Skip to main content
Category: OCR Enforcement and Penalties

CMS Enforcement of Administrative Simplification

Also known as: Administrative Simplification Enforcement, CMS Compliance Review Program
Simply put

This refers to the role the Centers for Medicare & Medicaid Services (CMS) plays, on behalf of the U.S. Department of Health and Human Services (HHS), in making sure the health care community follows the HIPAA Administrative Simplification requirements. These requirements aim to standardize how health care business is conducted to reduce burden and lower costs. CMS carries out this work primarily by conducting compliance reviews and responding to complaints about potential noncompliance.

Formal definition

CMS is charged, on behalf of HHS, with enforcing compliance with the adopted HIPAA Administrative Simplification requirements, which standardize administrative and financial transactions across the health care system. Enforcement is carried out through a Compliance Review Program and through investigation of complaints of potential noncompliance filed against covered entities and other regulated parties. Note that this enforcement authority is distinct from HHS Office for Civil Rights (OCR) enforcement of the HIPAA Privacy, Security, and Breach Notification Rules; CMS enforcement here focuses on Administrative Simplification standards such as standardized transactions, code sets, and identifiers. Complaints can be submitted through the Administrative Simplification Enforcement and Testing Tool (ASETT). Readers should verify specific enforcement procedures, scope, and organizational unit names against current CMS guidance, as these may change over time.

Why it matters

HIPAA is often discussed primarily in terms of privacy and security, but the Administrative Simplification provisions carry their own distinct set of standards governing how electronic administrative and financial transactions are conducted across the health care system. CMS enforcement of these standards matters because it addresses a different dimension of HIPAA compliance than the privacy and security obligations most compliance officers focus on. Standardized transactions, code sets, and identifiers are intended to reduce administrative burden and lower costs, and consistent enforcement is what makes those benefits achievable in practice.

A common point of confusion is that CMS and the HHS Office for Civil Rights (OCR) both enforce parts of HIPAA, but they cover different territory. OCR enforces the Privacy, Security, and Breach Notification Rules, while CMS enforces the Administrative Simplification standards on behalf of HHS. Organizations that only monitor OCR guidance may overlook their transaction standard obligations entirely, and a complaint filed against them for noncompliance with standardized transactions or code sets would be handled through CMS processes rather than OCR.

For covered entities and other regulated parties, understanding which agency handles which requirements helps ensure that complaints, compliance reviews, and remediation efforts are directed appropriately. Because enforcement procedures, organizational unit names, and program details can change over time, readers should confirm the current scope and process against CMS guidance rather than relying on a static understanding.

Who it's relevant to

Compliance and Privacy Officers
Those responsible for HIPAA compliance should recognize that Administrative Simplification requirements are enforced by CMS, separately from OCR's enforcement of the Privacy and Security Rules. Monitoring both enforcement tracks helps ensure that transaction standard obligations are not overlooked in a compliance program that otherwise focuses on privacy and security.
Health Plans, Clearinghouses, and Providers Conducting Standard Transactions
Covered entities and other regulated parties that conduct standardized administrative and financial transactions are subject to CMS compliance reviews and may be the subject of complaints regarding transactions, code sets, or identifiers. Understanding the ASETT complaint mechanism and the Compliance Review Program is useful for anticipating and responding to potential enforcement activity.
IT and EDI Teams
Teams responsible for electronic data interchange and transaction processing should be aware that technical adherence to adopted transaction and code set standards is a compliance matter enforced by CMS. Their work directly affects whether an organization can withstand a compliance review or respond to a noncompliance complaint.
Legal and Regulatory Advisors
Attorneys and advisors supporting healthcare organizations should distinguish CMS Administrative Simplification enforcement from OCR enforcement when advising clients, since complaints and reviews follow different processes and cover different requirements. Given that enforcement details can change over time, advisors should confirm current CMS procedures rather than rely on prior understanding.

Inside CMS Enforcement of Administrative Simplification

Administrative Simplification Provisions
The set of HIPAA requirements addressing standardized electronic transactions, code sets, unique identifiers, and operating rules. CMS generally has enforcement authority over these non-privacy, non-security aspects of Administrative Simplification, distinct from the Privacy and Security Rules enforced by HHS OCR.
Transactions and Code Sets Standards
Standards governing the format and content of certain electronic healthcare transactions (such as claims, eligibility inquiries, and remittance advice) and the code sets used within them. Covered entities that conduct these transactions electronically are generally expected to use the adopted standards.
Unique Identifiers
Standardized identifiers used in covered transactions, such as the National Provider Identifier (NPI) and the Employer Identification Number (EIN) for employers. Enforcement of proper identifier use typically falls within CMS's Administrative Simplification scope.
Complaint-Driven Enforcement Process
CMS generally investigates potential non-compliance with the transactions, code sets, identifiers, and operating rules requirements, often initiated through complaints. This process is administered separately from OCR's handling of Privacy, Security, and Breach Notification matters.
Corrective Action Orientation
CMS enforcement of Administrative Simplification typically emphasizes achieving compliance through corrective action and voluntary resolution, though civil monetary penalties may apply under the applicable authority. Specific penalty tiers and figures are adjusted over time and should be confirmed against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about CMS Enforcement of Administrative Simplification.

