Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 10, § 10.6.19

Other Medicare Contractor Duties

activein force · 2026-08-25 – presentas-observed

(The contractor also shall review section 10.3 of this chapter regarding the topics in this section

10.6.19. In the event of a conflict, those instructions take precedence over those in this section

10.6.19.)

The contractor shall adhere to all instructions in this chapter and other CMS provider enrollment

directives (e.g., technical direction letters). The contractor shall also assign the appropriate

number of staff to the Medicare enrollment function to ensure that all such instructions and

directives - including application processing timeframes and accuracy standards - are complied

with and met.

A. Training

The contractor shall provide (1) training to new employees, and (2) refresher training (as

necessary) to existing employees to ensure that each employee processes enrollment applications

in a timely, consistent, and accurate manner. Training shall include, at a minimum:

• An overview of the Medicare program

• A review of all applicable regulations, manual instructions, and other CMS guidance

• A review of the contractor’s enrollment processes and procedures

• Training regarding PECOS.

For new employees, the contractor shall also:

• Provide side-by-side training with an experienced provider enrollment analyst

• Test the new employee to ensure that the latter understands Medicare enrollment policy

and contractor processing procedures, including the use of PECOS

• Conduct end-of-line quality reviews for 6 months after training or until the analyst

demonstrates a clear understanding of Medicare enrollment policy, contractor procedures,

and the proper use of PECOS.

For existing employees, the contractor shall perform periodic quality reviews and refresher

trainings.

B. PECOS

The contractor shall:

• Process all enrollment actions (e.g., initials, changes, revalidations, revocations, appeals,

denials) through PECOS

• Deactivate or revoke the provider or supplier’s Medicare billing privileges in the Multi-Carrier System or the Fiscal Intermediary Shared System only if the provider or supplier

is not in PECOS; if the provider does not exist in MCS or FISS, the contractor shall

contact its PEOG BFL prior to taking action.

• Close or delete any aged logging and tracking (L & T) records older than 120 days for

which there is no associated enrollment application

• Participate in user acceptance testing for each PECOS release

• Attend scheduled PECOS training when requested

• Report PECOS validation and production processing problems through the designated

tracking system for each system release

• Develop (and update as needed) a written training guide for new and current employees

on the proper processing of Form CMS-855 and Form CMS-20134 applications, opt-out

affidavits, and the appropriate entry of data into PECOS.

C. Customer Service

1. Responding to Provider Enrollment Inquiries

The contractor’s customer service unit may handle provider enrollment inquiries that do not

involve complex enrollment issues. Examples of inquiries that can be processed by customer

service units include:

• Application status checks (e.g., “Has the contractor finished processing my application?”)

(The contractor may wish to establish electronic mechanisms by which providers can

obtain updates on the status of their enrollment applications via the contractor’s web site

or automated voice response (AVR).

• Furnishing information on where to access Form CMS-855 or Form CMS-20134

applications (and other general enrollment information) online

• Explaining to providers/suppliers which Form CMS-855 or CMS-20134 applications

should be completed.

2. Contractor’s Responsiveness to Inquiries

Excluding matters pertaining to application processing (e.g., development for missing data) and

appeals (e.g., appeal of revocation), the contractor is encouraged to respond to all enrollment-related provider/supplier correspondence (e.g., e-mails, letters, telephone calls) within 30

business days of receipt.

D. Contractor Outreach to Providers

The contractor is strongly encouraged to establish e-mail “list serves” with the provider

community to disseminate important information thereto, such as contractor address changes,

new CMS enrollment policies or internal contractor procedures, reminders about existing

policies, etc. By being proactive in distributing information to its providers and suppliers on a

regular basis (e.g., weekly, bi-weekly), the contractor can reduce the number of policy inquiries

it receives and help facilitate the submission of complete and accurate Form CMS-855 and Form

CMS-20134 applications.

E. Encouraging Use of Internet-based PECOS

When a prospective provider or supplier contacts the contractor to obtain a paper enrollment

Form CMS-855 or Form CMS-20134, the contractor shall encourage the provider or supplier to

submit the application using Internet-based PECOS. The contractor shall also notify the provider

or supplier of:

• The CMS Web site at which information on Internet-based PECOS can be found and at

which the paper applications can be accessed (https://www.cms.gov/Medicare/Provider-Enrollment-and-

Certification/MedicareProviderSupEnroll/index?redirect=/MedicareProviderSupEnroll/).

