US · guidance
CMS Pub. 100-08, ch. 10, § 10.6.19
Other Medicare Contractor Duties
(The contractor also shall review section 10.3 of this chapter regarding the topics in this section
10.6.19. In the event of a conflict, those instructions take precedence over those in this section
10.6.19.)
The contractor shall adhere to all instructions in this chapter and other CMS provider enrollment
directives (e.g., technical direction letters). The contractor shall also assign the appropriate
number of staff to the Medicare enrollment function to ensure that all such instructions and
directives - including application processing timeframes and accuracy standards - are complied
with and met.
A. Training
The contractor shall provide (1) training to new employees, and (2) refresher training (as
necessary) to existing employees to ensure that each employee processes enrollment applications
in a timely, consistent, and accurate manner. Training shall include, at a minimum:
• An overview of the Medicare program
• A review of all applicable regulations, manual instructions, and other CMS guidance
• A review of the contractor’s enrollment processes and procedures
• Training regarding PECOS.
For new employees, the contractor shall also:
• Provide side-by-side training with an experienced provider enrollment analyst
• Test the new employee to ensure that the latter understands Medicare enrollment policy
and contractor processing procedures, including the use of PECOS
• Conduct end-of-line quality reviews for 6 months after training or until the analyst
demonstrates a clear understanding of Medicare enrollment policy, contractor procedures,
and the proper use of PECOS.
For existing employees, the contractor shall perform periodic quality reviews and refresher
trainings.
B. PECOS
The contractor shall:
• Process all enrollment actions (e.g., initials, changes, revalidations, revocations, appeals,
denials) through PECOS
• Deactivate or revoke the provider or supplier’s Medicare billing privileges in the Multi-Carrier System or the Fiscal Intermediary Shared System only if the provider or supplier
is not in PECOS; if the provider does not exist in MCS or FISS, the contractor shall
contact its PEOG BFL prior to taking action.
• Close or delete any aged logging and tracking (L & T) records older than 120 days for
which there is no associated enrollment application
• Participate in user acceptance testing for each PECOS release
• Attend scheduled PECOS training when requested
• Report PECOS validation and production processing problems through the designated
tracking system for each system release
• Develop (and update as needed) a written training guide for new and current employees
on the proper processing of Form CMS-855 and Form CMS-20134 applications, opt-out
affidavits, and the appropriate entry of data into PECOS.
C. Customer Service
1. Responding to Provider Enrollment Inquiries
The contractor’s customer service unit may handle provider enrollment inquiries that do not
involve complex enrollment issues. Examples of inquiries that can be processed by customer
service units include:
• Application status checks (e.g., “Has the contractor finished processing my application?”)
(The contractor may wish to establish electronic mechanisms by which providers can
obtain updates on the status of their enrollment applications via the contractor’s web site
or automated voice response (AVR).
• Furnishing information on where to access Form CMS-855 or Form CMS-20134
applications (and other general enrollment information) online
• Explaining to providers/suppliers which Form CMS-855 or CMS-20134 applications
should be completed.
2. Contractor’s Responsiveness to Inquiries
Excluding matters pertaining to application processing (e.g., development for missing data) and
appeals (e.g., appeal of revocation), the contractor is encouraged to respond to all enrollment-related provider/supplier correspondence (e.g., e-mails, letters, telephone calls) within 30
business days of receipt.
D. Contractor Outreach to Providers
The contractor is strongly encouraged to establish e-mail “list serves” with the provider
community to disseminate important information thereto, such as contractor address changes,
new CMS enrollment policies or internal contractor procedures, reminders about existing
policies, etc. By being proactive in distributing information to its providers and suppliers on a
regular basis (e.g., weekly, bi-weekly), the contractor can reduce the number of policy inquiries
it receives and help facilitate the submission of complete and accurate Form CMS-855 and Form
CMS-20134 applications.
E. Encouraging Use of Internet-based PECOS
When a prospective provider or supplier contacts the contractor to obtain a paper enrollment
Form CMS-855 or Form CMS-20134, the contractor shall encourage the provider or supplier to
submit the application using Internet-based PECOS. The contractor shall also notify the provider
or supplier of:
• The CMS Web site at which information on Internet-based PECOS can be found and at
which the paper applications can be accessed (https://www.cms.gov/Medicare/Provider-Enrollment-and-
Certification/MedicareProviderSupEnroll/index?redirect=/MedicareProviderSupEnroll/).
