ACHDM

American College of Health Data Management

American College of Health Data Management

How to better facilitate cryptographic provider identity

In a complex healthcare world using real-time API-driven verification, organizations need to move beyond current trust models.



This article is part 2 in a 3-part series. Read part 1: Healthcare’s provider directory problem is an inherent trust issue.

As healthcare works to modernize provider directories and credentialing workflows, one foundational issue keeps rising to the surface — the current trust model was not designed for real-time API-driven verification.

We can improve data quality, streamline credentialing intake, implement FHIR APIs and standardize security profiles. But without a reliable way to verify the legal entity and their delegates behind a transaction, and the authority of that entity to make a claim, provider directory accuracy will continue to depend on manual processes that do not scale.

The reality is simple — provider and provider organization identity needs to become verifiable.

That does not mean replacing every system healthcare already uses. It means adding a trust layer that enables directory assertions, credentialing evidence and organizational identity to be verified in a consistent way across the ecosystem. The shift is from trusting a platform to verifying the proof.

CAQH helps, but it leaves gaps

CAQH ProView has created real value for healthcare. It reduced duplicate data entry, gave providers a common place to maintain credentialing information and gave participating payers a more efficient way to access provider-supplied data.

But CAQH is still a trusted intermediary model. In that model, payers trust the data because CAQH collected it, manages it and makes it available through its platform. Providers attest to information. Verification occurs through established workflows. Payers access the data through the CAQH environment.

This model improves consolidation, but it does not fully solve the trust problem. The credential does not travel with independently verifiable proof. Verification depends on access to the platform. Revocation or status change depends on notification, update and synchronization. A relying party still depends on the intermediary to confirm what is true. These are not failures of CAQH — they are the limits of a platform-centered approach.

Healthcare needs the next layer, which provides a way for authoritative issuers to sign credentials directly, and which also enables relying parties to verify those credentials without recreating the same centralized manual verification process.

A foundation for verifiable identity

The verifiable Legal Entity Identifier (vLEI) offers a path forward. The Legal Entity Identifier is already used globally to identify legal entities. The vLEI extends that model into a digital, cryptographically verifiable credential. It binds an organization’s identity to a secure key pair, enabling the organization to prove who it is in a digital transaction.

Most major U.S. healthcare organizations already have a Legal Entity Identifier that Is the basis for generating a vLEI. For healthcare, this matters because many provider directory and credentialing questions are really organizational identity questions. These include questions such as, is this medical group the legal entity it claims to be? Is this payer the organization operating the API client? Is this health system authorized to make a delegated credentialing assertion? Is this state licensing board the authoritative issuer of the license credential? And is this individual or system acting on behalf of the organization in an authorized role?

Today, these questions are often answered through onboarding workflows, contracts, attestations, static directories, certificates, proprietary systems and manual review. A vLEI-based model enables those questions to be answered through verifiable credentials and a shared chain of assurance.

The organization holds a cryptographically controlled identifier. Authoritative issuers can issue signed credentials. Relying parties can verify the issuer, the credential, the integrity of the data and the chain of authority. This moves the industry from repeated manual validation to reusable digital proof.

Identity is organizational, but authority Is contextual

In healthcare, identity is not enough by itself. A payer does not only need to know that a medical group exists. It needs to know whether that group participates in a specific network, whether a provider is affiliated with that group, whether a facility has been credentialed, and whether an individual or system has authority to make a claim on behalf of the organization.

Much of provider directory management is contextual. A provider may be in-network for one product, but not another. A facility may be credentialed through a delegated arrangement. A clinician may practice at one location, but not another. A contracting representative may be authorized for some transactions, but not all.

This is where role credentials matter. A legal entity can issue verifiable role credentials to individuals or systems acting on its behalf. In the provider directory context, that could include credentialing staff, contracting officers, authorized representatives or software systems making API-based assertions. In this era of AI, it could also be an organization enabling an AI agent to act on its behalf for certain transactions.

The question is not only, “Does this organization exist?” The deeper question is, “Does this organization, person or system have authority to make this assertion in this context?” Those are the questions that today are often answered through manual trust.

NPI identifies, vLEI proves

The National Provider Identifier remains essential. It gives healthcare a common identifier for providers and organizations across administrative transactions.

But the NPI was not designed to be a cryptographic identity infrastructure. It identifies a provider or organization. It does not prove that the entity presenting the identifier controls it. It does not establish legal entity status. It does not verify role authority. It does not carry signed credentials from authoritative issuers.

A vLEI does not replace the NPI; it strengthens the trust model around it. The NPI can continue to identify the provider or organization within healthcare transactions. The vLEI can help prove the legal entity identity, issuer authority and chain of trust behind related assertions.

Identifiers tell systems what record they are dealing with. Verifiable credentials help systems determine whether the assertion about that record can be trusted. Healthcare needs both.

UDAP secures access, but identity needs depth

The FAST/UDAP Security framework is an important step forward. It standardizes how organizations register and authenticate clients for secure FHIR API access, using certificates, signed software statements and trust community policies.

That is significant progress. But UDAP still depends on the identity claims available to it. A software statement can help identify the application making a request, but healthcare also needs deeper proof of the legal entity behind the application and the authority under which it is acting.

This is where vLEI can extend the model. A vLEI credential, or a reference to one, can be incorporated into the trust process so that API registration and access decisions can evaluate more than software identity. It also can evaluate organizational identity, legal entity status and role authority.

For provider directories, that matters. It means an API transaction can carry stronger evidence about who is making a directory assertion and why that party is authorized to make it.

This does not require healthcare to abandon the security infrastructure already being built. It extends it with a more consistent identity layer.

Liability does not change, but evidence improves

A common concern with any new credentialing infrastructure is whether it changes liability. A vLEI-based model does not change who is responsible for what.

A state licensing board is still responsible for attesting to licensure status. A payer is still responsible for credentialing decisions. A delegated credentialing organization is still responsible for the functions it has agreed to perform. What changes is the quality of evidence.

The closest analogy is a notarized signature. The notary does not become responsible for the content of the document. The notary provides independent evidence that a specific person signed a specific document at a specific time. A vLEI performs a similar function digitally and at scale.

If a state board issues a vLEI-anchored license credential, the board is doing what it already does, which is attesting to licensure status. The difference is that the credential can be independently verified by a relying party without calling the board, checking a website or relying on a static file. For a payer, this creates a stronger due diligence record. The decision is still the payer’s decision, but the evidence behind it is more immediately verifiable, portable and auditable.

What this means for provider credentialing

Pairing provider directory workflows with verifiable organizational identity enables several things with which the current system struggles.

Authoritative credentials can be verified directly. State boards, federal agencies, specialty boards and delegated credentialing organizations can issue credentials that relying parties can verify without repeating the same manual check.

Primary source verification can become less repetitive. Instead of every payer repeatedly checking the same source, credential issued by the authoritative source can carry reusable proof.

Directory assertions can become more accountable. A medical group, health system or network operator can sign assertions about affiliation, location, participation status or delegated credentialing activity.

Role authority can be clearer. Individuals and systems acting on behalf of an organization can carry verifiable role credentials, reducing ambiguity about who is authorized to make a claim.

Trust can become more portable. A credential does not have to live inside one proprietary platform. It can be presented and verified across systems that support the same open trust framework.

These capabilities will not replace existing credentialing systems overnight. But they can significantly reduce friction and strengthen the reliability of provider directory and credentialing workflows.

A trust layer for directory modernization

FHIR gives healthcare a common data language. FAST/UDAP gives healthcare a stronger security envelope for API access. CMS rules are accelerating the shift toward standardized exchange. But provider directory accuracy requires one more layer. It requires verifiable organizational identity.

A vLEI-based architecture gives healthcare a path to bind legal entities, role authority, credential issuers and directory assertions into a shared trust framework.

The industry does not need another static directory. It needs a way to verify who is making an assertion, why they are authorized to make it, and how far the evidence behind that assertion can be trusted. That is the shift from trusting the platform to verifying the claim.

In the next article, we will look at how this architecture could move from concept to adoption, and why payers, states and initiatives such as Utah’s State-Endorsed Digital Identity effort may provide the path forward.

Mark Scrimshire is chief interoperability officer at Onyx Health, where he leads its standards and interoperability strategy. He was the architect of CMS Blue Button 2.0 and author of the HL7 Da Vinci PDex standard on which CMS-0057 is built.


This article is part 2 in a 3-part series. Read part 1: Healthcare’s provider directory problem is an inherent trust issue.

More for you

Loading data for hdm_tax_topic #care-team-experience...