• The contractor’s address so that the applicant knows where to return the paper

application.

• Any supporting documentation required for the applicant's provider/supplier type.

• Other required forms as described in sections above. Notification can be given in any

manner the contractor chooses.

F. Adherence to Responsibilities Based Upon Jurisdiction - Audit and Claims Contractors

1. Background

For purposes of enrollment via the Form CMS-855A, there are generally two categories of

contractors: audit contractors and claims contractors. The audit contractor enrolls the provider,

conducts audits, etc. The claims contractor pays the provider’s claims. In most cases, the

provider’s audit contractor and claims contractor will be the same. On occasion, though, they

will differ. This can happen, for instance, with provider-based entities, whereby the parent

provider’s contractor (audit contractor) will process the provider’s enrollment application and a

different contractor will pay the provider’s claims (claims contractor).

Should the audit and claims contractors differ, the audit contractor shall process all changes of

information, including all Form CMS-588 changes. The audit contractor shall notify the

applicant during the initial enrollment process that all future changes of information must be sent

to the audit contractor, not the claims contractor. If the provider inadvertently sends a change

request to the claims contractor, the latter shall return the application per the instructions in this

chapter.

2. Process

If the audit contractor approves the Form CMS-855A transaction in question (e.g., initial

enrollment), it shall:

(i) Send an e-mail to the claims contractor identifying the specific Form CMS-855A transaction

involved and confirming that the information has been updated in PECOS. Pertinent identifying

information, such as the provider name, CCN, and NPI, shall be included in the e-mail

notification. The audit contractor need not include any supporting documentation in the e-mail

because PECOS will contain any documents (e.g., approval letters from the state).

(ii) As applicable, fax, mail, or email an encrypted copy of the submitted Form CMS-588 to the

appropriate claims contractor.

Upon receipt of the e-mail notification, the claims contractor shall access PECOS, review the

enrollment record, and, as needed, update its records accordingly.

The audit contractor shall ensure that all original copies of Form CMS-855A paperwork and

supporting documentation (including all Form CMS-588s), approval letters from the state, and

other written documents related to the application are uploaded in PECOS.

If the provider’s audit contractor and claims contractor are different, the audit contractor shall e-mail or fax a copy of all SOG Location approval/denial notices/letters it receives to the claims

contractor. This is to ensure that the claims contractor is fully aware of the SOG Location’s

action, as some may only send copies of the approval letters to the audit contractor. If the audit

contractor chooses, it can simply contact the claims contractor by phone or e-mail and ask if the

latter received the tie-in notice.

It is imperative that audit and claims contractors effectively communicate and coordinate with

each other in all payment-related and program integrity matters involving the provider.

G. Online Presence – Web Sites

The contractor must provide a link to CMS’ provider/supplier enrollment Web site located at

https://www.cms.gov/medicare/provider-enrollment-and-

certification/medicareprovidersupenroll/index.html?redirect=/medicareprovidersupenroll/ . The

link shall: (1) be available on the contractor’s existing provider outreach Web site (which should

be an established sub-domain of the contractor’s current commercial Web site), and (2) comply

with the guidelines stated in the Provider/Supplier Information and Education Web site section

(Activity Code 14101) under the Provider Communications (PCOM) Budget and Performance

Requirements (BPRs). Bulletins, newsletters, seminars/workshops and other information

concerning provider enrollment issues shall also be made available on the existing provider

outreach Web site. All contractor web sites must comply with section 508 of the Rehabilitation

Act of 1973 in accordance with, 36 CFR §1194 and with CMS’ Contractor Website Standards

and Guidelines posted on CMS’s web site.

The CMS Provider/Supplier Enrollment Web site gives users access to provider/supplier

enrollment forms, specific requirements for provider/supplier types, manual instructions,

frequently asked questions (FAQs), contact information, hot topics, and other pertinent

provider/supplier information. The contractor shall not duplicate content already provided at the

CMS provider/supplier enrollment website and shall not reproduce the forms or establish the

contractor’s own links to forms. It shall, however, have a link on its website that goes directly to

the forms section of the CMS provider/supplier enrollment site.

