FOUNDING5050% off for lifeSee pricing →
UPP
UPP
Universal Provider Passport
Sign in
Verification methodology

How we verify a credential — and prove it later.

Every field on a UPP passport is verified against the issuing authority, signed, and continuously re-checked. This page documents the exact sources, the workflow, the cadence, and how we handle disagreement and audit. No black boxes.

NCQA CR-aligned SOC 2 Type II 24/7 monitoring Avg verification < 30 days

The 11 primary sources

We query each authority directly. No aggregator middle layer, no cached snapshots presented as fresh. Every response is stored with its source URL, raw payload hash, and timestamp.

Live vs simulated, per source. UPP is pre-Seed. NPPES (free public CMS API) is live in production today. Every other source has a working adapter wired against its real API contract, returning deterministic fixtures until a partner key or data-license agreement is signed. Each card below tells you exactly what mode it is in right now — no hand-waving.
Source 01
NPPES
National Plan & Provider Enumeration System
NPI, taxonomy, practice address, sole proprietor status.
Every 24hView rules & evidence →
Source 02
CAQH ProView
Council for Affordable Quality Healthcare
Demographics, work history, attestations, malpractice history.
Real-time on attestationView rules & evidence →
Source 03
PECOS
Provider Enrollment, Chain & Ownership System
Medicare enrollment status, reassignments, opt-out status.
Every 24hView rules & evidence →
Source 04
OIG LEIE
Office of Inspector General — List of Excluded Individuals/Entities
Federal healthcare program exclusions and reinstatements.
Daily, on publishView rules & evidence →
Source 05
SAM.gov
System for Award Management
Federal debarment, suspension, and active exclusion records.
DailyView rules & evidence →
Source 06
NPDB
National Practitioner Data Bank
Malpractice payments, adverse actions, clinical privileges actions.
On query + scheduled re-queryView rules & evidence →
Source 07
ABMS
American Board of Medical Specialties
Board certification status, specialty, MOC participation, expiration.
Every 7 daysView rules & evidence →
Source 08
AOA
American Osteopathic Association
Osteopathic board certification status and specialty.
Every 7 daysView rules & evidence →
Source 09
DEA CSA
Drug Enforcement Administration — Controlled Substance Act registry
DEA number, schedules, registered address, expiration.
Every 24hView rules & evidence →
Source 10
State Medical Boards
All 50 state boards + DC, PR, USVI, Guam
License status, issue/expiration dates, disciplinary actions, restrictions.
Every 24hView rules & evidence →
Source 11
FSMB / ECFMG
Federation of State Medical Boards & Educational Commission for Foreign Medical Graduates
Disciplinary alert flags, ECFMG certification for IMGs, medical education verification.
Every 24h (FSMB) / on issue (ECFMG)View rules & evidence →
Source 12
AAMC / Medical School Registrar
Association of American Medical Colleges and accredited medical school registrars
Medical school enrollment, degree conferral, graduation date, and residency / fellowship completion — confirmed against the issuing institution's registrar.
On credential add + every 365dView rules & evidence →

The PSV workflow

Primary Source Verification is the same six steps for every credential, every time. Each step is timestamped, written to the immutable audit trail, and emits events that downstream systems (notifications, packets, receivers) subscribe to.

  1. Step 01
    ~5 min Provider

    Intake & identity proofing

    The provider proves who they are with a government ID, a live selfie, and confirmed email and phone.

    Provider creates a passport. Government ID + selfie match (NIST 800-63 IAL2). Email and phone independently verified.

  2. Step 02
    Seconds – 48h Verifier worker

    Primary source query

    We ask each issuing authority directly — state board, DEA, ABMS, OIG, and the rest — for the truth about each field.

    For every field, we query the issuing authority directly — never an aggregator. Raw response, source URL, and timestamp are captured.

  3. Step 03
    < 1s Match engine

    Match & normalize

    We compare what the provider said against what the source returned. Matches are recorded; mismatches are flagged for review.

    Returned data is matched against attested data using deterministic rules (NPI, license #, board ID). Field-level discrepancies are flagged, not silently overwritten.

  4. Step 04
    < 200ms Signing service (HSM)

    Cryptographic sign

    Verified fields are sealed with a cryptographic signature so any later tampering is detectable.

    Verified fields are bound to a credential record, hashed, and signed with UPP's verification key. The signature, source citation, and timestamp travel with the credential forever.

  5. Step 05
    Daily – event-driven Monitor scheduler

    Continuous monitoring

    We re-check every credential on a regular cadence. If anything changes, the provider and any organization holding the packet are notified.

    Every credential is re-queried on a fixed cadence. Any state change triggers re-verification and notifications to the provider and any organization holding an active packet.

