Blogs

How to Do Primary Source Verification (PSV) in Healthcare: A Step-by-Step Guide

Blog post featured image
Varun Krishnamurthy
Updated
August 24, 2026
Published
August 24, 2026

Quick summary

This guide covers primary source verification (PSV): confirming a provider's credentials directly with the issuing body. The Joint Commission, NCQA, URAC, and CMS all require it. PSV underpins payer reimbursement, accreditation, and patient safety.

You'll learn how PSV works end to end, how to verify each credential element, how to pick the right verification method, how to document your work, and how to build a program that survives accreditation surveys and delegated credentialing audits

The verification step that credentialing programs live by

Every credentialed provider in your network has a chain of qualifications behind them. None of that means anything until someone confirms it directly with the body that issued it.

That confirmation is called primary source verification (PSV). It is the difference between trusting a self-reported document and proving the credential exists. It is also the foundation on which payer contracts, accreditation surveys, and patient safety policies rest.

This guide is written for credentialing managers, compliance leaders, and operations teams at enterprise health systems, multi-entity provider groups, and growth-stage digital health organizations.

Why listen to us

Assured runs primary-source verification at scale for enterprise health systems like Houston Methodist, multi-entity provider groups operating across multiple states, and growth-stage digital health organizations. 

As an NCQA-certified CVO across all 11 verification elements with direct connections to 2,000+ primary sources, the guidance here reflects how PSV operates in practice, grounded in current Joint Commission, NCQA, URAC, and CMS requirements (including the July 2025 NCQA changes).

Blossom review

What is primary source verification?

Primary source verification is the process of confirming a provider's credentials directly with the issuing body. Instead of accepting a copy of a license or a CV, the credentialing team contacts the state medical board, the medical school, the certification body, or the federal database that actually issued the credential.

The Joint Commission defines PSV as the verification of a practitioner's reported qualifications by the source or by an approved agent of that source. NCQA and URAC use similar definitions in their respective credentialing standards.

Why primary source verification matters

PSV is a regulatory requirement, but the stakes are wider than that.

  • Patient safety. PSV is the control that catches expired, suspended, or fraudulent credentials before a clinician reaches a patient.
  • Accreditation and compliance. The Joint Commission, NCQA, URAC, and CMS all require PSV. Failed verification is one of the most common findings in accreditation surveys.
  • Payer reimbursement. Most commercial payers require evidence of completed PSV before paying claims. Incomplete verifications are a recurring cause of claim denials.
  • Malpractice and legal exposure. Negligent credentialing is a recognized legal theory. Organizations that grant privileges to a provider whose credentials were never verified can be held directly liable.
  • Revenue velocity. Every day a provider waits for credentialing is a day they cannot bill. PSV is often the longest step in that timeline, where automation has the most leverage.

What gets verified during PSV

The exact list depends on provider type and the accreditation body involved, but a standard PSV file usually includes:

  • State medical license: Confirmed active and in good standing with the state licensing board, including any disciplinary history.
  • DEA registration: Verified through the Drug Enforcement Administration or applicable state CSR.
  • Education and training: medical school, residency, and fellowship verified directly with the issuing institution.
  • Board certification: Verified by the Accreditation Council for Graduate Medical Education (ACGME), the Accreditation Council for Continuing Medical Education (ACCME), or the relevant specialty board.
  • Work history: A minimum of five years of work history, with gaps of six months or more explained per NCQA standards. NCQA accepts CV-based documentation; privileging by the Joint Commission may require employer verification.
  • Malpractice history: Reviewed through the malpractice carrier and the National Practitioner Data Bank (NPDB).
  • Sanctions and exclusions: Checked against the OIG List of Excluded Individuals and Entities (LEIE), SAM.gov, state Medicaid exclusion lists, and the Medicare opt-out and preclusion lists.
  • NPI registration: Confirmed against the National Plan and Provider Enumeration System (NPPES).
  • Attestation: A signed attestation by the provider confirming the application's accuracy.

For providers with international training, additional verifications may apply, including ECFMG certification for foreign medical graduates.

