Provider Directory Accuracy: Why Attestation Needs an Ongoing Workflow
Provider directory errors rarely begin as dramatic data failures. More often, a physician changes locations, a phone number is updated in one system but not another, a provider stops accepting new patients, or a network relationship changes without every downstream directory receiving the update.
Months later, the organization may be managing several versions of the same provider record across health plans, credentialing systems, public directories, internal databases, and provider-facing tools.
That is why provider directory accuracy is better treated as an ongoing operational workflow than as a periodic data-cleanup project.
Different payer types are subject to different provider-directory requirements. The No Surprises Act provisions discussed here govern applicable group health plans and health insurance issuers, while Medicare Advantage, Medicaid, and other CMS-regulated programs also operate under separate directory rules.
Under the No Surprises Act, plans and issuers subject to the law must establish processes to verify and update provider directory information at least once every 90 days. Providers and facilities have separate responsibilities to maintain business processes for supplying updated directory information, including when they enter or terminate network agreements, when material information changes, and when a plan or issuer requests an update.
For network and provider operations teams, the practical challenge is turning those requirements into a workflow that can keep up with real-world change.
Provider data changes continuously
A provider record is not static.
A clinician may practice at several locations. One location may stop accepting new patients while another continues to do so. Office hours change. Phone numbers are consolidated. A specialty designation is updated. A group adds a new site. A provider leaves the organization. Network participation changes.
Each individual change may seem small, but directory accuracy depends on getting the same change to every system and payer that relies on it.
Federal law defines provider directory information to include details such as provider names, addresses, specialties, telephone numbers, and digital contact information. It also covers corresponding information for medical groups, clinics, and facilities.
This is why directory accuracy cannot be solved simply by correcting records once a year. The data is attached to operational relationships that continue to change throughout the year.
The 90-day rule does not mean providers should wait 90 days
One easy mistake is to treat the No Surprises Act's 90-day verification requirement as the update cycle for provider organizations.
It is not.
The requirement to verify and update directory information at least once every 90 days applies to the health plan or issuer. Providers and facilities have their own statutory obligations to maintain processes for supplying directory information when relevant events occur.
Those events include beginning a network agreement, terminating one, making a material change to directory information, and responding when a plan or issuer requests updated information.
Operationally, that means a provider group should not wait for the next quarterly attestation if a location, phone number, specialty, or network relationship has already changed.
The better trigger is the change itself.
When provider data changes internally, the organization should be able to identify which external records may need to change with it.
Attestation and update are different tasks
Provider data workflows often combine several activities under the word “attestation.”
That can hide important differences.
An attestation may confirm that the payer's existing record is correct. An update changes information that is no longer correct. A verification process may require the payer to contact the provider or check another source before treating information as current.
Those workflows have different outcomes.
If an office receives an outreach request and simply confirms that everything is correct, the process can close quickly. If the office discovers that the payer has an old address, the workflow needs to capture the corrected value, identify the relevant provider or location, send the update through the required channel, and ideally retain enough evidence to show what was supplied.
The problem gets harder when most of the record is correct but one field is not.
A useful provider-data workflow therefore should not reduce every interaction to “attested” or “not attested.” It should preserve which fields were verified, which changed, and which could not be confirmed.
One provider can create many directory records
Directory maintenance becomes substantially harder when organizations grow.
Imagine a provider group with physicians practicing at several sites and participating with multiple health plans. The organization is not maintaining one record per clinician. In practice, it may be managing combinations of provider, location, specialty, group, payer, and network.
A physician changing one practice location can therefore create multiple update obligations.
The same problem appears during acquisitions. A newly acquired practice may have accurate clinical and employment records internally while payer directories still reflect a previous address, phone number, group affiliation, or network configuration.
That makes provider data management a reconciliation problem.
The internal system may contain the organization's preferred record, but the payer has its own version. Other public sources can contain still another version. The operational task is identifying disagreements and deciding which records need action.
“Unable to verify” needs its own workflow
Not every provider data request ends with a confident answer.
A payer may call a location that has closed. A directory may contain a phone number nobody recognizes. An office may know that a physician still works for the organization but be uncertain which plans currently list that clinician at a particular site.
These cases should not be forced into an accurate-or-inaccurate binary.
Federal law requires plans and issuers to establish procedures for removing providers or facilities when directory information cannot be verified within the period the plan or issuer specifies.
That makes “unable to verify” an operationally meaningful status.
A strong workflow should preserve the failed contact attempt, identify which field could not be confirmed, determine whether another source or office can resolve it, and route the record for follow-up rather than silently leaving stale information in place.
