PECOS Medicare Enrollment Pre-Check
Catch the mistakes in a Medicare enrollment before the contractor does. Send a draft CMS-855I, 855B or 855S as JSON and get back every problem SpreadRun can find with a rule ID: the NPI and taxonomy codes checked live against NPPES, the legal name against the IRS name, ZIP+4 on every location, anything that expires before the application is likely to finish, and the supporting documents the form asks for.
What a bad application can cost
- Rejection. If you do not supply missing information within 30 calendar days of the contractor's request, the application can be rejected, with no appeal, and you file a new one.
- Deactivation. Miss a revalidation and CMS can deactivate your Medicare billing privileges. Medicare does not pay for services furnished while you are deactivated.
- A wasted cycle. A name that does not match the IRS, a mistyped NPI or a missing document sends the application back for correction.
Sources: 42 CFR 424.525 and 424.540 and CMS's revalidation guidance, linked at the bottom of this page.
Where this fits. You still enroll in PECOS yourself, and the contractor still decides. SpreadRun works before that: deterministic checks of the draft against the form's own requirements and the public NPPES registry, plus the expiry-versus-timeline math a spreadsheet does not do. Credentialing teams can run it for every provider from a script, through the same API.
A clean pre-check does not guarantee that the enrollment will be approved. It cannot see what the contractor's reviewer sees, it is not an enrollment filing, and it is not legal advice.
Personal data. An enrollment draft can name a practitioner and carry license and DEA numbers. It is processed in memory only to produce the report and is not stored, and no value from your draft is repeated in the report. The NPI is sent to the public NPPES registry for the run. The sample drafts on this page describe an invented practice.
What it checks
- NPI. Ten digits that pass the CMS check digit, then a live NPPES lookup: on the registry, active, and the right type (individual for the 855I, organization for the 855B).
- Legal name. The legal business name against the IRS name you attest to, and against the NPPES record. A difference in punctuation only is a warning; anything else is an error.
- Taxonomy codes. Well formed, on the NPPES record, and the first one matching the record's primary taxonomy.
- Practice locations. Street, city, state and ZIP present; no P.O. box; a valid state code; ZIP+4, which the forms ask for; a telephone number; and for DMEPOS suppliers, posted hours of operation.
- Expiry against the timeline. Licenses, DEA registration, insurance, surety bonds and accreditation: anything already expired is an error, anything that expires inside your processing window is a warning.
- Supporting documents. The documents the form lists for your situation, such as the IRS CP-575, the CMS-588 for EFT, the CMS-460 if you participate, and for DMEPOS the liability insurance certificate and surety bond.
- Signatures. An authorized official for an organization's initial enrollment or revalidation; an authorized or delegated official for a change.
- Revalidation timing. A due date that has already passed.
Every report ends with a submission-readiness checklist: each area marked Ready, Review or Fix.
Who it's for
- Small practices and groups: check the draft before the application goes in.
- DME suppliers: hours, insurance, bond and documents in one pass.
- Credentialing consultants: run every client provider from one script.
- Software and automation: a plain REST endpoint with JSON in and JSON out.
Not checked
- What the contractor's reviewer sees and decides, including site visits, background checks and fingerprinting.
- Whether licenses, registrations and insurance are valid with the board or carrier. Dates are checked as you enter them.
- Ownership, managing employees, final adverse actions and other PECOS screens beyond the input.
- The CMS-855A, 855R, 855O and 20134 forms.
- Whether the documents you mark as ready are the right ones and complete.
Input and output
Send
One provider's draft as JSON: the form (855I, 855B or 855S), the reason, the NPI, legal names, taxonomy codes, practice locations, credentials with expiration dates, officials, and the documents you have ready. Up to 256 KB.
Check
Every rule on this page, plus one live NPPES lookup for the NPI.
Report
JSON with
status(PASS, WARN or FAIL),readiness(the checklist), andfindings(severity, ruleId, path such as/practiceLocations[0]/zip, message, source).
Every field, the input and output schemas and all rule IDs are in the API docs.