On a quarterly basis (specifically, no later than the 15th day of January, April, July, and October),

each contractor shall review and provide updates regarding its contact information shown at

URL: https://www.cms.gov/Medicare/Provider-Enrollment-and-

Certification/MedicareProviderSupEnroll/Downloads/contact_list.pdf. If the contractor services

several states with a universal address and telephone number, the contractor shall report that

information. In situations where no updates are needed, a response from the contractor is still

required (i.e., the contact information is accurate). In addition, only such information that

pertains to provider enrollment activity for the contractor’s jurisdiction is to be reported. All

updates shall be sent directly via e-mail to the contractor’s PEOG BFL.

H. Document Uploading and Retention

1. Introduction

To ensure that proper internal controls are maintained and that important information is recorded

in case of potential litigation, the contractor shall maintain documentation as outlined in this

section 10.6.19(H) and, as applicable, section 10.3. CMS cannot stress enough how crucial it is

for contractors to document their actions as carefully and thoroughly as possible.

The requirements in this section 10.6.19(H) are in addition to, and not in lieu of, all other

documentation or document maintenance requirements that CMS has mandated.

The contractor shall maintain and store all documents relating to the enrollment of a provider

into Medicare. These documents include, but are not limited to, Medicare enrollment

applications and all supporting documents, attachments, correspondence, and correspondence

tracking documentation, and appeals submitted in conjunction with an initial enrollment,

reassignment, change of enrollment, revalidation, etc.

Supporting documentation includes, but is not limited to:

• Copies of federal, state and/or local (city/county) professional licenses, certifications

and/or registrations;

• Copies of federal, state, and/or local (city/county) business licenses, certifications and/or

registrations;

• Copies of professional school degrees or certificates or evidence of qualifying course

work;

• Copies of CLIA certificates and FDA mammography certificates;

• Copies of any entry found on the MED report that leads to a provider or supplier’s

revocation, and;

• Copies of Centers for Disease Control and Prevention (CDC) Diabetes Prevention

Recognition Program (DPRP) recognition letters or certificates indicating full or MDPP

preliminary recognition.

See section 10.6.19(I) below for additional document uploading requirements.

2. Document Disposal

The contractor shall dispose of the aforementioned records as described below:

i. Provider/Supplier and Durable Medical Equipment Supplier Application

a. Rejected applications as a result of provider failing to provide additional

information

Disposition: Destroy when 7 years old.

b. Approved applications of provider/supplier

Disposition: Destroy 15 years after the provider/supplier's enrollment has ended.

c. Denied applications of provider/supplier

Disposition: Destroy 15 years after the date of denial.

d. Approved application of provider/supplier, but the billing number was

subsequently revoked

Disposition: Destroy 15 years after the billing number is revoked.

e. Voluntary deactivation of billing number

Disposition: Destroy 15 years after deactivation.

f. Provider/Supplier dies

Disposition: Destroy 7 years after date of death.

ii. Electronic Mail and Word Processing System Copies

a. Copies that have no further administrative value after the recordkeeping copy is

made. These include copies maintained by individuals in personal files, personal

electronic mail directories, or other personal directories on hard disk or network

drives, and copies on shared network drives that are used only to produce the

recordkeeping copy.

Disposition: Delete within 180 days after the recordkeeping copy has been produced.

b. Copies used for dissemination, revision or updating that are maintained in addition

to the recordkeeping copy.

Disposition: Delete when dissemination, revision, or updating is complete.

I. Keeping Record of Activities

As with document retention as described in subsection (H) above, it is important that the

contractor maintains records of its written and telephonic communications. The contractor shall

thus adhere to the instructions in this subsection (I).

1. Written Communications

(For purposes of this section 10.6.19(I)(1), “written correspondence” includes mailed, faxed, and

e-mailed correspondence. Note that this is different from supporting documentation

accompanying an enrollment application, the requirements for which are addressed in subsection

(H) above.)

Except as stated in this subsection (I)(1), the contractor shall:

• Retain copies of all written correspondence pertaining to the provider, regardless of

whether the correspondence was initiated by the contractor, the provider, CMS, state

officials, etc.

• Document when it sends written correspondence to providers. For instance, if the

contractor crafts an approval letter to the supplier dated March 1 but sends it out on

March 3, the contractor shall note this in PECOS.

