The National Practitioner Data Bank (NPDB): What Every US Healthcare Employer Needs to Know

A guide to what the NPDB reports, who must query it, how self-queries work, and where it fits alongside primary source verification and exclusion screening.

Learnsignal Education Team
Updated

Ask most US healthcare credentialing staff what "the Data Bank" means and they'll answer without hesitating — but ask them to explain exactly who has to query it, when, and what a self-query actually proves, and the answers get noticeably less confident. The National Practitioner Data Bank (NPDB) sits underneath a huge share of US credentialing and enrollment work, and getting the querying obligations wrong isn't a paperwork slip — it can mean staffing a role with someone whose history a proper check would have surfaced.

What the NPDB actually is

The NPDB is a federal repository, run by the Health Resources and Services Administration (HRSA), that collects reports on specific adverse actions taken against healthcare practitioners, providers, and suppliers. It was established by the Health Care Quality Improvement Act of 1986, with reporting later expanded by the Healthcare Integrity and Protection Data Bank provisions. The Data Bank itself doesn't investigate or adjudicate anything — it's a reporting and querying system, not an enforcement body. Its purpose is to stop a practitioner with a documented adverse history from moving between states or employers without that history following them.

What gets reported

Reportable events fall into several categories: medical malpractice payments made on a practitioner's behalf, adverse licensure actions taken by state medical or dental boards, adverse clinical privileges actions taken by hospitals and other healthcare entities, adverse professional society membership actions, negative actions on clinical privileges or panel membership taken by health plans, and exclusions from participation in federal or state healthcare programs. Entities required to report are generally the ones taking the adverse action — a hospital revoking privileges, a state board disciplining a license, a malpractice insurer making a payment — not the practitioner themselves.

Who is required to query

Hospitals are required to query the NPDB when granting initial clinical privileges or medical staff appointment, and again every two years for practitioners who hold privileges with them. Beyond hospitals, a wide range of other entities are authorized or required to query depending on context: state licensing boards, other healthcare entities that engage in formal peer review, health plans, and professional societies with a formal peer review process. This is why a single adverse report can follow a practitioner across state lines and across employers — anyone in that chain of authorized queriers who checks will see it, not just the entity that originally took the action.

Self-queries

Practitioners themselves can request a self-query, which returns whatever information exists about them in the Data Bank. This is commonly used before job applications, credentialing cycles, or licensure renewals, as a way for a practitioner to confirm what a prospective employer's query will show and to identify and dispute anything inaccurate before it affects a credentialing decision. A self-query report carries an official verification code that the practitioner can pass on to an employer or licensing board wanting to confirm its authenticity directly with the Data Bank, without the employer needing separate query authority for that specific purpose.

What the NPDB is not

It's worth being precise about the limits of what the Data Bank does. It is not a general-purpose criminal background check, not a substitute for primary source verification of education and licensure, and not open to the public — access is restricted to eligible entities and to the practitioner named in a report. It also isn't a credentialing decision-maker: a hospital's medical staff office or credentialing committee still has to interpret what a report means and decide what action, if any, it warrants. Two organisations with an identical NPDB report on the same practitioner can reasonably reach different credentialing conclusions depending on the surrounding context they gather through their own review.

Where NPDB fits alongside other credentialing checks

The NPDB is one input into a wider credentialing process, not the whole of it. It typically sits alongside primary source verification of licensure and education, exclusion list screening against federal and state databases, and any organisation-specific criteria a credentialing committee applies. Confusing "we queried the NPDB" with "we've completed credentialing" is a common gap — a clean NPDB report says only that no reportable adverse action exists in the Data Bank, not that every other element of a proper credentialing file has been verified.

FAQ

Do hospitals have to query the NPDB for every practitioner, every year?
Hospitals must query at initial appointment or when granting privileges, and at least once every two years thereafter for practitioners who continue to hold privileges. Many run more frequent internal reviews on top of that federal minimum, particularly around renewal cycles.

Can a practitioner see what's in their own NPDB file?
Yes, through a self-query. This returns the same information an authorized entity's query would return, along with a verification code the practitioner can share to confirm authenticity.

Is a malpractice payment automatically reported to the NPDB?
Payments made on a practitioner's behalf in connection with a written malpractice claim or judgment are reportable, regardless of whether the payment came with an admission of fault. The report itself doesn't state a legal conclusion about liability — it records that a payment was made.

Does a clean NPDB query mean a practitioner is fully credentialed?
No. It means no reportable adverse action currently exists in the Data Bank. A complete credentialing file also requires primary source verification, exclusion list screening, and whatever additional review a specific organisation's credentialing policy requires.

The NPDB is a narrow but consequential piece of the US credentialing landscape, and understanding exactly what it reports, who must query it, and what it doesn't cover is worth getting right before it becomes a gap in someone's file. Learnsignal's guides to OIG exclusion list screening and delegated credentialing cover the adjacent pieces of a complete credentialing process. Get in touch to talk through compliance training for US healthcare credentialing teams.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans