819,398 Providers. The Threat Isn't the License That Expired. It's Everything That Changed While You Weren't Looking.
The Claim That Came Back Wrong
Picture the moment a practice manager opens a remittance advice and finds a denial on a claim she filed five weeks ago. The provider is credentialed. The license is current. She checked. The reason code points to a billing address discrepancy, the address on file with the payer doesn't match the address on the claim.
The provider moved locations eight weeks earlier. NPPES was updated. The practice's credentialing system has the new address. But the payer's directory pulled from a roster submitted last quarter, before the move, and no one sent an update.
Nothing expired. Nothing lapsed. The system did what it was designed to do. And the claim still came back wrong.
This is the problem I keep returning to when I look at provider data at scale. Not the credential that expires and gets flagged. The data that quietly drifts, silently, in the intervals between the moments anyone is looking.
What Half Means When You're Standing in a Directory
That number above is worth sitting with. CMS reviewed Medicare Advantage provider directories and found that nearly half of all provider locations contained at least one inaccuracy. Not a handful of edge cases. Not the plans with obviously poor data hygiene. Nearly half, across the board, despite the industry spending more than two billion dollars annually to maintain this data (Ideon, March 2026).
The money is going in. The errors are accumulating anyway. Which means the problem isn't effort. It's timing. Provider data changes continuously, and verification systems were built to check it periodically.
We monitor 819,398 providers across 219,144 practices. What I see in that data, week over week, is not a story about expired licenses. It's a story about the distance between when something changed and when anyone noticed. Address updates that propagated to NPPES but not to payer rosters. Group affiliations that were terminated but never formally removed from directory submissions. Taxonomy codes that got corrected in one system and stayed wrong in three others.
The drift is not dramatic. It doesn't announce itself. It just accumulates, quietly, between the moments anyone runs a check.
The Interval That Compliance Forgot
For a long time, the credentialing cadence looked like this: an initial verification when a provider joined, a recredentialing cycle every two to three years, and maybe a semi-annual check in between. That was the standard. It was also, in retrospect, a very long time to leave provider data unattended.
NCQA changed that. Effective July 1, 2025, accredited organizations are required to review every provider every 30 days, covering license status, OIG exclusions, state medical board actions, and SAM.gov screening (MedCare MSO, April 2026). Monthly. Not semi-annual. Not annual. Every 30 days, for every provider in the roster.
CMS moved in the same direction on the directory side. The final rule CMS-4208-F2, effective January 1, 2026, requires Medicare Advantage organizations to update provider directory data within 30 days of becoming aware of a change, and to attest annually to accuracy. Starting with the 2027 plan year, that data becomes publicly visible through Medicare Plan Finder (HFMA, September 2025; ATTAC Consulting Group, December 2025).
The regulatory framing has shifted. The window for undetected data error is now measured in weeks, not quarters.
One Address Change, Six Weeks of Downstream Damage
Let me trace one pattern we see repeatedly, stripped of any identifying detail.
A provider at a Texas clinic updates her practice address in mid-February. She files the NPPES change request, it processes within a few days, and the NPI registry reflects the new location by the third week of February. Her credentialing system, updated by the practice coordinator, shows the correct address. The practice considers the update done.
But the payer's directory was last refreshed from a roster submission in December. That roster is not due for an update until April. The payer doesn't know about the move.
In March, the practice submits claims under this provider. The billing address on those claims matches NPPES, the correct one. The payer's adjudication system checks the claim address against the enrolled address in its own directory. The directory still has December's address. The addresses don't match. The claims are flagged for review, then denied.
The practice manager calls the payer. The payer confirms the directory is out of date. A corrected roster is submitted. The payer's update cycle runs. The directory reflects the new address six weeks after the original NPPES change.
During those six weeks, roughly eighteen claims touched that billing address. Several are denied, some are held pending, a few sneak through because different payers adjudicate differently. The practice resubmits. Some claims recycle cleanly. Others require appeals. One enters a dispute that drags into the following quarter.
No license expired. No credential lapsed. The data drifted, and no one was watching the drift.
This is not a hypothetical. It is the dominant pattern in what we see scanning provider data weekly. The problem is rarely the missing credential. It is the lag between when something changed and when every downstream system that needs to know has been told.
What the Financial Exposure Actually Looks Like
It is easy to frame this as an administrative inconvenience. It is not. Qualigenix, citing Sirius Solutions Global, puts the cost of a single credentialing lapse at $7,500 per day (June 2026). DR Credentialing cites research finding that nearly 20% of delayed Medicare claims trace to incomplete credentialing data, with revalidation delays accounting for an average of 15% of temporary billing suspensions in hospitals and clinics nationwide (March 2026). MGMA's survey data found that 54% of medical practices report credentialing-related denials are rising, and the common thread in those denials is not expired licenses. It is mid-cycle data errors: wrong taxonomy codes, dropped network affiliations, address mismatches (MGMA Stat poll, 2021).
And under CMS-4208-F2, a compliance action in one federal program now flows more consistently across programs. A Medicaid sanction can affect Medicare standing, which can ripple into commercial contracts that follow CMS standards. One data error, one enforcement action, one unmonitored change can now travel further and faster than it could two years ago.
What Watching the Data Between the Checks Actually Requires
Argoseer monitors provider records continuously against NPPES delta feeds, state license databases, OIG exclusion lists, and SAM.gov, flagging changes as they appear rather than at the next scheduled audit cycle. We are not a CVO, we do not perform NCQA primary source verification, and we do not issue or validate licenses. What we do is watch the gap: the interval between when your credentialing system last checked and when something in the underlying data changed.
When we find a mismatch, say, an NPPES address update that hasn't propagated to a payer roster, or a state license status change that occurred between re-credentialing cycles, the output is a structured alert that feeds into the workflow your existing credentialing system already manages. The framing I come back to is simple: your credentialing system tracks what you filed. We track whether it's still true.
Across 819,398 providers, 12,026 practices in our pipeline currently have at least one active data mismatch. Most of those are not expired licenses. Most are quiet drifts: addresses, affiliations, taxonomy codes, attestation statuses that changed while the credentialing calendar wasn't looking.
The Question That Doesn't Have a Clean Answer Yet
The 30-day monitoring requirement is now the standard. The 30-day directory update window is now the rule. The data is going public in 2027. The financial exposure for getting this wrong is documented and real.
So the question that I keep sitting with is not whether continuous monitoring matters. That argument is settled. The question is what happens to the 819,398 providers whose data is moving continuously, in systems that still mostly check it periodically, during the months while organizations are figuring out how to close that gap.
Because the drift doesn't pause while the compliance calendar catches up.
Argoseer
Building the future of provider data intelligence.
