Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 40.2.2.3

Requirements for A/B MACs, and CEDI

Last amended: 2015Year: 2015Length: 1,679 wordsOfficial source
40.2.2.3 - Security-Related Requirements for A/B MACs, and CEDI Arrangements With Clearinghouses and Billing Services (Rev. 3346, Issued: 09-04-15, Effective: 10-06-15, Implementation: 10-06-15) A billing service is an entity that markets claim preparation services to providers and should also be able to perform related transactions for providers, such as eligibility and claim status inquiries. The billing service collects a provider’s claim information and then bills the appropriate insurance companies, including Medicare. A billing service may submit claims only, or provide full financial accounting and/or other services. Billing services are considered to be provider business associates. As such, HIPAA requires that they comply with each of the privacy and security requirements that apply directly to providers. They are also required to ensure that they require that any clearinghouses, subcontractors or other business associates of their own that may be involved with handling of Medicare beneficiary data also meet those same security and privacy requirements. A billing service may view beneficiary or provider data to carry out their billing obligations for a provider, when a provider authorizes them to have that access. To qualify as a billing service, an entity must at a minimum submit initial claims on the provider’s behalf. A clearinghouse transfers or moves EDI transactions for a provider or billing service, and generally translates the EDI transactions from or into a proprietary format. (HIPAA defines a clearinghouse as a business associate of a provider or a health care plan that translates data from a non-standard format into a standard format or vice versa as preferred by their clients.) A clearinghouse generally accepts multiple types of incoming transactions and sends them to various payers, including Medicare. Clearinghouses often perform general and payer-specific edits on claims, and may handle multiple types of EDI transactions for a given provider. Clearinghouses frequently reformat data for various payers, and manage acknowledgments, remittance advice transactions, and claim status and eligibility queries. Some entities that refer to themselves as clearinghouses, however, do not edit or translate data, but simply serve as a “telecommunication switch,” moving transactions from point A to Point B or wherever directed under the terms of the agreement with a provider. A clearinghouse may also be called a value added network (VAN). A clearinghouse/VAN may not view privacy-protected Medicare data unless a signed authorization has been filed by the provider for whom the clearinghouse/VAN will submit or received Medicare EDI transactions. For EDI, a transaction that contains individually identifiable information about a Medicare beneficiary is considered to be privacy protected data. That provider may not authorize submission or receipt of data by a third party for a Medicare beneficiary unless that beneficiary is a current patient of the provider, has scheduled an appointment, or has inquired about the receipt of supplies or services from the provider. The provider authorization must be filed with the Medicare contractor to whom EDI transactions will be sent or from whom they will be received. In the case of a DME claim, this authorization need only be submitted to CEDI. If multiple A/B MACs are involved, an authorization must be submitted to each. Each clearinghouse/VAN that will submit or receive Medicare EDI transactions is prohibited from using the EDI number or password issued to any of the providers they serve. Each clearinghouse/VAN must obtain its own EDI number and password from each A/B MAC with which it will interact. For, DME, each Clearinghouse/VAN must obtain its own EDI number and password from CEDI. Some health care providers use or may want to use more than one billing service or clearinghouse/VAN. An A/B MAC and CEDI ability to handle more than one agent varies. Some A/B MACs and CEDIs are able to accommodate one or more clearinghouses/VAN for submission of a provider’s claims to Medicare, another agent to receive the provider’s remittance advice transactions, and a third clearinghouse/VAN to verify beneficiary Medicare eligibility for a provider. Others may not be able to accommodate more than one agent for a provider. A/B MACs and CEDIs are encouraged to support more than one agent for a provider, when permitted by their front end configuration. A/B MACs and DME MACs, or other contractors if designated by CMS must notify each provider that applies for permission to obtain eligibility data electronically that: • They are permitted to view Medicare eligibility data only for patients currently being treated by or who have requested treatment or supplies from that provider; • A provider cannot authorize a billing agent or clearinghouse to submit or obtain data from an A/B MACs and DME MACs that the provider is not entitled to personally submit or obtain; • A request for personally identifiable information for any other Medicare beneficiaries would be a violation of Medicare and HIPAA privacy requirements, and subject to the applicable penalties for such violations. A/B MACs, and DME MACs must notify each billing service and clearinghouse/VAN at the time of their application for access to Medicare eligibility data and by