Where primary sources come from

Primary sources fall into a few broad categories.

1. State and federal databases

State licensing boards (one per state, sometimes multiple per provider type), the DEA, the NPDB, OIG LEIE, SAM.gov, NPPES, CMS Medicare and Medicaid databases, and the Social Security Administration Death Master File.

2. Education and training bodies

Medical schools, residency programs, fellowship programs, the Educational Commission for Foreign Medical Graduates (ECFMG), and continuing medical education providers.

3. Certification bodies

The American Board of Medical Specialties (ABMS) and its member boards, the American Osteopathic Association (AOA), the National Commission on Certification of Physician Assistants (NCCPA), and other specialty certification bodies.

4. Past employers

Hospitals, medical staff offices, and prior clinical practices.

5. Professional and regulatory associations 

The Federation of State Medical Boards (FSMB), the AMA Physician Masterfile (an approved Designated Equivalent Source under Joint Commission rules), and state medical and dental councils.

6. Designated Equivalent Sources (DES)

Where a primary source is unavailable or impractical, accreditation bodies allow verification through a Designated Equivalent Source: a third party that maintains credential information identical to that of the primary source. Common DES options include the AMA Physician Masterfile, ABMS, ECFMG, AOA, and the FSMB Disciplinary Action Databank.

DES is not a shortcut. The Joint Commission no longer publishes a specific DES list; instead, it requires the accredited organization to determine whether the source meets its CVO criteria. NCQA and URAC each define their own approved DES list. Every use must be documented and justified in accordance with the relevant accreditation body's rules.

How primary source verification works

The PSV process is sequential, but several steps can be parallelized with the right tools.

1. Information collection

  • Gather the provider's application, attestation, current CV, signed release authorizing PSV, and supporting documents. 
  • Pull the provider's CAQH Provider Data Portal profile and confirm the attestation is current (within the past 120 days for NCQA Accreditation). 
  • Cross-check core identifiers (legal name, NPI, DOB) against NPPES. 
  • Flag any gaps in the CV of six months or more, so you can request written explanations upfront. 

If the provider is a foreign medical graduate, capture ECFMG certification details at this stage. The cleaner the intake, the fewer downstream verification failures.

2. Source identification

For each credential element on the file, identify the correct primary source and the accepted method of verification. 

Build a per-provider checklist. Every active state license means a separate board lookup; medical school, residency, and fellowship each need a source; board certification maps to the specific specialty board, and sanctions screening covers OIG LEIE, SAM.gov, state Medicaid exclusion lists, etc. 

3. Outbound verification

            Contact each source through its accepted method. 

  • For state licenses, use the state board's official license lookup or submit a written request. 
  • For DEA, use the DEA registration lookup. For the NPDB, submit an organizational query. 
  • For education, contact the registrar and request written verification. 
  • For board certification, use ABMS Certification Matters or the applicable specialty board. 
  • For prior employers, contact them directly where your accreditation body requires it.

Log every attempt with date, method, and status. That way, a survey trail exists even for pending verifications.

Where a primary source is unavailable or impractical, use an approved Designated Equivalent Source. Document the justification in accordance with your accreditation body's rules.

4. Response capture and file documentation

When the source confirms a credential, capture proof and document the verification with the date, source, verifier, and result. 

  • For online lookups, save a timestamped screenshot showing the URL. 
  • For written verification, file the signed letter. 
  • For phone verification, log the call notes with the verifier's name, the source representative's name, the date, and the specific credential verified. 

The Joint Commission requires that documentation include who completed the verification and what was specifically verified. Files missing those elements can fail review even when the credential itself has been confirmed.

5. Committee review

  • Cross-check that every credential element on the file is complete and that verification dates fall within your accreditation body's window (120 days for NCQA Accreditation, 90 days for CVO Certification). 
  • Flag any adverse findings, such as sanctions, malpractice actions, or disciplinary history, for committee attention. 
  • Compile the committee-ready file and present it at the credentialing committee meeting. 
  • Document the committee's decision, the vote, and any conditions attached to the approval. 
  • Store the completed file according to your retention schedule (typically at least 10 years for accreditation and payer audit purposes).

