Provider Network Integrity: A Data Intelligence Report

Learn more
Content Overview

Introduction

Provider directories matter because members rely on them. When a health plan member searches for an in-network doctor, they're trusting that the listing is current, that the provider is licensed, and that nothing disqualifies them from providing care. Federal and state rules require payers to keep these directories accurate and publish them through public APIs.

This report is a joint project between ProviderTrust and Defacto Health, building on Defacto's annual State of Provider Networks report. Defacto supplied data spanning 144 payer directories, covering every payer category it tracks. ProviderTrust ran that data through its verified provider data platform, checking provider records against primary sources, including federal and state exclusion lists, licensing boards, controlled substance registries, and board certification bodies.

The goal was straightforward: take the data payers already publish and see whether it holds up relative to the expectation that providers are qualified to be in-network. It largely does not.

Gaps show up in nearly every network examined, regardless of size or payer category. These are not edge cases involving a handful of poorly run plans; they are a consistent pattern across the industry.

The seven findings that follow are organized around one theme: the systems designed to catch exclusions, invalid NPIs, expired licenses, lapsed certifications, and controlled substance registration issues are not consistently catching these issues. Each finding is a distinct piece of evidence for that gap and a different argument for continuous monitoring over periodic point-in-time reviews.

The results are consistent across the industry:

Almost 9 in 10 payer networks analyzed (89%) carry at least one currently excluded provider.

Every single network analyzed carries at least one license, registration, or certification issue.

Roughly 1 in 5 providers industry-wide has a license status issue of some kind.

The Methodology

This analysis draws on two datasets:

1.

A blinded set of 144 payer networks, representing roughly 22.3 million providers. No organization names or business line tags appear in this dataset; it is used for statistical weight and industry-wide framing, and no row in it can be tied to a real company.

2.

A second dataset covering 42 organizations, already featured in ProviderTrust's public risk reports. This report does not cite these organizations individually — instead, this dataset is used in aggregate to break out patterns by payer segment: Commercial, Medicare Advantage, Affordable Care Act Plan, and Medicaid Managed Care.

ProviderTrust ran five layers of analysis against both datasets: federal and state exclusions; NPI status accuracy, including cross-reference against NPPES and the Medicare Opt Out list; license board actions and license status issues; controlled substance registration issues; and board certification status issues. The seven findings below each draw on one or more of these layers.

Two definitions matter for understanding the findings. License board actions capture confirmed disciplinary action against a license. License status issues capture a broader set of conditions that includes suspended, revoked, or expired licenses. Also, note that statistics throughout this report are presented as normalized rates rather than raw percentages, because payer networks in this dataset range from fewer than 20,000 providers to more than 1.7 million.

Payer identities in the blinded dataset are never disclosed. This protects payers while still allowing the findings to speak at full industry scale.

100% of all 144 networks

had at least one license, board action, or controlled substance registration issues

The 7 Key Findings

ProviderTrust’s five layers of analysis surfaced seven distinct findings. Read separately, they expose individual cracks in the credentialing system. Read together, they describe one underlying problem from different angles: the systems built to catch exclusions, invalid NPIs, expired licenses, lapsed certifications, and controlled substance registration issues are not catching them consistently enough — and periodic, point-in-time checks are a central reason why.

KEY FINDING 1

The Data Reveals Patterns, Not Anomalies

Learn more

KEY FINDING 2

Why a Fraction of a Percent Actually Matters

Learn more

KEY FINDING 3

Too Often, Credentials Quietly Expire

Learn more

KEY FINDING 4

The Major Blind Spot in Federal-Only Screening

Learn more

KEY FINDING 5

Standard Checks Miss More Than 25% of Exclusions

Learn more

KEY FINDING 6

Smaller Networks Don’t Mean Smaller Issues

Learn more

KEY FINDING 7

Medicaid Trends Differently, and That Signal Matters

Learn more

Property of ProviderTrust, Inc. | 2026 All Rights Reserved.