Why Primary Source Verification Is Not Enough: The Case for Trust-Scored Provider Data
Primary source verification answers one question: is this license currently active? It does not answer the question that matters for AI-driven health plans: how much should any downstream system trust this record, for this specific use case, right now?
Primary source verification is table stakes. It has been table stakes for twenty years.
Verifying that a physician's license is active, that their board certification is current, that their DEA registration has not lapsed: this is the minimum required to field a compliant provider network. Every credentialing platform in the market does it. The NCQA requires it. CMS audits it.
What primary source verification does not do is answer the question that matters for the next generation of health plan operations: how much should any downstream system trust this record, for this specific use case, right now?
That is a different question. And it does not have a binary answer.
The limitation of verified-or-not
Consider a provider record that has passed primary source verification. The license is active. The board certification is confirmed. The CAQH profile is complete.
Now consider three uses of that record:
Each of these uses requires a different level of data trust. The directory needs recency above all — a provider who moved out of network last month but whose record has not been updated is a compliance liability. The AI model needs concordance — if four sources agree on the same specialty but one outlier disagrees, the model needs to know. The regulatory submission needs provenance — a documented, auditable chain of custody from the primary source to the submitted record.
Primary source verification gives you verified-or-not. It does not give you the dimensional breakdown that downstream uses require.
What a trust score adds
The Data Trust Index applies eight dimensions to every provider data record:
Provenance (25%): Where did this record originate? CAQH, state licensing board, NPI registry, NCQA-certified CVO, or an unstandardized roster upload from a hospital system that last updated in 2023? The source pedigree matters enormously for how much weight a downstream system should assign.
Recency (15%): How current is this record? A license verification from yesterday carries different weight than one from eleven months ago, even if both say active. Provider data has modality-specific decay rates — specialty affiliations change slowly, but hospital privileges can change in days. The DTI applies decay functions by data type, not a uniform staleness threshold.
Concordance (10%): Do independent sources agree? When the CAQH profile, the state licensing board, and the Medicare enrollment all say the same thing about a provider's specialty, that concordance elevates the trust score. When they disagree, the discordance is a flag that primary source verification alone would miss.
Consent (20%): Is this provider data authorized for this specific use? A provider who authorized their data for directory publication did not necessarily authorize it for AI training or analytics. ConsentOS tracks which use cases are permitted and propagates revocation in real time.
The remaining four dimensions — Quality, Validation, Breadth, and Stability — address completeness, evidence base, dimensional richness, and variance. Together they produce a single score from 0 to 100 that travels with the record permanently.
The regulatory context
This is not a theoretical problem. CMS CRUSH requirements demand that health plans demonstrate not just that their provider data is accurate but that their data management processes are auditable and defensible. NCQA's 2025-2026 updated credentialing standards tighten primary source verification timelines and monitoring requirements. The No Surprises Act creates liability for directory inaccuracies.
Each of these requirements is fundamentally a data trust question. They are asking: how much do you actually know about the quality of your provider data, and can you prove it?
Binary verification provides a binary answer. A trust score provides a defensible, dimensional answer with an audit trail.
The integration model
SuperTruth does not replace primary source verification platforms. IntegrityNet ingests from the same sources: NCQA-certified CVOs, state licensing boards, NPI registry, CAQH, Medicare enrollment. The DTI Engine then scores what comes in across eight dimensions. ConsentOS governs what the scored data is authorized to be used for. The Data Reservoir distributes scored, consent-governed records via API to health plan directories, AI pipelines, and regulatory reporting systems.
The output is a provider record that carries its trust score permanently — not just a flag saying it was verified on a given date, but a scored, dimensional, auditable trust signal that any downstream system can condition on.
For health plans building AI models, that is the difference between a training dataset and a trusted training dataset.
Further reading: See our approach for health plans To discuss what trust-scored provider data looks like for your network, reach Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
Provider data that holds up under NCQA audit.
DTI scoring for credentialing, CMS CRUSH, and No Surprises Act.