Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 40.2.2.3
Requirements for A/B MACs, and CEDI
40.2.2.3 - Security-Related Requirements for A/B MACs, and CEDI
Arrangements With Clearinghouses and Billing Services
(Rev. 3346, Issued: 09-04-15, Effective: 10-06-15, Implementation: 10-06-15)
A billing service is an entity that markets claim preparation services to providers and
should also be able to perform related transactions for providers, such as eligibility and
claim status inquiries. The billing service collects a provider’s claim information and
then bills the appropriate insurance companies, including Medicare. A billing service
may submit claims only, or provide full financial accounting and/or other services.
Billing services are considered to be provider business associates. As such, HIPAA
requires that they comply with each of the privacy and security requirements that apply
directly to providers. They are also required to ensure that they require that any
clearinghouses, subcontractors or other business associates of their own that may be
involved with handling of Medicare beneficiary data also meet those same security and
privacy requirements. A billing service may view beneficiary or provider data to carry
out their billing obligations for a provider, when a provider authorizes them to have that
access. To qualify as a billing service, an entity must at a minimum submit initial claims
on the provider’s behalf.
A clearinghouse transfers or moves EDI transactions for a provider or billing service, and
generally translates the EDI transactions from or into a proprietary format. (HIPAA
defines a clearinghouse as a business associate of a provider or a health care plan that
translates data from a non-standard format into a standard format or vice versa as
preferred by their clients.) A clearinghouse generally accepts multiple types of incoming
transactions and sends them to various payers, including Medicare. Clearinghouses often
perform general and payer-specific edits on claims, and may handle multiple types of
EDI transactions for a given provider. Clearinghouses frequently reformat data for
various payers, and manage acknowledgments, remittance advice transactions, and claim
status and eligibility queries.
Some entities that refer to themselves as clearinghouses, however, do not edit or translate
data, but simply serve as a “telecommunication switch,” moving transactions from point
A to Point B or wherever directed under the terms of the agreement with a provider. A
clearinghouse may also be called a value added network (VAN). A clearinghouse/VAN
may not view privacy-protected Medicare data unless a signed authorization has been
filed by the provider for whom the clearinghouse/VAN will submit or received Medicare
EDI transactions. For EDI, a transaction that contains individually identifiable
information about a Medicare beneficiary is considered to be privacy protected data.
That provider may not authorize submission or receipt of data by a third party for a
Medicare beneficiary unless that beneficiary is a current patient of the provider, has
scheduled an appointment, or has inquired about the receipt of supplies or services from
the provider. The provider authorization must be filed with the Medicare contractor to
whom EDI transactions will be sent or from whom they will be received. In the case of a
DME claim, this authorization need only be submitted to CEDI. If multiple A/B MACs
are involved, an authorization must be submitted to each.
Each clearinghouse/VAN that will submit or receive Medicare EDI transactions is
prohibited from using the EDI number or password issued to any of the providers they
serve. Each clearinghouse/VAN must obtain its own EDI number and password from
each A/B MAC with which it will interact. For, DME, each Clearinghouse/VAN must
obtain its own EDI number and password from CEDI.
Some health care providers use or may want to use more than one billing service or
clearinghouse/VAN. An A/B MAC and CEDI ability to handle more than one agent
varies. Some A/B MACs and CEDIs are able to accommodate one or more
clearinghouses/VAN for submission of a provider’s claims to Medicare, another agent to
receive the provider’s remittance advice transactions, and a third clearinghouse/VAN to
verify beneficiary Medicare eligibility for a provider. Others may not be able to
accommodate more than one agent for a provider. A/B MACs and CEDIs are
encouraged to support more than one agent for a provider, when permitted by their front
end configuration.
A/B MACs and DME MACs, or other contractors if designated by CMS must notify each
provider that applies for permission to obtain eligibility data electronically that:
• They are permitted to view Medicare eligibility data only for patients currently
being treated by or who have requested treatment or supplies from that provider;
• A provider cannot authorize a billing agent or clearinghouse to submit or obtain
data from an A/B MACs and DME MACs that the provider is not entitled to
personally submit or obtain;
• A request for personally identifiable information for any other Medicare
beneficiaries would be a violation of Medicare and HIPAA privacy requirements,
and subject to the applicable penalties for such violations.
