NewsNPI23 Jul 2026 7 min read

Why Provider Directory Accuracy Rules Matter for Your NPI

New federal rules tie provider directory accuracy to Medicare revalidation and NPPES data quality. Here's what the 90-day and 5-year rules actually require.

By Patientary Team

Clipboard checklist representing provider directory verification requirements
Photo: RDNE Stock project

Provider directory accuracy just became a compliance requirement, not a courtesy. Anyone who searches the NPI registry to find a doctor, credential a provider, or feed data into a scheduling tool is relying on a chain of federal rules that most patients never see. Two of those rules now carry real teeth: the No Surprises Act's directory-verification requirements for health plans, and the Medicare revalidation cycle that keeps individual NPI registry records current in the first place. Together they turn what used to be a data-hygiene nice-to-have into something regulators actively enforce.

TL;DR: Health plans must verify their provider directories against source data at least every 90 days, and update entries within two business days of a provider-submitted change. Medicare providers and suppliers must revalidate their enrollment every five years (three years for DMEPOS suppliers), or risk having billing privileges deactivated. CMS refreshes the underlying NPI registry data monthly, with a supplemental weekly file, meaning any cached or stale copy of provider data is already out of date within weeks.

What the No Surprises Act Requires of Health Plans

The rule traces back to the Consolidated Appropriations Act's No Surprises Act provisions, specifically the directory-accuracy requirements at 45 CFR 149.610, finalised in the Federal Register's October 2021 'Requirements Related to Surprise Billing; Part II' rule. It applies to group health plans and health insurance issuers, and it's unusually specific about timing for a piece of healthcare regulation.

Health plans must verify and update their provider directory data at least once every 90 days. That's not an annual audit with a grace period, it's a recurring obligation that never really stops. When a provider submits a change themselves, a new address, a new phone number, a change in whether they're accepting new patients, the plan has two business days to reflect it in the public-facing directory.

If a plan can't verify a listed provider, the rule doesn't let it leave the old entry up anyway. That provider has to be removed from the directory until the details can be confirmed. For a plan's credentialing and compliance team, that's a real operational deadline, not a suggestion.

None of this works without a reliable upstream source. Health plans don't invent provider data from scratch, they cross-reference it, directly or indirectly, against the NPI registry, the public database CMS maintains through NPPES, the National Plan and Provider Enumeration System. If a provider's own NPPES record is wrong, that error has a route into every plan directory downstream of it.

Picture a mid-sized health plan's compliance team a few weeks after a provider notifies them of a new practice address. The 90-day cycle isn't the binding constraint here, the two-business-day clock is. Someone has to confirm the change, push it into the plan's directory system, and document that it happened inside the window, because auditors can and do ask for evidence. Teams that treat this as a batch job run once a quarter routinely miss it; teams that build a standing process around it don't.

Medicare Revalidation Keeps the NPI Registry Current

The No Surprises Act rules only work if the source data is trustworthy, and that's where Medicare's revalidation cycle comes in. CMS requires Medicare-enrolled providers and suppliers to revalidate their enrollment information, effectively re-confirming that everything on file, including what feeds into their NPI registry record, is still correct, every five years. DMEPOS suppliers, who deal in durable medical equipment, prosthetics, orthotics, and supplies, are on a tighter three-year cycle.

CMS doesn't spring this on anyone. Revalidation due dates are posted seven months in advance, and CMS maintains a public revalidation list so practices can check their own status rather than wait for a letter to show up. In practice, plenty of practices don't check.

Miss the deadline and nothing dramatic happens immediately, which is part of the problem. Billing privileges are typically deactivated somewhere between 60 and 75 days after the due date passes. There are no exemptions and no extensions. Deactivation isn't the same as being permanently removed from Medicare, but it does mean claims stop getting paid until enrollment is sorted out, which for a small practice can mean weeks of disrupted cash flow over what started out as paperwork.

It's not hard to imagine how this plays out at a small practice. The revalidation notice arrives addressed to an office manager who left eight months earlier, gets filed with routine mail, and nobody connects it to a deadline until claims start bouncing. By the time anyone notices, the practice is well past the 60-to-75-day window, billing privileges are deactivated, and reactivating them means submitting a full revalidation application under time pressure instead of the seven months' notice CMS originally gave. The fix is almost embarrassingly simple: know your revalidation date and treat it like a licence renewal, not a formality.

