myCGS Terms of Use
The Terms of Use provide privacy and security notices consistent with applicable federal laws, directives, and other federal guidance for accessing this Government system, which includes (1) this computer network, (2) all computers connected to this network, and (3) all devices and storage media attached to this network or to a computer on this network.
This system is for Government authorized use only.
Unauthorized or improper use of this system is prohibited and may result in disciplinary action and/or civil and criminal penalties.
Personal use of social media and networking sites on this system is limited as to not interfere with official work duties and is subject to monitoring.
By using this system, you understand and consent to the following:
- The Government may monitor, record, and audit your system usage, including usage of personal devices and email systems for official duties or to conduct HHS business. Therefore, you have no reasonable expectation of privacy regarding any communication or data transiting or stored on this system. At any time, and for any lawful Government purpose, the government may monitor, intercept, and search and seize any communication or data transiting or stored on this system.
- Any communication or data transiting or stored on this system may be disclosed or used for any lawful Government purpose.
The Centers for Medicare and Medicaid Services (CMS) maintains ownership and responsibility for this computer system and allows CGS Administrators, LLC to provide the services. Users must adhere to CMS information security policies, standards, and procedures.
CGS Administrators, LLC reserves the right to change these terms of use from time to time. You agree that you shall be bound by the terms of use appearing on this site at the time you are using the site. By using myCGS, you agree to release CGS Administrators, LLC from any and all claims, liabilities or damages related to your use. You further agree to indemnify and hold CGS Administrators, LLC harmless, including the payment of attorney's fees, for any breach of this Agreement, negligence, violation of law, or willful conduct on your part in connection with the use of this system.
Use of Data and Information
CGS Administrators, LLC provides the information on myCGS free of charge and for informational purposes only. Although CGS Administrators, LLC attempts to ensure the content is correct and complete, you agree not to hold CGS Administrators, LLC responsible for the accuracy of this information, and you assume all the risks associated with its use. CGS Administrators, LLC may change, delete or update information without notice.
CGS Administrators, LLC has no obligation to update information within this site. This means information on the site may be out of date at any given time. CGS Administrators, LLC also may make improvements or changes in the products or services described on the site at any given time without notice.
You may print a copy of the information displayed on this site. However, CGS Administrators, LLC does not transfer or grant any intellectual property or other rights to you, including any copyright, trademark, service mark, or patent rights, which CGS Administrators, LLC expressly reserves for itself. You agree not to distribute, manipulate, create derivative works from, or use the information on this site for any purpose other than as expressly authorized by CGS Administrators, LLC.
Any copy and/or alteration of the original data displayed on this site, including conversion to other media or other data formats, is the responsibility of the requestor. Any data manipulated or reprocessed by the user is the user’s responsibility and may not present CMS or CGS Administrators, LLC data. CGS Administrators, LLC is not responsible for any converted, processed or otherwise altered data or assistance with converting the data to another format.
ALL MATERIALS ON THE SITE ARE PROVIDED AS IS WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED. OWNER DISCLAIMS ANY AND ALL EXPRESS AND IMPLIED WARRANTIES, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
OWNER SHALL NOT BE LIABLE FOR ANY SPECIAL, INDIRECT, PUNITIVE, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING WITHOUT LIMITATION, LOST REVENUES OR LOST PROFITS, WHICH MAY RESULT FROM THE USE OF THESE MATERIALS.
Use of Beneficiary Data
CGS Administrators, LLC is obligated by the Federal Privacy Act, 5 U.S.C. Section. 552a and the HIPAA Privacy Rule, 45 C.F.R Parts 160 and 164, to protect the privacy of individual beneficiaries and other persons. By signing this agreement, the user agrees not to use CGS Administrators, LLC or CMS data to determine the identity of individual persons. Attempts to determine individual identities from public data is a violation of the federal Privacy Act, 5 U.S.C and the HIPAA Privacy Rule.
myCGS may be used to verify, not determine, Medicare beneficiary eligibility. Unauthorized transactions include attempting to acquire the Medicare beneficiary's Medicare ID when it is not known, and determining eligibility for Medicare, without first screening the patient. Proper usage of the MBI Lookup Tool is not considered an unauthorized transaction.
By using the eligibility function in the portal, you are also agreeing to your understanding of and adherence to CMS's HETS Rules of Behavior.
Scope and Authority of Use
By registering, you represent to us that you have the proper authority to use myCGS on behalf of yourself, any organization you represent, and/or any other person or entity you represent.
You agree to not access, use, or disclose any information obtained from this Website in a manner that may be unauthorized, unlawful, or beyond the specific purpose for which such information is made available, nor will you permit or enable others to do so.
Claim Submission/Remittances
By registering to use myCGS, you authorize myCGS/CGS Administrators, LLC to send electronic claim submissions and receive electronic response reports on your behalf. Additionally, you authorize myCGS/CGS Administrators, LLC to only provide electronic remittances going forward. By submitting a claim via myCGS, you understand that your processed Medicare claim will contain payment information and agree that you are authorized to endorse this access on behalf of your company.
