Primary Source Verification (NCQA PSV): What Changed in 2025-2026

NCQA shortened PSV completion windows to 120/90 days and tightened ongoing sanctions monitoring to every 30 days. Here's what changed and how to stay compliant.

Learnsignal Education Team
5 min read
Updated

Credentialing teams just lost a third of their runway. As of 1 July 2025, NCQA cut the window for completing primary source verification (PSV) from 180 days to 120 days for Accreditation and just 90 days for Certification — and tightened ongoing sanctions monitoring to at least every 30 days. For any organisation still running credentialing on the old six-month assumption, that's not a minor scheduling adjustment; it's a compliance gap waiting to be found at the next audit.

What primary source verification actually requires

PSV means confirming a practitioner's credentials directly with the issuing body or original source — not accepting a copy of a license or a CV entry at face value. NCQA's credentialing standards specify 11 elements that a complete PSV file must cover: state license, DEA registration, education and training, board certification, work history, malpractice history, sanctions checks, application processing, attestation content, and both initial and ongoing Medicare/Medicaid sanctions monitoring. Missing or stale verification on any one of these is a finding, not a formality — it's the difference between a credentialed practitioner and one whose file simply looks credentialed.

The window just got much tighter

Before July 2025, organisations had a relatively comfortable 180 days to complete PSV on a practitioner file. That's now been compressed to 120 days for NCQA Accreditation and 90 days for Certification — roughly a third to half of the previous runway. The practical effect: a credentialing process built around occasional batching or a "we'll catch up before the deadline" rhythm is now structurally too slow. Files that would have cleared comfortably under the old window can now lapse into non-compliance before anyone notices they're behind.

Ongoing monitoring tightened at the same time. License expirations, OIG and SAM exclusion checks, and sanctions monitoring must now happen at least every 30 days, replacing what was often a quarterly or semi-annual cycle. A practitioner who picks up a sanction or lets a license lapse is now expected to surface in an organisation's own monitoring within a month, not a quarter.

What's new beyond the timeline

Two other changes reshape how a credentialing program has to operate:

  • A formal Information Integrity requirement. Organisations must now run an annual audit of their credentialing data and train staff specifically on data integrity — this wasn't a standalone, named requirement before.
  • New application fields. Applications must include voluntary demographic fields (race, ethnicity, language) alongside a non-discrimination statement — a structural change to the intake form itself, not just the verification workflow behind it.

Separately, a July 2024 change loosened how much of the PSV workload can be outsourced: organisations may now delegate more than 50% of primary source verification to an NCQA-accredited or NCQA-certified delegate, a cap that previously constrained how much credentialing work could be handed off. For an organisation weighing whether to bring PSV capacity in-house or lean on a delegate to absorb the shorter windows, that's a real lever — but delegating volume doesn't delegate accountability for the underlying credentialing and privileging decision itself.

Why this matters beyond the audit checklist

Credentialing gaps don't stay contained to a paperwork finding. A practitioner working under a lapsed verification, or a sanction that monitoring should have caught within 30 days but didn't, is a direct patient-safety and liability exposure — not just a technical non-compliance. The same documentation discipline that matters when investigating and documenting an incident applies just as much upstream, before a practitioner ever sees a patient: a credentialing file is only as strong as the verification behind it, and a compressed timeline makes weak processes visible faster than before.

Building a credentialing process that survives the shorter window

  • Move from batch to continuous processing. A once-a-quarter credentialing push doesn't fit inside a 90-day Certification window with any margin for delay or missing documentation.
  • Automate the 30-day monitoring cycle. Manually checking OIG, SAM, and state license status every 30 days across a large practitioner roster is exactly the kind of recurring task that should be systematised, not left to a recurring calendar reminder.
  • Decide the delegation question deliberately. With the 50%+ delegation cap lifted, evaluate whether an NCQA-accredited delegate genuinely reduces risk for your organisation's volume, rather than defaulting to either fully in-house or fully outsourced.
  • Build the Information Integrity audit into the annual compliance calendar now, rather than treating it as a new item to scramble for closer to a survey.

Frequently asked questions

Does the shorter PSV window apply to every organisation immediately?
The 120-day (Accreditation) and 90-day (Certification) windows took effect 1 July 2025 as part of NCQA's current credentialing standards — organisations should confirm which standard applies to their specific accreditation or certification status.

What counts as "ongoing" sanctions monitoring under the new rule?
At minimum, checking license status, OIG and SAM exclusion lists, and sanctions at least every 30 days — a marked tightening from the quarterly or semi-annual cycles many organisations previously ran.

Can PSV be fully outsourced now?
Organisations can delegate more than 50% of PSV work to an NCQA-accredited or NCQA-certified delegate as of July 2024, but the credentialing organisation remains accountable for the underlying decision, not just the verification task.

A credentialing process that worked comfortably under a 180-day window doesn't automatically survive a 90-day one. Learnsignal's CPD training library covers credentialing, primary source verification, and the compliance processes healthcare organisations need to keep pace with tightening NCQA standards.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans