For most of the last two decades, provider credentialing was a solved problem in the sense that nobody expected it to change. A clinician practiced at one facility, held one state license, and appeared in one directory. Verification happened at credentialing, then again at recredentialing two or three years later. The cadence matched the care model.
That alignment is gone. Care delivery has fragmented across virtual visits, home-based services, retail and employer clinics, and multi-state practice, while the infrastructure underneath it has not been rebuilt. The result is a widening gap between how care is delivered and how the providers delivering it are verified.
Care Model Fragmentation
Legacy credentialing infrastructure was designed around a single assumption: one provider, one facility, one state license, one payer relationship at a time. Nearly every element of non-traditional care violates that assumption.
A telehealth clinician may hold licenses in a dozen states, each with its own board, renewal cycle, and scope-of-practice rules. A home-based care provider may deliver services across county lines under contracts with multiple managed care organizations (MCOs, the insurance plans that administer benefits under contract with states and CMS). A provider working across a virtual platform, a physical clinic, and an employer site generates three separate privileging relationships from one clinical role.
Each of those permutations is a credentialing event that must clear before a claim can be paid. The events do not replace one another; they accumulate. For a payer building or expanding a digital health network, network adequacy now depends on clearing a volume of credentialing work that grows faster than headcount.
Regulatory Acceleration
The regulatory direction of travel has moved decisively toward continuous verification, and it has done so faster than most plans have rebuilt for.
The National Committee for Quality Assurance (NCQA, the accrediting body whose Health Plan Accreditation standards govern credentialing practice for most commercial and Medicare Advantage plans) has shifted its standards toward ongoing monitoring rather than point-in-time verification. Sanctions, license actions, and exclusion listings are expected to be caught between review cycles, not at the next one.
The Centers for Medicare and Medicaid Services (CMS, the federal agency administering Medicare and Medicaid) requires Medicare Advantage organizations to keep provider directories current on a rolling basis rather than an annual refresh. And under the No Surprises Act, plans must respond to provider directory inquiries and correct inaccurate information on a short turnaround measured in days.
Read together, these are not three separate compliance obligations. They are one requirement stated three ways: the provider record must be accurate now, not accurate as of the last review.
The Cost of Standing Still
The clearest measure of how far the infrastructure has fallen behind is the provider directory. Published industry reviews have repeatedly found that roughly half of directory entries contain at least one inaccuracy, with an estimated 81 percent carrying some inconsistency across data fields or between the sources feeding them.
Health plans collectively spend on the order of $4 billion per year maintaining and correcting those directories. The spend is largely reactive: outbound calls, faxed attestation requests, and manual reconciliation across systems that were never designed to exchange data with one another. Four billion dollars a year currently purchases a directory that is roughly half accurate.
The cost is not only financial. A member who cannot find an in-network provider through the directory may go out of network, delay care, or abandon the search. Directory accuracy is a network adequacy problem, a member experience problem, and a compliance exposure, and it is the same problem in each case.
From Periodic Verification to a Continuous State
The strategic shift available to payers is not a faster version of the current process. It is a different model: treating the provider record as a continuously maintained state rather than a document verified at intervals.
In a periodic model, accuracy is a snapshot that begins decaying the moment it is taken. In a continuous model, the interval in which a record can drift out of date is compressed to the monitoring cadence. License actions, sanctions, exclusion listings, and practice-location changes surface as source records change rather than at the next scheduled review.
This is the capability the current regulatory environment assumes. NCQA continuous monitoring, rolling CMS directory updates, and short No Surprises Act correction windows all presuppose an infrastructure that maintains state rather than one that periodically re-verifies. Plans operating on a periodic model are not merely slower; they are structurally unable to meet the requirement.
What This Means for Payer Strategy
For payers evaluating where credentialing sits in their operating model, three questions separate a strategic posture from an administrative one.
Is provider data governed in one place, or reconciled across many? Every additional system holding an authoritative copy of a provider record is another source of the inconsistency that shows up in directory audits. A single governed record is the precondition for everything downstream.
Is verification a state or an event? If license, sanction, and exclusion status is confirmed only at credentialing and recredentialing, the plan is carrying unmonitored risk for the full interval between them, and cannot meet continuous-monitoring expectations without adding manual work.
Does network expansion scale with headcount or with infrastructure? If entering a new state or launching a virtual line requires proportionally more credentialing staff, credentialing is a constraint on growth. If it requires configuration rather than hiring, it is infrastructure.
CareLumi provides a technology-enabled credentialing workflow platform, including CARL, its context-graph and orchestration engine, automated agents, and optional expert-review capabilities. At the customer's direction and subject to customer-provided information and approvals, the platform may facilitate workflow actions such as preparation of applications, submissions, communications, and status follow-up, and can maintain continuous monitoring across licensure, sanction, and exclusion sources. CareLumi does not act as the customer's credentialing agent of record, does not make credentialing, enrollment, licensing, or payer decisions, and does not guarantee any third-party response, approval, completion date, or business outcome.
The Takeaway
"The plans that treat credentialing as strategic infrastructure will move faster, stay compliant, and keep their directories trustworthy. The plans that do not will find an administrative function has become a constraint on growth."
Care delivery is not going to move back inside the hospital. The credentialing model built for that era can be extended with more staff and more outbound calling for a while longer, but the regulatory floor has already moved past what that approach can reach. The question for payers is no longer whether to rebuild, but whether to do it before or after the next compliance deadline arrives.
Jake Keffer is a Sales Intern at CareLumi.
Directory accuracy and industry cost figures cited in this article are drawn from published industry research and are presented as historical observations, not performance benchmarks or commitments. Regulatory requirements described are summarized for general context and are not legal advice; consult counsel regarding obligations applicable to your organization.
