CAQH does not credential you.

That one sentence clears up most of the confusion around the CAQH portal. CAQH holds the information that payers use to credential you. Each health plan still runs its own review, makes its own decision, signs its own contract, and sets its own effective date. The profile is the data, the application is the trigger, and the payer makes the decision. Keep those three jobs straight and everything else about CAQH gets simpler.

CAQH credentialing is the process of creating and maintaining a provider profile in the CAQH Provider Data Portal, the shared online database commercial health plans pull from during credentialing. The provider enters licenses, education, work history, and practice details once, authorizes payers to read it, and re-attests every 120 days. CAQH stores the data. Each payer makes its own decision.

What CAQH actually is

CAQH stands for the Council for Affordable Quality Healthcare, an alliance of health plans and healthcare trade associations. It launched the provider portal in 2002 as an answer to a paper problem: every payer was asking the same providers for the same license numbers, malpractice history, and education records on different forms, at different times, and getting different answers by accident. One shared repository replaced all of that.

The idea caught on fast. About 80 percent of U.S. physicians now have a complete CAQH profile, the CAQH database manages more than 4.8 million provider records, and about 2.5 million providers have updated or attested their data within the last 120 days. Organizations participating in CAQH provide coverage to more than 300 million Americans.

That last part is why CAQH credentialing is not really optional. Technically it is voluntary. More than 1,000 health plans and healthcare organizations request that their network providers use the portal, and all 50 states accept the CAQH credentialing application as a standard form.

Who needs one? Any provider joining a commercial payer network: physicians and non-physician practitioners, behavioral health clinicians, therapists, and dentists. A profile also becomes relevant when a provider joins or changes a group practice, adds a practice location or state license, or comes up for recredentialing. Some provider types, facilities, and ancillary organizations use a different application or platform, so the payer's own instructions are always the final word.

The name map, because the names keep changing

Payer emails and manuals mix these terms freely, and the organization itself has changed names. Here is what each one means today.

Term What it means now
CAQH The established name used across payer instructions and provider workflows
CAQH ProView The former name of the provider-facing profile platform
CAQH Provider Data Portal The current name of the portal where providers maintain and share data
CAQH Provider ID The number that identifies one provider's record in the portal
DataSpring, powered by CAQH The current company brand behind the portal

In January 2026 CAQH converted from a nonprofit into a for-profit company owned by 12 shareholder companies affiliated with health plans, and on June 7, 2026 the company rebranded as DataSpring, powered by CAQH. Your account, profile, CAQH ID, and attestation history carried over unchanged. If one form asks for your ProView profile and another asks for your Provider Data Portal profile, they want the same thing.

What CAQH does and does not do

This is where most practices lose time, so it is worth being direct.

CAQH does not credential you. It collects and stores data. Credentialing decisions belong to each health plan's credentialing committee.

CAQH does not enroll you with payers. A complete, attested profile feeds each payer's credentialing review, but it is not an application. Enrollment still requires separate submissions, contracts, and effective dates with each plan.

CAQH does not cover government payers. Medicare enrollment runs through PECOS. Medicaid runs through state-specific portals. Neither reads a CAQH profile.

CAQH does not push updates to payers automatically. Authorized plans pull data on their own schedules. You can update a practice address on Monday and still appear at the old location in a payer directory weeks later.

CAQH does not maintain the profile for you. Expirations, attestations, and document refreshes are the provider's responsibility.

What goes in the profile

The portal asks for one standardized record covering the provider's professional life. The sections most practices fill in:

  • Personal and professional identifiers: legal name, date of birth, Social Security number, and Type 1 NPI
  • Education and training: medical school, residency, fellowship, with dates
  • State licenses and DEA registration, with expiration dates
  • Board certifications
  • Practice locations, hours, accessibility, and contact information
  • Hospital affiliations and admitting arrangements
  • Malpractice insurance coverage and claims history
  • Work history, typically the last five years, with explanations for any gaps
  • Disclosure questions about malpractice claims, license actions, and disciplinary history
  • Supporting documents uploaded as attachments: license, DEA, malpractice certificate, board certification, a signed W-9, and a current CV

The name field is where profiles most often break. If the license reads "John Q. Smith" and the profile reads "John Quincy Smith," primary source verification flags the mismatch and the application pauses. Match the license exactly, middle initial and all.

The five things a provider does in CAQH

Strip away the guidance and CAQH asks a provider for five things.

1. Get a CAQH Provider ID. Most providers are added when a health plan or group rosters them, which generates an ID and a registration invitation. A provider nobody has initiated can self-register in the portal. The ID follows the individual for an entire career, like an NPI. A clinician who already has one from a previous employer keeps it. Check before creating anything new, because a duplicate profile sends payers to the wrong record.

2. Complete the profile and upload documents. Expect to spend one to four hours on first-time data entry, plus however long it takes to chase down certificates and dates. Gather documents before starting, and keep the filenames clean. Profiles usually become visible to payers within days of attestation, though some practices report it taking three to ten business days.

3. Attest. Attestation is the provider's formal certification that the profile is accurate and current, and it is the step that activates the profile. A plan will not treat unattested data as usable. A profile that is fully filled in but never attested reads to a payer as unfinished, which is exactly the state that leaves a working provider unbillable.

