enrollment Applications and Reactivations – The contractor shall use an original

source to verify licensure notwithstanding the APS results.

In all cases, the contractor shall ensure that all licensure reviews required under this chapter are

performed. If licensure is not required for the provider/supplier, the contractor shall treat this in

PECOS as a situation where the provider/supplier passed the licensure review.

APS will display all licensure information relevant to the enrollment that the contractor is

processing. It is possible, though, that licensure data may appear involving enrollments and

parties other than those under review. The contractor need only take action based on licenses

related to the specific enrollment being processed.

10. Development

Should a PECOS or paper application require development --- and unless this chapter permits

telephonic development for the specific matter/info in question – the contractor shall issue the

development request via PECOS’s RFI functionality.

C. Impact on Application Transaction Types and Formats

This subsection (C) addresses certain PECOS functions, capabilities, and policies regarding

specific enrollment-related transactions, application types, and application formats (e.g., web,

paper), including associated signature requirements.

1. Revalidations

Except as otherwise described in this chapter, PECOS automatically handles revalidation

requests, tracking, and correspondence. It also prevents the submission of web applications

outside of the revalidation window. PECOS establishes timeframes and then queues mailings

based on revalidation history and enrollment dates, although CMS can modify timeframes and

request off-cycle revalidations at any time. Failure to respond to a revalidation request would

result in, as applicable to the situation, an automatic pend, deactivation, etc.

2. Form CMS-588/Electronic Funds Transfer (EFT)/Multi-Carrier System (MCS)/Special

Payment Addresses

Under PECOS:

a. All EFT information (including bank account data) must be entered, processed, and stored in

PECOS. The contractor shall no longer use the shared system to enter bank information.

b. All MCS transactions related to provider enrollment shall be entered into and updated through

PECOS. This includes provider codes, options, do not forward (DNF), effective periods,

linkages to PTANs, banking, etc.

c. The contractor shall continue to follow the instructions in section 10.6.23 of this chapter 10.

d. Notwithstanding any other instruction in this subsection (C)(2), the contractor need not

undertake pre-notification review of an EFT account if the latter already exists under the

provider/supplier’s TIN and the provider/supplier is merely adding it to a new enrollment under

that same TIN.

e. EFT Processing Checks – The contractor shall document in PECOS: (1) its verification that

the banking information is complete and correct; and (2) any required verification with the

authorized official, delegated official, contact person, or the individual physician/practitioner.

3. Reassignments

a. General Principle

As stated earlier, PECOS automatically processes reassignments received online; this includes

preventing a supplier from reassigning benefits to an ineligible party.

b. Location Group Assignment – When establishing a reassignment for PECOS applications, the

provider/supplier must determine and select which “Locations Groups” of the clinic/group at

which the provider/supplier will be performing services (i.e., billing from); this will help support

proper PTAN assignment. For paper applications, however, the contractor must make the

aforementioned determination based strictly on the information submitted (i.e., without

development on this specific issue); such data could include, for instance, the reported primary

and secondary practice locations and information that the group submitted.

4. Form CMS-855O and Form CMS-855I Conversions and Terminations

If a supplier who is enrolled via the Form CMS-855I or Form CMS-855O submits, respectively,

a web Form CMS-855O or a web Form CMS-855I to change the individual’s enrollment, the

supplier need not terminate the prior enrollment. PECOS 2.0 performs this function. (This only

applies to web applications.)

5. Certified Provider/Supplier Application – State Involvement

The contractor cannot send/email documents, approval recommendation packages, etc., to the

states, accrediting organizations (AO), and SOG Locations via PECOS. Said materials shall

continue to be sent via the Box system consistent with existing policy. (States, AOs, and the

SOG Locations do not have access to PECOS.) However, certain other components of the

survey/certification process are handled/managed through PECOS. This includes, but is not

limited to: (1) tracking applications sent to the state; and (2) storing and/or generating approval

letters to and from the state.

6. Appeals and Rebuttals

Appeals and rebuttals are stored in PECOS. The contractor can process the appeal/rebuttal via

PECOS and, as applicable, revise the enrollment record based on the appeal/rebuttal decision.

If the contractor receives an appeal that should have instead been sent to CMS, the contractor

shall enter the appeals data into PECOS and forward the appeal to CMS consistent with existing

instructions.

The provider cannot submit appeals and rebuttals via PECOS.

