Why provider-directory auditing needs to become continuous
A point-in-time review of a provider directory starts decaying the day it finishes. The files are large, they change all year, and the age of what we find in them is the whole argument.
By the Rollcall Health research team · 22 August 2026
The provider directories published on the CMS federal Marketplace run to 16.8 million listings across 104 directories, and the files are republished and revised all year. Any periodic manual review reads a snapshot, and the snapshot starts going stale before the next cycle begins. That is not a criticism of the people doing the reviewing. It is a property of the object being reviewed: published provider directories are too large and change too frequently for periodic manual review alone.
The evidence is the age of what we find
When we compare every listing in those files against dated federal records, the findings are not fresh mistakes. The median finding in the current published run had stood for 327 days when we read the file, and findings that rest on a federal exclusion had stood for a median of 740 days. A listing the federal record contradicts has typically sat in the published file for over a year, through however many review cycles that year contained. Duration is the one thing a periodic process cannot hide, because the federal record carries dates.
What continuous means here
Rollcall Health reads every published Marketplace directory file weekly and tests every listing against dated authoritative federal sources. The federal files move on their own cadences, monthly for some, and a finding is dated by the federal act rather than by our read, so what is claimed never outruns what the source supports. The published method lists each source and its cadence. Deterministic checks compute every finding: the same file and the same federal records produce the same rows, whoever runs them. Every row carries the date of the federal fact, the file it was read from, and the day it was read. None of it needs anything from a plan’s systems, because the audit reads what plans already publish.
Machines operate it. People govern it.
Agents run the weekly operation: they read the files, retry what failed, load the results, and draft the analysis of what moved and why. What they cannot do is change the method or publish. Every run has to pass its validation checks, a written review of its movement, and a human publication decision before anything reaches this site or the API. The method’s constants are frozen per version, a method change ships as a new visible version rather than a restatement of history, and a check added later is never backfilled into earlier runs. The system cannot silently change its own tests, and it cannot publish itself.
Open methods. Continuous machine operation. Human-governed publication. Rollcall Health is building an independent, open-method monitoring system for published health-plan provider directories: it continuously reads public directories, applies reproducible tests, and preserves dated evidence, while method changes and publication remain human-governed. The method is published today, and we are building toward an open audit protocol that others can run and check.
We can run these checks against your own published directory and send you the rows, each with its date and its federal source. It costs nothing and needs nothing from your systems.
Request findings for a directory →