also posting information on their web site that: • Their access is limited to submission of transactions and receipt of transactions for those providers that are their clients, but only if those providers authorized the billing agent and/or clearinghouse/VAN to submit or receive each transaction. • A billing agent or clearinghouse/VAN that has provider authorization to submit claim data for a provider cannot obtain eligibility data for that provider unless that was specifically authorized by the provider. • Likewise, the billing agent or clearinghouse/VAN cannot be sent remittance advice transactions for a provider unless specifically authorized to do so by that provider. Providers must submit these authorizations to their A/B MACs, DME MACs, CEDI or other contractors if designated by CMS in writing; an A/B MAC, DME MAC, CEDI or other contractor if designated by CMS is not permitted to accept a statement signed by a billing agent or clearinghouse/VAN alleging that they have such provider authorization on file. An original provider signature is required on these authorizations (but an A/B MAC, DME MAC, CEDI or other contractor if designated by CMS is allowed to accept an authorization signed by a provider by fax or mail). The A/B MAC, DME MAC, CEDI, or other contractor if designated by CMS is responsible for maintenance of files to establish system access for individual providers, identify those billing agents and clearinghouses/VANs authorized to access systems as the agent of a specific provider, and to record those transactions for which a billing agent or clearinghouse/VAN is authorized access as the representative of a specific provider. With authorization, a clearinghouse/VAN may send inquiries for a provider, and receive responses, but it may not view personally identifiable beneficiary data contained in those queries or responses, store it for longer than necessary to assure delivery to the provider (no longer than 30 days maximum), or use personally identifiable data in any reports. The EDI data sent or received belongs ultimately to the beneficiary, not to the clearinghouse/VAN that may translate and transport the data for a provider acting on the beneficiary’s behalf. Collection agents that contract with providers to collect “bad debts” and third party entities that may analyze data but do not have a specific initial claim submission role or are not responsible for posting of information in a remittance advice to patient accounts may not be sent beneficiary data by an A/B MAC, DME MAC, CEDI, or other contractor if designated by CMS. If a collection agent or such a third party has provided adequate privacy and security assurances to protect beneficiary data, the provider may share Medicare payment information with a collection agent, data analysis firm, or similar third party, but the provider would need to furnish that data to that entity agent in this situation, however. The Medicare program may not incur costs to furnish such data to collection agencies or to other entities that perform services that do not directly support Medicare activities. Delinquent collection, analysis of data related to a provider’s operations, and expenses related to other activities not directly related to Medicare claims or payments are considered provider business expenses. Such activities do not directly benefit Medicare and Medicare may not incur costs to supply data intended only for such uses. A provider must sign a valid EDI Enrollment Form (see Section 30.1 this chapter) prior to authorizing a billing agent or clearinghouse/VAN to submit/receive any EDI transactions on their behalf. A separate password and User ID is to be used for system access by each authorized provider, billing agent or clearinghouse. A vendor provides hardware, software and/or ongoing support for total office automation or submission of electronic EDI transactions directly to individual providers, billing agent or clearinghouses/VANs. Vendors supply the means for Medicare system access but have no right to direct access to the system of an A/B MAC, DME MAC, CEDI, or other contractor if designated by CMS. Vendor software is normally tested when it first begins to be used by providers, billing agents or clearinghouses/VANs. At the request of a vendor or a clearinghouse/VAN, an A/B MAC, DME MAC, CEDI or other contractor if designated by CMS may, but is not required to, test new software before a provider has agreed to begin using that software to exchange Medicare eligibility transactions with the contractor. When testing software prior to use by a provider, an A/B MAC, DME MAC, CEDI or other contractor if designated by CMS may not furnish a software vendor who does not currently submit or receive Medicare transactions with an EDI access number or password which would permit the vendor to access to actual Medicare beneficiary data. That software is to be tested using a test database or by other means that would not disclose actual beneficiary data to the vendor. This EDI access limitation for testing of new software does not apply to a clearinghouse/VAN with a history of submission/receipt of EDI transactions with the contractor, or when a software vendor is also a clearinghouse/VAN or a provider billing agent (in which case, testing should only involve data for beneficiaries for which the entity already submit/receives transactions).
Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 40.2.2.3: Requirements for A/B MACs, and CEDI | Justis AI