Does CMS enforce all parts of HIPAA, including the Privacy and Security Rules?
No. CMS enforces the Administrative Simplification provisions related to transactions and code sets, unique identifiers, and operating rules. The HIPAA Privacy Rule, Security Rule, and Breach Notification Rule are enforced by HHS Office for Civil Rights (OCR), not CMS. It is a common misconception that CMS handles all HIPAA enforcement; in practice, enforcement authority is divided, and you should confirm which agency has jurisdiction over a particular requirement before responding to an inquiry.
Is CMS enforcement of Administrative Simplification purely complaint-driven and reactive, so we only need to worry if someone reports us?
That is a misconception. While complaints are one avenue that can trigger CMS review of covered entities' compliance with transaction, code set, identifier, and operating rule standards, relying solely on the absence of complaints is not a sound compliance strategy. Organizations are generally expected to maintain ongoing compliance regardless of whether a complaint has been filed. You should verify current CMS enforcement processes against current guidance, as procedures may be updated over time.
Which specific standards fall under CMS Administrative Simplification enforcement that our compliance program should track?
CMS enforcement generally covers the standard electronic transactions, code sets, unique identifiers, and operating rules adopted under Administrative Simplification. Your compliance program should inventory the electronic transactions your organization conducts and map them to the applicable adopted standards. Because the specific standards and any updates are set out in regulation, confirm the current list and versions against the applicable regulatory text rather than relying on memory.
How should we prepare for a potential CMS compliance review of our electronic transactions?
In most cases, preparation involves documenting which covered transactions you conduct, evidence that they conform to the adopted standards and operating rules, and records of testing or validation with trading partners and clearinghouses. Maintaining documentation of how issues are identified and remediated is generally advisable. Because review procedures can change, verify the current expectations and any documentation requests against current CMS guidance.
What is the relationship between our business associates or clearinghouses and CMS Administrative Simplification obligations?
Covered entities remain responsible for the transactions they conduct even when a clearinghouse or vendor processes data on their behalf. Obligations attach through the defined relationships and, where applicable, business associate agreements. A vendor performing transaction processing does not remove the covered entity's own compliance responsibility. Confirm how responsibilities are allocated in your agreements and verify current requirements against the applicable regulation.
Does achieving HITRUST CSF certification demonstrate compliance with CMS-enforced Administrative Simplification standards?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification does not by itself establish compliance with HIPAA Administrative Simplification requirements enforced by CMS, and it is not a legal requirement. Transaction, code set, identifier, and operating rule compliance is assessed against the applicable federal standards. Treat HITRUST certification as a separate initiative and verify Administrative Simplification obligations against the current regulation.

Common misconceptions

HHS OCR enforces all of HIPAA, including the transaction and identifier standards.
OCR generally enforces the Privacy, Security, and Breach Notification Rules, while CMS generally handles enforcement of the Administrative Simplification transactions, code sets, unique identifiers, and operating rules. Readers should verify current allocation of authority against applicable guidance.
Administrative Simplification enforcement covers the confidentiality and safeguarding of PHI.
Administrative Simplification enforcement by CMS focuses on standardized transactions, code sets, and identifiers, not on the privacy or security safeguarding of PHI, which are addressed by the Privacy Rule (all forms of PHI) and Security Rule (ePHI only) enforced by OCR.
Any vendor touching healthcare data is directly subject to these standards.
The Administrative Simplification obligations generally attach to covered entities that conduct the adopted standard transactions, and flow to business associates through defined relationships and business associate agreements rather than to every vendor that touches data.

Best practices

Confirm which HHS component has enforcement authority for a given issue, CMS for transactions, code sets, identifiers, and operating rules; OCR for Privacy, Security, and Breach Notification, before responding to an inquiry or complaint.
Inventory the electronic transactions your organization conducts and verify that each uses the currently adopted standards, code sets, and unique identifiers.
Maintain documentation demonstrating conformance with transaction standards and identifier requirements, as this supports responses in a complaint-driven enforcement process.
Address any identified non-compliance promptly through corrective action, since CMS enforcement generally emphasizes resolution and correction.
Ensure business associate agreements and vendor relationships appropriately reflect Administrative Simplification obligations where transactions are handled on your behalf.
Verify current requirements, penalty provisions, and enforcement allocations against the applicable regulatory text, as figures and authorities are adjusted over time and state law or HITECH may impose additional requirements.