Research / The Verification Gap

Market brief · July 2026

The Verification Gap

Why provider credentialing stopped being an administrative function in 2025, and what that changes.

Reid Garrett, Founder and CEO, Bip Identity Inc.

The argument in one sentence

Credentialing has shifted from a periodic event to a continuously monitored, continuously provable state, and the tooling nearly every healthcare organization uses was designed for the first job, not the second.

Between July 2025 and January 2027, the rules governing how healthcare organizations verify and maintain provider identity are undergoing the most significant revision in more than a decade. The change is not that the rules got stricter. The change is structural.

That distinction sounds academic. It is not. It invalidates the underlying design of how most facilities, groups and health systems manage provider data today. A process built to produce a complete file every three years cannot produce a defensible record of what was true every thirty days. Spreadsheets, shared drives and document repositories were built for the first job. The market is now being graded on the second.

A folder of PDFs proves a moment in time. What the new standard requires is a record with time in it: who verified what, when, from which source, and what changed since. Most organizations have not re-tooled for that. They have added labor to an unchanged process, which does not close an evidentiary gap.

This brief lays out six forces converging on that gap, with sources. It is not a product pitch. The purpose is to establish the size and the timing of the problem, because the timing is the part most organizations have not yet absorbed.

Executive summary

If you read nothing else, read these five.

The thesis in full, in about a screen. The rest of the brief is the evidence, with sources, for a reader who wants to check the work.

  1. The change is structural, not merely stricter. Between July 2025 and January 2027, credentialing shifted from a periodic event to a continuously provable state — and the spreadsheets, shared drives and document repositories nearly every organization runs were built for the first job, not the second.
  2. Three regulatory clocks are already running. NCQA’s July 2025 standards rewrite, the CMS Medicare Advantage directory rule (CMS-4208-F2), and 2026 CMS enrollment enforcement each carry a date a specific person inside a facility already owns. The urgency does not have to be manufactured; it has to be surfaced.
  3. Identity was always the unverified layer. The NPI is an identifier, not an authenticator — it never bound a credential to a verified human being. From the 2025 federal fraud takedown to Operation Nightingale’s 7,600 fraudulent nursing diplomas, credentials built on false foundations verify cleanly.
  4. The cost is no longer only delay. Delay is budgeted; silent lapse is not. By the time a lapse surfaces through denials, the window to refile has often closed, which makes the loss unrecoverable rather than merely late.
  5. No existing category closes the gap. Document repositories, workflow tools, CVOs, payer platforms and directory tools each solve a piece of the old problem. A continuous, provable, portable record of provider identity — defensible under audit and discovery — is what none of them produces.

The three clocks already running

Three forcing functions, and each one carries a date.

Three separate regulatory timelines are converging inside an eighteen month window, each with an effective date already on the calendar.

Regulatory forcing functions, their effective dates, and what each one changes
Forcing functionEffectiveWhat it changes
NCQA standards rewriteJuly 1, 2025Shorter verification windows, monthly monitoring, evidence of information integrity. 2026 survey cycles are already producing failures.
CMS Medicare Advantage directory rule (CMS-4208-F2)Jan 1, 2026, then PY 2027A 30-day update requirement and an annual accuracy attestation now. Direct submission to CMS and public visibility on Medicare Plan Finder in 2027.
CMS enrollment enforcement2026PECOS treated as source of truth, 30-day reporting windows, cross-program termination cascades across state lines.

Sources: NCQA, 2025 credentialing standards revision · CMS-4208-F2, finalized September 19, 2025 (Federal Register) · CMS, Medicare provider enrollment and reporting requirements.

Six forces

What is actually converging, one force at a time.

01

The regulatory clock

Three separate regulatory timelines are converging inside an eighteen month window, and each carries a date that a specific person inside a facility already owns. The detail sits in the table above.

The point

Every one of these forcing functions is dated, and the date belongs to the organization, not to a vendor. Urgency does not have to be manufactured. It has to be surfaced.

  • The three dates most facilities can name if asked: next accreditation survey or delegation audit, next PECOS revalidation, next provider start date or site opening.
  • The cross-program termination rule is the least discussed and the most dangerous. It means an organization can be billing under an excluded provider because of an action taken in a state it does not operate in.
  • Directory accuracy becomes publicly visible in 2027 via Medicare Plan Finder, which converts a compliance problem into a competitive and reputational one.
02

The identity problem is no longer theoretical

The premise underneath all credentialing is that the person is who they claim to be and holds what they claim to hold.

Federal enforcement over the last three years has repeatedly demonstrated that this premise fails, at scale, and that the failure is not detected by the systems designed to catch it.

The Department of Justice’s 2025 National Health Care Fraud Takedown — the largest in US history — charged 324 defendants, including 96 doctors, nurse practitioners, pharmacists and other licensed medical professionals, across 50 federal districts, in schemes involving more than $14.6 billion in alleged fraud. Identity misuse runs directly through the case list.

