ACHDM

American College of Health Data Management

American College of Health Data Management

How payers and states could build the next generation of provider trust

Provider trust will grow if there’s a practical adoption signal, which is most likely to come from the payers and state initiatives.




A verifiable provider identity model will not scale because it is technically elegant. It will scale when it becomes operational, when it delivers benefits and reduces burdens for the providers and organizations that use it.

That is the next challenge for provider directory modernization. Healthcare can define verifiable organizational identity, issue role credentials and connect those credentials to API security workflows. But unless the model shows up inside real payer, provider, licensing and directory workflows, it will remain a promising architecture rather than a working trust layer.

The reality is simple. Provider trust needs a practical adoption signal. For provider directories and credentialing, that signal is most likely to come from payers.

Why payers move first

Providers credential with many payers. That makes payers one of the natural starting points for adoption.

A national payer manages provider participation across multiple products, geographies, delegated credentialing arrangements and regulatory requirements. It also carries the operational burden when provider identity, credentialing evidence, network participation or directory data is wrong. That gives payers both the problem and the workflow leverage.

If a payer signals that verifiable organizational identity is a preferred part of network participation or credentialing intake, the demand begins to move through the ecosystem.

Medical groups need a way to prove organizational identity. Health systems need to support signed delegated credentialing assertions. State boards and credential issuers begin to see a practical reason to issue digitally verifiable credentials. When that verifiable organization identity is portable across multiple payers, the benefits compound.

This is how many healthcare standards scale. The industry does not adopt new infrastructure only because it is better in theory. It adopts when the workflow changes, the administrative burden becomes too high or the new model makes the existing process easier to operate. For provider trust, payer adoption can create that signal.

Adoption must be operational

For this model to work, payer adoption cannot be theoretical. The payer has to use them in real workflows.

That begins with the payer obtaining its own organizational vLEI. This is the “eat your own cooking” step. If a payer expects providers, health systems and credential issuers to use verifiable organizational identity, the payer should be able to prove its own legal entity identity in the same framework.

The next step is role authority. Payers need to issue verifiable role credentials to the people and systems authorized to participate in provider contracting, credentialing, network management and directory operations. Provider trust is not only about the organization. It is also about who or what is authorized to act on behalf of that organization.

Then the payer must connect the trust layer to existing infrastructure. In practice, that means integrating vLEI-based organizational identity into FHIR API access, FAST/UDAP software statements, provider directory workflows, credentialing intake and delegated credentialing oversight.

It should begin as an added trust layer alongside CAQH, NPI, existing credentialing platforms and provider data management workflows. During the transition, payers will still need to credential providers with and without verifiable credentials. The goal is not to create a two-tier provider experience, but rather to make the verifiable path more efficient over time.

For example, payers could offer faster credentialing timelines, reduced recredentialing burden or simplified directory attestation for providers and organizations that can present verifiable credentials from authoritative sources. That creates adoption through operational value, not mandate pressure alone.

Multi-payer coordination matters

One national payer can create a meaningful signal, but several national payers moving together can make the signal much more difficult to ignore.

If major payers align around a common expectation for portable, verifiable organizational identity and credential evidence, provider organizations will begin to see it as a shared operating pattern. That matters because the value of verifiable credentials depends on portability.

A board-signed license credential should not have to be recreated for each payer. A delegated credentialing attestation should not live only inside one platform. A network participation assertion should be usable by parties that support the same trust framework. This requires neutral coordination.

Healthcare needs a pre-competitive trust framework, not another proprietary provider identity system. DirectTrust is one logical convening body because of its role in healthcare trust infrastructure, standards, accreditation and security frameworks. CAQH also could play a role because of its payer relationships and credentialing context, provided the model remains open and portable rather than proprietary and platform-controlled.

The key point is simple. Multi-payer coordination reduces fragmentation. Without that coordination, verifiable provider identity risks becoming another set of parallel workflows. With it, the industry has a clearer path toward reusable proof.

The ecosystem must participate

Payers can create demand, but they cannot scale the model alone.

Provider directory and credentialing workflows run through EHRs, credentialing platforms, clearinghouses, enrollment systems, API gateways, HIEs, QHINs, state and federal agencies and health plan operating environments. For verifiable provider identity to become useful, it must appear in the systems where the work already happens.

