Provider directory update frequency depends on the coverage type and the action involved. For plans and issuers subject to the No Surprises Act directory provisions, CMS describes verification at least every 90 days and database updates within two business days after receiving changes from a provider or facility. Separate Medicare Advantage and Medicaid requirements also apply. CMS explains these provisions in its consumer protections overview, page 25.
A verification cycle and an update deadline measure different things. Verification checks whether existing information remains correct. An update incorporates new information after a change is reported. A health plan needs a process for both.
The following comparison covers selected federal requirements. It is a starting point for an operating calendar, not a complete inventory of every state, product, or contractual obligation.
|
Coverage or channel |
Timing |
What starts the clock |
|
No Surprises Act directory provisions for applicable group health plans and issuers |
Verify at least every 90 days; update the database within two business days of provider or facility changes |
Scheduled verification or receipt of a reported change |
|
Medicaid managed care electronic directories under 42 CFR 438.10 |
Update no later than 30 calendar days after receiving updated provider information |
Receipt of updated information |
|
Public Provider Directory APIs for applicable MA, Medicaid, and CHIP payers |
Make information available within 30 calendar days after receipt |
Receipt of directory information or an update |
Sources: CMS No Surprises Act overview; federal Medicaid managed care rule describing the electronic directory standard; CMS Provider Directory API guidance.
Do not apply the No Surprises Act schedule to Medicare Advantage or Medicaid simply because the organization administers those products. Map each directory and publication channel to its governing requirements. For Medicare Advantage online directories, CMS marketing guidance also specifies updates within 30 days of receiving information requiring a change. See the Medicare Communications and Marketing Guidelines.
CMS’s June 2026 No Surprises Act overview says implementing regulations for the directory provision are still forthcoming and calls for a good faith, reasonable interpretation in the meantime. That does not make the underlying obligations optional. State requirements and contracts may add obligations, so the compliance team should approve the final timing matrix.
Consider an illustrative example: a practice verifies its address during a scheduled review, then moves two weeks later. Waiting for the next review leaves members using the old location even though a material change has occurred.
The operating response should begin when the update arrives. Capture its receipt date, identify the affected practitioner and location, reconcile any conflicting information, and publish the correction within the applicable timeframe. Then verify that the member-facing directory actually displays it.
Treat a directory as a set of provider, location, and network relationships. A clinician may practice at several addresses and participate in different products at each one. Updating a single address field without preserving those relationships can create a new error while fixing the old one.
DataSpring’s provider directory management solution uses information entered and confirmed by practices, supported by analytics. Group administrators can manage shared directory details centrally. These capabilities can support the collection process, while the health plan remains responsible for how approved information reaches its directories.
A completed outreach campaign does not show that a correction reached a member. Track three separate dates: the date information arrived, the date it was approved, and the date it became visible in each required channel.
Useful operating measures include the percentage of applicable records verified within the required cycle, the percentage of updates published on time, and the age of unresolved exceptions. Review late items by cause: provider nonresponse, conflicting evidence, system rejection or a missed publication step. That breakdown tells the team where to improve.
Keep evidence of the source, outreach attempts, decision and publication result. An audit trail should explain what the team knew and what it did, rather than merely showing that a batch job ran.
No. Calendar quarters differ in length. Where the requirement is every 90 days, calculate the interval in days and set reminders early enough to complete verification within it.
No. An attestation can be useful evidence, but the health plan must establish that the required information, timing, and publication processes satisfy the obligations that apply to its product. Credentialing and directory workflows may have different requirements.
No. Receipt, validation, and publication are separate steps. Reconcile the accepted changes against what appears in the directory and any required API.
A sustainable directory program connects scheduled verification with timely handling of reported changes. Explore DataSpring Provider Data Management to see how a shared data foundation can support those workflows, or Book Consultation to discuss your current process.