4. Authorize payers to read the profile. This is the separate switch most people miss. A provider can grant global access, which lets any participating organization request the profile, or authorize specific organizations one at a time. A plan without authorization sees nothing, so a perfect profile that the payer cannot access is a common cause of stalled applications.

5. Maintain it. The profile is not a form you complete once. Licenses renew, malpractice certificates expire, providers move, and CAQH requires re-attestation every 120 days, four times a year, even when nothing changed. Every update should go into CAQH, NPPES, and PECOS on the same day so the three systems never drift apart.

How it connects to payer enrollment

The full sequence for one commercial payer looks like this: the group submits the payer's application (the trigger), the payer pulls the CAQH profile (the data), runs primary source verification against it, sends the file to its credentialing committee, and then executes a contract with an effective date. That is the data layer, the verification layer, and the contracting layer in order.

For a clean file, the whole thing usually runs 90 to 120 days. The stages break down roughly like this: profile completion and attestation takes one to three weeks, primary source verification takes 30 to 60 days, the credentialing committee decision takes 15 to 45 days, and contract execution takes 15 to 60 days. The CAQH stage is short and it gates everything after it. A profile with an unexplained work-history gap or a lapsed malpractice certificate stops the sequence before verification begins. In practice, enrollment stalls cluster around a handful of causes:

  • A missed re-attestation. The 120-day clock ran out and the data went stale while looking complete.
  • An expired document. A license renewal or new malpractice certificate was filed with the state or carrier but never uploaded to the profile.
  • Mismatched information. A practice address, tax ID, or name that reads one way in the profile and another way on the payer's application.
  • An unexplained history gap. A blank stretch in work history that a reviewer cannot clear without asking.
  • A missing authorization. The plan doing the credentialing was never granted access to the profile.

Nothing breaks loudly when any of these happen. Claims continue to process for payers you are already enrolled with. Patients keep coming. What quietly stops is forward motion on new applications and renewals, and practices often discover the lapse weeks later when someone asks why an application is stuck.

CAQH vs. payer-direct credentialing

Some payers accept the CAQH profile as the core of the credentialing submission, and some still want their own application forms on top of it. Either way, CAQH is the comparison that matters.

CAQH profile Payer-direct credentialing
What you complete One standardized profile Each payer's own application forms
Data entry Enter once, share with many Enter the same data once per payer
Document uploads One set, uploaded once Same documents sent to each payer separately
Authorization Authorize each payer (or globally) to read it The application itself grants access
Attestation Re-attest every 120 days Varies by payer's recredentialing cycle
What it replaces The repetitive parts of credentialing paperwork Nothing; it is the paperwork
What it does not replace The payer's own review, contracting, and effective date A CAQH profile, which the payer may require separately

Think of it this way: CAQH is the shared intake form, and each payer still runs its own credentialing process on top of it.

CAQH vs. NPI vs. PECOS vs. payer credentialing vs. payer enrollment

These records work together, but they are not interchangeable.

Record or system Primary purpose What completion proves
Type 1 NPI Identifies an individual provider The individual has an identifier, not approval
Type 2 NPI Identifies an organization The organization has an identifier, not network participation
CAQH Provider Data Portal Stores and shares professional and practice data The profile was submitted and maintained at a point in time
Payer credentialing Lets a health plan verify qualifications The payer completed its credentialing review
Payer contracting and enrollment Establishes network terms and system setup The provider may participate under the payer's written terms and effective date
PECOS Manages Medicare provider and supplier enrollment The Medicare enrollment action was processed by CMS

One more note on Medicaid: Medicaid enrollment itself runs through state systems, but many Medicaid managed-care plans do use CAQH during their credentialing, so a Medicaid-focused practice often needs the profile anyway.

Running CAQH at the practice level

One clinician maintaining one profile is a calendar reminder. A group with dozens of providers is an operations function, and the profile is where enrollment problems hide. The practices that do not get tripped up share a few habits.

Assign an owner. Every profile needs a person responsible for it, whether that is the provider, a credentialing coordinator, or an outside service. The portal supports delegate access, so someone other than the clinician can keep the data current. Just remember that attestation carries the provider's own certification, so the provider still needs to review before signing.

Track attestation dates centrally. Set reminders at day 90 and day 105 of each 120-day cycle. Groups should keep a single calendar of every provider's attestation date rather than trusting each clinician to notice a reminder email, which usually lands in an inbox nobody monitors.

Track document expirations separately. Licenses, DEA registrations, malpractice certificates, and board certifications expire on their own schedules, independent of the attestation cycle. Set reminders 60 days out, because an expired attachment invalidates the section it supports even when the attestation is fresh.

Reconcile the addresses. The practice address in CAQH, in NPPES, in PECOS, and on the payer contract should match exactly. Small differences generate directory errors downstream, and directory errors carry regulatory consequences under No Surprises Act verification rules.

Authorize before you apply. Build payer authorization into the application checklist as a separate, explicit step. Confirm it the same day the application goes in, and again if the application comes back for anything.

Review annually. Once a year, walk through every section of each profile: work history, hospital affiliations, current documents, license expiration dates. The annual review catches drift that quarterly attestation misses, because attestation is a confirmation, not an audit.

Credentialing is a process that starts with data, and CAQH is where that data lives for commercial payers. If you are still working out how credentialing fits into billing overall, our guide to what provider credentialing is covers the full picture, and our methodology page explains how we evaluate credentialing service firms in the directory.

CAQH is the data. Keep it current and enrollment keeps moving.