Yes, Medicare accepts physician signature attestations for most medical record entries, but not to fix unsigned physician orders. If a Medicare contractor flags a missing or illegible signature, the record's original author must sign and date a written attestation tying it to the specific patient and date of service. You have 20 calendar days from contractor contact to submit it, and a valid attestation typically buys the reviewer 15 extra days to finish the file.
TL;DR:
- Verifications must be signed and dated by the original author within 20 days of contractor contact, or the claim risks denial.
- Signatures on physician orders are not fixable with attestations, and only the exact author can sign a valid attestation.
- Attestations require specific elements, including the author’s printed name, signature, date, beneficiary’s name, and explicit record reference.
- Signature logs and EHR audit trail data can support illegible signatures but cannot replace the need for proper attestations.
- Practicing daily signature checks and responding immediately to signature gaps can significantly reduce claim rejections and revenue loss.
Table of Contents
- What to Do the Day You Discover a Missing Signature
- Orders vs. Everything Else: What Medicare Will and Won't Fix
- How to Write an Attestation Medicare Will Actually Accept
- Handling Illegible Signatures, Signature Logs, and EHR Notations
- The 20-Day Clock: Deadlines and Who Sends the Request
- Where Signature Attestations Go Wrong
- Preventing the Problem Before It Reaches a Contractor Letter
- What Actually Moves the Needle on This Problem
- A Faster Way to Catch Signature Gaps Before They Cost You
- Where to Verify These Rules Yourself
- Sources
What to Do the Day You Discover a Missing Signature
Speed matters more than perfection here. Once your practice spots a missing or illegible signature, whether from an internal audit or a contractor letter, the clock starts running and the steps you take in the first 24 to 48 hours determine whether the claim survives.
Start by locating the original chart entry and preserving whatever audit trail your EHR keeps around it. Do not edit the entry itself. Then go directly to the clinician who authored it. Only that physician, nurse practitioner, or other qualified provider can sign a valid attestation. Someone else signing on their behalf, even a covering physician or supervisor, invalidates the attestation entirely.
- Pull the original documentation and any EHR audit-trail data (timestamps, user ID, edit history) before anything else changes.
- Get the actual author to sign and date a written attestation that names the beneficiary and date of service explicitly.
- Build or update a signature log that maps initials, stamps, or illegible marks to a printed name and credential.
- Submit everything within the 20-calendar-day window and keep proof of submission, such as a fax confirmation or certified mail receipt.
- If the unsigned item is a physician order rather than a progress note or other record entry, loop in clinical leadership immediately. An attestation almost never rescues an unsigned order.
Pro Tip: Keep a blank attestation template pre-loaded in your EHR's document library. When a request comes in, staff can pull it up, route it to the physician for signature, and return it the same day instead of drafting language from scratch under deadline pressure.
Orders vs. Everything Else: What Medicare Will and Won't Fix
CMS draws a hard line between physician orders and other types of documentation, and that distinction decides whether an attestation can save a claim at all. Per the Medicare Learning Network's signature requirements fact sheet, attestations are accepted for medical record entries generally, but they are not a substitute for a properly signed order. If a physician order lacks a signature, the reviewing contractor will typically disregard it outright rather than accept a later attestation as a fix.
Authorship rules are equally strict. The person signing the attestation must be the same person who authored the original entry. A colleague filling in, a supervising physician who reviewed the chart later, or an office manager signing "on behalf of" the provider does not satisfy CMS requirements. CR 6698 / MM6698 reinforces this by defining exactly what counts as an acceptable signature log and attestation statement, and it draws the same author-only line.
An attestation cannot backdate a plan of care, and it cannot substitute for a signature the payer's policy requires to exist before a specific event, like a certification date for home health or hospice eligibility.
Medicare recognizes three acceptable formats for resolving a signature issue:
- An on-page printed signature paired with the provider's credentials, directly on the original document.
- A separate attestation statement, signed and dated by the author, referencing the exact record it corrects.
- A signature log, maintained anywhere in the medical record, that maps marks or initials to full names and credentials.
What happens next depends entirely on which category the entry falls into. Reviewers disregard unsigned orders regardless of any attestation you submit later. For other entries, once a valid attestation or signature log resolves the ambiguity, the reviewer will consider that documentation as part of the medical necessity determination. That single distinction is why so many practices lose appealable claims: they treat every missing signature the same way when Medicare does not.
