A delegation agreement takes the credentialing file off the plan’s desk and puts it on the practice’s. What it does not move is the accountability. The plan still answers to CMS and to NCQA for every provider on the network, and the practice still answers to the plan for every element in the file.
What this covers
- NCQA requires the plan to evaluate a delegate’s capacity within the 12 months before delegation starts, and to audit credentialing files every year after that.
- The delegation agreement has to require reporting at least semiannually, and the plan keeps the right to approve, suspend or terminate any practitioner.
- Medicare reporting duties stay with the practice: an adverse legal action, a change of ownership or a new location goes to the contractor within 30 days under 42 CFR 424.516(d).
- The annual audit pulls 5 percent of credentialing files or 50 files, whichever is less, with at least 10 initial and 10 recredentialing files in the sample.
- Malpractice history and work history gaps fail late, because both are verified once and then never refreshed.
Delegation moves the work. It does not move the responsibility, and the file still has to be produced on request.NCQA puts the pre-delegation evaluation and the annual file audit on the plan, and the plan can revoke the delegation.
Where a rule is federal, the citation is in the text. Where the number is a payer or accreditation requirement, the policy is in the sources. Read the delegation agreement before the audit, because that document is the checklist the plan will score against.
What the contract actually moves
The rule that decides this sits in the Medicare Advantage contract provisions. Under 42 CFR 422.504(i)(4)(iv), when an MA organization delegates work to a first tier, downstream or related entity, the contract must say either that the plan reviews the credentials of the medical professionals itself, or that the plan reviews and approves the credentialing process and audits that process on an ongoing basis. There is no third option where nobody looks.
Medicaid managed care states the same principle from the other end. 42 CFR 438.230(b)(1) says the MCO keeps ultimate responsibility for complying with its contract with the state no matter what relationship it has with a subcontractor, and 42 CFR 438.230(c)(1)(i) requires the delegated activities and the related reporting responsibilities to be named in writing.
| What moves to the delegate | What stays where it was |
|---|---|
| Primary source verification of license, DEA or CDS, education, board status, work and malpractice history | The standard itself, which the plan still audits against every year |
| File assembly, committee packets and decision letters | The plan’s right to approve, suspend or terminate any practitioner |
| Roster maintenance and status changes | The reporting cadence written into the agreement, at least semiannual |
| The labor cost of a slow file | The revenue cost: claims wait until the file is clean and the payer agrees |
| None of the plan’s contract obligations to CMS or the state | Those, which the plan keeps and can revoke the delegation over |
The delegation agreement is the audit checklist. If it does not name the delegated activities, the reporting cadence, the performance evaluation and the remedies for noncompliance, the practice has nothing to point at when a finding is disputed.
The pre-delegation audit
NCQA requires the plan to evaluate a delegate’s capacity within the 12 months before delegation starts. That evaluation is not a conversation. Plans ask for the credentialing policies, the source used for each verification element, the committee roster, several months of committee minutes, and a provider roster with the credentialing and recredentialing date for each practitioner. Many then run a file audit using the method they will use every year after.
The annual method is fixed. A plan audits 5 percent of its credentialing files or 50 files, whichever is less, and the sample has to include at least 10 initial credentialing files and 10 recredentialing files. Where fewer than 10 practitioners were credentialed or recredentialed since the last audit, the plan audits the whole universe instead of a sample. The scoring is element by element against the plan’s own tool.
- Written credentialing and recredentialing policies, with the verification source named for each element
- The last 12 months of credentialing committee minutes, signed, dated and showing quorum
- A provider roster with the credentialing date and the next recredentialing date for every practitioner
- Dated evidence of monthly sanction and exclusion monitoring, not a description of the process
- The signed delegation agreement, including sub-delegation rules if a credentials verification organization does the verification
- An internal file audit you ran against the plan’s tool before the plan ran it
Findings come back with a deadline. Plans commonly require a corrective action plan within 30 calendar days, and a delegate that does not respond can lose the arrangement. A practice that is not NCQA-accredited or certified is audited every year. One that holds either credential gets automatic credit for the delegated elements.
A delegate is scored against the plan’s audit tool, which can add criteria beyond the NCQA element list. Ask for the tool and the scoring thresholds before the audit is scheduled.
What the practice still reports
The enrollment side of the work never delegates. Under 42 CFR 424.516(d), a physician, a nonphysician practitioner or their organization must report a change of ownership, any adverse legal action, and any change, addition or deletion of a practice location to the Medicare contractor within 30 days. Every other enrollment change goes in within 90 days. The delegation agreement does not touch those deadlines: the practice is the entity on the enrollment record.
