US provider operations · By Prateek Singh, CPCS

DataSpring/CAQH Credentialing Checklist for US Medical Practices

A practical provider-data checklist for building a complete, controlled and maintainable credentialing file.

The direct answer

A useful DataSpring/CAQH credentialing checklist has four controls: one accurate provider profile, one complete document file, one authorization and attestation process, and one maintenance calendar. A complete profile supports credentialing workflows, but it does not replace payer enrollment, contracting or final approval.

Before opening the portal

Provider-data readiness checklist
Data groupItems to prepareControl question
IdentityLegal name, other names used, date of birth where required, individual NPI and taxonomyDoes the identity match licenses, NPPES and payer records?
PracticeEntity name, TIN, organizational NPI, locations, billing and correspondence detailsAre provider, entity and location relationships clear?
ProfessionalLicenses, education, training, board details, work history and hospital affiliations where applicableAre dates complete and unexplained gaps addressed?
Risk and complianceMalpractice coverage, claims history and disclosure information where requestedAre supporting explanations and documents current?
DocumentsCV, certificates, licenses, insurance documents and requested formsAre files legible, current, correctly named and easy to retrieve?
AccessProvider authorization, delegated-user access and attestation ownershipWho is authorized to enter, review and attest?

The 12-point DataSpring/CAQH checklist

  1. Confirm the correct provider profile and individual NPI.
  2. Standardize the provider’s legal name and other names used across supporting records.
  3. Review practice entities, TINs, organizational NPIs and service locations.
  4. Verify taxonomy and specialty data against the intended payer workflow.
  5. Complete education, training and work-history dates without unexplained gaps.
  6. Upload current licenses, malpractice information, CV and other requested documents.
  7. Review hospital affiliations, board information and disclosure responses where applicable.
  8. Authorize only the health plans or organizations required for the active workflow.
  9. Use delegated access rather than sharing credentials informally.
  10. Resolve every incomplete or expired-data indicator before attestation.
  11. Record who reviewed and who completed the provider attestation.
  12. Create a quarterly and event-driven maintenance schedule.

What the official provider-data resource says

The current DataSpring provider-data fact sheet describes one profile used by many organizations, document upload, health-plan authorization and quarterly profile updates. It also states that the credentialing application is accepted in all 50 states. Individual payers and organizations still determine what additional information or workflow they require.

Maintenance is not only a quarterly task

Quarterly review is a useful baseline, but material changes should trigger a controlled update. Examples include a new license, address, service location, malpractice policy, board status, legal name, tax relationship, disclosure answer or employment arrangement. Track the change across every system that relies on the same data; a portal update does not guarantee that every payer record changes automatically.

Access and security controls

  • Use client-authorized and portal-supported delegation.
  • Limit access to the minimum functions required.
  • Do not place portal passwords in ordinary email or shared spreadsheets.
  • Keep an audit trail of updates, attestations and supporting documents.
  • Do not place patient information in a provider credentialing tracker.

Official sources

Related Neeraj RCM guidance

See US medical credentialing support, credentialing versus payer enrollment and what to check when a credentialed provider still cannot bill.

Frequently asked questions

Is DataSpring the same as the former CAQH Provider Data Portal?

DataSpring is the 2026 brand shown on current provider-data materials, while many payer and practice workflows still use the familiar CAQH terminology.

Does a complete DataSpring profile enroll a provider with every payer?

No. The profile supports provider-data exchange, but each payer or organization controls credentialing, enrollment, contracting and final decisions.

How often should the profile be reviewed?

DataSpring materials advise providers to update the profile quarterly. Practices should also update it when material provider or practice information changes.

Should portal credentials be emailed to an outside team?

No. Access should follow the portal’s delegation features, client authorization, least-privilege controls and the organization’s security procedures.

Scope note: This article provides administrative workflow guidance. Payers, government programs, licensing boards and healthcare organizations control their own requirements and decisions. Do not submit patient information through the public website.

About the reviewer

Prateek Singh, CPCS leads credentialing and revenue-cycle operations at Neeraj RCM Global Solutions. The review standard is to separate provider-data preparation, payer enrollment, contracting and effective-date confirmation rather than treating all activity as one undefined “credentialing” status.

Discuss the exact provider or payer bottleneck.

Share the provider count, states, target payers and current administrative status—without patient information.