How to choose the right verification method

The Joint Commission and NCQA accept four methods:

  • Direct correspondence. Written verification by letter, fax, or email from the issuing source.
  • Documented telephone verification. A logged phone call to the source, with notes confirming the verifier, the source representative, the date, and the result.
  • Secure electronic verification. Verification through the source's official website or API.
  • Reports from a CVO. A verification report from a Credentials Verification Organization that meets accreditation standards.

A photocopy of a license is not a PSV on its own. PSV requires evidence of contact with the issuing source.

How to verify each credentialing element

Here is how each element is typically verified in an audit-defensible way.

1. How to verify a state medical license

  • Go to the state medical board's official license lookup for every state in which the provider is (or will be) licensed. 
  • Search by license number or provider name.
  •  Confirm the license status, issue date, expiration date, and any disciplinary actions. 
  • Capture a screenshot showing the URL and the verification date. 
  • Repeat for every state license on the provider's file. Multi-state providers routinely have to check five to ten state boards.

2. How to verify DEA registration

  • Access the DEA registration lookup through the DEA website or through a data service connected to the DEA registration database. 
  • Confirm the DEA number, expiration date, schedule authority, and registered address. 
  • Where the state also requires a controlled substance registration (CSR), verify that separately through the state's controlled substance authority. 
  • Capture the verification with a screenshot or written confirmation.

3. How to verify medical education and training

Contact the registrar of each educational institution the provider attended and request written verification of enrollment, degree conferred, and graduation date. 

For foreign medical graduates, verify ECFMG certification through the ECFMG's Certification Verification Service.

4. How to verify board certification

Use ABMS Certification Matters for physicians certified through an American Board of Medical Specialties (ABMS) member board. 

  • For osteopathic physicians, verify through the American Osteopathic Association (AOA). 
  • For physician assistants, use the National Commission on Certification of Physician Assistants (NCCPA). 
  • For other specialty certifications, verify directly with the applicable board. 
  • Confirm the current status, certification date, and expiration date, then capture the verification proof.

5. How to query the National Practitioner Data Bank (NPDB)

  • Register your organization for NPDB query access through the NPDB portal. 
  • Submit an organizational query for the provider. 
  • Review the response for any malpractice payments, adverse actions related to licensure or clinical privileges, exclusions, and other reportable events. 
  • If the query returns any reportable action, document the finding and route it to the credentialing committee for review. 
  • Store the NPDB response in the credentialing file with the query date.

6. How to check sanctions and exclusions

Run parallel checks against the OIG LEIE (List of Excluded Individuals and Entities), SAM.gov, the Medicare opt-out list, the Medicare preclusion list, every applicable state Medicaid exclusion list, and every state licensing board sanction record. Document each check with the date, the database, and the result. Any adverse finding must be escalated to a peer-review body, not resolved inside the credentialing team.

7. How to verify work history

Review the provider's CV against the application. Any gap of six months or more must be explained in writing before the file goes to the committee. Under NCQA standards, CV-based documentation is typically sufficient to document the required 5 years of work history. 

For Joint Commission privileging, or where your organization requires it, contact prior employers directly for written verification of dates and role. Document any gap explanation in the file.

8. How to verify NPI registration

Look up the provider's NPI in the NPPES (National Plan and Provider Enumeration System) registry. Confirm that the NPI is active, the taxonomy code matches the provider's specialty, and the address on file matches the current practice address. Capture the NPPES record as documentation. Cross-check the NPI against every state license and DEA registration to catch identity mismatches early.

Regulatory requirements

PSV is governed by several overlapping bodies. Knowing which applies to your organization is the starting point for a defensible program.

1. The Joint Commission

The Joint Commission requires accredited organizations to perform PSV at hire and at renewal. For hospitals and critical access hospitals, the requirements are in the Human Resources and Medical Staff chapters. Other Joint Commission programs use parallel standards for behavioral health and for ambulatory care.