EHR vendors can support organizational identity and role credentials in provider, facility and affiliation management. Clearinghouses can support verifiable credentials in enrollment and payer-provider transactions. Credentialing platforms can accept signed credentials from authoritative issuers instead of relying only on manual source checks. QHINs and health information networks can help propagate a consistent trust framework across participating organizations.

This is similar to how other healthcare interoperability capabilities have scaled. The SMART on FHIR standard gained traction because developers, EHR vendors, providers and regulators could see where it fits inside real workflows. The same lesson applies here. Verifiable provider trust will scale when it becomes useful to the ecosystem, not just technically possible.

Utah SEDI: A practical starting point

Every national architecture needs a place to start. Utah’s State-Endorsed Digital Identity initiative provides a practical starting point because it already reflects many of the same principles of open standards, cryptographic verification, privacy-preserving design and state-level digital identity governance.

That matters because a state that doesn't have a digital identity foundation would need to begin with the basic trust model. Utah has already done much of that work. The conversation can move more quickly to implementation.

The most practical use case is professional licensing. If the Utah Division of Occupational and Professional Licensing became a vLEI-capable issuer, it could issue digitally signed license credentials to physicians or other licensed professionals. A payer operating in Utah then could accept those credentials as authoritative evidence inside its credentialing workflow.

This would not change the responsibility of the licensing board. The board would still be attesting to licensure status. It would not change the responsibility of the payer. The payer would still make its own credentialing decision. What changes is the evidence. Instead of calling the board, checking a website or relying on a static file, the payer could verify a board-signed credential cryptographically. The evidence becomes portable, verifiable and auditable.

That kind of proof point can change policy conversation. After a state licensing authority and a payer demonstrate the model in a real credentialing workflow, other states can evaluate something concrete. The question moves from, “Could this work?” to “How do we implement it safely and consistently?”

Implications for provider trust

A payer-and-state adoption pathway enables several things with which the current system struggles.

Provider trust can start inside real workflows. Credentialing intake, directory updates, delegated credentialing oversight and network participation are practical places to begin.

State licensing authorities can become digital credential issuers. Boards can continue serving as authoritative sources, but in a form that relying parties can verify directly.

Providers can reduce repeated evidence submissions. If verifiable credentials are accepted by multiple payers, providers don't have to keep repeating the same attestation and documentation process.

Directory assertions can become more accountable. Network status, affiliation, location and delegated credentialing assertions can be signed and audited instead of reconciled only through periodic outreach.

Trust can become portable. The same evidence can be evaluated by multiple organizations if they support the same open trust framework.

These capabilities will eventually reduce friction, improve auditability and strengthen the reliability of provider directory and credentialing workflows.

Moving to practical implementation

The industry needs one or two payers willing to serve as anchor participants. Those payers should obtain organizational vLEIs, issue internal role credentials and integrate verifiable organizational identity into provider directory and credentialing workflows.

The industry also needs at least one state licensing authority willing to issue verifiable credentials. Utah is a strong candidate because of SEDI’s alignment with open, cryptographic, rights-preserving digital identity.

Standards and trust framework organizations also need to resolve implementation details. How should vLEI credentials be referenced in FAST/UDAP workflows? Should full credential chains be embedded, or should high-volume API transactions use a reference and resolution model? How should payers handle coexistence during a multi-year transition period? What incentives make the verifiable path easier for providers rather than simply adding another requirement?

These are not reasons to wait; they are the work of implementation. Healthcare has already moved from paper claims to electronic transactions, from custom interfaces to FHIR APIs, and from local exchange models to national trust frameworks. Provider trust is the next layer that needs modernization.

The industry has modernized how data moves; now it needs to modernize how provider identity, credentialing evidence and network participation are trusted. That will not happen through technology alone. It will happen when payers, states, trust framework organizations and health technology vendors align around a shared model that makes verifiable trust operational.

Mark Scrimshire is chief interoperability officer at Onyx Health, where he leads its standards and interoperability strategy. He was the architect of CMS Blue Button 2.0 and author of the HL7 Da Vinci PDex standard on which CMS-0057 is built.



More for you

Loading data for hdm_tax_topic #reducing-cost...