Any 'documents' the user retrieves via the myCGS e-Remittance feature are EXACT copies/facsimiles of the print version that can be viewed in the presented format, downloaded, and/or printed.
Secure Form Submission
Secure forms successfully submitted via myCGS will automatically generate inbox messages containing important information about the secure form submissions. The first message advises the user of the submission of the form in myCGS and contains a transaction ID. Within 24 hours of receiving this message, excluding weekends and holidays, the user should receive a second confirmation message that contains the official date of receipt by CGS and the DCN for this form submission.
Green Mail
By selecting to receive any of the specified letters electronically via CGS’s “Green Mail” process, I hereby agree that I have the authority to make this decision on behalf of my NPI and/or PTAN. I understand that by making this selection, I am now the only person associated with this NPI and/or PTAN that can change this selection. I understand that by selecting this option I may be automatically signed up for all letter types available for my NPI and/or PTAN in the future.
I understand this consent is effective until further notice by CGS or until I withdraw it by returning to the myCGS portal and changing my NPI and/or PTAN preferences. If I withdraw my consent to Green Mail, I understand you will resume delivery by U.S. Mail for the selected Electronic Document(s) within seven (7) days of the update. If my account is inactivated for any reason, this selection will remain as-is and “open” to other provider administrators for modification.
I understand Green Mail will be provided in Portable Document Format (PDF) and that I must have Adobe® Acrobat® viewer software installed on my computer to view these documents. I understand if I do not have the ability to access and retain PDF documents, I should not consent to Green Mail.
I understand that, from time to time, email notifications may not transmit properly and that it is my responsibility to log into myCGS and check my message inbox for mail.
Any 'documents' delivered, accepted, and retrieved by the user via myCGS Green Mail are EXACT copies/facsimiles of the print version that can either be viewed in the presented format, downloaded, and/or printed at the user’s option.
Roles and Responsibilities
CGS allows users to create login IDs in the myCGS portal. This requires the initial user login creation, followed by the registration process for each provider PTAN/NPI combination. This initial user will be listed as a provider administrator for this account. Users can request access to existing provider PTAN/NPI combinations and are approved by the administrator.
Provider administrators are granted permission to all functions of the application. The provider administrator grants access for all subsequent users to access, view, and print from this website the information related to said provider. Users can request changes to permissions granted by the provider administrator. If, during the 5-day request window, no action is taken by the provider administrator, then no changes will occur.
Provider administrators are responsible for maintaining access for the account and reviewing all accounts at least every 360 days to ensure that each user's access is still appropriate.
This includes the following:
- Creating and/or approving provider users
- Creating and/or approving additional provider administrators
- Assigning a temporary password to the provider users when needed
- Assigning and/or approving application permissions to the provider users
- Terminating user access
- Terminating additional provider administrator access
- Changing the provider administrator
- Recertifying user and administrator access
- Unlocking users or additional provider administrators who have locked out their user ID due to entering incorrect passwords.
Any access granted and maintained by the provider administrator is the sole responsibility of that provider administrator. CGS Administrators, LLC has no responsibility for maintaining provider user access and permission to the data assigned to them by the provider administrator. The provider user can access information as granted by the provider administrator and must work through their provider administrator to resolve any access issues.
Each user of myCGS must have a unique user ID and password. Generic contact (user) names are not permitted. This means that we expect each user to have a legitimate first and last name associated with each user ID. Examples of generic usernames are: Front Desk, Account Coordinator, Billing Department, User A, or the name of your provider office. No sharing of user IDs and passwords is permitted. CGS Administrators, LLC will delete, without notice, any usernames we find that are generic.
CGS Administrators, LLC has the right to terminate any user's access if suspicious or improper activity is determined.
Users should not use the portal in multiple tabs as this would cause errors with your submissions.
Protect Your Password
All user accounts must have passwords because the password is a means to authenticate the identity of the person using an account as the authorized user and to prevent misuse by unauthorized users.
Passwords are case sensitive and must comply with the latest minimum acceptable password requirements.
More secure password information can be found below in the 'Passwords' section under 'Rules of Behavior'.
Do not leave the system accessible on your computer when you are away from the computer. Remember to log off and close your browser each and every time you exit the system.
Recertification of Access
myCGS requires that all users, including provider administrators, periodically update their profile. In addition to the profile verification process, provider administrators must also recertify provider users, and additional provider administrators, who have access to myCGS for the same PTAN/NPI combination. Non-compliance with the recertification process by the provider administrator or the provider user will result in denial of access to myCGS. CGS reserves the right to request that users recertify access at any time. CGS has the right to deny recertification and terminate any user's access if suspicious or improper activity is determined.
Automated Interfaces
The use of any application, program, or macro (among other examples) that interfaces with myCGS is prohibited. myCGS is a stand-alone portal and shall only be used "as is" by the user.
Medicare Information Databases
Users are not authorized to use the myCGS eligibility and claim status functions to create non-CMS controlled Medicare databases. Users cannot create and host local Medicare eligibility and claim status databases that replicate the functionality of myCGS.