Without that exception path, verification programs can produce false confidence simply because every record eventually receives a checkbox.
Payers need to turn provider responses into directory updates
The other half of the process happens after corrected information reaches the payer.
Under the federal directory provisions, plans and issuers must have a process to update their database within two business days after receiving applicable provider or facility directory information.
That creates a useful operational distinction between receiving an attestation and applying it.
A network operations team may successfully reach a provider office, confirm that an address has changed, and document the new information. If the result remains in a call note or spreadsheet without reaching the directory system, the outreach has not solved the underlying problem.
The result needs to be structured enough to update the system that powers the directory.
That is why provider outreach should ideally capture individual fields rather than only free-text notes. An address change, accepting-new-patients status, specialty correction, phone update, and location closure should each be identifiable as separate outcomes.
Structured responses also make quality control easier because teams can see which fields change most often and which records repeatedly fail verification.
Provider Directory APIs solve distribution, not necessarily verification
CMS also has separate interoperability requirements for certain payer categories.
Medicare Advantage organizations, Medicaid and CHIP agencies, and specified managed care entities are required to make provider directory information available through public-facing Provider Directory APIs. CMS says those APIs must include information such as provider names, addresses, phone numbers, and specialties. Certain directory information must be made available within 30 calendar days after the payer receives the provider information or update.
APIs make directory information easier to distribute electronically, but they do not remove the underlying data-quality problem.
An API can distribute an incorrect address just as efficiently as a correct one.
The harder problem remains upstream: determining whether the data is current, obtaining corrections when it is not, associating those corrections with the right provider and location, and recording enough evidence to trust the change.
The technical interface and the verification workflow solve different parts of the problem.
Medicare Advantage directories are becoming more visible to consumers
There is also a newer Medicare Advantage development that raises the stakes for directory data quality.
Under CMS-4208-F2, Medicare Advantage organizations must make provider directory information available to CMS for publication through Medicare Plan Finder. For Contract Year 2027, CMS is implementing a process that allows plans to supply contracted provider and facility data through machine-readable JSON files or FHIR-based APIs.
CMS then ingests and validates that information before it appears in Medicare Plan Finder. The validation process checks technical and field-level requirements, while the Medicare Advantage organization remains responsible for the accuracy of the underlying provider information.
That distinction reinforces the same operational point: moving provider data through an API does not make the data correct.
CMS guidance also describes circumstances in which provider directory information can be suppressed from Medicare Plan Finder, including failure to complete required attestation, fatal technical validation errors, or reported data-quality issues that exceed a CMS threshold.
For provider organizations, these are payer-side requirements rather than new provider attestation rules. But they increase the downstream visibility of the information providers send to Medicare Advantage plans. A stale location, network relationship, or practice detail is no longer just an internal payer-directory problem when that data can ultimately shape what beneficiaries see while comparing coverage.
CMS has also described the National Provider Directory as the longer-term destination for these FHIR-based feeds, with the goal of connecting provider, payer, and directory information more systematically.
The direction is increasingly clear: provider data is moving toward more structured, reusable, and externally visible infrastructure. That makes accurate upstream verification more important, not less.
CMS is also moving toward more centralized provider data
CMS currently operates a National Provider Directory that allows providers to access, manage, and verify their directory information. The system also supports public search and is being developed as part of CMS's broader effort to make provider information more reusable across the healthcare ecosystem.
The National Provider Directory does not eliminate plan-specific directory processes. Network participation, accepting-new-patient status, contracted locations, and other payer-specific fields can still depend on the relationship between a provider and an individual health plan.
It does, however, reinforce an important design principle: provider data becomes easier to manage when it can be represented as structured information rather than repeated manually across disconnected forms and phone conversations.
For provider organizations, the long-term opportunity is not simply maintaining another directory. It is reducing the number of times the same basic information has to be verified, reformatted, and resubmitted independently.
Build the workflow around the change event
The most scalable provider directory programs begin before the payer asks for an attestation.
When an organization changes a practice location, closes an office, updates a phone number, adds a specialty, or ends a network relationship, that event should create a data-maintenance workflow.
The workflow then needs to identify which external organizations may need the new information and track whether the change has been delivered and confirmed.
A useful provider directory record typically needs to answer a small set of operational questions:
- What information changed?
- Which provider, group, or location does it affect?
- Which payers or directories may hold the old value?
- When was the new information sent?
- Was it received or verified?
- Is anything still unresolved?
- What evidence supports the current value?
That is different from treating provider directory work as a periodic list of phone calls.
