Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 10, § 10.4.1.3.2

Data Verification

activein force · 2026-08-25 – presentas-observed

A. Means of Verification

Except as stated otherwise in this chapter or in another CMS directive, the contractor shall verify

and validate – via the most cost-effective methods available, including via PECOS (as described

and directed in section 10.3) - all information furnished by the provider on or with the

application, assuming a data source is available. The general purpose of the verification process

is to ensure that all of the data furnished on the Form CMS-855 or Form CMS-20134 is accurate.

Examples of verification techniques include, but are not limited to: (i) site visits; (ii) third-party

data validation sources; (iii) state professional licensure and certification websites (e.g., medical

board sites); (iv) federal licensure and certification websites (if applicable); (v) state business

web sites (e.g., to validate “doing business as” name); and (vi) Yellow Pages (e.g., to verify

certain phone numbers).

The list of verification techniques identified in this section 10.4.1.3.2 is not exhaustive. Except

as prescribed otherwise in section 10.3, if the contractor is aware of another means of validation

that is as cost-effective and accurate as those listed, it may use it. However, all SSNs and NPIs

listed on the application shall be verified through PECOS. The contractor shall not request an

SSN card or driver’s license to verify an individual’s identity or SSN.

B. Overall Verification Principles

Unless stated otherwise in this chapter or in another CMS directive, the following apply:

1. A data element is considered “verified” when, after attempting at least one means of

validation, the contractor is confident that the data is accurate. (The contractor shall use its best

judgment when making this assessment.)

2. The contractor need only make one verification attempt (i.e., need only use one validation

technique) before either: (i) concluding that the furnished data is accurate; or (ii) requesting

clarifying information if the data element cannot be verified (though the contractor is encouraged

to make a second attempt using a different validation means prior to requesting clarification).

C. Concurrent Reviews

(For PECOS application submissions, note that PECOS’s automatic verifications of applications

from related entities shall take precedence – e.g., in terms of length of time between application

submissions, depth of the relationship between the associated parties – over the instructions in

this section 10.4.1.3.2(C).)

If the contractor receives multiple Form CMS-855 or Form CMS-20134s for related entities, it

can perform concurrent reviews of similar data. For instance, suppose a chain home office

submits initial Form CMS-855As for four of its chain providers. The ownership information

(Sections 5 and 6) and chain home office data (Section 7) is the same for all four providers. The

contractor need only verify the ownership and home office data once; it need not do so four

times – once for each provider. However, the contractor shall document in each provider’s

PECOS record that a single verification check was made for all four applications.

For purposes of this requirement: (1) there must be an organizational, employment, or other

business relationship between the entities; and (2) the applications must have been submitted

within a few weeks of each other. As an illustration, assume that Group Practice A submits an

initial Form CMS-855B on January 1. Group Practice B submits one on October 1. Section 6

indicates that Smith is a co-owner of both practices, though both entities have many other owners

that are not similar. In this case, the contractor must verify Smith’s data in both January and

October. It cannot use the January verification and apply it to Group B’s application because:

(1) the applications were submitted nine months apart; and (2) there is no evidence that the

entities are related.

D. Contacting another Contractor

During the verification process, the contractor may need to contact another Medicare contractor

for information regarding the provider. The latter contractor shall respond to the former

contractor’s request within three business days absent extenuating circumstances.

E. Proof of Life Documentation

When an enrollment record is updated to reflect an erroneous date or report of death, the

contractor shall request documentation that supports “proof of life” (e.g., Retirement, Survivors,

and Disability Insurance document issued by SSA). If the provider cannot obtain such

documentation, the contractor shall submit a request to its PEOG BFL containing the provider’s

name, date of birth, and SSN so that CMS can confirm proof of life with SSA.

History

(Rev. 13355; Issued: 08-13-25; Effective: 05-05-25; Implementation: 05-05-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
36d3aa2d8f151bb027aef00080f956e1f08d2aed83780d79a58a3f23aabf60b7
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.