Cookies
We may use "cookies" or similar technologies in order to track usage of myCGS and help us in improving our services. Most Internet browsers allow you to erase cookies from your hard drive, block all cookies, or receive a warning before a cookie is stored. Please refer to your Internet browser's help files or user guides to learn more about these functions.
Contacting Us
When sending myCGS feedback through the Contact Us section of myCGS, please do not transmit any of the following information to CGS Administrators, LLC. Revealing this information online could expose you or others as a target for Medicare fraud and abuse.
- Personal information, including Social Security numbers.
- Beneficiary information, including Medicare IDs, coinsurance and deductible information, dates of Medicare entitlement, copies of or information from Medicare claim forms, Medicare reports of eligibility, and Medicare Summary Notices (MSNs).
- Information covered under the Freedom of Information Act (1967) and/or the Privacy Act of 1974.
- Claim specific data.
The Contact Us form is for feedback only. If you need assistance with the myCGS application, you must call the Level 1 Triage Support at 866-590-6703.
Basic Security & Privacy Awareness Training
By signing this agreement, the user acknowledges they are aware of and have participated in basic security and privacy awareness training both prior to initial use of the myCGS system and annually thereafter.
Rules of Behavior
Compliance with Security & Privacy Policies
- I understand and accept responsibility for company security and privacy policies and rules of behavior
- I understand that violation of laws, such as the Privacy Act of 1974, copyright law, and 18 USC 2071, can result in monetary fines and/or criminal charges that may result in imprisonment
- I certify that I have not been sanctioned, reprimanded, excluded, debarred, or otherwise disciplined in connection with participation in any federal program
- I understand that I may be granted access to U.S. Government information systems, and that such access is provided for U.S. Government-authorized use only. I realize that I have no reasonable expectation of privacy regarding any communication or data that I transmit or store on these information systems; and that for any lawful U.S. Government purpose, my activities on these information systems may be monitored, intercepted, and searched.
- If I have knowledge of a security incident and fail to report it, I understand that I will share in the responsibility for the outcome and any consequences or actions that may arise
- I will immediately report known or suspected disclosures or system problems that could lead to the unauthorized disclosure of confidential/sensitive information to the EDI Help Desk and my supervisor and/or my business unit's Systems Security Officer or Privacy Official
- I will not direct or encourage others to violate policies
- I will not use company resources for personal gain
Confidential/Sensitive Information
- I am aware that I am responsible for learning and understanding how to recognize and identify confidential/sensitive information
- I will only access confidential/sensitive information as required to perform my assigned job functions (i.e., a need-to-know basis). I will never attempt to access files or information for which I am not expressly authorized to view.
- I will not share confidential/sensitive information with anyone who does not have a valid business need-to-know, such as family or friends
- I will not copy or duplicate information and data, whether confidential/sensitive in nature or not, unless required in support of a business-related responsibility or function. I will never knowingly or willingly conceal, remove, mutilate, obliterate, falsify or destroy information in an improper/unapproved manner. I understand that I am not permitted to use company or customer information for non-business or personal purposes.
- Whenever appropriate, I will mark documents containing confidential/sensitive information FOR OFFICIAL USE ONLY to alert readers to the confidential/sensitive nature of this information. I will include an approved confidentiality stamp on all non-public documents that I create.
- I understand that confidential/sensitive paper documents must be stored in a secure manner when not in use, when I am away from my desk, and after normal working hours. I will secure documents or forms containing confidential/sensitive information in a manner that prevents unauthorized or inadvertent viewing whenever I am not using them or when visitors are present.
- I will dispose of unneeded or end-of-life paper documents using the company-approved methods
- I understand that electronic media should not be discarded except in approved e-media shredding bins or as otherwise directed by company security policies
- I will not duplicate information or data protected by a copyright law without documented approval from management, the manufacturer, licensee or applicable site license agreement
- I understand that removable electronic media, such as USB portable flash memory devices (jump drives/thumb drives) and optical discs (DVD-ROM, CD-ROM, etc.), containing PHI/PII or confidential/sensitive information must be encrypted using company-approved encryption methods
Passwords
- I will not disclose my password to anyone, whether in person or on the phone. This includes my manager, coworkers, auditors, the help desk, technical support, system administrators, CMS, visitors, family, friends, etc. There are no exceptions.
- I will not write down my passwords, automate their entry in macros or scripts, or store them in a computer file. I will protect them as I would the most confidential/sensitive information. I will not share or sign someone else onto a system with my ID or password.
- I will change my password when the system requires it or when I initiate it only. I understand that the help desk will not call me or email me requesting that I change my password.
- When creating a password, I will not use common words found in the dictionary; names of family, pets or sports teams; dates of birth; or other identifiable phrases associated with me
- When creating a password, I will not use letters or numbers that are near each other on the keyboard (ex. hjkl) or appear in a logical sequence (ex. 123456 or abcdefg)
These Terms are put in place to protect the data of your patients and your company. CGS requires that all myCGS user agree to follow these Terms of Use.