7. Web vs. Paper Applications

a. Paper Applications

The contractor shall: (i) enter into PECOS the basic information about a received application (a

process called “intake”) such that PECOS can send a confirmation correspondence and, if

applicable, associate the application with an existing enrollment; and (ii) upload into PECOS any

images of the paper application and/or all supporting documentation. Note that these tasks do

not constitute the creation of a web-based application. Providers/suppliers submitting paper

applications:

• Must use fillable versions thereof, meaning the information cannot be handwritten. (This

includes situations where the provider/supplier is submitting an application page pursuant to

a development request; the page must be from a fillable application. If the provider/supplier

submits a handwritten application or page, the contractor shall develop for a fillable one

rather than return the application, though intake shall still be completed.) Note that this

requirement applies:

o To all CMS applications for which a fillable version thereof is available (e.g., CMS-

588), including situations where the provider must submit corrected/revised pages of

the application pursuant to a development request

o Only to CMS form applications and not to (i) supporting documentation or (ii)

responses to development requests not involving the submission of corrected/revised

application pages (e.g., supporting documentation need not be in a fillable format).

• Must submit the application via mail

• Will receive correspondence via the PCV. (However, the provider/supplier must still submit

any additional materials related to its application (e.g., application pages, supporting

documents) via paper.)

One hundred percent (100%) of paper applications and appeals/rebuttals/CAPs (regardless of

type (A/B/I) or transaction (initial/change of information)) must be entered into PECOS within

two business days of receipt. This includes uploading all hard copies of received

applications/appeals/rebuttals and attachments into PECOS.

The minimum data elements that must be part of the contractor’s “intake” are:

• Type of document (application or supporting document)

• Date of Receipt

• Method of receipt (mail, email, fax, upload)

• Application type

• Submission reason (initial, change, revalidation)

• State

• Name

• TIN

• DCN

(Regarding the intake of attachments and supporting documentation, the contractor need not

separate the documents (or pages of documents) within the 2-business day period if they are

submitted in bulk. Only the bulk document need be uploaded.)

At a minimum, the contractor shall upload the image of the entire application submission

package (i.e., the application and all supporting documentation) as a single document at

application intake, though the contractor may upload each document separately (i.e., application,

EFT, PAR, license, etc.). The effective date of the document upload/received date is the same as

the date of contractor entry/intake.

If the application fails to include all the information needed to perform intake, the application

shall not be considered a submission. No action is required in PECOS, and the contractor shall

handle the document consistent with the document retention polices in the contractor’s internal

document control system.

b. Signatures

For paper applications, handwritten (wet) signatures in ink and digital/electronic signatures

(digital or electronic signatures such as those created by digital signature options, such as Adobe)

are acceptable. For web applications, electronic signatures (which can be uploaded) are required.

Given the advent of PECOS 2.0, certain previous certification statement instructions pertaining

to Internet-based PECOS applications are no longer applicable (e.g., the ability to submit paper

certification statements after submission). In addition, because certification statements must be

signed before the application is submitted, there will be much less need for the contractor to

develop for them. Nevertheless, the contractor must still verify signatures consistent with the

instructions in this chapter; this includes documenting the validity of an uploaded signature via

the PECOS signature upload processing check.

c. Web and Paper Usage

A provider/supplier that submits a web application is not prohibited from submitting future

enrollment applications via paper. Likewise, a provider/supplier that submitted its initial

application via paper may always submit future applications via web. In each scenario, the

contractor shall follow the instructions in this section 10.3 et seq. that are applicable to the type

of application (PECOS vs. paper) that was submitted. For instance, suppose a provider

previously submitted its initial application via web and now submits a paper change of

information request. The contractor shall upload the submission into PECOS, develop for any

missing or unsigned/undated certification statement, avail itself of any processing alternatives

that are applicable to paper applications, etc.

Notwithstanding the above, when the provider/supplier submits a web application, any updates to

the application---such as, for example, pursuant to a development request or the submission of

additional documentation---before the application is processed to conclusion (e.g., approved,

denied, rejected) must be via PECOS. The provider/supplier cannot submit its update via paper.

d. Documents Received Outside of Application Submissions

(1) General Guidance - The contractor may receive documents unrelated to a particular

application submission, appeal, or rebuttal. This could include, for example, a W-9, a new

CLIA certificate, an updated license, a surety bond cancellation notice, an FDA certification,

a CMS-460, insurance documents, etc. These documents must be uploaded into PECOS

consistent with the instructions in this section 10.3 et al. and the timeframe described in

section 10.3(C)(7)(a).

(2) Special Situations

• For submitted stand-alone paper Form CMS-588s and CMS-460s, the contractor shall

intake the document as the application type that corresponds to the enrollment record that

will be impacted by the submission (e.g., Form CMS-855I, CMS-855A).

• When paper Form CMS-855I and Form CMS-855B applications are submitted

concurrently pursuant to a reassignment, the contractor shall intake the two applications

separately and individually.

8. Business and Practice Location Names/Assignments

The “DBA name” and “Other name” data fields are not required in PECOS. If the

provider/supplier nevertheless submits this data, the other name/DBA name should be at the

organization level while the name at the practice location level should be, in effect, the name on

the location’s “front door.”