• The contractor’s address so that the applicant knows where to return the paper
application.
• Any supporting documentation required for the applicant's provider/supplier type.
• Other required forms as described in sections above. Notification can be given in any
manner the contractor chooses.
F. Adherence to Responsibilities Based Upon Jurisdiction - Audit and Claims Contractors
1. Background
For purposes of enrollment via the Form CMS-855A, there are generally two categories of
contractors: audit contractors and claims contractors. The audit contractor enrolls the provider,
conducts audits, etc. The claims contractor pays the provider’s claims. In most cases, the
provider’s audit contractor and claims contractor will be the same. On occasion, though, they
will differ. This can happen, for instance, with provider-based entities, whereby the parent
provider’s contractor (audit contractor) will process the provider’s enrollment application and a
different contractor will pay the provider’s claims (claims contractor).
Should the audit and claims contractors differ, the audit contractor shall process all changes of
information, including all Form CMS-588 changes. The audit contractor shall notify the
applicant during the initial enrollment process that all future changes of information must be sent
to the audit contractor, not the claims contractor. If the provider inadvertently sends a change
request to the claims contractor, the latter shall return the application per the instructions in this
chapter.
2. Process
If the audit contractor approves the Form CMS-855A transaction in question (e.g., initial
enrollment), it shall:
(i) Send an e-mail to the claims contractor identifying the specific Form CMS-855A transaction
involved and confirming that the information has been updated in PECOS. Pertinent identifying
information, such as the provider name, CCN, and NPI, shall be included in the e-mail
notification. The audit contractor need not include any supporting documentation in the e-mail
because PECOS will contain any documents (e.g., approval letters from the state).
(ii) As applicable, fax, mail, or email an encrypted copy of the submitted Form CMS-588 to the
appropriate claims contractor.
Upon receipt of the e-mail notification, the claims contractor shall access PECOS, review the
enrollment record, and, as needed, update its records accordingly.
The audit contractor shall ensure that all original copies of Form CMS-855A paperwork and
supporting documentation (including all Form CMS-588s), approval letters from the state, and
other written documents related to the application are uploaded in PECOS.
If the provider’s audit contractor and claims contractor are different, the audit contractor shall e-mail or fax a copy of all SOG Location approval/denial notices/letters it receives to the claims
contractor. This is to ensure that the claims contractor is fully aware of the SOG Location’s
action, as some may only send copies of the approval letters to the audit contractor. If the audit
contractor chooses, it can simply contact the claims contractor by phone or e-mail and ask if the
latter received the tie-in notice.
It is imperative that audit and claims contractors effectively communicate and coordinate with
each other in all payment-related and program integrity matters involving the provider.
G. Online Presence – Web Sites
The contractor must provide a link to CMS’ provider/supplier enrollment Web site located at
https://www.cms.gov/medicare/provider-enrollment-and-
certification/medicareprovidersupenroll/index.html?redirect=/medicareprovidersupenroll/ . The
link shall: (1) be available on the contractor’s existing provider outreach Web site (which should
be an established sub-domain of the contractor’s current commercial Web site), and (2) comply
with the guidelines stated in the Provider/Supplier Information and Education Web site section
(Activity Code 14101) under the Provider Communications (PCOM) Budget and Performance
Requirements (BPRs). Bulletins, newsletters, seminars/workshops and other information
concerning provider enrollment issues shall also be made available on the existing provider
outreach Web site. All contractor web sites must comply with section 508 of the Rehabilitation
Act of 1973 in accordance with, 36 CFR §1194 and with CMS’ Contractor Website Standards
and Guidelines posted on CMS’s web site.
The CMS Provider/Supplier Enrollment Web site gives users access to provider/supplier
enrollment forms, specific requirements for provider/supplier types, manual instructions,
frequently asked questions (FAQs), contact information, hot topics, and other pertinent
provider/supplier information. The contractor shall not duplicate content already provided at the
CMS provider/supplier enrollment website and shall not reproduce the forms or establish the
contractor’s own links to forms. It shall, however, have a link on its website that goes directly to
the forms section of the CMS provider/supplier enrollment site.
