Exclusion screening · Credentialing

Exclusion screening for credentialing verification organizations

NCQA and URAC now treat exclusion checking as a standing obligation rather than a credentialing-day box: sanctions and OIG/SAM exclusions must be re-monitored on a 30-day cycle. Whatever your verification concludes, every delegating health plan, hospital, and IPA inherits it, errors included. Provider Signals runs continuous, all-source monitoring with the API and bulk throughput a high-volume CVO needs.

No credit card required · All 50+ sources on every plan · Includes all-state Medicaid
90+
organizations hold NCQA CVO Certification, a small and closely audited market where screening accuracy is the whole value you sell.
Every 30 days
NCQA's 2025 standards, effective for surveys from July 1, 2025, set ongoing monitoring of OIG/SAM exclusions, sanctions, and licensure on a 30-day cycle.
$1.56M
19 skilled nursing facilities settled with HHS-OIG in May 2025 for employing excluded individuals; that is the downstream liability a CVO's verification can trigger.
Screened against 50+ federal & state sources — on every plan, including Free. See the full list →

The 30-day clock you are now measured against

Start with the standard, because the standard is what a CVO has to engineer around. NCQA's 2025 credentialing requirements, in effect for surveys conducted on or after July 1, 2025, call for ongoing monitoring of Medicare and Medicaid exclusions (OIG and SAM), sanctions, and license actions on at least a 30-day cycle. Findings cannot simply sit in a log either; an exclusion or sanction surfaced between cycles has to be routed to the credentialing committee or another designated peer-review body so that someone acts on it. URAC's credentialing program sets a parallel expectation of continuous sanction monitoring between full credentialing events. For most provider organizations this is a back-office detail. For a CVO it is the deliverable.

Miss the cadence and the failure does not stay quiet. A practitioner can be clean at credentialing and excluded four months later, well before the 36-month recredentialing window comes around. If your monitoring only fires on that cycle, the gap between events is exactly where an active exclusion hides while claims keep flowing under the client's billing number.

Your files are what the delegation auditor samples first

When a health plan delegates credentialing to you, it does not hand off accountability. The plan remains answerable to NCQA for the work you perform on its behalf, so it audits you to prove the work holds up. Those delegation audits run on file-review sampling rather than a full read of every record. A reviewer pulls a sample of credentialing files, often the familiar eight-and-thirty pattern where an initial set of eight expands to thirty once problems appear, and scores each file against the standards.

Sampling is precisely why a single screening defect is dangerous. One file in the sample with a stale exclusion check, a missing source, or an unaddressed hit can pull the score under the passing threshold and put the delegation agreement under review. The auditor reads that one bad file as evidence of a process gap, not a one-off. And because you are the shared screening function, the same gap repeats across every client roster you maintain. A defect that would embarrass an in-house team at one hospital propagates, in your case, to each plan, IPA, and hospital that relies on your auto-credit.

What a cleared-but-excluded practitioner costs the client

Exclusion carries no de minimis exception. No federal health care program will pay for any item or service furnished by an excluded person, whether the work is clinical, administrative, or buried inside a bundled or per-diem rate. When your verification clears someone who is in fact excluded, the client's exposure compounds:

  • Up to $20,000 per item or service furnished by the excluded individual, an amount that rises with the annual inflation adjustment.
  • An assessment of up to three times the amount claimed for each item or service.
  • Overpayment recovery on everything the excluded person touched, with False Claims Act liability layered on top.

This is not a theoretical tail risk. In May 2025, nineteen skilled nursing facilities settled with HHS-OIG for roughly $1.56 million after employing people they knew or should have known were excluded. The penalty attaches to the client's claims; the contractual fault, and the awkward audit conversation, attach to you.

State Medicaid lists deserve equal weight to the federal LEIE here. Because plans and IPAs draw Medicaid dollars, a practitioner reinstated at the federal level can still sit on an individual state's exclusion list, and a CVO serving clients across several states has to check all of them. Most screening tools price that all-state coverage as a paid tier. Provider Signals includes every state on every plan.

Throughput, every state, and an evidence trail that survives audit

You are not screening one roster. You are screening many clients' rosters at once, against a clock measured in 30-day windows. The product has to match that reality:

  • API and bulk verification. Push thousands of practitioners through programmatically and pull structured results straight into your credentialing platform, rather than having staff key names into government portals one at a time.
  • Continuous re-screening between cycles. Every practitioner is re-checked on each refresh, which covers the ongoing-monitoring requirement at credentialing, at the 36-month recredentialing event, and in the months between.
  • All 50+ sources, every state. OIG LEIE, SAM.gov, OFAC, Medicare Opt-Out, and each state Medicaid list, so a client anywhere is covered with no per-state surcharge.
  • Immutable, dated records. Exportable evidence of what was screened, against which sources, and when, ready for NCQA and URAC surveys and for the file-review sampling a delegation audit runs.
  • Per-client segmentation. Each delegating plan's roster and its evidence stay separate, so an audit produces exactly the file set that client needs without manual untangling.