In reassignment situations, providers/suppliers can assign in PECOS multiple primary practice

locations (PPLs), one PPL, or none at all. If the provider/supplier wishes to add, change, or

remove a PPL designation, no signature is necessary.

9. Contact Persons/Parties for PECOS Applications

(The instructions in this subsection (C)(9) supersede those in section 10.6.9 of this chapter with

respect to PECOS applications.)

For PECOS applications only, there are three types of contacts:

a. “Enrollment Representatives” (ER): These are persons whom the provider/supplier may

designate in its PECOS application submission as having the authority to contact the contractor

about the provider/supplier’s enrollment once the provider/supplier is enrolled. ERs will not be

contacted by CMS (except in response to an ER’s inquiry) either by mail, e-mail, telephone, the

PCV, etc., and their contact information will not be part of the official application or be shown

on the PECOS screens. Moreover, the provider/supplier need not have any ERs if it so chooses.

b. “Application Contacts” (AC): These individuals are somewhat akin to the longstanding

category of “contact persons.” They are: (1) optional for the provider/supplier; (2) valid contacts

only for the application in question; and (3) neither added to the formal enrollment record nor

contacted by CMS on any matter other than the application. If the provider/supplier chooses to

list ACs, it must also designate a “Primary AC” from this list; this person will receive any

physical letters the contractor sends while the other ACs will receive e-mails.

(In addition:

• If the provider/supplier submits a paper application -- which does not differentiate

between an ER and an AC -- the contractor can leave the ER field in PECOS blank.

• If a provider/supplier submitting a PECOS application chooses not to have an ER, the

contractor shall follow current guidance regarding with whom it can discuss post-enrollment matters if no contact person is listed (e.g., with authorized and delegated

officials).

• If an ER requests information regarding a pending application, the contractor shall follow

current guidance regarding with whom it can discuss matters concerning pending

applications.)

c. Correspondence Address – This is the same address that has long been used for provider

enrollment applications. Its meaning and use will not change with the advent of PECOS 2.0.

Except as otherwise stated in subsections 9(a) through (c) above, the contractor shall:

• Continue to use the correspondence address as normal

• Use ACs (as opposed to ERs) for communications regarding the application in question

• Respond to any ER questions if they are related to a matter outside of the contractor’s

current processing of an application. (If the question is not related to the present

application, the contractor shall notify the ER that it cannot respond to the query.)

10. Contacting CMS

For matters that require CMS/PEOG BFL input or decision --- and unless otherwise instructed in

this chapter --- the contractor shall request CMS ‘review’ using the ‘assignment’ functionality in

PECOS. The contractor shall include the pertinent data/question/note in the section provided

during the assignment/review process and attach any pertinent documentation (e.g., review of

adverse legal action documentation).

D. Additional Guidance

1. Revocations – Except as otherwise instructed by CMS, all CMS-directed revocations will be

processed in their entirety by CMS within PECOS.

2. Screening Levels – PECOS will automatically set the provider/supplier’s correct screening

level. Should the screening level nonetheless need to be adjusted, the contractor shall seek CMS

approval via PECOS.

E. Chapter 10 Applicability

1. Except as otherwise noted, the PECOS instructions in section 10.3 et seq. take precedence

over all others in this chapter pertaining to the same issue or operational procedure.

2. Certain existing instructions in chapter 10 (including those in section 10.3 et seq.) require (or,

in a few cases, do not require) particular data elements on the application to be completed. The

contractor shall observe that PECOS may or may not mandate that the provider complete

particular data fields before proceeding to succeeding fields. This might render moot some of

the processing alternatives and exemptions discussed in this chapter. The contractor may

therefore disregard those alternatives/exemptions that are immaterial to the situation.

3. Certain existing data elements on the applications and which are listed in this chapter 10 may

not be reflected in PECOS. In such cases, the contractor may disregard the instructions in this

chapter pertaining thereto.

4. Except as otherwise stated, the term “PECOS” in this chapter refers to PECOS 2.0 and

incorporates the phrase “Internet-based PECOS.”

5. All instances in section 10.3 et seq. in which the contractor must now document a data

element verification or a telephonic communication in PECOS rather than in the provider file

shall include the applicable information required under section 10.6.19(L). Note that the

contractor may document such communications in PECOS even for paper applications.

6. In cases where use of the PCV is not required but permissible, the contractor is very strongly

encouraged to utilize that mechanism.

7. All clock stoppages otherwise permitted under this chapter can be applied with respect to the

policies in this section 10.3.

History

(Rev. 13355; Issued: 08-13-25; Effective: 05-05-25; Implementation: 05-05-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
63b308b00b3ce28b76202932260fc1a03672506adf5883250435f5afc4404c86
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.