  • Impersonation of a licensed physician — using a real provider’s name, NPI and state license number to sign federal medical certifications.
  • Multi-year schemes to impersonate a licensed registered nurse across several healthcare agencies.
  • Aggravated identity theft using advanced practice nurses’ NPI numbers without their knowledge.

Separately, Operation Nightingale — the HHS Office of Inspector General’s investigation into fraudulent nursing diplomas sold through several Florida schools — accounted for more than 7,600 fraudulent diplomas and transcripts. Twelve further defendants were charged in the September 2025 Phase II, on top of the twenty-five charged in the original action, and state boards continue to issue revocations to nurses who already passed the NCLEX and obtained licensure.

The point

Employers who hired those nurses passed a credentialing check. The license was real. The education record underneath it was not. Verification chains inherit trust, so a credential built on a fraudulent foundation verifies cleanly.

  • The NPI is an identifier, not an authenticator. It was never designed to bind a credential to a verified human being.
  • DOJ and CMS have both shifted toward pre-payment, data-driven detection, which compresses the time between anomalous data and enforcement action.
  • The exposure for a facility is not only the fraudulent provider. It is every claim submitted under that provider, every certification they signed, and every patient they touched.
03

The financial cost is already quantified

The revenue consequence of credentialing delay is well documented and no longer contested.

$1K–$5K

Lost per provider, per day, from payer enrollment delay. Reported by 69% of organizations.

2026 State of Payer Enrollment survey
78%

Of active lapses go undetected for 60 days or longer.

Medical Billers and Coders · analysis across 190 specialty practices

One in five hospitals able to quantify the impact report losses exceeding $1 million a year. Delay of that kind is at least visible while it happens.

The point

Delay is a known and budgeted cost. Silent lapse is an unknown and unbudgeted one, and it is the larger risk. By the time a lapse surfaces through denials, timely filing limits have often expired, making the revenue unrecoverable rather than merely delayed.

  • An analysis across 190 specialty practices found that 61% carry at least one active credentialing lapse at any given moment.
  • Multi-location enrollment updates fail at a rate roughly 34% higher than single-location updates.
  • For any organization adding sites, acquiring practices or expanding service lines, growth itself increases the probability of an undetected lapse.
04

The data itself is fragmented by design

The reason this is hard is not that credentialing teams are careless.

It is that no organization holds a complete, current picture of any provider, because provider data is distributed across parties who each maintain a partial and separately maintained copy.

$2.76B

Annual cost of directory maintenance to physician practices — close to $1,000 per practice per month, and about one staff day per week.

CAQH · The Hidden Causes of Inaccurate Provider Directories
~20

Health plan contracts a typical practice responds to, each through a different platform, format and schedule. Large practices carry more than 30.

CAQH
540

Average days that roughly 40% of directory inaccuracies persist, despite federal mandates requiring updates within 90 days.

American Journal of Managed Care · Persistence of Provider Directory Inaccuracies After the No Surprises Act
The point

Every party holds a partial truth. No party holds the record. An accuracy standard applied to a system with no authoritative source is a standard that cannot be reliably met by effort alone.

  • Providers re-enter the same information dozens of times per year, which is itself a source of error and staleness.
  • Payers report the structural failure sits in roster ingestion: files arriving in varying formats and timing, where without automated normalization and NPI matching, errors compound rather than correct.
05

The workforce stopped being static

The periodic model assumed a stable medical staff. That assumption is gone.

$9.6B

Estimated size of the US locum tenens market in 2025, with an estimated 56,000 physicians working locum assignments.

Staffing Industry Analysts
80%

Of healthcare organizations plan to maintain or increase locum usage. Permanent physician recruitment now averages roughly 300 days.

AMN Healthcare
42

States, plus DC and Guam, in the Interstate Medical Licensure Compact as of 2026 — accelerating multi-state licensure and therefore multi-state credentialing obligations.

Interstate Medical Licensure Compact · membership as of 2026
The point

The rules tightened at exactly the moment the workforce became more fluid. That collision is what makes the new standard unmanageable through added labor.

  • The unit of credentialing is no longer a provider joining an organization. It is a provider moving continuously among organizations, states and payers.
  • Every move regenerates the entire verification burden from zero, for every party involved.
  • Higher mobility plus higher turnover means the average file is stale more often, for longer, across more organizations simultaneously.
06

The liability layer

Underneath the compliance and revenue arguments sits the exposure that reaches the board.

Negligent credentialing is a recognized theory of direct institutional liability in a substantial number of states, distinct from vicarious liability for a physician’s conduct. Courts have found organizations liable on two grounds: the organization had an adequate process and failed to follow it, or it followed its process and the process itself was inadequate. Both are decided years after the fact, on the evidence in the file.

In a recent action described by Brewster and De Angelis involving a physician alleged to have lacked proof of current clinical competence for a specific procedure, necessary documents were found missing during discovery.

The point

In litigation, the credentialing system is not a workflow tool. It is the evidence. An organization that cannot reconstruct what it knew, and when it knew it, is defending a case with an incomplete record.

