CAQH Profile Maintenance and Re-Attestation: What Credentialing Teams Miss
A provider changes practice locations in February. The credentialing team updates its internal system, tells the largest health plans, and moves on. Months later, someone discovers that an old address is still sitting in the provider's CAQH profile, a supporting document has expired, and an attestation deadline has passed.
Nothing about the original change was complicated. The problem was that the change had to remain synchronized across several administrative systems, each with its own workflow and timing.
That is what makes CAQH profile maintenance deceptively difficult. Completing a profile once is an onboarding task. Keeping dozens, hundreds, or thousands of profiles accurate is an operating process. For credentialing teams, the distinction matters.
A CAQH Profile Is a Living Provider Record
CAQH profiles consolidate provider information that participating organizations can use in credentialing and other provider-data processes. A profile can contain professional, practice, licensing, education, insurance and other information, along with supporting documentation.
The important word is "current." A provider who joins a new practice location, renews a license, changes liability coverage or updates contact information has created a provider-data event. Even when the change is correctly recorded somewhere inside the organization, that does not automatically mean the corresponding CAQH information has been reviewed and updated.
CAQH's June 2025 Provider Data Portal guide states that re-attestation is required every 120 days, or every 180 days for Illinois providers, to keep information maintained and accurate for health plan use. The guide also instructs providers to update profile information and supporting documentation before completing re-attestation.
That distinction is easy to miss. Re-attestation is not simply clicking a recurring confirmation button. It is a checkpoint at which the underlying record should be reviewed.
Furthermore, CAQH's portal environment itself is changing. The current CAQH portal directs users who have migrated into CAQH Unity, while providing a migration path for users coming from the Provider Data Portal. Interface changes may alter where teams click, but they do not remove the underlying operational problem: provider information has to stay synchronized as reality changes.
Why Re-Attestation Becomes a Credentialing Problem
The difficulty appears when the calendar and the provider record drift apart. Consider a credentialing department responsible for 300 clinicians. Their providers did not all start on the same day, licenses do not expire together, practice changes occur unpredictably, and supporting documents arrive through different channels. One provider may be waiting on updated liability documentation while another has a new service location and a third has changed a professional detail that needs review.
The team therefore has two different clocks to manage. The first is the attestation clock. A profile needs periodic re-attestation under the applicable CAQH schedule.
The second is the change clock. Provider information can become outdated at any point between attestations.
Managing only the first clock creates a familiar failure mode. A coordinator receives an upcoming re-attestation task, opens the profile and then discovers that several changes have accumulated since the last review. What appeared to be a five-minute recurring task becomes a research project involving operations, the provider, practice management and document collection.
The opposite failure is possible too. A team can be diligent about processing individual changes while losing visibility into which profiles are approaching re-attestation. Good CAQH profile maintenance has to accommodate both.
Small Data Changes Can Create Large Administrative Detours
The operational consequence of stale provider data is rarely confined to one database.
Suppose a clinician begins seeing patients at a second location. Internally, scheduling knows the new address. The practice management system has been updated. Patients are being booked there. However, the credentialing workflow did not receive the change, so the provider's external administrative records still reflect the previous configuration.
Now the team has conflicting versions of the provider's information. That discrepancy may surface during credentialing or enrollment work, provider-data verification, or another downstream administrative process. The exact consequence depends on the payer, network, provider and type of discrepancy, so an outdated CAQH field should not automatically be treated as a guaranteed claim denial or enrollment failure.
Nonetheless, discrepancies create investigation. Someone has to determine which record is correct, identify where the outdated information lives, gather supporting information, make the appropriate updates and confirm that the change has propagated through the relevant processes.
The expensive part is often not changing the address. It is discovering the mismatch after another workflow has already encountered it.
This is why treating CAQH maintenance as a periodic clerical assignment understates its importance. Provider data sits upstream of several administrative processes, and inaccurate upstream information creates work downstream.
The Better Trigger Is the Provider Change Itself
Calendar reminders are necessary, but they are not sufficient. A stronger process connects CAQH profile maintenance to the events that change provider information in the first place. When credentialing teams learn that a provider has changed a practice location, renewed a relevant document, updated professional information or experienced another material change, that event should trigger a review of the systems and organizations that depend on the affected data. Think of it as a change map.
If a provider adds a location, which internal records need updating? Which external records need review? Who owns each action? Does documentation need to be collected? Is confirmation required before the item can be closed?
This approach changes the role of re-attestation. Instead of using the re-attestation deadline as the moment when months of accumulated changes are discovered, the team handles material updates closer to when they occur. Re-attestation then becomes a structured verification point, not a rescue operation.
Although this requires coordination across departments, it can make the workload more predictable. Credentialing stops depending on someone remembering to tell the right person after an operational change.
The goal is a better connection between the source event and the maintenance task.
Scaling Requires Managing Exceptions, Not Just Profiles
At small scale, an experienced coordinator may carry much of this process in memory. That approach deteriorates as the provider roster grows.
A larger credentialing operation needs to know, at minimum, which profiles require attention, what changed, what information is missing, what documentation is approaching expiration, what has already been reviewed and what still requires action. A practical work queue might distinguish among several states: upcoming re-attestation, provider change received, documentation needed, update in progress, ready for review and completed. The labels themselves matter less than the visibility they create.
Without clear states, a spreadsheet row marked "CAQH pending" can represent five completely different situations. One provider may simply need final review. Another may be missing a document. Another may require information from a practice manager. Another may already have been completed but never recorded internally.
Those differences determine the next action. This is also where automation can be useful, particularly around repetitive outreach and verification. SuperDial's provider data management workflows are designed to handle repeatable payer and provider-facing processes while returning structured data, summaries, next actions and source evidence. The purpose is not to remove credentialing judgment. It is to keep routine information gathering from consuming the capacity needed for exceptions.
At scale, that separation becomes increasingly important. A credentialing specialist should spend more time resolving ambiguous cases and less time repeatedly checking whether straightforward information has changed.
The Red Flags That Tell You Maintenance Is Reactive
Most teams do not need a sophisticated maturity model to determine whether CAQH maintenance is under control. The warning signs are visible in daily work.
A profile should not routinely reveal surprises when someone opens it for re-attestation. Credentialing staff should not have to search email to determine whether a location change was ever processed. The organization should not depend on one employee's memory to know which providers require attention. Supporting documentation should not become visible only after it blocks completion.
Another red flag is disagreement about ownership. If practice operations assumes credentialing will learn about provider changes automatically, while credentialing assumes practice operations will submit a request, the process has no reliable trigger.
The underlying question is simple: When provider information changes today, what causes the CAQH maintenance workflow to start? If the answer is a named process with an owner, a queue and a completion record, the organization has something it can scale. If the answer is "someone usually emails us," the re-attestation calendar is carrying far more responsibility than it should. CAQH maintenance works best when periodic attestation is the final check on a continuously maintained provider record, rather than the mechanism a team relies on to discover that the record became stale months earlier.
Sources
- CAQH, Provider Data Portal for Providers User Guide v45.0, last updated June 4, 2025: https://proview.caqh.org/Login/Download?filename=CAQH+Provider+Data+Portal+for+Providers+User+Guide+v45.0.pdf
- CAQH, CAQH Unity / Provider Portal, accessed 2026: https://portal.caqh.org/
Run a pilot on a real workflow.
Bring a representative batch, define the output schema, and validate ROI with your payer mix in 30 to 90 days.

