Skip to content
Search

What Is the Required Frequency for Provider Directory Updates?

DataSpring Logo in Green

Provider directory update frequency depends on the coverage type and the action involved. For plans and issuers subject to the No Surprises Act directory provisions, CMS describes verification at least every 90 days and database updates within two business days after receiving changes from a provider or facility. Separate Medicare Advantage and Medicaid requirements also apply. CMS explains these provisions in its consumer protections overview, page 25.

A verification cycle and an update deadline measure different things. Verification checks whether existing information remains correct. An update incorporates new information after a change is reported. A health plan needs a process for both.

Which timing requirements should health plans distinguish

The following comparison covers selected federal requirements. It is a starting point for an operating calendar, not a complete inventory of every state, product, or contractual obligation.

Coverage or channel

Timing

What starts the clock

No Surprises Act directory provisions for applicable group health plans and issuers

Verify at least every 90 days; update the database within two business days of provider or facility changes

Scheduled verification or receipt of a reported change

Medicaid managed care electronic directories under 42 CFR 438.10

Update no later than 30 calendar days after receiving updated provider information

Receipt of updated information

Public Provider Directory APIs for applicable MA, Medicaid, and CHIP payers

Make information available within 30 calendar days after receipt

Receipt of directory information or an update

Sources: CMS No Surprises Act overview; federal Medicaid managed care rule describing the electronic directory standard; CMS Provider Directory API guidance.

Do not apply the No Surprises Act schedule to Medicare Advantage or Medicaid simply because the organization administers those products. Map each directory and publication channel to its governing requirements. For Medicare Advantage online directories, CMS marketing guidance also specifies updates within 30 days of receiving information requiring a change. See the Medicare Communications and Marketing Guidelines.

CMS’s June 2026 No Surprises Act overview says implementing regulations for the directory provision are still forthcoming and calls for a good faith, reasonable interpretation in the meantime. That does not make the underlying obligations optional. State requirements and contracts may add obligations, so the compliance team should approve the final timing matrix.

Why quarterly verification does not solve every update

Consider an illustrative example: a practice verifies its address during a scheduled review, then moves two weeks later. Waiting for the next review leaves members using the old location even though a material change has occurred.

The operating response should begin when the update arrives. Capture its receipt date, identify the affected practitioner and location, reconcile any conflicting information, and publish the correction within the applicable timeframe. Then verify that the member-facing directory actually displays it.

Treat a directory as a set of provider, location, and network relationships. A clinician may practice at several addresses and participate in different products at each one. Updating a single address field without preserving those relationships can create a new error while fixing the old one.

Build a workflow around verification and reported changes

  1. Start with a shared intake process for provider submissions, delegated group rosters, network contracting updates, and member-reported problems. Assign every item an owner and a due date based on its applicable requirement. Keep the original receipt timestamp when the item moves between teams.
  2. Use targeted outreach to resolve uncertainty. A disconnected number should generate a phone verification task; a network participation dispute should reach the contracting owner. Sending the entire record back for confirmation can add work without resolving the specific issue.
  3. Define an escalation path for nonresponse and contradictory evidence. For records that cannot be verified, follow the applicable removal and escalation requirements; do not silently treat missing confirmation as proof that a clinician has left the network.

DataSpring’s provider directory management solution uses information entered and confirmed by practices, supported by analytics. Group administrators can manage shared directory details centrally. These capabilities can support the collection process, while the health plan remains responsible for how approved information reaches its directories.

Measure completion at the point members use the data

A completed outreach campaign does not show that a correction reached a member. Track three separate dates: the date information arrived, the date it was approved, and the date it became visible in each required channel.

Useful operating measures include the percentage of applicable records verified within the required cycle, the percentage of updates published on time, and the age of unresolved exceptions. Review late items by cause: provider nonresponse, conflicting evidence, system rejection or a missed publication step. That breakdown tells the team where to improve.

Keep evidence of the source, outreach attempts, decision and publication result. An audit trail should explain what the team knew and what it did, rather than merely showing that a batch job ran.

Frequently asked questions

Is every 90 days the same as once per calendar quarter?

No. Calendar quarters differ in length. Where the requirement is every 90 days, calculate the interval in days and set reminders early enough to complete verification within it.

Does a provider profile attestation automatically satisfy directory requirements?

No. An attestation can be useful evidence, but the health plan must establish that the required information, timing, and publication processes satisfy the obligations that apply to its product. Credentialing and directory workflows may have different requirements.

Does receiving a data feed mean the directory has been updated?

No. Receipt, validation, and publication are separate steps. Reconcile the accepted changes against what appears in the directory and any required API.

Keep directory information moving

A sustainable directory program connects scheduled verification with timely handling of reported changes. Explore DataSpring Provider Data Management to see how a shared data foundation can support those workflows, or Book Consultation to discuss your current process.