— CASE STUDY

Making Medicare claims data easier to access securely at scale

Building and operating CMS APIs for secure Medicare claims data sharing

theta. advanced product direction and delivered API, authentication, and credentialing capabilities for CMS’s BCDA and DPC products. The work gave authorized organizations a more dependable way to receive Medicare claims data for care coordination, performance analysis, and value-based care.

— CASE STUDY

Making Medicare claims data easier to access securely at scale

theta. advanced product direction and delivered API, authentication, and credentialing capabilities for CMS’s BCDA and DPC products. The work gave authorized organizations a more dependable way to receive Medicare claims data for care coordination, performance analysis, and value-based care.

customer

Centers for Medicare & Medicaid Services (CMS)

Contract Role

Subcontractor

Mission

Secure Medicare claims-data exchange

Delivery Focus

Product strategy, API delivery, and credentialing automation

Capabilities

Build & Integrate | Data & Intelligence | Secure, Test & Release

Mission Context

CMS needed to make large volumes of Medicare claims data available to authorized care organizations and providers without weakening privacy, identity, or access controls. BCDA supports accountable care and alternative payment models with bulk claims data, while DPC supports data exchange for care coordination. theta. worked across product direction, backend services, authentication, and credentialing to make both products easier to adopt and operate.

Why it mattered

Claims data can help care organizations identify gaps, understand utilization, and coordinate services, but only when access is timely, dependable, and limited to properly authorized users.

Claims data can help care organizations identify gaps, understand utilization, and coordinate services, but only when access is timely, dependable, and limited to properly authorized users. Manual credentialing and fragmented access patterns constrained the value of the data.

The Challenge

Open valuable data without weakening trust
1

Secure access at scale

CMS needed to distribute bulk claims data while enforcing authorization and protecting beneficiary information.

2

Complex participation models

Different accountable-care and payment models introduced distinct eligibility and access requirements.

3

Credentialing friction

Manual provider and organization verification slowed onboarding and increased administrative effort.

How theta. Delivered

Secure access from participant onboarding through API delivery
1

Set product direction

theta. shaped roadmaps and priorities around user needs, program requirements, and the operational realities of large-scale data exchange.

2

Delivered API capabilities

theta. built and integrated backend services that supported dependable access to Medicare claims data.

3

Strengthened identity and access

theta. implemented authentication and authorization patterns that limited data access to approved users and organizations.

4

Automated credentialing

theta. reduced manual onboarding effort by automating provider and organization verification workflows.

Outcomes

A more dependable path to authorized claims data
theta. made the path from approved participation to usable claims data more secure, repeatable, and operationally sustainable.

Streamlined authorized data access

Participating organizations gained a clearer, more dependable path to the Medicare claims data they were permitted to use.

Lower credentialing burden

Automated verification reduced avoidable manual work in provider and organization onboarding.

Durable operational continuity

Documentation, training, and structured transition practices preserved product knowledge for continued operation and improvement.

Customer voice

Secure exchange that can extend across programs

Built for What Comes Next

Secure exchange that can extend across programs
The resulting product and platform patterns support continued expansion of secure claims-data exchange across value-based care programs without tying the solution to one participation model.

Technical environment

Technology and delivery practices

Akamai, AWS EC2, ECS, ElastiCache, ELB, RDS, KMS, WAF, Shield, Java, Ruby, Go, PostgreSQL, Redis, Docker, Jenkins, Packer, Ansible, Terraform, SonarQube, GitHub, New Relic, CloudWatch, Splunk, and VictorOps

Have a complex mission to turn into a usable digital product?

Let us start with the policy, people, systems, and operating realities that shape the work.

Related work

Related case studies

01-cdoc-case-study-hero

CDOC

theta. kept essential corrections workflows moving while CDOC transitioned from aging custom applications to a modern enterprise suite. By resolving data issues, restructuring backend logic, and improving applications that would remain in place, theta. reduced friction in the legacy environment and created a safer path through a complex, multi-system transition.
02-va-pact-act-case-study-hero

VA

theta. expanded VA’s Rapid Ready for Decision approach to PACT Act claims, connecting claims workflows with existing health data so eligible cases could move forward with less manual retrieval and fewer avoidable exams. The work paired product strategy, prototyping, secure integration, and iterative delivery around the needs of Veterans and claims processors.
04-reportstream-case-study-hero

CDC

theta. delivered FHIR-based services and last-mile integrations that enabled ReportStream to receive, process, and route public health data across organizations with different technical capacities. The work strengthened an adaptable, observable exchange used for COVID-19 reporting and other public health needs.
Scroll to Top