Credentialing data integrity: what the CAQH database gets wrong about providers
CAQH holds credentialing data on more than 1.6 million providers, yet health plans routinely find that profiles are incomplete, outdated, or contradicted by primary sources. The database was designed to reduce paperwork, not to guarantee data integrity. That gap costs the credentialing system billions in rework, delays, and downstream errors.
CAQH stores credentialing data on more than 1.6 million healthcare providers across the United States. Every major health plan touches it. Most credentialing workflows start there. And the data is wrong more often than anyone in the industry wants to admit.
The problem is not that CAQH exists. Centralizing provider data was a necessary step. The problem is that the industry treats CAQH as a source of truth when it was designed to be a source of convenience. Those are not the same thing, and the difference shows up in every credentialing audit, network directory error, and provider enrollment delay that health plans absorb every quarter.
What is the CAQH database?
CAQH stands for the Council for Affordable Quality Health Care. Its Provider Data Portal, formerly known as CAQH ProView, is a centralized online repository where healthcare providers enter and maintain their professional, educational, and practice information. Health plans, hospitals, and other organizations pull from this portal during credentialing, re-credentialing, and provider directory updates.
The premise is simple: instead of filling out dozens of separate applications for each payer, a provider fills out one profile. Participating organizations then access that profile to verify credentials, check malpractice history, confirm DEA registrations, and validate board certifications.
Over 1.4 million providers actively use the portal. More than 1,000 health plans, hospitals, and managed care organizations participate. CAQH estimates the system saves the industry $2.4 billion annually in administrative costs.
But cost savings and data integrity are different metrics. CAQH optimized for the first. Nobody adequately owns the second.
What insurance companies use CAQH for credentialing?
Nearly every major commercial payer in the U.S. uses CAQH. UnitedHealthcare, Aetna, Cigna, Humana, Anthem (Elevance Health), and most Blue Cross Blue Shield affiliates pull credentialing data from the portal. Medicaid managed care organizations in most states participate. Medicare Advantage plans rely on it for initial and re-credentialing cycles.
CAQH is also used by credentialing verification organizations (CVOs) that handle outsourced credentialing for smaller health plans and hospital systems. This means the data does not just affect one payer; it cascades across the entire network participation chain.
When a CAQH profile contains an error, that error propagates to every organization that pulls from it. One wrong address, one expired attestation, one missing specialty code can trigger denials, directory inaccuracies, and compliance failures across multiple payers simultaneously.
How often does the CAQH database require a provider to update?
CAQH requires providers to re-attest their profile data every 120 days. If a provider does not complete re-attestation within that window, their profile status changes and participating organizations may lose access to the data.
This 120-day cycle is one of the most cited pain points in provider credentialing. Here is why it fails as a data integrity mechanism:
First, re-attestation is self-reported. The provider clicks through screens confirming that existing data is still accurate. There is no independent verification at the point of attestation. A provider can attest to data that has already changed without knowing it, or without caring enough to update it.
Second, 120 days is a long time. A provider can change practice locations, lose board certification, face a malpractice action, or let a DEA registration lapse within that window. The data is stale by design.
Third, many providers treat re-attestation as an administrative chore. They click through without reviewing each field. Studies from MGMA and AHLA have documented that practice managers frequently flag CAQH re-attestation as a low-priority task that gets done in bulk at the deadline, not carefully reviewed.
What is CAQH provider data for?
CAQH provider data serves three primary functions: credentialing, re-credentialing, and provider directory maintenance. Health plans use it to verify that a provider meets network participation requirements. Hospitals use it during medical staff privileging. State Medicaid programs reference it during enrollment.
But the data has expanded far beyond its original scope. Payers now use CAQH data to populate member-facing directories, feed network adequacy calculations, support claims adjudication logic, and inform value-based contracting decisions. CMS uses provider directory accuracy as a compliance metric under the CRUSH (Comprehensive Review and Update of Supplemental Healthcare) framework.
This scope creep is the core of the integrity problem. Data that was entered by a provider for the purpose of credentialing is now being used to make network adequacy determinations, calculate geographic access standards, and populate the directories that patients use to find in-network care. Each downstream use requires a higher level of data trust than CAQH was built to deliver.
Key statistics
The numbers tell the story of a system designed for efficiency, not accuracy.
The five integrity failures CAQH cannot fix
The current ranking content focuses on operational issues: expired attestations, incomplete profiles, changing requirements. Those are symptoms. The underlying integrity failures are structural.
1. Self-attestation is not verification
CAQH relies on providers to enter and confirm their own data. This is a data collection mechanism, not a data verification mechanism. Primary source verification happens downstream, performed by individual health plans or their CVOs. But many organizations treat the CAQH profile as if it has already been verified, simply because it exists in a centralized system.
The distinction matters. A provider's NPI, license number, DEA registration, and board certification status all need to be verified against the issuing authority. CAQH does not do this. It stores what the provider typed.
2. No provenance chain
When a health plan pulls data from CAQH, it gets a snapshot. It does not get a record of when each field was last changed, who changed it, or what the previous value was. There is no audit trail that follows the data from entry through attestation through consumption.
This is a provenance failure. The DTI framework assigns 25% of its total weight to Provenance because knowing where data came from and how it got to its current state is the single most important dimension of data trust. CAQH provides none of this.
3. No concordance checking
Concordance means that a data point is consistent across multiple independent sources. If CAQH says a provider practices at 123 Main Street, and the state licensing board says 456 Oak Avenue, and the NPI registry says 789 Elm Boulevard, there is a concordance failure.