• Document all referrals to CMS, the UPIC, or the OIG

In cases where the written correspondence is sent directly via or to PECOS (e.g., PCV), the

contractor need not separately document this; PECOS will retain this information (date, time,

etc.). For all other written correspondence not sent via or to PECOS, the contractor (1) shall

upload a copy of the correspondence into PECOS (e.g., fax, a printed copy of the e-mail) and (2)

shall note in PECOS:

• The type of correspondence (e.g., approval letter)

• The form of correspondence (e.g., fax, e-mail)

• The date and time the correspondence was sent

• The party to whom the correspondence was sent (e.g. provider name, contact person)

2. Telephonic or Face-to-Face Contact

(Telephonic or face-to-face contact is hereafter referred to as “oral communication.”)

The contractor shall document any and all actual or attempted oral communication with the

provider, any representative thereof, or any other person or entity regarding a provider. This

includes, but is not limited to, the following situations:

• Telephoning a provider about its application. (Even if the provider official was

unavailable and a voice mail message was left, this must be documented.)

• Requesting information from the state or another contractor concerning the applicant or

enrollee

• Contacting the UPIC for an update concerning a particular case

• Phone calls from the provider

• Conducting a meeting at the contractor’s headquarters/offices with officials from a

hospital concerning problems with its application

• Telephoning PEOG, the state agency, or the SOG Location and receiving instructions

therefrom about a problem the contractor is having with an applicant or an existing

provider

• Telephoning the provider’s billing department with a question about the provider.

When documenting oral communications, the contractor shall indicate (1) the time and date of

the call or contact, (2) who initiated the contact, (3) who was spoken with, and (4) what the

conversation pertained to. Concerning the last requirement, the contractor need not write down

every word that was said during the conversation. Rather, the documentation should merely be

adequate to reflect the contents of the conversation.

The documentation requirements in this subsection (I)(2) only apply to enrolled providers and to

providers that have already submitted an enrollment application. In other words, these

documentation requirements go into effect only after the provider submits an initial application.

To illustrate, if a hospital contacts the contractor requesting information concerning how it

should enroll in the Medicare program, this need not be documented because the hospital has not

yet submitted an enrollment application.

All oral communications addressed in this subsection (I)(2) shall be documented in PECOS.

If an application is returned, the contractor shall document this. The manner of documentation

lies within the contractor’s discretion.

J. Documenting Verification of Data Elements

Once the contractor has completed its review of the Form CMS-855 and Form CMS-20134

applications (e.g., approved/denied application, approved change request) as well as opt-out

affidavits, it shall document that it has: (1) verified all data elements on the application, and (2)

reviewed all applicable names on the above- mentioned forms against the OIG/LEIE and the

System for Access Management (SAM). It can be drafted in any manner the contractor chooses

so long as it certifies that the above-mentioned activities were completed.

For each person or entity that appeared on the OIG/LEIE or SAM, the contractor shall document

any positive findings via a screen printout and upload it into PECOS. In all other situations, the

contractor is not encouraged to document its reviews via screen printouts. Simply using the

verification statement described above is sufficient. Although the contractor has the discretion to

use screen prints if it so chooses, the aforementioned verification statement is still required.

K. Release of Information

On October 13, 2006, CMS published System of Records Notice for PECOS in the Federal

Register. Consistent with this notice, once the provider has submitted an enrollment application

(as well as after it has been enrolled), the contractor shall not release – either orally or in writing

- provider-specific data to any outside person or entity unless specified otherwise in this chapter.

(Provider-specific data includes, but are not limited to, owners/managers, adverse legal history,

practice locations, group affiliations, effective dates, etc.) Examples of outside persons or

entities include, but are not restricted to, national or state medical associations or societies,

clearinghouses, billing agents, provider associations, or any person within the provider’s

organization other than the provider’s authorized official(s), delegated official(s), or contact

persons. The only exceptions to this policy are:

• A routine use found in the aforementioned System of Records applies.

• The provider (or, in the case of an organizational provider, an authorized or delegated

official): (1) furnishes a signed written letter on the provider’s letterhead stating that the

release of the provider data is authorized; and (2) the contractor has no reason to question

the authenticity of the person’s signature. The letter can be mailed, faxed, or e-mailed to

the contractor. The contractor shall upload the letter in PECOS.

• The release of the data is specifically authorized in some other CMS instruction or

directive.

(These provisions also apply in cases where the provider requests a copy of any Form CMS-855

or CMS-20134 paperwork the contractor has on file that the provider does not already have

access to in PECOS. For instance, if the provider already uses PECOS for application

submissions, the contractor can simply refer the provider to PECOS if the document in question

is in PECOS. If the provider does not use PECOS, the contractor shall not require the provider

to do so in order to access the document(s) but shall follow the above instructions; the latter shall

also be followed if the provider uses PECOS but the requested document is not in PECOS.)