On a quarterly basis (specifically, no later than the 15th day of January, April, July, and October),
each contractor shall review and provide updates regarding its contact information shown at
URL: https://www.cms.gov/Medicare/Provider-Enrollment-and-
Certification/MedicareProviderSupEnroll/Downloads/contact_list.pdf. If the contractor services
several states with a universal address and telephone number, the contractor shall report that
information. In situations where no updates are needed, a response from the contractor is still
required (i.e., the contact information is accurate). In addition, only such information that
pertains to provider enrollment activity for the contractor’s jurisdiction is to be reported. All
updates shall be sent directly via e-mail to the contractor’s PEOG BFL.
H. Document Uploading and Retention
1. Introduction
To ensure that proper internal controls are maintained and that important information is recorded
in case of potential litigation, the contractor shall maintain documentation as outlined in this
section 10.6.19(H) and, as applicable, section 10.3. CMS cannot stress enough how crucial it is
for contractors to document their actions as carefully and thoroughly as possible.
The requirements in this section 10.6.19(H) are in addition to, and not in lieu of, all other
documentation or document maintenance requirements that CMS has mandated.
The contractor shall maintain and store all documents relating to the enrollment of a provider
into Medicare. These documents include, but are not limited to, Medicare enrollment
applications and all supporting documents, attachments, correspondence, and correspondence
tracking documentation, and appeals submitted in conjunction with an initial enrollment,
reassignment, change of enrollment, revalidation, etc.
Supporting documentation includes, but is not limited to:
• Copies of federal, state and/or local (city/county) professional licenses, certifications
and/or registrations;
• Copies of federal, state, and/or local (city/county) business licenses, certifications and/or
registrations;
• Copies of professional school degrees or certificates or evidence of qualifying course
work;
• Copies of CLIA certificates and FDA mammography certificates;
• Copies of any entry found on the MED report that leads to a provider or supplier’s
revocation, and;
• Copies of Centers for Disease Control and Prevention (CDC) Diabetes Prevention
Recognition Program (DPRP) recognition letters or certificates indicating full or MDPP
preliminary recognition.
See section 10.6.19(I) below for additional document uploading requirements.
2. Document Disposal
The contractor shall dispose of the aforementioned records as described below:
i. Provider/Supplier and Durable Medical Equipment Supplier Application
a. Rejected applications as a result of provider failing to provide additional
information
Disposition: Destroy when 7 years old.
b. Approved applications of provider/supplier
Disposition: Destroy 15 years after the provider/supplier's enrollment has ended.
c. Denied applications of provider/supplier
Disposition: Destroy 15 years after the date of denial.
d. Approved application of provider/supplier, but the billing number was
subsequently revoked
Disposition: Destroy 15 years after the billing number is revoked.
e. Voluntary deactivation of billing number
Disposition: Destroy 15 years after deactivation.
f. Provider/Supplier dies
Disposition: Destroy 7 years after date of death.
ii. Electronic Mail and Word Processing System Copies
a. Copies that have no further administrative value after the recordkeeping copy is
made. These include copies maintained by individuals in personal files, personal
electronic mail directories, or other personal directories on hard disk or network
drives, and copies on shared network drives that are used only to produce the
recordkeeping copy.
Disposition: Delete within 180 days after the recordkeeping copy has been produced.
b. Copies used for dissemination, revision or updating that are maintained in addition
to the recordkeeping copy.
Disposition: Delete when dissemination, revision, or updating is complete.
I. Keeping Record of Activities
As with document retention as described in subsection (H) above, it is important that the
contractor maintains records of its written and telephonic communications. The contractor shall
thus adhere to the instructions in this subsection (I).
1. Written Communications
(For purposes of this section 10.6.19(I)(1), “written correspondence” includes mailed, faxed, and
e-mailed correspondence. Note that this is different from supporting documentation
accompanying an enrollment application, the requirements for which are addressed in subsection
(H) above.)
Except as stated in this subsection (I)(1), the contractor shall:
• Retain copies of all written correspondence pertaining to the provider, regardless of
whether the correspondence was initiated by the contractor, the provider, CMS, state
officials, etc.
• Document when it sends written correspondence to providers. For instance, if the
contractor crafts an approval letter to the supplier dated March 1 but sends it out on
March 3, the contractor shall note this in PECOS.
