Print this page Print this page | Close

  ID Proofing and Multi-Factor Authentication Overview

CMS has adopted Identity Proofing (ID Proofing) and Multi-Factor Authentication (MFA) services to provide certain users with the ability to view unmasked beneficiary information on the MSPRP. The ID Proofing process requires you to provide information to CMS sufficient to prove that you are the person you claim to be.To prove your identify successfully, CMS uses Experian's risk-based alternative (RBA) solution, which requires users to submit personally identifiable information (PII). This process works in conjunction with MFA, which uses two different authentication factors to verify your identity: the password associated with your login ID, and either a push notification or a security code sent to you via authentication app that you enter when you log in.

Once you successfully complete the process, you can choose whether or not to use your MFA factor to view previously masked beneficiary information when you log in to the MSPRP.

Existing users who have not completed the ID Proofing and MFA process can continue to access the MSPRP as they do today.

Note: If you are a registered user for both the CRCP and MSPRP systems, you can initiate the ID Proofing process on one application and then continue the process on the other. Once you complete ID proofing for one application, you are automatically ID proofed on the other.

ID Proofing Requirements

To complete the ID Proofing process, you will be required to enter current personally identifiable information (i.e., full legal name, social security number, date of birth, current residential address, personal email, and personal phone number). Do not use a business address or phone number, as these are not identifiable information. Before you start the process, the default MFA status displayed on your home page will be Initial Process and the Next Step will be Getting Started. After you finish the process, the final MFA status will be Complete.

MFA access is granted when you:

• Successfully complete the ID Proofing process,
• Register a factor, and
• Activate that factor

Once you have successfully completed the ID Proofing process, your status does not expire, so you will not ever need to repeat the process. You can continue to activate, deactivate, and reactivate factors for devices as needed. MFA access for one MSPRP account extends to all your MSPRP accounts.

To begin, click the Continue button, or click Cancel to return to the Account List page and cancel the ID Proofing process at this time.

January 2025