Why the NPI Registry Data Changes Every Month

Both of those rules assume there's a live, changing dataset underneath them, and there is. CMS doesn't publish the NPI registry once and leave it alone, it releases a full replacement file every month, plus a supplemental weekly file so anyone consuming the data doesn't have to wait a full month to catch a change. New enumerations, deactivations, address updates, and specialty changes all flow through on that schedule.

That cadence is the whole point. Provider data isn't static, people move practices, retire, add credentials, change their billing address, or get deactivated for missing a revalidation deadline. A monthly full file and a weekly incremental file exist specifically because the underlying reality shifts constantly. Any system that pulls a copy of NPI registry data once and treats it as permanent is, by design, working against how CMS built the pipeline.

Patientary's data team puts it plainly: the monthly and weekly NPPES files aren't paperwork, they're CMS's own admission that provider data has a shelf life. A lookup tool that hasn't refreshed in months isn't wrong on purpose, it's just old.

RuleWhat it requiresWho it applies to
Medicare revalidation cycleProviders/suppliers revalidate enrollment every 5 years (3 years for DMEPOS suppliers)Medicare-enrolled providers/suppliers
No Surprises Act directory rulesHealth plans verify directory data at least every 90 days, update within 2 business days of a provider-submitted changeHealth plans/issuers
NPPES file refreshCMS publishes a full monthly NPI file plus a weekly incremental fileAnyone consuming NPPES data
Three separate rules, one shared goal: keeping provider data close to reality.

What This Means If You're a Provider

None of this is really about health plans or CMS's internal processes. It's about whether the record tied to your NPI is the one patients, payers, and referral partners actually see.

  • Check your own NPPES record periodically, the same way you'd check a credit report, using NPI Lookup to confirm your address, specialty, and taxonomy codes are current.
  • Respond to Medicare revalidation notices as soon as they arrive, not when a claim gets rejected. CMS gives seven months' notice for a reason.
  • Remember that health plans are legally required to verify your details every 90 days. If your NPPES record is stale, that staleness has a direct line into every payer directory downstream of it.
  • If you've recently updated your NPI details, confirm the change actually landed using a validation check rather than assuming it went through.

What This Means If You Build Software

The same logic applies to anyone building on top of provider data: scheduling tools, credentialing platforms, directory search, AI agents that need to confirm a provider is real before booking or billing against them. Caching NPI registry data indefinitely, or shipping a static snapshot inside an app, guarantees drift. CMS is telling you, via the monthly-plus-weekly release schedule, roughly how fast that drift happens.

The practical fix is to treat NPI data the way you'd treat any other live reference dataset: pull from a source that reflects the actual refresh cadence, rather than one that was accurate on the day someone downloaded it. Patientary's MCP server exposes current NPI registry and ICD-10-CM data to AI agents and applications directly, so a lookup reflects this month's file rather than whatever was true when a static export was generated.

Check whether your own NPPES record is current before a health plan, or a patient, finds an outdated one.

Look up an NPI

Frequently asked questions

How often does NPPES data change?

CMS publishes a full replacement NPI file every month, plus a supplemental weekly file, so changes like new enumerations, deactivations, and address updates are available between monthly releases.

What happens if I miss my Medicare revalidation deadline?

CMS posts revalidation due dates seven months in advance. Miss it, and Medicare billing privileges are typically deactivated 60 to 75 days after the due date, with no exemptions or extensions granted.

Are health plans required to keep provider directories accurate?

Yes. Under the No Surprises Act's directory rules (45 CFR 149.610), health plans and issuers must verify directory data at least every 90 days and update it within two business days of a provider-submitted change. Providers who can't be verified must be removed from the directory until they are.

How often should software refresh cached NPI data?

At minimum, in line with CMS's own release cadence: monthly, with attention to the weekly incremental file for anything time-sensitive. A static or indefinitely cached copy will drift out of sync with the live NPI registry.

Anything cited above is general reference, not medical, coding or billing advice. To look something up against live data, run a free NPI lookup, or search the ICD-10-CM code set.

More guides

Look it up, then build on it

Search providers and codes free, then get an API key for your software or your AI agent — no card to start.

Get an API key