Provider directory accuracy: the 50 percent error rate problem in health plan data
CMS audits consistently find error rates approaching 50 percent in Medicare Advantage provider directories. That means half the records a member sees when searching for a doctor may list the wrong phone number, wrong address, or wrong acceptance status. The problem is not a technology gap. It is a data trust gap, and fixing it requires scoring every provider record before it reaches a directory.
CMS found that nearly half of all provider directory entries in Medicare Advantage plans contained at least one inaccuracy. That was not a one-time finding. The agency has repeated similar audits across multiple years, and the numbers barely move. The 50 percent error rate is not a bug in the system. It is the system.
This is a problem that costs patients time, money, and sometimes their health. A member calls a listed provider only to learn the practice closed two years ago. A patient drives 40 minutes to an office that no longer accepts their plan. A parent tries to schedule a pediatric specialist visit and discovers the phone number connects to a fax machine. These are not edge cases. They are the median experience.
Key statistics
Why directory errors persist at 50 percent
The root cause is structural. Provider data changes constantly. Physicians move offices, join new groups, drop insurance panels, and update their hours. The average physician changes something about their practice profile every 18 to 24 months. Many change something every few months.
Health plans collect this data through attestation. A provider fills out a form, a plan loads it into a database, and the directory reflects whatever was submitted. There is no continuous verification. There is no real-time reconciliation. The data is static from the moment it enters the system.
By the time a member searches a directory, the underlying record may be three months old, six months old, or older. A record that was accurate on the day it was entered becomes inaccurate the moment the provider changes anything, and nobody tells the plan.
How quality of healthcare data is defined in terms of accuracy, completeness, and relevance
Data quality in healthcare is measured across multiple dimensions, not just whether a single field is correct. Accuracy means a record reflects the real world: the address in the directory matches the address where the provider actually practices. Completeness means every required field is populated: specialty, phone number, office hours, languages spoken, accepting-new-patients status. Relevance means the data is current and applicable to the user's need: a directory entry for a provider who retired last year is accurate in a historical sense but irrelevant to a member looking for care today.
The DTI framework formalizes this. SuperTruth scores every record from 0 to 100 across eight dimensions: Provenance (25%), Consent (20%), Recency (15%), Quality (10%), Concordance (10%), Validation (10%), Breadth (5%), and Stability (5%). For provider directory data, the dimensions that matter most are Recency (how recently was this record verified against reality), Concordance (does this record agree with other authoritative sources), and Validation (has a primary source confirmed this data).
A directory entry that was last attested 14 months ago, contradicts the provider's listing on their own practice website, and has never been cross-referenced against NPPES or CAQH data would score poorly on all three dimensions. That record should not appear in a member-facing directory. But under current processes, it does.
What the regulatory landscape actually requires
CMS has escalated enforcement. The REAL Health Providers Act specifically targets the directory accuracy problem in Medicare Advantage. The No Surprises Act includes provisions requiring accurate provider directories to protect patients from surprise billing when they rely on directory information to select in-network providers.
State regulators have added their own requirements. California, New York, and Illinois have passed laws mandating regular directory audits with specific accuracy thresholds. Some states require quarterly verification of provider data. Others require plans to remove or flag listings that have not been verified within 90 days.
CMS's CRUSH (Compliance Review through Utilization Statistics and Highlights) framework adds another layer. Plans that fail directory accuracy audits face corrective action plans, civil monetary penalties, and potential enrollment suspensions. The financial exposure is real: a plan with 500,000 members and a 50 percent error rate across its directory faces regulatory risk on hundreds of thousands of individual listings.
But regulation alone has not fixed the problem. Plans have been subject to directory accuracy requirements for years, and the error rate has not meaningfully declined. The issue is not willingness to comply. It is the absence of infrastructure to maintain accuracy at scale.
What the three criteria for evaluating healthcare system effectiveness reveal about directories
Healthcare systems are commonly evaluated on three criteria: access, quality, and cost. Provider directory accuracy touches all three.
Access: a directory is the front door to the health system for insured members. When half the entries are wrong, access is impaired at the most basic level. A member who cannot reach a listed provider effectively has no access to that provider, regardless of what their benefits say.
Quality: directory errors create downstream quality failures. A patient who is bounced between disconnected phone numbers and closed offices delays care. Delayed care leads to worse outcomes, higher acuity encounters, and emergency department utilization that could have been avoided.
Cost: every failed appointment attempt, every misdirected referral, every surprise out-of-network bill traces back to a directory error. The administrative cost of processing member complaints about directory inaccuracies alone runs into millions of dollars annually for large plans. The clinical cost of delayed or forgone care is harder to quantify but likely larger.
The credentialing data connection
Directory errors do not originate in the directory. They originate upstream, in credentialing databases and enrollment systems. When a provider's credentialing record contains an outdated address, that address propagates into the directory. When CAQH data has not been updated, plans that rely on CAQH for directory population inherit the error.
This is the same problem we documented in Credentialing data integrity: what the CAQH database gets wrong about providers. The CAQH ProView database contains records for over 1.7 million providers, but the accuracy of those records depends entirely on providers voluntarily updating their profiles. Many do not.
The propagation chain works like this: a provider fails to update CAQH, the plan ingests the stale CAQH record during its quarterly credentialing cycle, the credentialing system feeds the directory, and the member sees an outdated listing. Every link in the chain assumes the previous link is accurate. Nobody verifies.
Why attestation-based models fail
The current model relies on providers to attest that their information is correct, typically once or twice per year. This model has three fatal flaws.
First, providers have no incentive to update their information proactively. Their reimbursement does not depend on directory accuracy. Their patients find them through referrals, not directories. The administrative burden of updating multiple plans' portals is real, and the benefit to the provider is zero.
Second, annual or semi-annual attestation cycles guarantee staleness. A provider who moves offices in February and attests in December leaves a 10-month gap during which the directory is wrong. Multiply that by tens of thousands of providers per plan, and the aggregate error rate is predictable.
Third, attestation captures only what the provider reports. It does not cross-reference against external sources. A provider might attest that they accept new patients while their front office is actually turning away new patients due to capacity. The attestation is technically what the provider submitted. It is not necessarily true.
What a scored approach looks like
The alternative to attestation is continuous scoring. Instead of asking "Did the provider say this is correct?" the question becomes "How much evidence supports the claim that this record is accurate right now?"
This is what DTI does for provider records. Every field in a provider directory entry can be scored against multiple dimensions. The address can be validated against NPPES, CAQH, the provider's own website, claims data showing where services were rendered, and third-party location databases. The phone number can be verified through automated calling or cross-referencing against public listings. The accepting-new-patients status can be tested against appointment availability data or call center records.
A record that scores high on Recency (verified within 30 days), Concordance (matches across three or more independent sources), and Validation (confirmed by primary source) can be trusted. A record that scores low on any of these dimensions gets flagged, investigated, or removed from member-facing display.
This is not a one-time audit. It is continuous scoring. The DTI Engine processes records as they flow through the system, updating scores as new evidence arrives. When a provider's claims data shows they are billing from a new address, the Concordance score for the old address drops. When the NPPES record updates, the Validation score adjusts. The directory reflects reality because the scoring reflects reality.
The downstream AI problem
Directory data does not just serve members looking for a doctor. It feeds AI systems. Network adequacy algorithms, care navigation tools, appointment scheduling bots, and referral routing engines all consume provider directory data. When that data is 50 percent wrong, every system built on top of it inherits the error.
A care navigation AI that recommends a provider based on directory data sends a patient to a ghost listing. A network adequacy model that counts an inactive provider as available inflates the plan's compliance metrics. A referral routing system that directs patients to providers who are not accepting new patients creates friction that the patient experiences as a system failure.
As we described in Why AI models trained on unscored health data will fail in production, the accuracy of any AI output is bounded by the accuracy of its input data. A directory with a 50 percent error rate means every AI system consuming that directory starts at 50 percent accuracy, before the model itself introduces any additional error.
What health plans need to do differently
The path forward has three components.
First, replace annual attestation with continuous verification. This means integrating multiple data sources, including claims, NPPES, CAQH, state licensing boards, practice management systems, and third-party databases, into a reconciliation engine that flags discrepancies in near real time.
Second, score every record before it reaches the directory. A record that cannot meet a minimum trust threshold should not be displayed to members. This is the same principle that applies to clinical data: if you would not let a model train on unverified data, you should not let a member act on an unverified directory listing.
Third, build accountability into the data supply chain. Every record in a directory should carry provenance metadata: where did this data come from, when was it last verified, and what sources support it. This is what Explainable data provenance requires. When a member or a regulator asks why a listing was wrong, the plan should be able to show exactly what data it had, when it had it, and what scoring led to the decision to display it.
The cost of inaction
The financial exposure is significant. CMS penalties for directory inaccuracies can reach tens of thousands of dollars per violation. State regulators are adding their own enforcement mechanisms. The REAL Health Providers Act creates additional federal liability.
But the real cost is member trust. A member who cannot find an accurate provider listing through their plan's directory loses confidence in the plan. They call the plan's customer service line, driving up operational costs. They seek care out of network, driving up claims costs. They complain to regulators, driving up compliance costs. Or they delay care entirely, driving up clinical costs when they eventually present with a more serious condition.
The 50 percent error rate is not just a data quality problem. It is a trust problem. And trust problems compound.
From directory data to data trust infrastructure
The provider directory accuracy problem is a microcosm of the broader health data trust challenge. Every system in healthcare, from claims processing to clinical AI, depends on data that nobody has verified. The directory is just the most visible failure because members interact with it directly.
Solving it requires the same infrastructure that solves the broader problem: a scoring framework that evaluates every record across multiple dimensions, a reconciliation engine that flags discrepancies across sources, and an audit trail that proves what was known and when.
The DTI Engine scores every provider record for provenance, recency, and concordance, the three dimensions that break credentialing audits. If your team is facing NCQA or CMS compliance pressure, or if you are preparing for CRUSH audits and REAL Health Providers Act requirements, talk to the SuperTruth commercial team. Schedule a conversation or call (215) 918-4140.
Further reading:

Jason Alan Snyder
Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.
About SuperTruth · LinkedIn · Substack · jasonalansnyder.com
See it in practice
Provider data that holds up under NCQA audit.
DTI scoring for credentialing, CMS CRUSH, and No Surprises Act.