That duty carries weight. 42 CFR 424.535(a)(9) allows CMS to revoke enrollment when the report is missed, and CMS weighs whether the data was reported at all, how late it arrived and how material it was. A practice that moved a location in March and reported it in September has handed the contractor a revocation basis no vendor can absorb.
The delegation agreement adds a second reporting layer. NCQA requires the agreement to call for at least semiannual reporting from the delegate, and many plans ask for monthly or quarterly rosters plus immediate notice of anything serious. One California health plan’s delegation policy requires immediate notice of any concern about a practitioner’s credentials, with a narrative covering the conclusions, actions and follow-up for every case of disciplinary action, denial or suspension.
Put the deadlines in one place. An adverse legal action against a provider or an owner, a change of ownership, and a new or closed practice location all go to the Medicare contractor within 30 days under 42 CFR 424.516(d)(1). Any other change to the enrollment goes in within 90 days. Roster adds, term changes and status changes go to the delegating plan on the cadence the agreement sets, at least semiannually. A license restriction, sanction or exclusion found in a monthly check goes to the plan on discovery, and then into the monitoring log.
A missed report under 42 CFR 424.516(d) is a revocation basis under 42 CFR 424.535(a)(9), and Medicare pays nothing for services furnished while a provider is deactivated.
The records the practice still has to produce
Three retention clocks apply to a delegated arrangement, and they are different lengths. The practice cannot outsource the ability to answer a request, so it has to know which clock is running on which document.
| Rule | What it covers | How long |
|---|---|---|
| 42 CFR 424.516(f) | Medical records and orders behind a Part A or Part B claim | 7 years from the date of service, with access on request |
| 42 CFR 422.504(i)(2)(iv) | Books, contracts and records held by a first tier, downstream or related entity | Through 10 years from the final date of the contract period, or the completion of an audit, whichever is later |
| 42 CFR 438.230(c)(3)(iii) | Records of a Medicaid managed care subcontractor | 10 years on the same terms |
| NCQA credentialing standards | Credentialing files | At least through the survey look-back period; NCQA does not set a longer minimum |
CMS holds the provider responsible for producing documentation even when another entity keeps it. Failure to produce is a revocation basis under 42 CFR 424.535(a)(10), which allows a revocation of up to one year for each act of noncompliance. Saying the vendor holds the file is not a defense.
A practice that delegates credentialing should still keep its own copy of every file the vendor builds, with the verification date and the source attached to each element. If the vendor changes, the practice has to answer without its cooperation.
A file without a verification date is a file an auditor cannot score. Keep the date and the source next to each element, not only the document.
What surfaces late in a file audit
The rows that fail a delegated credentialing audit are rarely the ones the practice worried about. They are the items verified once at onboarding and never looked at again.
Malpractice history is the first. NCQA expects the past five years of malpractice settlements or judgments to be verified, either through the National Practitioner Data Bank or through a loss report from the carrier. A file that holds the certificate of coverage but not the claims history fails that row. NCQA’s 2025 standards also shortened the window in which each verified element has to be current, from 180 days to 120 days before the credentialing decision, and to 90 days for certification.
Work history is the second. A gap longer than six months needs an explanation in the file, and a gap of a year or more needs it in writing. That explanation is collected once, at initial credentialing, so a recredentialing packet built from the old application carries the same unexplained gap forward.
The third is the attestation. It has to be signed and dated by the practitioner, and what it confirms has to match what the file shows. A mismatch with a primary source becomes a written clarification, dated and signed, that goes into the file as an addendum.
The credit report question
A credit report is not one of the verification elements in an NCQA credentialing file review, and Medicare enrollment screening does not use one. The screening levels that exist, limited, moderate and high, add database checks, a site visit and fingerprints, not a consumer report. Where a financial item does reach a credentialing file, it arrives through the plan’s own application or its audit tool, and the delegate is scored against that tool.
Medicare’s financial exposure is debt-based rather than score-based, and it is real. CMS may revoke enrollment where a provider failed to repay a debt that CMS referred to the Treasury (42 CFR 424.535(a)(17)), and a felony conviction for a financial crime within the past 10 years is its own revocation ground (42 CFR 424.535(a)(3)(ii)(B)). Neither appears in a license check.
