Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 40.2.2.4
Release of Medicare Data
40.2.2.4 - Release of Medicare Data
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
The CMS is required by law to protect all Medicare beneficiary-specific information
from unauthorized use or disclosure. Disclosure of Medicare beneficiary data is
restricted under the provisions of the Privacy Act of 1974 and HIPAA. CMS instructions
allow release of data to providers or their authorized billing agents for the purpose of
preparing an accurate claim. Such information may not be disclosed to anyone other than
the provider, supplier, or beneficiary for whom the claim was filed.
A/B MACs, DME MACs or other contractors if designated by CMS must give access to
any clearinghouse that requests access to data on behalf of providers as long as they
adhere to the following rules:
• Each clearinghouse requesting access to eligibility data must sign a Trading
Partner Agreement (TPA) and agree to adhere to CMS rules of behavior (Refer to
www.cms.gov/HETSHelp);
• Each provider that contracts with a clearinghouse must sign a valid EDI
Enrollment Form before data can be sent to the third party (see Section 30.1);
• The provider must explain the type of EDI services to be furnished by its
clearinghouse in a signed statement authorizing the clearinghouse’s access to
data;
• The clearinghouse must be able to associate each inquiry with the provider
making the inquiry. That is, for each inquiry made by a provider through a
clearinghouse, the clearinghouse must be able to identify the correct provider
making the request for each beneficiary’s information and be able to assure that
responses are routed only to the provider that originated each request; and
• There is no record of prior violation of a TPA by this clearinghouse with the A/B
MAC, DME MAC or other contractor if designated by CMS to whom a request
for access to the data is submitted that would indicate that beneficiary data could
be at risk of improper disclosure if access was approved for this clearinghouse.
A. All providers and clearinghouses that wish to obtain Medicare beneficiary data must
apply to A/B MACs, DME MACs or other contractor if designated by CMS for access to
the records.
B. Providers and clearinghouses must submit each query to the A/B MACs, DME MACs
or other contractor if designated by CMS with which they are registered. CMS supports
multiple EDI and non-EDI methods for obtaining eligibility data, including ASC X12
270/271 eligibility (see IOM Pub. 100-04 Chapter 31 for more information on the ASC
X12 270/271 eligibility transaction).
C. When an inquiry is submitted, the A/B MAC, DME MAC, HETS 270/271, or other
contractor if designated by CMS must be able to ensure that:
• An EDI agreement has been signed by the provider;
• A TPA has been signed by the clearinghouse; and
• Each inquiry identifies the provider that initiated the query and to which the
response will be routed.
D. Providers must be notified that:
•
they may obtain eligibility data only for the approved use of preparing
accurate Medicare claims;
•
access to eligibility data is limited to individuals within a provider’s
organization who are involved in claim preparation and submission; and
•
they and their authorized third party agents must agree not to request
eligibility data for a beneficiary unless the provider has been contacted by the
beneficiary, a personal representative of a beneficiary such as a relative or
friend, or a health care provider currently treating the beneficiary concerning
provision of health care services or supplies to the beneficiary.
E. Medicare contractors, as designated by CMS, must:
•
Provide notification of these requirements to all providers requesting
electronic receipt of eligibility data;
•
remind providers to notify them when there is a change in clearinghouse,
arrangements cease with a clearinghouse, or the provider leaves the Medicare
program;
•
delete each provider from their EDI eligibility security file if there is no
longer a business relationship between the Medicare contractor and provider,
or if the Medicare contractor or the provider is no longer serving the Medicare
program; and
•
remind providers, clearinghouses and other third parties that access rights to
beneficiary eligibility data may be revoked if they fail to adhere to the
requirements for access.