How to Write an Attestation Medicare Will Actually Accept
A vague "I attest this is my note" statement will not survive review. Medicare and its contractors expect specific elements, and skipping even one gives the reviewer grounds to reject the attestation outright.
Every valid attestation needs:
- The author's printed name and professional credentials (MD, DO, NP, PA, etc.).
- A handwritten or electronic signature from that same author.
- The date the attestation was signed, which must be after the original entry, never backdated to match it.
- The beneficiary's name and date of service, stated explicitly rather than implied.
- Clear language tying the attestation to the specific record entry it corrects.
- A truthful statement affirming the entry reflects the care actually provided.
Noridian's sample attestation offers language close to what most Medicare Administrative Contractors expect: something like, "I, [printed name], hereby attest that the medical record entry for [beneficiary name] on [date of service] is complete and accurate, and I authored this entry on the date of service indicated." Treat this as a starting point, not a script. Wording expectations shift slightly between MACs, so check your local contractor's published guidance before submitting anything verbatim.
Electronic signatures work the same way, provided they carry a clear notation. Language such as "Electronically signed by," "Validated by," or "Completed by" alongside the typed name satisfies the documentation authentication guidance that DME MACs distribute to physicians. A typed name with no such indicator, on its own, is not sufficient proof of authorship.
Never backdate an attestation to make it look contemporaneous with the original entry. That crosses from a documentation fix into falsification, and it carries real legal exposure beyond the immediate claim denial.
Pro Tip: Build your attestation template with the beneficiary name and date-of-service fields locked at the top, forcing staff to fill them in before the physician ever sees the document. Missing beneficiary identification is one of the most common reasons MACs reject an otherwise valid attestation.
Handling Illegible Signatures, Signature Logs, and EHR Notations
Illegible handwriting is one of the most common signature complaints Medicare contractors raise, and it has one of the simplest fixes: a signature log. A signature log lists every provider's initials, signature mark, or stamp alongside their printed name, credentials, and the dates they were active in that record. It can live on the original document or as a completely separate page in the medical record.
One detail trips up a lot of practices: creation date does not matter. Per CR 6698 guidance, contractors will accept a signature log regardless of when it was created, as long as it is part of the patient's medical record and accurately maps the mark to the author. You can build one retroactively in response to a request, provided the mapping is accurate and complete.
For EHR-based records, audit trail data adds another layer of proof. When you respond to a contractor request, include:
- User ID and login credentials tied to the entry.
- Timestamps showing when the entry was created and, separately, when it was signed.
- Any edit history showing the entry was not altered after the fact.
Reviewers treat this metadata as supporting evidence for authorship, not a replacement for the signed attestation itself. Submit both together. An electronic signature also needs the right notation to count. Phrases like "Electronically signed by [Name], [Credential]" or a system-generated "Validated by" stamp satisfy Medicare's expectations, while a bare typed name sitting at the bottom of a note typically does not.
The 20-Day Clock: Deadlines and Who Sends the Request
The 20-calendar-day window starts the moment a contractor makes contact, whether by phone or by receipt of a written request, and missing it usually means the entry gets excluded from consideration regardless of how solid your attestation would have been. Submit a valid attestation or signature log inside that window, and the reviewer typically extends the overall review period by 15 calendar days to account for the additional documentation.
Several types of review contractors can send these requests, and each operates a little differently:
| Contractor type | Common trigger | What to track |
|---|---|---|
| Medicare Administrative Contractor (MAC) | Routine claims review or prepayment audit | Contact date, method, MAC name |
| Unified Program Integrity Contractor (UPIC) | Suspected fraud or abuse pattern | Full request letter, response deadline |
| Recovery Audit Contractor (RAC) | Post-payment claim review | Claim numbers under review |
| CERT (Comprehensive Error Rate Testing) | Random national error-rate sampling | Sample ID, submission confirmation |
| Supplemental Medical Review Contractor (SMRC) | Targeted CMS-directed review | Review topic, submission tracking number |
- Log the exact date and method of contact the moment it happens, not after your team drafts a response.
