Skip to main content
Call
Complianceaka CMS Provider Directory API, Plan Provider Directory API

What is Provider Directory API? Definition, Formula, and Benchmark

Reviewed by QuickIntell RCM Editorial Team · Last reviewed

Updated

Definition

The Provider Directory API is a CMS-mandated FHIR API that health plans must expose publicly with their contracted provider network data. It enables third-party applications, comparison sites, and regulators to query plan networks in a standardized format, improving directory accuracy through greater visibility.

Overview

The Provider Directory API is a CMS-mandated FHIR API through which health plans publicly expose their contracted provider network data. Established by the CMS Interoperability and Patient Access Final Rule (CMS-9115-F), it requires Medicare Advantage, Medicaid managed care, CHIP managed care, and Qualified Health Plans to expose provider directory data via FHIR R4 APIs conforming to the Da Vinci Plan Network IG. Unlike the Patient Access API, the Provider Directory API is open — no member authentication required — because the data is public information about the plan's contracted network.

The API exposes structured data about practitioners (name, NPI, specialty, languages, accepting-new-patients status), organizations (affiliated groups and facilities), locations (addresses, accessibility, hours), and the plan's contracted network membership. Updates must be reflected in the API within 30 days of the underlying data changing; stale directories have been a longstanding industry complaint and the rule's directory-freshness requirements addressed that pain point directly.

Industry use cases have evolved since the rule's effective date. Comparison sites and consumer-facing tools use the API to aggregate cross-plan directory data, enabling side-by-side plan comparison and provider-participation verification. Healthcare startups have built specialty-specific tools — mental-health-provider-matching apps, surgical-subspecialty finders, pediatric-network evaluators — on top of the API data. Regulators use it for network-adequacy assessment and directory-accuracy audits.

The API has exposed longstanding directory-accuracy problems. Many plans' directories continue to list providers who are no longer accepting new patients, have relocated, or are no longer contracted — despite the API exposing the data, the underlying source-of-truth issues persist in many plans. Secret-shopper audits published by regulators and consumer groups have found directory inaccuracy rates of 20–40% for some plans. CMS enforcement has gradually increased penalties for chronic inaccuracy.

For RCM and payer operations, the Provider Directory API is an ongoing operational obligation. Plans must maintain source-of-truth data in their provider-contracting systems, refresh API data promptly, and respond to regulatory inquiries. Investment in directory-management infrastructure has become a compliance priority; dedicated directory-accuracy programs are common at larger plans.

For providers, the API surfaces how they appear across plan directories and enables proactive correction of inaccurate listings. Credentialing-verification organizations and provider-data-management platforms use the API to help providers audit their cross-plan directory presence.

Provider Directory API is one of the compliance areas where documentation discipline determines audit outcomes more than policy sophistication. Practices that invest in clean Provider Directory API records, consistent fhir api workflows, and auditable network adequacy evidence come out of OIG, RAC, and MAC audits with materially smaller recoupment exposure than practices with equivalent policies but weaker paper trails.

From a board-reporting standpoint, Provider Directory API belongs in the compliance committee's quarterly dashboard. The reporting line should include volume, exception rate, and any open remediation action; reviewers tie Provider Directory API metrics to the broader compliance program KPIs so an emerging Provider Directory API risk surfaces before it becomes a formal finding. Pairing the Provider Directory API trend with fhir api gives the committee a single view of whether the control environment is strengthening or drifting.

Industry benchmark

CMS-9115-F compliance date: July 2021 for covered plans. Directory-update SLA: 30 days. Directory-accuracy rates (secret shopper audits): 60–80% for most plans, with chronic underperformers at 40–60%.

Worked example

A patient uses a specialty-finder app to locate in-network pediatric endocrinologists within 25 miles of their ZIP code. The app queries the Provider Directory API of the patient's health plan, filters for specialty and distance, and returns 14 matching providers with accepting-new-patient status and contact details.

Frequently asked questions — Provider Directory API

Is authentication required?

No — the Provider Directory API is open because it publishes plan-network data that is already public information. No member authentication or SMART flow is needed to query it.

How fresh must directory data be?

Updates must be reflected in the API within 30 days of underlying data changes. In practice most plans update more frequently but source-of-truth gaps cause persistent inaccuracy.

Who uses the API besides members?

Comparison sites, specialty-finder apps, network-adequacy regulators, credentialing-verification organizations, healthcare research teams, and provider-data-management platforms.

Disclaimer

This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.