How we compare to enterprise screening vendors

Legacy exclusion-screening platforms are sold as enterprise contracts, commonly $15,000 to $200,000 a year, and many still bill state Medicaid coverage as an add-on. That structure fits a single large employer, not a CVO that has to cover every state for every client. Provider Signals offers the same continuous, all-source monitoring on a self-serve footing, with API access and pricing that scales by the roster you actually monitor.

CategoryProvider SignalsTypical incumbent
All state Medicaid listsIncluded, every planOften an add-on
Continuous re-screeningYesVaries / batch
Self-serve sign-upFree in minutesSales cycle
Entry pricingFree up to 10, then from $120/mo~$15K–$200K/yr

OIG guidance has long recommended screening at hire and monthly afterward, and NCQA now codifies a 30-day cycle. Provider Signals runs continuously, so a verified practitioner is re-checked between recredentialing events instead of resting on a single point-in-time result. See how the engine works on the exclusion screening overview, review other segments on the industry hub, or size your client volume on the pricing page.

How we match your roster

Exclusion screening is only as good as its matching. We match each person or entity against every source using the full identifier set together — NPI, first name, last or organization name, city, state, and ZIP — never one field alone. NPI alone misses records (the OIG LEIE and many lists don’t carry an NPI for every entry); a name or a location alone produces false matches on common names. When a source record has no NPI, we fall back to name plus location.

Because accuracy depends on your input, provide complete, correct details for every roster entry. When more than one possible match is found, we show you all candidates with their source records so you can confirm, select, or merge — we never auto-flag anyone as excluded. Always verify a match against the primary source before taking any action.

Frequently asked questions

How do you match my roster to the exclusion lists?

We match on the full identifier set together — NPI, first name, last or organization name, city, state, and ZIP — not on any single field. NPI alone misses entries (the LEIE and other lists don’t include an NPI for every record), and names or locations alone cause false matches, so when a source has no NPI we fall back to name plus location. The more complete and accurate your roster details, the more precise the match.

What happens when there’s more than one possible match?

We present every candidate match with its source record and let you select or merge the correct one — we never automatically mark a provider as excluded. A potential match is a prompt to verify against the primary OIG or SAM source, not a final determination. This keeps a human in the loop and protects against acting on a misidentification.

What monitoring cadence does NCQA expect from a CVO in 2025?

For surveys conducted on or after July 1, 2025, NCQA's standards call for ongoing monitoring of OIG and SAM exclusions, applicable sanctions, and license actions on a cycle of no more than 30 days, with anything found routed to a peer-review body for action. Provider Signals re-screens continuously and alerts on any new match, which keeps you inside that window without a monthly manual sweep.

One of our files has a screening gap. What does that do to a delegation audit?

Delegation audits sample your files rather than read all of them, so a single record with a stale check or an unresolved hit can drag the sampled score below the passing mark and trigger a corrective-action plan or a pulled delegation. Continuous monitoring and a dated record for every practitioner are what keep each sampled file defensible.

We credential for clients in a dozen states. Are all the Medicaid lists covered?

They are. Every state Medicaid exclusion and sanction list is included on every plan, alongside the OIG LEIE, SAM.gov, OFAC, and Medicare Opt-Out. This matters for multi-state work because someone reinstated federally can remain on a state list, and most incumbents charge per state for that coverage. We do not.

Can we screen large rosters by API instead of portal lookups?

Yes. Bulk roster uploads and an API let you submit practitioners programmatically and receive structured results back into your credentialing system, which replaces clerks keying names into government portals and scales as your book of clients grows.

Will the evidence hold up for NCQA and URAC surveys?

Each screen produces a dated, exportable, tamper-evident record of what was checked, against which sources, and when. That trail is built to satisfy NCQA and URAC surveys and the file-review sampling your health-plan clients run before they extend auto-credit to your work.

How is pricing structured for a CVO's volume?

Billing tracks the number of practitioners you monitor across all clients. The first 10 are free, plans begin at $120/mo, and cost scales with your roster rather than a fixed enterprise contract in the $15K to $200K range. Model your volume on the pricing page.

Sources: NCQA: CVO Certification FAQs (90+ certified CVOs) · NCQA: Credentialing & CVO Certification standards update (30-day ongoing monitoring) · HHS-OIG: $1.56M settlement for employing excluded individuals (May 2025) · eCFR: 42 CFR 1003.210, CMP amounts and assessments · HHS-OIG: Exclusions Program.

Screen every client's roster — continuously.

Start free in minutes, or book a demo to see the API and bulk workflow.

Provider Signals™ Risk — part of NPI Data Services, a product of VBC Risk Analytics, Inc. — does not provide legal advice. We are not a consumer reporting agency, and our screening tools are not FCRA background checks; use them as part of, not a substitute for, your own compliance program and counsel’s guidance. See our Terms.