Credit checks belong to employment screening, and some states restrict them. Colorado’s Employment Opportunity Act bars most employers from requesting a consumer credit report unless the information is substantially related to the job. If a vendor presents a credit check as a credentialing requirement, ask which standard, policy or contract clause requires it.
The last row is the monitoring log, and it cannot be repaired after the fact. NCQA’s 2025 standards require sanctions, exclusions, license limitations and expirations to be reviewed at least monthly, or within 30 calendar days of a new alert from a monitoring service. An auditor asks for twelve dated months with a named reviewer.
Running the arrangement so the audit is boring
Delegation works when the practice treats the vendor as a supplier whose work it still owns. A vendor that runs outsourced medical billing services and credentialing from the same system can usually produce a file on short notice. One that cannot should not be holding the delegation.
Store the signed delegation agreement, the plan’s audit tool and the reporting calendar in one place. The tool says what gets scored. The agreement says when reports are due and what happens when they are late.
Hold the application, the attestation, the verification output with dates, the committee minutes and the decision letter. Do not let the vendor’s portal be the only copy of a record the plan can demand for 10 years.
Identify who runs the sanction and exclusion checks and who reviews the result. Undated checks are treated the same as no checks.
Start the packet 90 to 120 days before the cycle date so every element is verified inside the current window before the committee meets.
Audit a handful of your own files each quarter against the same tool. Findings you write yourself cost nothing. Findings an auditor writes start a corrective action clock.
Enrollment, CAQH and payer files all move on separate calendars, and the practice still owns the dates. Credentialing is mostly calendar work, whether or not a vendor runs it. When a delegation agreement is about to be signed or renewed, book a credentialing file review before the plan schedules its audit.
Delegated credentialing questions, answered
It means the practice or its vendor assembles and verifies the credentialing file and the plan accepts that work instead of rebuilding it. The plan still reviews and approves the process, audits it at least annually, keeps the right to approve, suspend or terminate any practitioner, and remains accountable to CMS and NCQA for the network.
No. The plan keeps ultimate responsibility for its own contract, and the practice keeps every duty that runs to the payer or to Medicare. Reporting an adverse legal action, a change of ownership or a new location within 30 days is the practice’s obligation under 42 CFR 424.516(d), and a missed report is a revocation basis under 42 CFR 424.535(a)(9).
NCQA requires the plan to evaluate the delegate’s capacity within the 12 months before delegation starts. Plans review written credentialing policies, the source used for each verification element, committee rosters and recent committee minutes, a provider roster with credentialing and recredentialing dates, and often a sample of files scored against the plan’s audit tool.
The standard method is 5 percent of credentialing files or 50 files, whichever is less, with at least 10 initial credentialing files and 10 recredentialing files in the sample. Where fewer than 10 practitioners were credentialed or recredentialed since the last audit, the plan reviews the whole universe instead of a sample.
Not as a verification element. NCQA’s file review covers license, DEA or CDS, education and training, board certification, work history, malpractice history, state licensing sanctions, Medicare and Medicaid sanctions, the application and the attestation. A credit report is not on that list, and Medicare enrollment screening does not use one. Ask for the standard or clause that requires it.
NCQA requires credentialing files to be retained at least through the survey look-back period and does not set a longer minimum. The plan’s audit right over a delegated entity’s records runs 10 years from the final date of the contract period, and Medicare requires medical records and orders to be kept 7 years from the date of service under 42 CFR 424.516(f).
The plan issues findings, and the delegate usually gets 30 calendar days to return a corrective action plan. Some plans reassess within three to six months and may terminate the agreement if the findings are not cured. A practice that is not already NCQA-accredited or certified can be refused delegation and told to reapply later.
The bottom line
Delegation is a change of hands, not a change of owner. The plan keeps its contract obligations, and the practice keeps its enrollment reports, its retention duties and its ability to produce a file on demand. Build the arrangement so that the annual audit is a records check rather than a negotiation.
Who owns the dates on your credentialing files?
We assemble and verify credentialing files, run the monthly sanction and exclusion checks with dated records, keep the enrollment reporting calendar for Medicare and Medicaid, and give the practice a copy of every file we build. Send the payer list and the delegation agreement, and we will map the next audit.
Request a free credentialing file auditThis article describes Medicare, Medicaid and commercial credentialing and delegation requirements as published at the time of writing and is not legal advice. Requirements vary by Medicare Administrative Contractor, state, payer and accreditation program, so confirm current rules with each one.