- Record the contractor's name and the specific claim or beneficiary identifiers referenced in the request.
- Keep a copy of everything you submit, along with delivery confirmation, in a dedicated compliance file separate from the patient chart.
Missing the 20-day window is one of the more avoidable ways practices lose otherwise defensible claims.
Where Signature Attestations Go Wrong
The same handful of mistakes show up across most denied attestations, and nearly all of them are preventable with a five-minute process check before submission.
The most frequent error is having the wrong person sign. A covering physician, a resident, or an office manager signing "for" the original author invalidates the attestation immediately, no matter how accurate the underlying note is. Late submissions past the 20-day window are the second-biggest cause, followed closely by attestations that omit the beneficiary's name or date of service, which reviewers cannot tie back to a specific claim.
Auditors also watch for specific red flags: unsigned orders submitted with an attestation attached (a mismatch that signals someone misunderstood the rules), signature stamps used without a corresponding signature log, and inconsistent authorship where the documented provider doesn't match who actually signed.
- Train staff on the order-versus-entry distinction, since that single misunderstanding drives the most denials.
- Run pre-claim signature checks before submission rather than waiting for a contractor letter.
- Maintain signature logs continuously, not just when a request arrives.
- Build a same-day attestation workflow so requests never sit unanswered near the deadline.
Pro Tip: Add a signature-completeness check to your EHR's pre-submission workflow. Catching a missing signature before the claim goes out costs your practice nothing. Catching it after a contractor letter arrives costs staff hours and puts reimbursement at risk.
Preventing the Problem Before It Reaches a Contractor Letter
Reacting well to a signature request matters, but preventing the gap in the first place protects more revenue with less staff time. Automated compliance alerts that scan documentation before claims go out can flag unsigned entries and illegible signatures while there's still time to fix them, rather than weeks later when a MAC comes asking.
A standing attestation repository, paired with a documented audit checklist, also cuts response time dramatically when a request does land. Instead of scrambling to locate the original author and reconstruct a signature log from memory, staff pull from a system that already tracks who signed what and when. Resources like Himshield's Physician Practice Audit Survival Checklist, documentation education guidance, and query process best practices all reinforce the same principle: the fastest attestation is the one you never have to write under deadline pressure.
What Actually Moves the Needle on This Problem
Most practices treat signature attestation as a paperwork chore they handle after a denial letter shows up. That's backward. The real fix happens weeks earlier, at the point of documentation, not the point of appeal.
One change consistently reduces unsigned entries more than any policy memo: routing every unsigned note back to the authoring physician within 24 hours, before it ages into the chart untouched. Practices that wait for month-end chart audits to catch these gaps end up with a pile of entries where the physician barely remembers the encounter, which makes writing an accurate attestation harder and riskier.
Clinical workflow and compliance will always pull in different directions a little. Physicians are moving fast between patients, and a signature prompt feels like one more interruption. The practices that manage this well don't add more friction. They shrink it, usually with a single tap or click at the point of care. If your practice does nothing else this quarter, build that same-day signature loop. It's the lowest-effort change with the highest return.
— Elena
A Faster Way to Catch Signature Gaps Before They Cost You
Checklists and manual audits catch some signature problems, but they catch them late, often after the claim has already gone out the door. Himshield's platform flags unsigned or illegible signatures directly in your EHR data before submission, and when a contractor does ask for documentation, it helps assemble a submission-ready response instead of leaving your billing team to reconstruct the paper trail from scratch.

That speed matters because the 20-day clock doesn't pause for a busy front office. Himshield's per-provider, per-payer revenue leakage reports show you exactly where signature and documentation gaps are costing your practice, and its one-click physician e-signature workflow gets corrections back from the clinician the same day instead of the same week. If you want to see where your own practice stands, start with Himshield's free 30-day audit or learn more about how the platform connects to your EHR to catch these gaps before they ever reach a contractor's desk.
Where to Verify These Rules Yourself
Before relying on any attestation language in an active claim dispute, check it against the primary sources. The MLN905364 signature requirements fact sheet and CR 6698 / MM6698 remain the two foundational CMS documents on this topic, and Noridian's sample attestation statement offers usable template language. Every MAC publishes its own version of these instructions, so confirm jurisdiction-specific wording on your local MAC's website before submitting.
