Export Medicare site certificates

Medicare site certificates can be used for:

  • Access to Health Identifier services for HI lookups
  • eRx Script exchange.

Medicare does not always distribute new certificate disks to practices that use Medicare Online when their certificates expire. Instead, Medicare provides a facility to renew the practice's certificates when sending and receiving claims.

Medicare certificates are used by eRx Script exchange for sending electronic scripts and by Bp Premier for HI Lookups. These certificates cannot be updated automatically by Medicare's renewal facility. You may be required to export the certificates using Medicare's PKI certificate manager.

More information on Medicare's PKI Certificate Manager can be found on the Department of Human Services website.

Before you can export certificates

Identify the certificate store location

  1. The Medicare Certificate store file is called HIC.psi. On the Bp Premier server, browse to c:\Program Data\BPOnline in a file explorer and check that a file called HIC.psi exists in the folder.
  2. If the file is not in this location, log in to Bp Premier on the server and go to Setup > Configuration > Online Claiming.
  3. Identify the path displayed in the Path to Certificate store field. The path will usually be a UNC path (for example, '\\servername\BPOnline').

Obtain PIC passphrase

Ensure you have the letter from Medicare that identifies the PIC passphrase for Online Claiming. The PIC password is linked to the store file and the practice certificates and is required to export certificates.

Install PKI certificate manager

  1. If Medicare's PKI certificate manager has not been installed, download the certificate manager software from the Department of Human Services.
  2. Unzip and install PKI Certificate Manager Software on the computer where the certificate store is located.

Identify the export folder

Create a new folder with a meaningful name on the server on which you installed PKI certificate manager. Use this folder to export the certificates.

You are now ready to export the certificates.

Export from PKI Certificate Manager

  1. On the computer on which you installed PKI Certificate Manager, open the Windows Control Panel.
  2. Double-click PKI Certificate Manager.
  3. If this is the first time that PKI certificate manager has been used, the software will ask you for the location of the store.
  4. If the software does not ask, click on Setup on the right of the screen. Select Use an Existing Store and click Next.

  5. Browse to the Path to Certificate storeyou identified. By default, the path should be C:\ProgramData\BPOnline\HIC.psi. Click Finish.
  6. The View Certificates screen will appear. Click on the Personal tab to view all personal certificates held in this certificate store.
  7. Highlight the first certificate that shows the practice name and click Export. The Certificate Export screen will appear.
  8. Enter the PIC passphrase.
  9. If the password is valid, the Certificate Export screen will appear. Browse to the folder where you want to export the certificates to.
  10. Type in the filename FAC_Sign.p12 and select the file type P12.
  11. Click Open and tick Include Private Key.
  12. Click Next.
  13. Enter the PIC Passphrase again. Click Finish.
  14. Repeat steps 6–12 for the other certificate with the practice name held in the store. However, at step 9, type in the filename FAC_Encrypt.p12 instead and keep following the instructions.
  15. Close the PKI Certificate Manager.

The certificates can now be used for HI Lookups or eRx.

Last updated 23 July 2020