10 Provider Data Problems That Quietly Disrupt Health Plan Operations
- Updated on: Aug 13, 2026
- 6 min Read
By
- Published on Aug 13, 2026
A member searches the directory, finds a cardiologist, and calls. The number rings at a dental office two towns over. That call becomes a complaint. The complaint becomes a grievance. Six months later it shows up as an access-to-care finding, and by then nobody can reconstruct which roster file introduced the wrong phone number or when. Somewhere between three and five departments touched that record, and each of them assumed a different team owned it. None of this is exotic. CMS reviewed Medicare Advantage online directories and found that 48.74 percent of listed locations had at least one inaccuracy, with the errors most likely to block access to care showing up at 41.75 percent of locations. Nearly half. That’s the environment provider data management solutions were built for, and the failure rate has been remarkably stable across audit cycles. What follows is not a list of data quality platitudes. It’s ten specific structural problems, and what makes them expensive is where they surface.
Why These Problems Stay Invisible
Provider data has a defect pattern common to any shared asset with no single owner. The error gets created in one department and paid for in another. Network operations loads a roster. Credentialing verifies a subset of fields. Configuration builds the contract. Claims adjudicates against it. Member services fields the call. The directory publishes what it was handed. Each function validates what it needs and passes the rest through untouched, so an error introduced at intake can travel a long way before anyone notices. By the time the cost lands, it lands as a claim rework queue, a grievance trend, or an audit finding, none of which look like a data problem on the surface. They look like a claims problem, a service problem, and a compliance problem.
The Ten Problems
1. No declared source of truth for a shared field
Practice address arrives from the credentialing application, the contracting packet, the delegated group’s monthly roster, and the provider’s own portal update. Four sources, four values, and no rule about which wins. Most plans have an implicit answer, usually “whatever loaded last.” That’s a race condition, not a governance policy. Write the precedence rule down field by field, because the field-level answer varies: the group roster may be right about locations while the provider is right about panel status.
2. Address types collapsed into one field
Billing address, mailing address, credentialing address, and actual practice location are four different things that get flattened into one directory record constantly. This single issue drives a large share of “provider not at this location” findings, and it’s why directory audits catch errors that internal QA never does. Internal QA checks whether the field is populated and formatted. The auditor calls the number and asks if the doctor is there.
3. Phantom locations inherited from group rosters
A twelve-site medical group submits a roster listing every provider at every site. It’s easier for them, and technically each provider is affiliated with the group. Your directory now shows a nephrologist at twelve addresses, eleven of which she has never worked at. Members drive to the wrong one. Network adequacy calculations count twelve access points where there is one. This inflates coverage on paper in exactly the way regulators are now looking for.
4. Panel status nobody owns
“Accepting new patients” changes faster than any other field in the directory and has the weakest ownership. It isn’t in the contract, it isn’t verified at credentialing, and the provider has little incentive to report it. It’s also one of the fields CMS audits by picking up the phone, which makes it one of the highest-frequency inaccuracies in every review round.
5. Specialty and taxonomy drift
The provider self-reports a specialty. The NUCC taxonomy code on the NPI record says something adjacent. Your internal specialty list, built years ago for a different network, maps both to a third value. Members search on your internal taxonomy, adequacy is measured on another, and claims edits fire on a third. When those three disagree, you get a network that looks adequate in the model and fails in the member’s search.
6. Individual and organizational NPIs treated as interchangeable
Type 1 belongs to a person. Type 2 belongs to an organization. They serve different purposes, and merging them creates records where a person appears to hold an entity’s attributes. The downstream damage is unusually broad: claims route incorrectly, exclusion screening checks the wrong entity, and directory entries display a facility where a member expects a clinician.
7. Effective and termination dates that don’t match the contract
A provider terminates on March 31. The roster reflects it in May. Claims for April adjudicate in-network, then get reprocessed. The directory keeps listing the provider until someone catches it. The exposure runs in both directions. Under the No Surprises Act, plans must verify directory information at least every 90 days, update it within two business days of receiving a change, and honor in-network cost sharing when a member reasonably relied on incorrect directory information. A stale termination date is not a clerical issue. It’s a financial liability with a member attached to it.
