CMS-588 Signature Rejection: Which Authorized or Delegated Official Must Sign
A CMS-588 can be rejected when the signature does not belong to an authorized or delegated official recognized for the enrollment. The paper form requires the correct signer, an original signature, and the signature date.

A CMS-588 EFT form can be complete in every banking field and still fail because the wrong person signed it. For a paper CMS-588, the signature and date must come from the authorized representative or delegated official identified through the CMS-855 enrollment record; electronic PECOS workflows should follow the certification path presented in PECOS. For a billing manager, this is an easy place to lose time because the person who manages the bank account or prepares the EFT packet is not automatically the person who is permitted to sign the enrollment form. The safest workflow is to verify signer authority before the form reaches the signature stage, rather than discovering the mismatch after the MAC rejects the submission.
The signer is part of the enrollment record
The person signing CMS-588 should be an authorized or delegated official whose role is recognized in the Medicare enrollment information. A convenient internal signer is not enough if that person does not hold the required role.
Before printing the final form, enrollment staff should verify the signer against PECOS rather than relying on job title alone.
Before the signer touches the form, compare the person against the authorized or delegated official information in the Medicare enrollment record. A CFO, owner, practice administrator, or bank signer can be important internally without automatically being the person CMS recognizes for CMS-588 certification. Resolve that mismatch before the packet reaches the signature stage.
The paper form needs an original signature and date
The rule also calls for an original signature and the date signed. That means the signature step should be treated as a controlled part of the submission packet, not as a last-minute administrative task.
If staff route the form electronically for internal review, make sure the final paper version still receives the required original signature before mailing.
Use a signature-control cover sheet that shows the entity, NPI or Medicare enrollment context, bank account being changed, authorized signer, and date the current CMS-588 was downloaded. This is simple enough for a small practice but prevents staff from circulating an old form for signature after the underlying enrollment or official roles have changed.
Why billing and enrollment roles get confused
The employee who knows the EFT account may be a billing manager, controller, or practice administrator. That operational responsibility does not automatically make the person an authorized or delegated official for CMS-588.
Separating “prepared by” from “signed by” in the internal checklist helps prevent the wrong employee from signing simply because that person completed the bank section.
If the contractor rejects the EFT submission, classify the defect precisely. A signature defect, missing bank support, or entity-name mismatch should be corrected as an EFT problem unless the contractor notice identifies a broader enrollment issue. Precise status language prevents billing from interpreting every CMS-588 development as a denial of Medicare participation.
A simple pre-signature control
Add one checkpoint before signature: confirm the intended signer is listed in PECOS in the appropriate role. Then obtain the original signature and date and keep a copy of the completed packet.
This small control is more efficient than correcting a rejected EFT submission after the fact.
When an authorized or delegated official changes, update the Medicare enrollment record on the appropriate timeline instead of maintaining a private list of 'people who can sign CMS forms.' The reliable source is the current enrollment relationship recognized by CMS, not an internal delegation that was never reflected in the payer record.
Handle a CMS-588 signature development without reopening the whole enrollment
If the contractor develops or rejects the EFT form for a signature problem, read the notice narrowly. Confirm whether the defect is the signer’s role, a missing signature or date, the form version, or supporting bank documentation. Correct that specific EFT defect unless the contractor identifies a broader enrollment problem. Calling every CMS-588 issue an enrollment denial can cause billing and leadership to escalate the wrong case.
Recheck the authorized representative or delegated official against the CMS-855 enrollment record before obtaining a replacement paper signature. If the official information itself is outdated, resolve the enrollment-record change rather than repeatedly asking an ineligible signer to execute a new form. Keep the original notice, corrected CMS-588, supporting bank evidence, and proof of resubmission together so the next follow-up starts from a complete history.
Close the development item only after the team has confirmed the contractor accepted the correction or has identified the next specific request. That final status should be communicated to finance and billing separately from the broader Medicare enrollment status.
Maintain signer authority as part of enrollment governance
The best prevention is not a longer signature checklist; it is keeping official roles current. When an owner, authorized representative, or delegated official leaves the organization or changes responsibilities, enrollment staff should evaluate whether the Medicare record needs an update. A private spreadsheet saying someone is allowed to sign does not override the role information CMS has on file.
Use a controlled signer list that is generated from or reconciled to the current enrollment record. For each entity, record the official’s name, role, last verification date, and the system or case used to verify it. That gives finance a practical way to route EFT forms without treating bank-signing authority, corporate officer status, and Medicare enrollment authority as interchangeable concepts.
This governance also helps when the practice has multiple legal entities. The same executive may be an authorized representative for one enrolled entity but not another. Matching the signer to the exact entity and CMS-855 record before execution is the small operational step that prevents a technically complete CMS-588 from failing at certification.
For multi-entity practices, add the legal business name and NPI to every signature request. A centralized finance team may support several practices that share officers but have different Medicare enrollment records. The extra entity label keeps staff from using a signer who is valid for one organization on a CMS-588 belonging to another. If the signer role is uncertain, pause the signature request and verify the enrollment record before routing the form. That is faster than obtaining a signature, mailing or uploading the form, and waiting for a contractor development request to reveal that the wrong entity relationship was used.
Operational checklist
- Identify who prepared the EFT information
- Verify the intended signer is an authorized or delegated official in PECOS
- Obtain the original signature on the paper CMS-588
- Confirm the signature date is present
- Keep a copy of the signed submission packet
Frequently asked questions
Who should sign CMS-588?
An authorized or delegated official whose role aligns with the Medicare enrollment record.
Can the billing manager sign just because they prepared the form?
Not automatically. The signer must have the appropriate authorized or delegated official role.
Does a paper CMS-588 need a signature date?
Yes. The CMS-588 signer rule requires the original signature and date.
How can a practice prevent a wrong-signer rejection?
Verify the intended signer in PECOS before the form is routed for signature.