  6. Step 06
    Annual + on-change Provider + system

    Versioning & re-attestation

    Every verification is saved as an immutable version, so you can always see exactly what was true on any past date.

    Each verification produces an immutable version. Providers re-attest demographics annually or on change; verifications continue independent of attestation.

Continuous monitoring

Verified once isn't verified.

Credentials drift. Licenses expire, DEA renewals lapse, board certifications change status, exclusion lists update overnight. UPP re-checks every credential on a fixed cadence so a packet you send today still reflects reality tomorrow.

Real-timeInstant on attestation or event
DailyRe-checked every 24 hours
WeeklyRe-checked every 7 days
Event-drivenOn query + scheduled re-query
Discrepancy handling

When sources disagree, we don't pick a winner.

Silent reconciliation is how bad credentialing data spreads. UPP surfaces every mismatch with full provenance so the committee — not the platform — decides.

Surface, don't reconcile

When attested data and source data disagree, both values are shown side-by-side with the source citation. UPP never silently rewrites the provider's record to match a source, and never rewrites a source to match attestation.

Severity classification

Discrepancies are tagged Informational (formatting, casing), Material (date drift > 30 days, address mismatch), or Blocking (license status mismatch, exclusion hit, identity mismatch). Blocking issues prevent packet send until resolved.

Provider-led resolution

Providers see every discrepancy in their wallet with a one-click flow to either update their attestation or open an evidence ticket. Resolution steps are themselves logged as evidence.

Receiver visibility

Hospitals and payers receiving a packet see the full discrepancy history — not a sanitized snapshot. Nothing is hidden from the credentialing committee.

Source-down handling

If a primary source is unreachable, the affected field is marked stale with the last successful timestamp. We never substitute cached data as fresh verification.

Audit trail

Every read, write, and verification is provable.

The audit trail is the substrate the rest of the methodology rests on. It's append-only, hash-chained, and exportable — so a credentialing committee, an auditor, or a court can independently reconstruct what was verified, by whom, and when.

Every action is logged

Reads, writes, verifications, packet sends, consent grants, and admin actions are all recorded with actor, timestamp, IP, and request ID.

Append-only & hash-chained

Audit entries are append-only and chained via SHA-256 — any tampering breaks the chain and is detected on next read.

Customer-managed keys (Enterprise)

Enterprise customers can bring their own KMS keys. UPP encrypts at rest with AES-256 and in transit with TLS 1.2+.

Provider-facing transparency

Providers see every access to their record — who looked, when, and why — in their wallet activity log.

Export on demand

Full audit trails are exportable as signed JSON for legal hold, NCQA file review, or internal investigation.

Isolated infrastructure

Production runs in HIPAA-eligible, SOC 2 Type II infrastructure with isolated tenancy boundaries and least-privilege access controls.

Data protection & security

How we protect data — from storage to deletion.

UPP handles some of the most sensitive data in healthcare: identities, licenses, malpractice history, and federal exclusions. Our security model is built to protect that data at every layer — with specifics you can verify and auditors can test.

Encryption at rest — every byte, every field

All stored data is encrypted at rest with AES-256-GCM. PII and credential payloads receive field-level encryption with HSM-backed keys so that even in the unlikely event of storage compromise, individual fields remain unreadable without the key material. Key rotation is automatic and audited.

Encryption in transit — TLS 1.3, pinned, HSTS

Every API call, webhook, and packet transfer uses TLS 1.3 with perfect forward secrecy. We enforce HSTS, use certificate pinning for mobile and embedded clients, and reject any downgrade attempt. SFTP endpoints require strong cipher suites and key-based authentication.

Customer-managed keys (Enterprise)

Enterprise customers can bring their own AWS KMS, Azure Key Vault, or GCP Cloud KMS keys. UPP never holds the plaintext of your master key — we use envelope encryption so your KMS policy, rotation schedule, and revocation rights remain under your control.

Role-based access with least privilege

Access is governed by role-based controls (RBAC) mapped to real job functions: provider, reviewer, committee member, admin, auditor. Each role receives the minimum permissions required. MFA is enforced for all admin and reviewer accounts. Enterprise plans support SSO/SAML and SCIM provisioning.

Tenant isolation at the infrastructure layer

Production runs on HIPAA-eligible, SOC 2 Type II infrastructure with isolated tenancy boundaries. Databases, caches, and object storage are segmented so that no tenant's data is co-mingled with another's at the persistence layer. Network policies enforce microsegmentation between services.

Provider-facing access transparency

Providers see every access to their record — who looked, when, from which IP, and for what stated purpose — in their wallet activity log. Any anomalous access pattern triggers an automatic alert to the provider and to UPP's security operations team.

Data retention & deletion you control

Providers can request full export or deletion of their passport at any time. Enterprise customers set retention policies aligned with legal hold requirements. Deleted data is cryptographically shredded — not just unlinked — and the shredding event itself is logged in the immutable audit trail.

