Medicare Provider Enrollment Systems: NPPES, I&A, and PECOS - JE Part A
Having Trouble Accessing or Using PECOS?
Contact External User Services (EUS) for assistance with PECOS account access, password resets, login issues, system errors, and other technical questions related to using PECOS.
Phone: 866-484-8049
Live chat: https://eus.cms.gov/helpdesk
Email: EUS_Support@cms.hhs.gov
Medicare Provider Enrollment Systems: NPPES, I&A, and PECOS
Medicare provider enrollment is managed through three CMS systems: NPPES, I&A, and PECOS. Each system serves a distinct purpose, and providers must use all three correctly to enroll and maintain their Medicare records. These systems are connected but do not automatically update each other. To avoid errors and delays, providers should complete actions in the correct order and ensure all information is consistent across systems.
A successful enrollment process begins with accurate provider identification (NPPES), followed by proper access and permissions (I&A), and ends with application submission and management (PECOS). Completing steps out of order is a leading cause of delays, rework, and rejected applications.
- National Plan and Provider Enumeration System (NPPES)
- Identity & Access (I&A) Management System
- Provider Enrollment, Chain, and Ownership System (PECOS)
National Plan and Provider Enumeration System (NPPES)
NPPES is the system where providers apply for and maintain their National Provider Identifier (NPI). The NPI is a unique 10‑digit identifier used for billing, claims processing, and provider identification.
Providers must obtain an NPI before enrolling in Medicare and must keep NPPES information accurate and up to date. This includes name, address, and taxonomy (specialty). Updates made in NPPES do not transfer automatically to PECOS, which is why providers should always update NPPES first before submitting enrollment applications.
Taxonomy codes are standardized classification codes used to identify a healthcare provider's type, classification, and area of specialization. Providers are required to select at least one taxonomy code when applying for a (NPI) through NPPES. While multiple taxonomy codes may be associated with a provider to reflect different specialties or practice areas, one taxonomy code must be designated as the primary taxonomy.
Avoid Common NPPES Issues
Delays often occur when information does not match across systems. For example, if a provider updates their address in PECOS but not in NPPES, the mismatch can trigger development requests or application rejection. Providers should review and confirm NPPES data before submitting any PECOS application to avoid these issues.
Identity & Access (I&A) Management System
The Identity & Access (I&A) Management System controls access to PECOS, NPPES, and other CMS systems using a single user ID and password.
Each user must create and maintain their own account. Shared accounts are not allowed and may result in access issues, security concerns, or delays. Providers are responsible for managing their own profile information and ensuring it is accurate and secure.
I&A accounts include built‑in security features such as password requirements, security questions, and multi‑factor authentication (MFA), which must be completed to access CMS systems.
Connections and Access
A connection in I&A is the link between a user and a provider or organization that allows access to CMS systems. These connections are required before a user can view or update records in PECOS.
There are two primary connection types:
- Employer Connections link a user directly to a provider or organization with which they are associated. These connections are commonly used for employees who require access to CMS systems as part of their job responsibilities.
- Surrogacy Connections allow a user to act on behalf of a provider or organization. This type of connection is frequently used by office staff, practice administrators, billing personnel, credentialing specialists, and third-party billing or consulting organizations that perform enrollment-related functions for providers.
Surrogacy is commonly used for staff or third‑party billers and must be requested and approved before access is granted.
Roles and Permissions
I&A roles determine what actions a user can take.
- Authorized Official (AO): Has the highest level of authority within an organization and is responsible for managing access, staff, and user connections. The AO may establish and approve relationships within CMS systems and perform key enrollment functions on behalf of the organization.
- Delegated Official (DO): Acts under the authority of the Authorized Official and may update enrollment information, manage users, and access permissions, and submit applications on behalf of the organization.
- Access Manager (AM): Responsible for managing staff access and user connections. Access Managers can add, modify, and remove user permissions but may have limited authority to certify or sign enrollment applications.
- Staff End User: Can view and update information based on assigned permissions but cannot manage user access, assign roles, or approve connections.
- Individual Providers: Healthcare professionals who furnish services to Medicare beneficiaries. They may enroll and submit claims directly to Medicare or reassign their billing rights to an organizational provider.
- Organizational Providers: Entities such as hospitals, clinics, physician group practices, and other healthcare organizations that provide services to Medicare beneficiaries and bill Medicare under the organization's enrollment record.
- Third-Party Organizations: Businesses such as billing agencies, credentialing consultants, and staffing companies that maintain business relationships with individual or organizational providers and perform enrollment-related activities on their behalf.
- Surrogates: Individuals who are granted permission to act on behalf of a provider or organization through an approved connection in I&A. Surrogates may perform delegated tasks within CMS systems based on the specific permissions assigned to them.
It is important to note that being assigned a role in I&A does not automatically grant authority to sign, certify, or submit PECOS applications. The individual must also be appropriately established in PECOS.
Avoid Common I&A Issues
Most access issues occur because surrogacy is missing or has not been approved, roles are incorrect, or accounts are inactive or not set up properly.