2. NCQA

NCQA sets the credentialing standards used by most commercial health plans and managed care organizations. The CR 3 standard covers PSV. NCQA's standards changed substantially on July 1, 2025: the PSV window was reduced from 180 days to 120 days for Credentialing Accreditation and 90 days for CVO Certification. 

NCQA also added monthly monitoring requirements for license expirations, OIG and SAM exclusions, and sanctions, with escalation to a peer-review body. 

See our full breakdown of the 2025 NCQA credentialing standards updates for the operational implications.

3. URAC

URAC accredits health plans and CVOs against its own credentialing standards. Like NCQA, URAC requires PSV for specified credential elements and continuous monitoring between cycles. URAC accreditation is widely accepted by commercial payers as evidence of credentialing rigor.

4. CMS

The Centers for Medicare and Medicaid Services requires PSV for providers participating in Medicare and Medicaid programs. Federal regulations under 42 CFR govern revalidation cycles and exclusion screening. 

5. State licensing boards

State medical boards are the primary source for medical licensure. They also impose their own verification rules, especially for providers practicing across multiple states or under interstate compacts like the Interstate Medical Licensure Compact (IMLC).

Who is responsible for primary source verification?

Under accreditation rules, the accredited organization is responsible for PSV, not the provider. That responsibility cannot be transferred to the provider, even when the provider has a complete CAQH profile or maintains their own credential file.

In practice, day-to-day execution falls to one of three setups.

1. In-house credentialing team

Medical staff services at enterprise health systems, credentialing managers at multi-entity provider groups, and operations leaders or credentialing coordinators at growth-stage digital health organizations may form an in-house credentialing team. This setup works well when volumes are predictable and the team is staffed accordingly.

2. Credentials Verification Organization (CVO)

A CVO is a specialized partner that performs PSV on behalf of the accredited organization. NCQA-certified CVOs operate under defined standards and can be certified across all 11 NCQA evaluation elements.

Health plans seeking NCQA Health Plan Accreditation can receive automatic credit for verification work performed by an NCQA-certified CVO, thereby simplifying delegation and reducing the audit scope.

3. Delegated credentialing arrangement

Larger provider organizations can sign delegated credentialing agreements with health plans. The provider organization (or its CVO partner) performs the verification on behalf of the plan. 

Delegation requires an NCQA-aligned program, audit-ready documentation, and annual oversight reviews. For more on this, see our guide to building a delegation-ready credentialing program.

Regardless of structure, accountability stays with the accredited organization. Outsourcing the work does not outsource the responsibility, which is why oversight, audit trails, and documentation matter as much as the verifications themselves.

PSV during recredentialing and ongoing monitoring

PSV is not a one-time event. NCQA, The Joint Commission, and URAC all require recredentialing on a defined cycle (typically every 36 months for NCQA). Every recredentialing cycle requires a fresh PSV for the relevant elements.

Between cycles, organizations also have to continuously monitor credentials, which is where network management workflows take over from the initial credentialing process. Under the 2025 NCQA standards, monthly monitoring is required for:

  • License expirations, with renewal documentation
  • OIG LEIE exclusions
  • SAM.gov exclusions
  • State Medicaid exclusion lists
  • State licensing board sanctions

Findings must be escalated to a peer-review body and not handled within the credentialing team. This shift from periodic checks to continuous monitoring is one of the most significant operational changes credentialing teams have undergone in the last decade. 

For a deeper walkthrough of recredentialing requirements, see our guide.

How to avoid common PSV mistakes

Most PSV failures come from the same handful of patterns.

  1. Treating photocopies as verification: A copy of a license, a screenshot from the provider, or a CV entry is not PSV. Surveyors specifically look for evidence of contact with the primary source.
  2. Relying on aggregator databases for initial credentialing: While aggregator databases can support ongoing monitoring, most accrediting bodies require direct contact with primary sources for initial credentialing.
  3. Skipping documentation of the verifier and date: Joint Commission requires that PSV documentation include who completed the verification, what was specifically verified, and the date. Files missing those elements can fail review, even when the credential itself has been confirmed.
  4. Confusing CVO certification with full coverage: A CVO can be certified for a subset of the 11 NCQA evaluation elements, not all. Organizations using a CVO partner must confirm which elements are covered and where responsibility for verification still lies with the accredited organization.
  5. Manual workflows at a multi-state scale. A two-person team running spreadsheets can keep up with 20 providers in two states. The same team cannot keep up with 200 providers across 15 states without missed renewals, lapsed verifications, and broken audit trails.
  6. Stale CAQH data. The CAQH Provider Data Portal is the data foundation for most credentialing workflows. When attestations lapse or profile data goes stale, every downstream verification is compromised.

How software and support help

Manual PSV breaks at scale. Modern programs rely on two layers: automation that handles verification and expert support that resolves what automation cannot.

1. What automation does

A purpose-built credentialing platform connects directly to primary sources and runs verification in parallel. For most credential elements, this collapses what was once a multi-week manual process into a same-day digital exchange. The strongest platforms also:

  • Pre-fill provider data from CAQH, NPPES, DEA, and state medical boards
  • Run pre-submission validation to catch missing fields and data mismatches before verification starts
  • Capture proof of verification (screenshots, documents, timestamps) into a single file
  • Track expirations and trigger renewals before deadlines
  • Run continuous monitoring against sanctions, exclusions, and license status
  • Generate audit-ready files for accreditation surveys and delegated credentialing reviews

2. What managed services add

Automation handles the predictable work. Managed services handle the edge cases. For example, a school that does not appear in the National Student Clearinghouse, a state board with a unique verification process, a CAQH profile with stale data, or a payer-specific submission that needs a phone call.

The right managed services partner has subject matter experts across credentialing, licensing, and payer enrollment, weekly check-ins with the customer team, and a shared communication channel for escalations. 

3. How Assured approaches PSV

Assured is an AI-native credentialing platform built for enterprise health systems like Houston Methodist, multi-entity provider groups operating across many states, and growth-stage digital health organizations. The platform runs PSV across 2,000+ primary sources in parallel, automatically pulls provider data from CAQH, and validates submissions before they go out. Assured is an NCQA-certified CVO across all 11 verification elements, which means delegated credentialing partners can rely on Assured's PSV work without re-verification.

A few specifics:

  • Credentialing files are completed within 48 hours of documentation completion, compared with an industry norm of 60 to 120 days.
  • First-pass approval rates are 95%+, driven by pre-submission validation that catches issues before they lead to rejections.
  • Compliance issues are detected 22 days earlier than manual processes, with sanctions flagged within 24 hours.
  • Renewals are auto-initiated 60 days before expiration.
  • Customer support responds within 24 hours, with a named specialist assigned to every account.

Customers, including Tono Health, Blossom Health, Prosper Health, Birches Health, and Platinum Dermatology Partners, use Assured to scale credentialing across multiple states and provider types without adding internal headcount. 

For a deeper comparison of manual and automated approaches, see our breakdown of manual vs. automated PSV.

assured dashboard

Best practices for an audit-ready PSV program

A defensible PSV program shares a few common attributes:

  • Every verification is documented with date, source, verifier, and result
  • Workflows are tied to an information integrity audit on at least an annual cycle
  • CVO partners are NCQA-certified across the elements that the organization needs to be covered
  • Records are retained according to state and federal requirements
  • The credentialing committee meets at least monthly with documented minutes
  • Delegation reviews include sample file access and audit documentation packages

The goal is a program that withstands a survey, a delegated credentialing audit, and a regulator's question without requiring file rebuilds after the fact.

Get PSV right at scale

Primary source verification is one of the highest-leverage controls in healthcare operations. Done well, it protects patients, defends revenue, and clears the path to in-network status. Done poorly, it stalls billing, creates audit risk, and exposes the organization to liability.

For enterprise health systems, multi-entity provider groups, and growth-stage digital health organizations running PSV at volume, the right combination of automation and managed expertise is the difference between a defensible program and one that is constantly catching up.

Book a demo to see how Assured runs PSV across 2,000+ primary sources, with NCQA-certified coverage across all 11 verification elements.

Discover the true cost of ineffecient network management

Talk to Assured experts today and stop revenue from slipping through the cracks
Get in touch