24/7 incident detection & response

Our security operations center monitors for anomalous queries, brute-force attempts, and data exfiltration patterns via SIEM integration. If a breach is suspected, affected customers are notified within 72 hours. We run quarterly penetration tests and annual third-party risk assessments.

Why UPP is the clear choice

What makes us different — with the specifics that matter.

Credentialing is crowded with attestation profiles, legacy CVOs, and generic identity tools. Here is exactly where UPP diverges, why each difference matters operationally and legally, and the proof points behind the claim.

PSV-first, not attestation-first

vs. CAQH ProView, Modio, Medallion

Every field on a UPP passport is verified at the source before it is presentable. Competitors lead with self-attested profiles and bolt verification on as a paid add-on or a manual ops queue.

Why it matters

Hospitals and payers receive evidence, not assertions. NCQA file review, Joint Commission audits, and CMS directory accuracy reviews all require source-cited proof — not a profile screenshot.

Proof: 11 primary sources queried directly. Raw payload hashed, timestamped, and stored with each field.

Reusable signed packets, not point-to-point files

vs. symplr CVO, MD-Staff, Echo, Verge

A single verified passport produces signed, time-bound packets that any hospital, payer, or board can consume. Legacy tools rebuild a credential file from scratch for every receiver.

Why it matters

Eliminates the 90–150 day re-credentialing slog when a physician joins a new system or a new payer panel. One verification, many disclosures, zero re-keying.

Proof: Avg. time-to-revenue cut by up to 80% across pilot cohorts. Median packet send-to-accept under 7 days.

Continuous monitoring on every source, every day

vs. Manual CVO recheck cycles, batch monthly reports

Sanctions, license revocations, and DEA lapses can land overnight. We re-query the 11 sources on a fixed cadence (most daily, NPDB on Continuous Query) and re-sign on change.

Why it matters

A packet sent yesterday still reflects reality today. No annual re-verification cliff. No surprise OIG hits between recredentialing cycles.

Proof: Daily sweeps of NPPES, PECOS, OIG LEIE, SAM.gov, DEA, state boards, FSMB. NPDB Continuous Query enrollment supported.

Discrepancies are surfaced, never silently reconciled

vs. Aggregator data feeds, opaque CVO reports

When attested data disagrees with a primary source, both values are shown side-by-side with full provenance. We never overwrite either side to make the record look clean.

Why it matters

Silent reconciliation is how bad data spreads across the credentialing ecosystem. Committees need to see the mismatch to make a defensible decision — and to defend it years later in litigation.

Proof: Severity-tagged (Informational / Material / Blocking) with one-click provider resolution and immutable resolution history.

Tamper-evident, exportable audit trail

vs. Database-row history logs, PDF-only audit reports

Every read, write, verification, packet send, and consent grant is append-only and SHA-256 hash-chained. Any tampering breaks the chain and is detected on next read.

Why it matters

When a malpractice suit, NCQA file review, or DOJ subpoena lands, you can reconstruct exactly what was verified, by whom, when, and from which source — in signed JSON.

Proof: Customer-managed KMS keys on Enterprise. Signed JSON export. Provider-facing access log built in.

Provider-owned, portable identity

vs. Hospital-owned credential files, CVO-locked records

The provider — not the hospital, not the CVO, not the aggregator — owns the passport. They grant time-bound, revocable disclosures to each receiver.

Why it matters

Physicians change jobs, add payer panels, and join locums networks constantly. Provider-owned identity is the only model that survives those transitions without re-verifying from zero.

Proof: Revocable packet share links. Per-field consent. Wallet activity log shows every external access.

Built for integration, not for lock-in

vs. Closed credentialing suites with proprietary data exports

Direct API and SFTP connectors to Epic, Cerner, symplr, MD-Staff, Modio, Echo, Verge — plus NPPES, CAQH, PECOS, and state boards. Data flows in and out without re-keying.

Why it matters

MSOs and payer ops teams already have systems. UPP augments them with verified data and continuous monitoring; it does not force a rip-and-replace.

Proof: Documented REST API, webhook events, signed JSON exports, and bring-your-own SSO/SAML on Enterprise.

Compliance-aligned by default

vs. Generic identity platforms repurposed for healthcare

Methodology mapped to NCQA CR-001 through CR-008, Joint Commission MS.06.01.03/05/07, and CMS directory accuracy rules under the No Surprises Act.

Why it matters

Buyers do not have to translate our outputs into their auditor's framework. The packet itself satisfies the evidence requirement for the cited standard.

Proof: SOC 2 Type II, HIPAA-eligible infrastructure, BAA on Enterprise, NCQA-aligned PSV workflow documented above.

