Skip to main content
Three separate systems stand between an organization and a paid Medicare claim: the National Provider Identifier, which identifies; Medicare enrollment, which authorizes billing; and state licensure and corporate-practice law, which decide who may deliver the service at all. Clearing one says nothing about the other two. The recurring question from digital health founders (“can our Delaware C-corp get an NPI and enroll as a Part B entity?”) is really three questions, and the answers are yes, probably, and usually not.

Gate 1: the NPI identifies, it does not authorize

The NPI is a HIPAA identifier, not a credential. Under 45 C.F.R. § 162.406 it is “a 10-position numeric identifier … and no intelligence about the health care provider in the number.” Any “health care provider,” including an organization, that conducts standard electronic transactions must obtain one (§ 162.410), and NPPES issues them without checking licensure. There are two types: Type 1 for individuals and Type 2 for organizations, and CMS’s own examples of Type 2 holders include “health care provider corporations formed by groups/individuals, and single member LLCs with an EIN.”1 CMS’s NPI fact sheet is explicit about what the number does not do. Having an NPI does not “ensure a provider is licensed or credentialed,” does not “guarantee payment by a health plan,” and does not “enroll a provider in a health plan.”1 A technology company can obtain a Type 2 NPI in an afternoon. That is the least informative fact about it.

Gate 2: enrollment authorizes billing, and discloses ownership rather than restricting it

Medicare pays only enrolled providers and suppliers. 42 C.F.R. § 424.505: “To receive payment for covered Medicare items or services … a provider or supplier must be enrolled in the Medicare program.” Enrollment is “the process that Medicare uses to establish eligibility to submit claims” (§ 424.502).2 An organization enrolls as a clinic or group practice on the CMS-855B, which requires a Type 2 NPI, a legal business name matching IRS records, practice locations, and disclosure of every person or organization with 5% or more ownership or “managing control,” plus managing employees.3 Read the federal rules end to end and you will find a disclosure regime, not an ownership test: neither the CMS-855B, nor 42 C.F.R. Part 424, nor chapter 10 of the Program Integrity Manual requires a group practice to be owned by physicians.4 Federal law does not have a corporate practice of medicine doctrine. What the federal rules do require is compliance with state law. 42 C.F.R. § 424.516(a)(2) conditions enrollment on “compliance with Federal and State licensure, certification, and regulatory requirements, as required, based on the type of services or supplies the provider or supplier type will furnish and bill Medicare,” and § 424.510(d)(2)(iii) requires the applicant to submit “all applicable Federal and State licenses.” The Program Integrity Manual puts the burden where you would expect: “The responsibility for determining what licenses are required to operate a supplier’s business is the sole responsibility of the supplier,” and the contractor “shall not grant billing privileges to any business not appropriately licensed as required by the appropriate state or federal agency.”5 So the Medicare Administrative Contractor is not going to audit your corporate structure against a state’s CPOM doctrine. It will enroll a TIN that completes the form truthfully. That is a trap, not a permission: a group practice enrolled in Medicare in violation of state law has certified compliance it does not have, and every claim it submits is exposed on that basis. See Enforcement, and what happens when structures fail.

Reassignment: how the entity gets paid for a clinician’s work

Medicare’s default is to pay the individual who furnished the service. 42 U.S.C. § 1395u(b)(6) permits payment to someone else only in enumerated cases: principally to “the employer of such physician” where the physician must turn over fees as a condition of employment, or to an entity under “a contractual arrangement” that submits the bill and meets program-integrity safeguards.6 The regulation, 42 C.F.R. § 424.80, adds that the receiving entity must itself be enrolled, and for contractual reassignments imposes joint and several liability for overpayments and gives the clinician unrestricted access to the claims submitted in their name.7 This is the mechanism behind the CMS-855R: each clinician reassigns benefits to the group’s TIN. In an MSO-PC structure the clinicians are employed by the professional entity and reassign to it. They do not reassign to the MSO, because the MSO is not the entity furnishing the professional service and, in a CPOM state, cannot lawfully employ them to do so. See Enroll in Medicare.

Gate 3: state law decides who may deliver the service

Enrollment establishes eligibility to submit claims for covered services. Whether a corporation may furnish physician services is a question the state answers, and in roughly two-thirds of jurisdictions the answer for a lay-owned general corporation is no. The CPOM doctrine prohibits a corporation owned by non-licensees from practicing medicine, employing physicians to practice, or controlling clinical judgment; the state’s professional corporation act separately restricts who may own the entity that does practice. Medicare’s definition of physicians’ services at 42 C.F.R. § 410.20(b) (services “furnished by a legally authorized” physician acting within scope) imports the same state-law answer. Put the three gates together and the position of a technology company is: Which is why the standard answer is the MSO-PC structure: the professional entity obtains the Type 2 NPI, enrolls on the CMS-855B, receives the reassignments, and holds the payer contracts; the technology company is the management services organization and is paid a management fee. A payment model or contract that says “the participant must be a Medicare Part B-enrolled organization” is therefore not asking whether you are a corporation. It is asking whether the entity that will bill is one that state law allows to furnish the service.