8. Exclusion screening that happens once
Credentialing screens against the OIG exclusion list at onboarding, then again at recredentialing, which for most plans means every three years. OIG updates the List of Excluded Individuals and Entities monthly and recommends monthly screening for exactly that reason. The gap between those two cadences is where liability accumulates, and it is not theoretical: OIG’s self-disclosure settlements for employing excluded individuals posted through late 2025 and into 2026 range from about $20,000 to well over $350,000 per organization. Continuous monitoring against exclusion, sanction, and debarment sources is where credentialing and directory accuracy stop being separate projects. This is the part of provider data management solutions that most plans underbuild, because it looks like a credentialing function rather than a data function. Verisys works this angle directly, monitoring for sanctioned, opted-out, and deceased providers against a database covering more than 4.7 million practitioners.
9. Licensure tracked by provider instead of by jurisdiction
A provider licensed in four states has four expiration dates, four boards, and four disciplinary histories. Tracked as one row with one date, three of those go unwatched. Telehealth made this dramatically worse. A behavioral health provider may hold licenses across a dozen states with staggered renewal cycles, and a lapse in one jurisdiction affects only the members seen there, which makes it precisely the kind of error a single-date spreadsheet cannot represent.
10. Records for providers who are no longer practicing
Retired, deceased, and Medicare opt-out providers persist in directories for years. CMS auditors have repeatedly flagged listings for providers who died or retired well before the review. There’s no natural trigger for removal. Nobody submits a roster update saying a physician passed away. Without an external check against death, opt-out, and licensure-surrender sources, these records simply age in place.
Where Each Problem Actually Surfaces
| # | Problem | Created in | Surfaces in | Regulatory exposure |
| 1 | No source of truth | Intake | Everywhere | Directory accuracy |
| 2 | Collapsed address types | Credentialing | Directory audits | Access to care findings |
| 3 | Phantom locations | Group rosters | Network adequacy | Adequacy overstatement |
| 4 | Unowned panel status | Nowhere | Member calls | Audit inaccuracy rate |
| 5 | Taxonomy drift | Configuration | Search and adequacy | Adequacy miscount |
| 6 | NPI type confusion | Intake | Claims and screening | Payment integrity |
| 7 | Date mismatches | Contracting | Claims rework | NSA cost-sharing liability |
| 8 | One-time exclusion screening | Credentialing | Payment integrity | OIG civil monetary penalties |
| 9 | Single-row licensure | Credentialing | Recredentialing | Licensure lapse |
| 10 | Inactive providers | Nowhere | Directory audits | Directory accuracy |
The middle column is the useful one. Four of these problems surface in a department that had no ability to prevent them, which is why remediation projects scoped inside one function tend to fail.
What Changed In 2026
For years, directory accuracy was an internal number. Plans set their own tolerance, audits arrived occasionally, and the data stayed in the plan’s own systems. That structure is ending on two fronts. Under CMS-4208-F2, Medicare Advantage organizations must make in-network provider and facility data available to CMS for publication, update it within 30 days of becoming aware of a change, and attest at least annually that what they submitted is accurate. That data is slated to populate Medicare Plan Finder for plan year 2027, which moves your directory from your website to the tool beneficiaries use to choose a plan. Then the REAL Health Providers Act, enacted in February 2026 as part of the Consolidated Appropriations Act, adds statutory verification and removal timelines beginning with plan year 2028, along with annual accuracy analyses and publicly reported accuracy scores in the years that follow. An attestation signed by a named executive changes the internal conversation about data quality more than any audit ever did.
Where To Start
Pick one field, not one department. Take a practice address, trace every system it enters your organization through, and write down which source wins and why. That exercise usually takes an afternoon and surfaces more than a quarter of remediation work will. Then compare two cadences on paper: how often you screen for exclusions, and how often the source list updates. If the first number is measured in years and the second in months, you’ve found the gap that carries the most direct financial exposure on this list. Which of the ten does your plan actually have documented ownership for? In most organizations, the honest answer is somewhere between two and four.