Providers should verify connections, confirm roles, and allow time for system updates before attempting to access PECOS.
Provider Enrollment, Chain, and Ownership System (PECOS)
PECOS is the system used to enroll in Medicare, update enrollment records, revalidate information, and manage reassignment of benefits. It is a secure, web‑based system managed by CMS that allows providers to complete enrollment activities electronically.
PECOS allows providers to submit applications online, track application status in real time, upload documentation, and electronically sign certification statements, eliminating the need to mail paper forms.
Benefits of PECOS
Using PECOS improves efficiency and reduces errors by allowing providers to:
- Submit applications electronically, eliminating the need to complete and mail paper enrollment forms
- Track application status in real time, allowing providers to monitor progress and respond promptly to requests for additional information
- Update enrollment information quickly, making it easier to report changes such as practice locations, ownership information, reassignments, and contact details
- Upload supporting documentation securely, reducing delays associated with mailing or faxing required documents
- Complete Medicare revalidation requirements more efficiently, helping providers maintain compliance and avoid interruptions to their Medicare billing privileges
PECOS applications are typically processed faster than paper applications, helping reduce delays and improve overall enrollment timelines.
Complete Applications Correctly
When enrolling in Medicare or making changes to an existing enrollment record, providers must select the correct CMS application form that corresponds to their provider type and enrollment purpose. Using the correct application form is essential for timely processing and helps avoid unnecessary delays or requests for additional information.
The most commonly used Medicare enrollment forms include:
- CMS-855I for individual providers, such as physicians and non-physician practitioners enrolling in Medicare as individuals. Also, Sole Proprietor or Sole Owners.
- CMS-855B for organizational providers, including group practices, clinics, and certain other healthcare organizations.
- CMS-855R for reassignment of benefits, allowing an individual provider to reassign Medicare billing rights to an enrolled organization or group practice.
- CMS-855O for providers who order, certify, refer, or prescribe services for Medicare beneficiaries but do not bill Medicare directly.
Applications must be signed and certified by the appropriate individual. For individual enrollments, the provider typically signs the application. For organizational enrollments, an AO or DO will be required to sign. Although application information can be entered and saved in PECOS, the application is not considered complete or officially received until all required signatures and certifications have been submitted.
Begin and Manage Applications
Providers can use PECOS to complete initial Medicare enrollment by submitting new enrollment applications electronically, submit updates or changes to existing enrollment information such as practice locations, contact information, ownership details, or reassignment arrangements, and revalidate enrollment when requested by CMS to confirm that enrollment records remain current and accurate.
Before submitting an application, providers should carefully review each section to verify that all information is complete, accurate, and consistent with records maintained in NPPES and I&A. Attention should be given to provider demographics, practice locations, ownership information, licensing data, taxonomies, and supporting documentation. Incomplete or inconsistent information may result in a Request for Information (RFI), which occurs when the MAC requires additional information before processing can continue.
Track Application Status
PECOS provides real‑time status updates and alerts when action is required, such as missing documentation or requests for information (RFI). Timely responses to these requests help prevent delays and ensure faster processing.
How the Systems Work Together
Each system has a specific role, and data does not automatically transfer between systems. Providers should follow this order when completing enrollment activities:
- Update demographic information in NPPES
- Verify that the provider's NPI record is current and accurate
- Confirm legal name, practice and mailing addresses, contact information, and taxonomy codes
- Make any necessary updates before beginning Medicare enrollment activities
- Verify access, roles, and connections in I&A
- Ensure all required I&A accounts are active and secure
- Confirm that appropriate roles, permissions, and connections have been established
- Verify that Authorized Officials, Access Managers, staff end users, and surrogates have the access needed to perform their responsibilities in PECOS
- Complete enrollment or updates in PECOS
- Submit initial enrollment applications, enrollment changes, revalidations, or reassignment requests
- Upload any required supporting documentation
- Complete all required certifications and signatures before submission
Maintaining alignment across all three systems helps prevent errors, reduce rework, and improve processing timelines.
Prevent Common Enrollment Issues
Providers can significantly reduce Medicare enrollment delays by following established CMS procedures and maintaining accurate information across NPPES, I&A, and PECOS.
Ensure names, addresses, and other demographic information match across all systems as inconsistencies between NPPES, I&A, and PECOS are a common cause of enrollment delays.
Complete NPPES updates before submitting PECOS applications so enrollment records reflect current information, verify I&A access, roles, and connections before starting an application, and confirm that Authorized Officials, Access Managers, staff end users, and surrogates have the appropriate permissions needed to complete enrollment activities.
Select the correct Medicare enrollment application type, upload all required supporting documentation, and complete all required certifications and signatures promptly, since applications are not considered complete until all required signatures have been submitted and missing information may result in processing delays or application rejection.
Where to Get Help
Providers should contact the appropriate support group based on the issue they are experiencing.
Contact EUS for PECOS login, account access, password resets, technical errors, and system navigation questions.
Contact Noridian for enrollment application assistance, status updates, supporting documentation requirements, revalidation requirements, reassignment of benefits, and other Medicare enrollment processing questions.