The ACCESS model as the worked example

CMS’s Innovation Center ACCESS Model (Advancing Chronic Care with Effective, Scalable Solutions) was written for technology-enabled chronic care, and more than 150 organizations accepted for its first cohort had, in CMS’s words, mostly “not previously served Medicare beneficiaries.”8 Its eligibility rules illustrate every gate above. A participant must “be a Medicare Part B–enrolled organizational entity, identifiable by a single TIN, that is eligible to bill under the Medicare Physician Fee Schedule”; must “designate and maintain a Medicare-enrolled physician as Medical Director”; and must “ensure that all physicians and non-physician practitioners furnishing or supervising care are individually Medicare-enrolled … and have reassigned their Medicare billing rights to the participating TIN and practicing within applicable licensure and scope-of-practice standards.” Organizations not yet enrolled may apply but “will not be fully approved for participation until the Medicare enrollment process is complete.”9 Nothing in the Request for Applications names “technology company” as a participant type, and nothing excludes one. The RFA has three roles: the Part B-enrolled participant, self-certified vendors in a non-endorsing tools directory, and device makers in the FDA’s parallel TEMPO pilot, and a technology company can be any of them. But to be the participant, the entity holding the TIN must be one that can lawfully furnish physician services in every state where it enrolls patients. For a venture-backed platform in a CPOM state that means the affiliated professional entity is the participant, its physician-owner or an employed physician is the medical director, and the platform is the MSO behind it. See Get a health technology company into Medicare Part B for ACCESS and the ACCESS reference page.

Why the distinction matters more in 2026

Two federal developments make the enrolling entity’s identity visible in ways it was not:
  • Platform modifiers on telehealth claims. The Consolidated Appropriations Act, 2026 added 42 U.S.C. § 1395m(m)(10), directing CMS by January 1, 2027 to require codes or modifiers on telehealth claims for services “furnished through a telehealth virtual platform … by a physician or practitioner that contracts with an entity that owns such virtual platform” or where the practitioner “has a payment arrangement with an entity for use of such virtual platform.”10 CMS will be able to see, claim by claim, which services flowed through a platform-MSO arrangement.
  • OIG’s telemedicine fraud alert. The Office of Inspector General’s July 2022 Special Fraud Alert lists seven characteristics of suspect telemedicine-company arrangements, including practitioners compensated “based on the volume of items or services ordered” and practitioners lacking “sufficient contact with or information from the purported patient to meaningfully assess the medical necessity” of what they order.11 An MSO that has the right entity enrolled but runs the clinical relationship like the alert describes has solved the wrong problem.

Sources

  1. 45 C.F.R. § 162.406, § 162.408, § 162.410; CMS, NPI Fact Sheet (Dec. 2024); CMS-855B instructions (Type 2 examples).
  2. 42 C.F.R. § 424.505; § 424.502 (definitions of “enroll,” “owner,” “managing employee”).
  3. CMS, Form CMS-855B, Medicare Enrollment Application: Clinics/Group Practices and Other Suppliers (rev. 12/2025); ownership disclosure also at 42 C.F.R. § 420.206 and § 424.510(d)(2).
  4. CMS, Medicare Program Integrity Manual, Pub. 100-08, ch. 10 (rev. 13717, July 8, 2026). The absence of a physician-ownership requirement is an inference from the form, the regulation, and the manual as read in August 2026, not a CMS statement.
  5. 42 C.F.R. § 424.516(a)(2); Program Integrity Manual ch. 10, § 10.2.2.4(B) (stated in the IDTF standards, applying the general rule).
  6. 42 U.S.C. § 1395u(b)(6).
  7. 42 C.F.R. § 424.80.
  8. CMS, ACCESS Model accepted applicants (updated Aug. 17, 2026).
  9. CMS Innovation Center, ACCESS Model Request for Applications v1.1 (Feb. 12, 2026), Participant Eligibility Criteria at 13–14 and Appendix A Q11; ACCESS Technical FAQs (updated Mar. 18, 2026).
  10. Consolidated Appropriations Act, 2026, Pub. L. 119-75, § 6209(g) (Feb. 3, 2026), adding 42 U.S.C. § 1395m(m)(10). Enrolled bill text.
  11. HHS OIG, Special Fraud Alert: OIG Alerts Practitioners To Exercise Caution When Entering Into Arrangements With Purported Telemedicine Companies (July 20, 2022).
Last modified on August 27, 2026