CAQH does not cross-reference its data against NPPES, state licensing databases, DEA records, or hospital privileging files. Each health plan is left to perform its own concordance checks, and most do so incompletely.
4. Recency decay between attestation cycles
The 120-day re-attestation cycle creates a predictable decay pattern. On day 1 after attestation, the data is as fresh as it will ever be. By day 119, it could be four months out of date. Health plans that pull data on day 100 of a cycle are making credentialing decisions on information that may no longer reflect reality.
The DTI framework weights Recency at 15%. For credentialing data, where a provider's status can change on any given day due to licensure actions, malpractice events, or practice relocations, recency should arguably carry even more weight.
5. No downstream integrity tracking
Once data leaves CAQH and enters a health plan's credentialing system, there is no mechanism to track whether that data was used correctly, whether it was overridden by a human, or whether it was combined with other data in a way that introduced errors. The chain of custody ends at the point of download.
This means that even if CAQH data were perfect at the moment of export, the health plan has no way to prove that the data in its credentialing files matches what CAQH provided. Every manual touch, every system migration, every spreadsheet export introduces entropy.
What NCQA and CMS actually require
NCQA credentialing standards (CR 1 through CR 8) require health plans to verify provider credentials through primary sources. This includes medical education, residency training, board certification, state licensure, DEA/CDS registration, malpractice history, and work history. NCQA explicitly states that CAQH data alone does not satisfy PSV requirements.
CMS has increased enforcement around provider directory accuracy through the No Surprises Act, the Transparency in Coverage rule, and the CRUSH initiative. Plans must verify that directory information, including addresses, phone numbers, accepting-new-patients status, and specialty designations, is accurate. CAQH-sourced data that has not been independently verified does not meet this standard.
The gap between what CAQH provides and what regulators require is where credentialing failures live. Health plans that treat CAQH as a verified source rather than a starting point are building compliance risk into their operations.
What trust-scored provider data looks like
A trust-scored credentialing record is fundamentally different from a CAQH profile. It includes:
Provenance metadata. Every field carries a record of its source, the date it was sourced, and the method of verification. A license number is not just a number; it is a number verified against the state licensing board on a specific date via a specific method.
Concordance scoring. Each data point is cross-referenced against independent sources. Address data is checked against NPPES, state boards, and claims data. Specialty data is checked against board certification records and hospital privileging files. Discrepancies are flagged with severity scores.
Recency timestamps. Every field has a last-verified date, not just a last-attested date. The difference is critical. Attestation means the provider said it was correct. Verification means an independent source confirmed it.
Validation status. Each element is scored for whether it has been validated through primary source verification, secondary source verification, or self-report only. A DTI score below a defined threshold triggers re-verification before the data can be used for credentialing decisions.
Stability tracking. Fields that change frequently, such as practice addresses for locum tenens providers, are flagged with volatility scores. Stable data gets a higher trust score. Volatile data requires more frequent verification.
The cost of getting this wrong
Credentialing data errors are not abstract. They have measurable financial and operational consequences.
A provider whose CAQH profile lists the wrong specialty code may be credentialed for services they do not provide, or excluded from panels they should be on. Both outcomes cost money. The first creates claims exposure. The second creates network gaps.
A provider whose address is wrong in CAQH feeds that error into member-facing directories. When a patient calls a number that is disconnected or drives to an office that has moved, that is a CMS compliance violation and a patient experience failure.
CMS fines for provider directory inaccuracies have increased under the CRUSH framework. Plans that cannot demonstrate data integrity in their credentialing files face both financial penalties and corrective action plans that consume operational resources for months.
The American Medical Association estimates that providers spend an average of 15.6 hours per week on administrative tasks, with credentialing paperwork representing a meaningful share. When CAQH data errors force re-credentialing cycles, both provider and plan resources are wasted.
Why the CAQH lookup by NPI is not enough
Many practice managers and credentialing specialists use the CAQH lookup by NPI number as a quick check to see if a provider has an active profile. This lookup confirms that a profile exists and that attestation is current. It does not confirm that the data in the profile is accurate.
Existence is not accuracy. Currency is not validity. An active CAQH profile with a current attestation can still contain wrong addresses, outdated board certifications, missing malpractice disclosures, and incorrect taxonomy codes. The NPI lookup gives a false sense of confidence that the data has been vetted.
Health plans need to move from asking "does this provider have a CAQH profile?" to asking "what is the trust score on this provider's credentialing data?" The first question is binary. The second question is quantitative and actionable.
From data collection to data trust
CAQH solved the data collection problem. It did not solve the data trust problem. The industry built its credentialing infrastructure on the assumption that centralized collection equals verified truth. That assumption has never been correct, and the regulatory environment is now catching up.
CMS CRUSH enforcement, NCQA 2025-2026 standards updates, and state-level provider directory accuracy mandates are all converging on the same requirement: health plans must be able to demonstrate that their provider data is not just collected, but verified, current, and traceable. CAQH alone cannot meet that standard. It was never designed to.
The path forward is not to replace CAQH. It is to score every record that comes out of it before that record enters a credentialing decision. Provenance, recency, concordance, validation: these are not optional quality metrics. They are the dimensions that determine whether a credentialing file will survive an audit.
The DTI Engine scores every provider record for provenance, recency, and concordance, the three dimensions that break credentialing audits. If your team is facing NCQA or CMS compliance pressure on provider data integrity, talk to the SuperTruth commercial team. Schedule a conversation or call (215) 918-4140.
Further reading:

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
Provider data that holds up under NCQA audit.
DTI scoring for credentialing, CMS CRUSH, and No Surprises Act.