The change itself becomes the trigger, and attestation becomes one method of validating the resulting records.
Measure unresolved records, not just outreach volume
Provider data programs can easily optimize for the wrong metric.
A team may complete 10,000 calls or send thousands of attestations and still have poor directory accuracy if the difficult records remain unresolved.
Outreach volume measures activity.
A better operational view focuses on whether each record reached a trustworthy state.
That means separating records that were verified unchanged from records that were corrected, records waiting for an update to propagate, and records that could not be verified.
It is also useful to know how long records remain unresolved and which fields or provider groups repeatedly produce discrepancies.
Those measures reveal where the actual data-quality problem lives.
A high contact rate is helpful, but it is not the same thing as an accurate directory.
Automation should make provider data more auditable
Provider directory outreach is a natural automation candidate because much of the work is repetitive.
Someone contacts the practice, identifies the provider or location, verifies a defined set of fields, records changes, and sends the result into another system.
But automating the conversation is only part of the solution.
The output should preserve what was verified, what changed, who or what source supplied the information, when the verification occurred, and whether anything still needs human review.
An ambiguous response should become an exception rather than a guessed value. A disconnected number should trigger another verification path. A correction should be represented in structured fields so that it can move into the downstream directory process.
The point is not simply to replace a manual call.
It is to turn a provider interaction into data that another system can trust and use.
Frequently Asked Questions
How often must health plans verify provider directory information?
Under federal law, covered group health plans and health insurance issuers must establish processes to verify and update provider directory information at least once every 90 days. The law also requires procedures for handling records that cannot be verified.
Do providers have provider directory responsibilities too?
Yes. Providers and facilities subject to the federal requirements must maintain business processes for supplying directory information to plans and issuers. The law identifies events including entering or terminating a network agreement, material changes to directory information, and requests from a plan or issuer.
What information is considered provider directory information?
Federal law includes information such as provider names, addresses, specialties, telephone numbers, and digital contact information. It also covers corresponding directory information for medical groups, clinics, and facilities.
Does a Provider Directory API guarantee the data is accurate?
No. An API provides a structured way to make provider directory information available. Accuracy still depends on whether the underlying provider and network information has been verified and updated correctly.
CMS's Medicare Advantage directory process makes this distinction explicit: CMS can validate whether a submitted feed meets technical and field-level requirements, while the plan remains responsible for the accuracy of the provider data itself.
What should provider data attestation capture?
The exact fields depend on the organization and payer, but the workflow should make clear which data was verified, which fields changed, when verification occurred, the source of the information, and whether unresolved items require follow-up.
How does Medicare Plan Finder affect provider directory accuracy?
Beginning with Contract Year 2027 implementation, Medicare Advantage organizations are supplying provider directory data to CMS for display through Medicare Plan Finder.
That makes directory data more visible to beneficiaries and increases the importance of accurate upstream provider information, even though the submission and attestation requirements themselves sit with the Medicare Advantage organization.
The takeaway
Provider directory accuracy is not a database-cleanup problem that can be solved once.
Provider organizations change continuously, and each change can create downstream inconsistencies across payer networks and public directories. Federal requirements reflect that reality by placing ongoing responsibilities on both plans and providers rather than treating directory maintenance as a one-time exercise.
The operational goal is to shorten the distance between a real-world change and an accurate external record.
That means treating changes as workflow triggers, verifying individual fields, preserving evidence, separating unresolved records from confirmed ones, and making the result structured enough to move into the systems that publish and use provider directory data.
The growing visibility of directory information through Medicare Plan Finder and the development of CMS's National Provider Directory make that discipline even more important.
When provider data becomes part of a continuously updated, externally visible infrastructure, attestation can no longer be treated as an occasional cleanup exercise.
It has to become part of the normal lifecycle of provider data.
Sources
- U.S. House of Representatives, Office of the Law Revision Counsel. 42 U.S.C. § 300gg-115, Protecting Patients and Improving the Accuracy of Provider Directory Information.
- U.S. House of Representatives, Office of the Law Revision Counsel. 42 U.S.C. § 300gg-139, Provider Requirements to Protect Patients and Improve the Accuracy of Provider Directory Information.
- Centers for Medicare & Medicaid Services. Provider Directory API.
- Centers for Medicare & Medicaid Services. Medicare Plan Finder MA Provider Directory Technical Guide.
- Centers for Medicare & Medicaid Services. National Provider Directory.
Run a pilot on a real workflow.
Bring a representative batch, define the output schema, and validate ROI with your payer mix in 30 to 90 days.