A/B MACs, and DME MACs must notify each billing service and clearinghouse/VAN at
the time of their application for access to Medicare eligibility data and by also posting
information on their web site that:
• Their access is limited to submission of transactions and receipt of transactions
for those providers that are their clients, but only if those providers authorized the
billing agent and/or clearinghouse/VAN to submit or receive each transaction.
• A billing agent or clearinghouse/VAN that has provider authorization to submit
claim data for a provider cannot obtain eligibility data for that provider unless that
was specifically authorized by the provider.
• Likewise, the billing agent or clearinghouse/VAN cannot be sent remittance
advice transactions for a provider unless specifically authorized to do so by that
provider.
Providers must submit these authorizations to their A/B MACs, DME MACs, CEDI or
other contractors if designated by CMS in writing; an A/B MAC, DME MAC, CEDI or
other contractor if designated by CMS is not permitted to accept a statement signed by a
billing agent or clearinghouse/VAN alleging that they have such provider authorization
on file. An original provider signature is required on these authorizations (but an A/B
MAC, DME MAC, CEDI or other contractor if designated by CMS is allowed to accept
an authorization signed by a provider by fax or mail). The A/B MAC, DME MAC,
CEDI, or other contractor if designated by CMS is responsible for maintenance of files to
establish system access for individual providers, identify those billing agents and
clearinghouses/VANs authorized to access systems as the agent of a specific provider,
and to record those transactions for which a billing agent or clearinghouse/VAN is
authorized access as the representative of a specific provider.
With authorization, a clearinghouse/VAN may send inquiries for a provider, and receive
responses, but it may not view personally identifiable beneficiary data contained in those
queries or responses, store it for longer than necessary to assure delivery to the provider
(no longer than 30 days maximum), or use personally identifiable data in any reports.
The EDI data sent or received belongs ultimately to the beneficiary, not to the
clearinghouse/VAN that may translate and transport the data for a provider acting on the
beneficiary’s behalf.
Collection agents that contract with providers to collect “bad debts” and third party
entities that may analyze data but do not have a specific initial claim submission role or
are not responsible for posting of information in a remittance advice to patient accounts
may not be sent beneficiary data by an A/B MAC, DME MAC, CEDI, or other contractor
if designated by CMS. If a collection agent or such a third party has provided adequate
privacy and security assurances to protect beneficiary data, the provider may share
Medicare payment information with a collection agent, data analysis firm, or similar third
party, but the provider would need to furnish that data to that entity agent in this situation,
however. The Medicare program may not incur costs to furnish such data to collection
agencies or to other entities that perform services that do not directly support Medicare
activities. Delinquent collection, analysis of data related to a provider’s operations, and
expenses related to other activities not directly related to Medicare claims or payments
are considered provider business expenses. Such activities do not directly benefit
Medicare and Medicare may not incur costs to supply data intended only for such uses.
A provider must sign a valid EDI Enrollment Form (see Section 30.1 this chapter) prior
to authorizing a billing agent or clearinghouse/VAN to submit/receive any EDI
transactions on their behalf. A separate password and User ID is to be used for system
access by each authorized provider, billing agent or clearinghouse. A vendor provides
hardware, software and/or ongoing support for total office automation or submission of
electronic EDI transactions directly to individual providers, billing agent or
clearinghouses/VANs. Vendors supply the means for Medicare system access but have
no right to direct access to the system of an A/B MAC, DME MAC, CEDI, or other
contractor if designated by CMS.
Vendor software is normally tested when it first begins to be used by providers, billing
agents or clearinghouses/VANs. At the request of a vendor or a clearinghouse/VAN, an
A/B MAC, DME MAC, CEDI or other contractor if designated by CMS may, but is not
required to, test new software before a provider has agreed to begin using that software to
exchange Medicare eligibility transactions with the contractor. When testing software
prior to use by a provider, an A/B MAC, DME MAC, CEDI or other contractor if
designated by CMS may not furnish a software vendor who does not currently submit or
receive Medicare transactions with an EDI access number or password which would
permit the vendor to access to actual Medicare beneficiary data. That software is to be
tested using a test database or by other means that would not disclose actual beneficiary
data to the vendor. This EDI access limitation for testing of new software does not apply
to a clearinghouse/VAN with a history of submission/receipt of EDI transactions with the
contractor, or when a software vendor is also a clearinghouse/VAN or a provider billing
agent (in which case, testing should only involve data for beneficiaries for which the
entity already submit/receives transactions).