• Document all referrals to CMS, the UPIC, or the OIG
In cases where the written correspondence is sent directly via or to PECOS (e.g., PCV), the
contractor need not separately document this; PECOS will retain this information (date, time,
etc.). For all other written correspondence not sent via or to PECOS, the contractor (1) shall
upload a copy of the correspondence into PECOS (e.g., fax, a printed copy of the e-mail) and (2)
shall note in PECOS:
• The type of correspondence (e.g., approval letter)
• The form of correspondence (e.g., fax, e-mail)
• The date and time the correspondence was sent
• The party to whom the correspondence was sent (e.g. provider name, contact person)
2. Telephonic or Face-to-Face Contact
(Telephonic or face-to-face contact is hereafter referred to as “oral communication.”)
The contractor shall document any and all actual or attempted oral communication with the
provider, any representative thereof, or any other person or entity regarding a provider. This
includes, but is not limited to, the following situations:
• Telephoning a provider about its application. (Even if the provider official was
unavailable and a voice mail message was left, this must be documented.)
• Requesting information from the state or another contractor concerning the applicant or
enrollee
• Contacting the UPIC for an update concerning a particular case
• Phone calls from the provider
• Conducting a meeting at the contractor’s headquarters/offices with officials from a
hospital concerning problems with its application
• Telephoning PEOG, the state agency, or the SOG Location and receiving instructions
therefrom about a problem the contractor is having with an applicant or an existing
provider
• Telephoning the provider’s billing department with a question about the provider.
When documenting oral communications, the contractor shall indicate (1) the time and date of
the call or contact, (2) who initiated the contact, (3) who was spoken with, and (4) what the
conversation pertained to. Concerning the last requirement, the contractor need not write down
every word that was said during the conversation. Rather, the documentation should merely be
adequate to reflect the contents of the conversation.
The documentation requirements in this subsection (I)(2) only apply to enrolled providers and to
providers that have already submitted an enrollment application. In other words, these
documentation requirements go into effect only after the provider submits an initial application.
To illustrate, if a hospital contacts the contractor requesting information concerning how it
should enroll in the Medicare program, this need not be documented because the hospital has not
yet submitted an enrollment application.
All oral communications addressed in this subsection (I)(2) shall be documented in PECOS.
If an application is returned, the contractor shall document this. The manner of documentation
lies within the contractor’s discretion.
J. Documenting Verification of Data Elements
Once the contractor has completed its review of the Form CMS-855 and Form CMS-20134
applications (e.g., approved/denied application, approved change request) as well as opt-out
affidavits, it shall document that it has: (1) verified all data elements on the application, and (2)
reviewed all applicable names on the above- mentioned forms against the OIG/LEIE and the
System for Access Management (SAM). It can be drafted in any manner the contractor chooses
so long as it certifies that the above-mentioned activities were completed.
For each person or entity that appeared on the OIG/LEIE or SAM, the contractor shall document
any positive findings via a screen printout and upload it into PECOS. In all other situations, the
contractor is not encouraged to document its reviews via screen printouts. Simply using the
verification statement described above is sufficient. Although the contractor has the discretion to
use screen prints if it so chooses, the aforementioned verification statement is still required.
K. Release of Information
On October 13, 2006, CMS published System of Records Notice for PECOS in the Federal
Register. Consistent with this notice, once the provider has submitted an enrollment application
(as well as after it has been enrolled), the contractor shall not release – either orally or in writing
- provider-specific data to any outside person or entity unless specified otherwise in this chapter.
(Provider-specific data includes, but are not limited to, owners/managers, adverse legal history,
practice locations, group affiliations, effective dates, etc.) Examples of outside persons or
entities include, but are not restricted to, national or state medical associations or societies,
clearinghouses, billing agents, provider associations, or any person within the provider’s
organization other than the provider’s authorized official(s), delegated official(s), or contact
persons. The only exceptions to this policy are:
• A routine use found in the aforementioned System of Records applies.
• The provider (or, in the case of an organizational provider, an authorized or delegated
official): (1) furnishes a signed written letter on the provider’s letterhead stating that the
release of the provider data is authorized; and (2) the contractor has no reason to question
the authenticity of the person’s signature. The letter can be mailed, faxed, or e-mailed to
the contractor. The contractor shall upload the letter in PECOS.
• The release of the data is specifically authorized in some other CMS instruction or
directive.
(These provisions also apply in cases where the provider requests a copy of any Form CMS-855
or CMS-20134 paperwork the contractor has on file that the provider does not already have
access to in PECOS. For instance, if the provider already uses PECOS for application
submissions, the contractor can simply refer the provider to PECOS if the document in question
is in PECOS. If the provider does not use PECOS, the contractor shall not require the provider
to do so in order to access the document(s) but shall follow the above instructions; the latter shall
also be followed if the provider uses PECOS but the requested document is not in PECOS.)