Try it now
- ReadyNPI is well formed and active in NPPES as the right type
- FixLegal name matches the IRS name and the NPPES record
- FixTaxonomy codes match the NPPES record
- FixPractice locations are complete, with ZIP+4
- FixLicenses, registrations and insurance stay current through the processing window
- FixSupporting documents for this form are ready
- FixThe right person is set to sign
- n/aRevalidation is not past its due date
| Severity | Rule | Where and what |
|---|---|---|
| Error | PEC- | /practiceLocations[0]/street1A practice location must be a street address, not a P.O. box. |
| Error | PEC- | /credentials[1]/expirationDateThis item has already expired. Renew it before you submit. |
| Error | PEC- | /documents/cp575Missing supporting document: IRS confirmation of the TIN and legal business name (for example CP-575) (Section 12 of the form). |
| Error | PEC- | /provider/legalNameThe legal business name does not match the IRS name you gave. CMS requires the name reported to the IRS. |
| Error | PEC- | /provider/legalNameThe legal business name does not match the organization name on the NPPES record for this NPI. The CMS-855B asks for the same legal business name and TIN used to get the NPI. |
| Error | PEC- | /officialsAn organization's initial enrollment or revalidation must be signed by an authorized official. None is listed. |
| Error | PEC- | /practiceLocations[1]/stateUse the 2-letter postal code for a US state or territory. |
| Error | PEC- | /provider/taxonomyCodes[1]A taxonomy code is 10 characters: 9 letters or digits followed by X. |
| Error | PEC- | /practiceLocations[1]/zipA ZIP code is 5 digits, or ZIP+4 as 12345-6789. |
| Warning | PEC- | /credentials[0]/expirationDateThis item expires inside the processing window you set. Renew it now, or plan to report the renewal while the application is pending. |
| Warning | PEC- | /practiceLocations[0]/phoneNo telephone number for this location. The form asks for one if applicable. |
| Warning | PEC- | /practiceLocations[0]/zipOnly 5 digits. The form asks for ZIP code + 4; look up the full ZIP+4 for this address. |
Pricing
$25.00 per completed pre-check. One provider's draft, one full report.
- Billed when a report is produced, PASS, WARN or FAIL. Invalid input is never billed, and neither is a run stopped because the NPPES registry could not be reached.
- Paid from the same prepaid credits as every SpreadRun API, in $5, $20, $50 or $100 packs. A $50 pack covers 2 pre-checks. Credits never expire. All pricing
- Checking many providers? Talk to us first so we can tell you honestly whether this fits.
Call it from code
Fields, rule IDs, error codes and limits are in the API docs.
curl -X POST "https://www.spreadrun.com/api/v1/pecos-enrollment-precheck" \
-H "Authorization: Bearer $SPREADRUN_API_KEY" \
-H "Content-Type: application/json" \
--data-binary @enrollment_draft.jsonQuestions
Does a clean pre-check mean my enrollment will be approved?
No. It means the draft passed the checks on this page. The Medicare Administrative Contractor reviews the application, may ask for more information, and may run site visits and background checks. SpreadRun cannot see any of that. This is a pre-submission error check, not an enrollment filing, and not legal advice.
Which forms does it cover?
The CMS-855I (individual practitioners), CMS-855B (clinics, group practices and certain other suppliers) and CMS-855S (DMEPOS suppliers), for initial enrollment, revalidation and changes of information. The CMS-855A, 855R, 855O and 20134 are not covered yet.
How does the registry check work?
Each run sends the NPI, and only the NPI, to the public NPPES NPI Registry API and compares the answer with your draft: whether the NPI exists and is active, whether it is the right type for the form, whether the name matches, and whether your taxonomy codes are on the record. The registry answer is used for that run only. It is not stored, cached or included in the report. If the registry cannot be reached, the run stops and you are not charged.
Where does the processing window come from?
From you. Set processingWindowDays to how long you expect the application to take; the default is 90 days. Anything that expires inside that window is flagged so you can renew it first. CMS does not publish a single processing time that we could verify, so we do not claim one. CMS does say PECOS applications tend to process faster than paper ones.
Why does revalidation timing matter?
Most providers and suppliers revalidate every 5 years, DMEPOS suppliers every 3. If you miss it, CMS can deactivate your Medicare billing privileges, and Medicare does not pay for services furnished while you are deactivated. Give the due date from the CMS revalidation lookup and the pre-check flags a date that has passed.
Is my data stored?
No. The draft is processed in memory for the length of the request and is not stored or shared. Findings name the field, the rule and the problem, never a name, number or date from your draft. For billing and usage we log the time, endpoint, result status, upload size and duration, never the contents.
When is a run charged?
When the pre-check finishes and returns a report, whether it says PASS, WARN or FAIL: $25.00 per completed pre-check. Requests rejected before a report exists are free, and so is a run stopped because the NPPES registry could not be reached.
Sources
- CMS-855I (05/23) enrollment application for physicians and non-physician practitioners
- CMS-855B (12/2025) enrollment application for clinics, group practices and certain other suppliers
- CMS-855S (12/23) enrollment application for DMEPOS suppliers
- 42 CFR part 424, subpart P: enrollment (424.510), revalidation (424.515), rejection (424.525), deactivation (424.540)
- 42 CFR 424.57: DMEPOS supplier standards
- CMS: Medicare revalidations
- CMS: NPI check digit
- NPPES NPI Registry
SpreadRun is not affiliated with or endorsed by CMS. Where this check and the forms or regulations differ, the forms and regulations control.
More validators: PBJ Staffing Data Pre-Submission QA | the full catalog