  • Classification does not insulate the organization. Courts have extended the duty to independent contractors granted privileges.
  • Peer review privilege is narrower than commonly assumed. Where a claim is brought directly against the entity, credentialing and recredentialing records can become discoverable.

07 · What follows structurally

Every existing category solves a piece. None solves the whole.

Put the seven forces together and a specific conclusion falls out.

The conclusion

The market is being asked to produce something it structurally cannot produce with current tooling: a continuous, provable, portable record of provider identity and credential state, maintained across organizational boundaries, defensible under audit and under discovery, at a moment when the workforce is more mobile and the data is more fragmented than at any prior point.

Each is a rational response to the old rule, which is why none of them resolves the new one.

Existing categories of credentialing tooling, what each does, and what each leaves open
CategoryWhat it doesWhat it leaves open
Document repositoriesStore credential artifactsNo provenance. A file, not a record.
Credentialing workflow toolsAccelerate the existing processChanges the speed, not the artifact produced.
CVOsVerify at a point in timeDelivers a result, not a continuously maintained state.
Payer-side platformsOptimize the plan’s view of its networkSolves for the plan, not the facility or the provider.
Directory toolsReconcile listingsTreats a downstream symptom of upstream fragmentation.

The gap is not speed. Speed was the old problem.

What the market needs and cannot buy

Four things, none of which is turnaround time.

Provenance
A record where every change carries its source and timestamp, so state can be reconstructed at any point in the past rather than only observed in the present.
Identity binding
Verification bound to a real, authenticated human being, not to an identifier that can be borrowed, inherited or stolen.
Provider-held attestation
The person with the most accurate information and the strongest incentive to keep it current is the one maintaining it.
Portability
A credential verified once does not need to be reconstructed from scratch by every subsequent party.

That last point carries the largest downstream consequence. A record that travels with the provider, rather than being rebuilt inside every organization, is the only architecture that reduces total system cost rather than relocating it. It is also the only architecture that gets more valuable as more parties adopt it.

The readiness check

Seven questions, and the difficulty is the finding.

Diagnostic, not rhetorical. Most organizations cannot answer them quickly, and how hard they are to answer is itself the measurement.

How would you learn that a provider in your organization was excluded or terminated by a program in a state you do not operate in?

08 · Where Bip fits

A platform problem, not a tooling problem.

Bip was built from an identity and fraud background rather than a credentialing services background. The premise is that provider credentialing is an identity and trust problem wearing an administrative workflow costume, and that the workflow cannot be fixed durably without fixing the trust layer underneath it.

Provenance by default
Every write to a provider record produces an append-only, tamper-evident event with a source and a timestamp. The audit artifact is a byproduct of normal use rather than something assembled retroactively under pressure.
Provider-held, provider-attested data
Providers maintain and periodically attest to their own credential record, producing a timestamped attestation trail. That is the only way accuracy scales with a mobile workforce.
Portability across organizations
Bip is built so the credential record binds to the provider and is shared under their control with the facilities that need it, rather than reconstructed from zero inside each organization’s silo.
The bottom line

A facility does not simply move faster. It ends the year holding something it did not have before: a defensible, reconstructible record of what it knew about every provider, and when. That is the actual demand the 2025 and 2026 rule changes created. Speed was always a nice-to-have. Proof is now a requirement with a date attached.

Request access

Sources

Everything this brief rests on.

Regulatory and standards

  • NCQA, 2025 Credentialing and Recredentialing standards revision — ncqa.org
  • CMS-4208-F2, Medicare Advantage provider directory final rule — federalregister.gov
  • CMS, Medicare provider enrollment and PECOS requirements — cms.gov

Fraud and enforcement

  • DOJ, 2025 National Health Care Fraud Takedown — justice.gov/opa
  • HHS-OIG, Operation Nightingale — oig.hhs.gov
  • DOJ, Operation Nightingale Phase II charges — justice.gov/usao-sdfl

Financial impact

  • 2026 State of Payer Enrollment survey
  • Medical Billers and Coders, credentialing lapse analysis across 190 specialty practices — medicalbillersandcoders.com

Data fragmentation

  • CAQH, The Hidden Causes of Inaccurate Provider Directories — caqh.org
  • American Journal of Managed Care, Persistence of Provider Directory Inaccuracies After the No Surprises Act — ajmc.com
  • Health Affairs, The Role of Administrative Waste in Excess US Health Spending — healthaffairs.org

Workforce

  • Staffing Industry Analysts, US locum tenens market — staffingindustry.com
  • AMN Healthcare, locum tenens trends — amnhealthcare.com
  • Interstate Medical Licensure Compact, member states — imlcc.org

Liability

  • Brewster and De Angelis, Hospital Negligent Credentialing — brewsterlaw.com
  • Illinois Association of Defense Trial Counsel, Institutional Negligence and Negligent Credentialing — iadtc.org

Market brief · July 2026 · Reid Garrett, Founder and CEO, Bip Identity Inc.