It is recommended that the contractor notify the provider of the broad parameters of the
aforementioned policy as early in the enrollment process as possible.
The following information shall be made available over-the-phone to a caller who is able to provide a
provider/supplier’s name, PTAN, TIN/SSN, and NPI number; the caller need not be listed on the
provider/supplier’s enrollment record as a contact person:
• Revalidation status (i.e., whether or not a provider/supplier has been revalidated)
• Revalidation due date
• Revalidation approval date
• The specific information related to a revalidation development request
• The date a provider/supplier was deactivated due to non-response to a revalidation or non-response to a development request.
In addition:
• When sending emails, the contractor shall not transmit sensitive data, such as SSNs or
EINs, without first encrypting the email.
• The contractor may not send PECOS screen printouts to the provider.
• With the exception of Form CMS-855S applications, if any contact person listed on the
provider’s enrollment record requests a copy of a provider’s Medicare approval letter or
revalidation notice and the contact person does not have access to PECOS, the contractor
shall send to the contact person via email, fax or mail. (This excludes certification
Letters from the state agency, for the contractor does not generate these approvals.) If the
contact person has access to PECOS, the contractor can simply refer the individual to
PECOS. If the contact person does not use PECOS, the contractor shall not require the
contact person to do so in order to access the document(s) but shall follow the above
instructions; the latter shall also be followed if the contact person uses PECOS but the
requested document is not in PECOS.)
L. Security
The contractor shall ensure that the highest level of security is maintained for all systems and its
physical and operational processes in accordance with the CMS/Business Partners Systems
Security Manual (BPSSM) and the Program Integrity Manual.
Applications shall never be removed from the controlled area to be worked on at home or in a
non-secure location. Also, provider enrollment staff must control and monitor all applications
accessed by other contractor personnel.
All contractor staff shall be trained on security procedures as well as relevant aspects of the
Privacy Act and the Freedom of Information Act. This applies to all management, users, system
owners/managers, system maintainers, system developers, operators and administrators -
including contractors and third parties - of CMS information systems, facilities, communication
networks, and information.
Note that these instructions are in addition to, and not in lieu of, all other CMS instructions
regarding security.
M. Establishment of Relationships
To the maximum extent possible, and to help ensure it becomes aware of recent felony
convictions of practitioners and owners of health care organizations, the contractor shall
establish relationships with appropriate state government entities – such as, but not limited to,
Medicaid fraud units, state licensing boards, and criminal divisions –to facilitate the flow of
felony information from the state to the contractor. For instance, the contractor can request that
the state inform it of any new felony convictions of health care practitioners.
N. Monitoring Information from State Licensing Boards
To help ensure that only qualified physicians and non-physician practitioners are enrolled in
Medicare, the contractor shall undertake the activities described below. (For purposes of this
section, the term “practitioner” includes both physicians and non-physician practitioners. In
addition, the instructions in this section, apply only to these practitioners.)
No later than the 15th day of each month, the contractor shall review state licensing board
information for each state within its jurisdiction to determine whether any of its currently
enrolled practitioners have, within the previous 60 days:
• Had a medical license revoked, suspended, or inactivated (due to retirement, death, or
voluntary surrender of license);
• Otherwise lost a medical license or have had a license expire.
For those practitioners who no longer have a valid medical license, the contractor shall take the
necessary steps pursuant to this chapter.
The mechanism by which the contractor performs these monthly licensure reviews lies within its
discretion, though the most cost-effective method shall be used.
O. Regarding Potential Identity Theft or Other Fraudulent Activity
If --when conducting the verification activities described in this chapter -- the contractor believes
that a case of identity theft or other fraudulent activity likely exists, the contractor shall notify its
PEOG BFL immediately; the BFL will instruct the contractor as to what, if any, action shall be
taken (For example, a physician indicates that the physician is not establishing a new practice
location or changing EFT information and that the application submitted in the physician’s name
is false.)
History
(Rev. 13355; Issued: 08-13-25; Effective: 05-05-25; Implementation: 05-05-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
fd6fc0d3eb819a133ddbeda7e634a72f1ad6701b5e921630fb37ef98f76568f0
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.