It is recommended that the contractor notify the provider of the broad parameters of the

aforementioned policy as early in the enrollment process as possible.

The following information shall be made available over-the-phone to a caller who is able to provide a

provider/supplier’s name, PTAN, TIN/SSN, and NPI number; the caller need not be listed on the

provider/supplier’s enrollment record as a contact person:

• Revalidation status (i.e., whether or not a provider/supplier has been revalidated)

• Revalidation due date

• Revalidation approval date

• The specific information related to a revalidation development request

• The date a provider/supplier was deactivated due to non-response to a revalidation or non-response to a development request.

In addition:

• When sending emails, the contractor shall not transmit sensitive data, such as SSNs or

EINs, without first encrypting the email.

• The contractor may not send PECOS screen printouts to the provider.

• With the exception of Form CMS-855S applications, if any contact person listed on the

provider’s enrollment record requests a copy of a provider’s Medicare approval letter or

revalidation notice and the contact person does not have access to PECOS, the contractor

shall send to the contact person via email, fax or mail. (This excludes certification

Letters from the state agency, for the contractor does not generate these approvals.) If the

contact person has access to PECOS, the contractor can simply refer the individual to

PECOS. If the contact person does not use PECOS, the contractor shall not require the

contact person to do so in order to access the document(s) but shall follow the above

instructions; the latter shall also be followed if the contact person uses PECOS but the

requested document is not in PECOS.)

L. Security

The contractor shall ensure that the highest level of security is maintained for all systems and its

physical and operational processes in accordance with the CMS/Business Partners Systems

Security Manual (BPSSM) and the Program Integrity Manual.

Applications shall never be removed from the controlled area to be worked on at home or in a

non-secure location. Also, provider enrollment staff must control and monitor all applications

accessed by other contractor personnel.

All contractor staff shall be trained on security procedures as well as relevant aspects of the

Privacy Act and the Freedom of Information Act. This applies to all management, users, system

owners/managers, system maintainers, system developers, operators and administrators -

including contractors and third parties - of CMS information systems, facilities, communication

networks, and information.

Note that these instructions are in addition to, and not in lieu of, all other CMS instructions

regarding security.

M. Establishment of Relationships

To the maximum extent possible, and to help ensure it becomes aware of recent felony

convictions of practitioners and owners of health care organizations, the contractor shall

establish relationships with appropriate state government entities – such as, but not limited to,

Medicaid fraud units, state licensing boards, and criminal divisions –to facilitate the flow of

felony information from the state to the contractor. For instance, the contractor can request that

the state inform it of any new felony convictions of health care practitioners.

N. Monitoring Information from State Licensing Boards

To help ensure that only qualified physicians and non-physician practitioners are enrolled in

Medicare, the contractor shall undertake the activities described below. (For purposes of this

section, the term “practitioner” includes both physicians and non-physician practitioners. In

addition, the instructions in this section, apply only to these practitioners.)

No later than the 15th day of each month, the contractor shall review state licensing board

information for each state within its jurisdiction to determine whether any of its currently

enrolled practitioners have, within the previous 60 days:

• Had a medical license revoked, suspended, or inactivated (due to retirement, death, or

voluntary surrender of license);

• Otherwise lost a medical license or have had a license expire.

For those practitioners who no longer have a valid medical license, the contractor shall take the

necessary steps pursuant to this chapter.

The mechanism by which the contractor performs these monthly licensure reviews lies within its

discretion, though the most cost-effective method shall be used.

O. Regarding Potential Identity Theft or Other Fraudulent Activity

If --when conducting the verification activities described in this chapter -- the contractor believes

that a case of identity theft or other fraudulent activity likely exists, the contractor shall notify its

PEOG BFL immediately; the BFL will instruct the contractor as to what, if any, action shall be

taken (For example, a physician indicates that the physician is not establishing a new practice

location or changing EFT information and that the application submitted in the physician’s name

is false.)

History

(Rev. 13355; Issued: 08-13-25; Effective: 05-05-25; Implementation: 05-05-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
fd6fc0d3eb819a133ddbeda7e634a72f1ad6701b5e921630fb37ef98f76568f0
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.