Side-by-side: UPP vs. the alternatives

Capability-by-capability comparison with attestation networks (CAQH ProView) and legacy CVO / credentialing suites (symplr, MD-Staff, Modio, Echo, Verge).

CapabilityUPPAttestation networkLegacy CVO / suite
Primary source verification included
Yes — all 11 sources, every credential
No — attestation only
Yes — manual, per request
Continuous monitoring
Daily on most sources; NPDB Continuous Query
No
Quarterly or annual recheck
Reusable signed packets across receivers
Yes — one verification, many disclosures
No — receiver pulls profile each time
No — new file per receiver
Provider-owned, revocable consent
Yes — per-packet, time-bound
Partial — global roster authorization
No — hospital owns file
Discrepancy surfacing with provenance
Side-by-side, severity-tagged, never overwritten
Not applicable (no PSV)
Buried in PDF report
Tamper-evident, exportable audit trail
Append-only, SHA-256 chained, signed JSON export
Profile change history only
Internal DB log, PDF on request
Typical time-to-completion
Initial passport < 30 days; reuse < 7 days
Provider time only; receiver still verifies
90–150 days per receiver
Integration with EHR / MSO suites
API + SFTP to Epic, Cerner, symplr, MD-Staff, Modio, Echo, Verge
Limited bulk exports
Vendor-specific, often manual
Compliance mapping out of the box
NCQA CR, Joint Commission MS.06, CMS NSA directory
Roster compliance only
Varies by vendor
The net effect: UPP is the only platform that combines provider-owned identity, primary-source verification on every field, daily continuous monitoring, and a tamper-evident audit trail in one reusable, signed packet. That combination is what turns credentialing from a 90–150 day cost center into infrastructure — and what makes us the defensible choice when an auditor, a payer, or a court asks you to prove it.
The result

The nation's first truly portable credentialing passport — one that never expires and never has to be reconstructed.

Continuously verified at the source. Continuously updated as the world changes. Always available the moment a hospital, payer, board, or locums network needs it. Built once, owned by the provider, and trusted by every receiver — for the life of the career.

Never expires Continuously updated Provider-owned, fully portable Always audit-ready
Frequently asked questions

Common questions about trust, PSV, and auditability.

These answers explain how UPP handles the edge cases and concerns that credentialing committees, compliance officers, and providers ask most often.

Glossary

Terms used throughout this methodology.

Precise definitions for the concepts, statuses, and processes described in the verification workflow, discrepancy handling, and audit trail sections.

PSV (Primary Source Verification)

The process of verifying a credential by querying the issuing authority directly, rather than accepting self-attested data, photocopies, or third-party summaries.

Attestation

A provider's signed declaration that the information in their profile is accurate and complete. Attestations expire after 120 days on UPP.

Discrepancy

Any mismatch between attested data and primary-source data. Discrepancies are classified as Informational, Material, or Blocking based on severity.

Blocking discrepancy

A mismatch that prevents a credential packet from being sent until resolved. Examples include license status mismatch, exclusion hits, or identity mismatches.

Material discrepancy

A significant mismatch that does not block packet sending but requires committee awareness. Examples include date drift > 30 days or address mismatches.

Informational discrepancy

A minor mismatch such as formatting, casing, or punctuation differences. Does not affect credentialing decisions but is logged for completeness.

Credential packet

A compiled, signed set of verified credentials shared with a hospital, payer, or board. Packets are versioned and include the full audit trail.

Audit trail

An append-only, hash-chained log of every read, write, verification, and access event on a credential record. Tamper-evident by design.

Source citation

The metadata attached to every verified field, including the source name, retrieval URL, timestamp, and raw payload hash.

Stale flag

A status marker applied when a primary source is unreachable or the credential has not been re-verified within its expected cadence. Indicates the last successful check timestamp.

Continuous Query (NPDB)

An NPDB enrollment that pushes real-time alerts when a report is filed against a provider, replacing the need for periodic re-query.

Revalidation (PECOS)

The periodic re-enrollment required by CMS to maintain Medicare billing privileges. PECOS revalidation due within 60 days surfaces as a Material warning.

Exclusion (OIG LEIE / SAM.gov)

A federal prohibition on participation in Medicare, Medicaid, or other government programs. Any active exclusion is a Blocking discrepancy.

MOC / OCC

Maintenance of Certification (ABMS) or Osteopathic Continuous Certification (AOA). Participation lapses on time-limited certifications are surfaced as Material discrepancies.

Cryptographic sign

A digital signature applied to a verified credential using an HSM-backed key pair. Proves the credential was verified by UPP and has not been altered since signing.

Tenant boundary

The isolation layer that ensures organizations can only access their own packets and provider data. Enforced at the infrastructure level with role-based access controls.

Verify a credential against this methodology.

Create a passport in minutes, or talk to us about onboarding your hospital, payer network, or board.