CMS Electronic Signature Requirements for Medicare

CMS electronic signature requirements for Medicare let providers sign claims, enrollment applications, and medical records electronically, as long as the signature system prevents tampering, ties each signature to a verified individual, and produces an audit trail. The provider whose name appears on the signature carries full responsibility for the content of the record. Get the mechanics wrong and the consequences run from denied claims to civil monetary penalties of up to $28,619 per false claim.

What Makes an Electronic Signature Valid

CMS does not mandate a specific technology. It sets functional requirements that any signing system has to meet. The software must protect the document against modification after the signature is applied, and the organization must apply administrative safeguards that comply with applicable federal standards.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements In practice, that means once the record is signed, no one can alter its content without the system flagging or invalidating the signature.

Authentication has to tie the signing act to a specific person. Most systems do this with unique login credentials, multi-factor authentication, or digital certificates that lock a signature to a particular user session. The provider whose name appears on the electronic signature takes full responsibility for the authenticity of the information in the record.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements If your credentials are used to sign a note you never reviewed, you are still on the hook for what that note says.

Every medical record entry must be legible, complete, dated, timed, and authenticated by the person who provided or evaluated the service. The requirement sits in the Conditions of Participation at 42 CFR 482.24 for hospitals and extends through Medicare policy to other provider types.2eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services The date and time stamp is not decoration. Auditors compare the signature timestamp against the time of service, and a large gap raises questions about whether the signer actually performed the work.

What CMS Will Not Accept

Stamped signatures are not valid on Medicare documentation. A rubber stamp of a provider’s name does not count as an electronic or handwritten signature. The single exception applies to providers with a physical disability under the Rehabilitation Act of 1973 who can document their inability to sign; in that case the stamp functions as a certification that the provider reviewed the document.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements

Sharing electronic signature credentials is equally disqualifying. If one staff member logs in under another provider’s account and signs a record, the signature is fraudulent, even if the actual provider later agrees with the content. Each electronic signature must be traceable to the individual who personally executed it. Casual credential sharing is a fast path to False Claims Act exposure, because every claim supported by an improperly authenticated record is potentially a false claim.

Scribes and AI-Generated Notes

Scribes, including AI transcription tools, are not providers of items or services. CMS does not require a scribe to sign or date a progress note, and Medicare reviewers will not deny a claim solely because the scribe did not sign.3Centers for Medicare & Medicaid Services. Scribe Services Signature Requirements What matters is the treating practitioner’s signature, which affirms the note accurately reflects the care delivered.

The same principle governs AI documentation. When any scribe drafts the note, the practitioner must sign the entry to authenticate both the documentation and the care provided or ordered.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements The AI drafts; the provider authenticates. Skipping that step turns every associated claim into a compliance problem.

Fixing a Missing or Illegible Signature

Most signature deficiencies are correctable. CMS accepts two tools: attestation statements and signature logs.

An attestation statement is a written declaration by the original author confirming the entry is theirs. It must be signed and dated by the author and contain enough information to identify the patient.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements CMS considers attestations regardless of when they were created, with one caveat: an attestation cannot backdate a plan of care.

The trap most providers miss: attestation statements cannot fix a missing signature on an order. Orders require the original signature at the time they are issued. If the prescribing provider never signed the order, an after-the-fact attestation will not save the claim.

A signature log is a typed list pairing each provider’s printed name with the corresponding handwritten or electronic signature. Organizations can create the log at any time. Including credentials in the log is encouraged but not required, and reviewers will not deny a claim for missing credentials in the log itself.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements

When a Medicare contractor asks for an attestation or signature log, the billing entity has 20 calendar days from the date of phone contact or receipt of the request letter to submit it. Once the contractor receives the material, the review period extends by 15 additional calendar days.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements These deadlines do not apply to Comprehensive Error Rate Testing contractors, which operate on their own timelines.

Hospital Authentication Rules

Hospitals carry extra obligations under the Medicare Conditions of Participation. 42 CFR 482.24 requires the hospital to use a system of author identification and record maintenance that ensures the integrity of authentication and protects record security.2eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services Every entry must be legible, complete, dated, timed, and authenticated by the person responsible for the service, whether written or electronic.

Orders carry a stricter timing standard. All orders, including verbal orders, must be dated, timed, and authenticated promptly by the ordering practitioner.2eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services The regulation does not define “promptly” by a specific hour count; hospitals set their own policies, and CMS surveyors watch for patterns of delayed authentication. The final diagnosis and complete medical record must be finished within 30 days of discharge.

Standing orders and electronic order sets are allowed only if medical staff and hospital nursing and pharmacy leadership have reviewed and approved them, they are consistent with nationally recognized evidence-based guidelines, and they are periodically reviewed for continuing safety and usefulness.2eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services

Retention and Audit Trails

Providers who furnish certain ordered services, including durable medical equipment, clinical laboratory services, imaging, and home health, must retain documentation for seven years from the date of service under 42 CFR 424.516(f).4Centers for Medicare & Medicaid Services. Medical Record Maintenance and Access Requirements Retained material includes written and electronic records for orders, certifications, and payment requests, along with the NPI of the ordering provider.5GovInfo. 42 CFR 424.516 – Additional Provider and Supplier Requirements Some state laws impose longer retention periods, so the seven-year federal floor is not always the last word.

The electronic signature system should also maintain an audit trail logging the date, time, and identity of every signature event. Contractors can pull these logs during routine review or investigation. Discrepancies get noticed: a signature applied days after the service was supposedly rendered, or identical timestamps across dozens of records, will draw scrutiny and can lead to denials or a wider probe. Audit data must be stored in a format investigators can review without proprietary software.

Signatures on Enrollment Applications

Enrollment through the Provider Enrollment, Chain, and Ownership System (PECOS) supports electronic signing and submission directly in the portal.6Centers for Medicare & Medicaid Services. Enrollment Applications A paper application requires a handwritten signature. There is no hybrid: you cannot submit paper with an electronic signature attached.

What Signature Failures Cost

The everyday consequence is a denied claim or recoupment of a payment already received. If a required signature is missing from a medical record, CMS may deny the associated claims.1Centers for Medicare & Medicaid Services. Complying with Medicare Signature Requirements The denial can hit during initial processing or years later on post-payment audit, which is why the seven-year retention rule exists.

More serious patterns, such as systematic credential sharing or backdated signatures, can trigger False Claims Act liability. For 2025, the civil monetary penalty for a False Claims Act violation ranges from $14,308 to $28,619 per false claim.7Federal Register. Civil Monetary Penalties Inflation Adjustments for 2025 These amounts remain in effect through 2026 after the Office of Management and Budget determined no inflation adjustment would be made for 2026 because the required Consumer Price Index data was unavailable. When each improperly signed record supports a separate claim, the per-claim penalties compound quickly. A single audit covering a few months of records can produce six-figure exposure.