General operational information only. Payer, state, contractual and regulatory requirements vary. Confirm current requirements with the applicable payer or agency.
Quick answer
What practice leaders need to know
NPPES issues and maintains NPIs. DataSpring, formerly CAQH, collects provider information that participating health plans may use for credentialing. PECOS manages Medicare enrollment actions. They are separate systems, and updating one does not automatically update the others.
System responsibility map
One provider record, four separate destinations
Updating one system does not automatically repair the others. Follow the record from identity through payer participation.
Creates and maintains Type 1 and Type 2 NPI records.
Shares an authorized clinician profile and supporting documents with participating organizations.
Processes Medicare enrollment, changes, revalidation and reassignment actions.
Controls the payer's credentialing, contract, product, location and effective-date records.
NPPES, DataSpring, PECOS and each applicable payer
Confirm how the address is used in every record, then retain each submission and effective-date confirmation.
Source verification
Check the rule beside the guidance.
NPPES maintains NPIs, while changes made there do not automatically update the provider's Medicare enrollment record.
Verify with CMS NPI Fact SheetPECOS is CMS's online Medicare enrollment management system for enrollment, changes, revalidation and related actions.
Verify with CMS PECOSDataSpring, formerly CAQH, supports provider-data sharing with participating organizations. It does not complete Medicare enrollment.
Verify with DataSpring for CliniciansNPPES creates and maintains the NPI record
The National Plan and Provider Enumeration System is used to apply for and maintain National Provider Identifiers. The record identifies an individual or organization in standard healthcare transactions. It does not enroll the provider with Medicare or a commercial payer, and CMS specifically notes that issuance of an NPI does not prove licensure or credentialing.
DataSpring, formerly CAQH, supports provider data sharing
The platform long known as the CAQH Provider Data Portal is now presented as DataSpring for clinicians. Many participating health plans use it to collect credentialing information from individual providers. A provider enters education, work history, licenses, malpractice coverage, practice locations and other details, authorizes selected organizations to view the record, uploads supporting documents and completes periodic attestations. We retain CAQH in this guide because practices and payers still commonly use that name.
PECOS manages Medicare enrollment
PECOS is CMS's online Medicare enrollment system. Eligible providers and suppliers can submit initial enrollments, report changes, add or update reassignment relationships and complete revalidation activities. The correct application depends on whether the applicant is an individual, group, clinic, institution or another supplier type.
The systems should tell one consistent story
Legal names, addresses, ownership, taxonomy, licenses and affiliations should be reviewed across all applicable records. Updating CAQH does not automatically update NPPES, PECOS or a payer's internal system. Each change needs an owner and a list of affected records.
Build a sequence instead of opening every portal at once
Start by confirming the legal and provider structure, then verify identifiers and source documents. Next, update applicable profile systems and prepare payer-specific submissions. A tracker should record which system was updated, when it was attested or submitted, what remains open and when the next follow-up is due.
A practical setup sequence for a new group
Confirm the legal entity, tax record, ownership and service address before creating or updating the organizational NPI. Review each clinician's Type 1 NPI and taxonomy. Complete or refresh the individual provider's CAQH profile when target commercial payers use it. Complete the correct PECOS enrollment and reassignment actions when the practice will bill Medicare. Commercial payer applications, Medicaid enrollment, electronic claim enrollment, ERA and EFT may still require separate submissions after these records are ready.
Changes require a system-by-system impact review
When a practice changes its address, ownership, legal name, tax information or group relationships, list every system and payer record affected. Determine the required reporting deadline and effective date for each. Save confirmation numbers and copies of submissions. This prevents a common problem where the public NPI record shows one address, CAQH shows another and the payer's internal file still shows the former location.
Use one source record for repeated data
Create a controlled provider record for the facts that appear in multiple systems: legal name, professional name, NPI, tax identification number, taxonomy, licenses, education, work history, malpractice coverage, service locations and group affiliations. Assign an owner and a last-verified date to each field. Staff can then prepare applications from the same reviewed source instead of copying an older payer form. The portals remain separate, but the practice's internal source of truth should be consistent.
A new address shows why the systems cannot be treated as one
Suppose a group opens a second location. The organization may need to update NPPES, report the location through PECOS for Medicare, update provider profiles in CAQH and submit location or roster changes to each payer. The payer may also require electronic claim configuration for the new service location. Completing only the NPPES update does not establish participation at that address. The tracker should show every required system, the effective date requested, the acknowledgement received and the first claim tested from the location.
CMS identity access sits behind the Medicare workflow
NPPES and PECOS use CMS identity and access relationships, but access to a portal is not the same as authority to complete every action. An organization should identify its authorized official, access managers, staff users and any approved surrogate relationships. Keep access assigned to named users and remove former staff promptly. A credentialing vendor may prepare information or work through an authorized relationship, but the practice still needs accountable internal ownership, an appropriate signer and access continuity when personnel change.
The same field can have a different operational meaning
An address in NPPES helps describe the provider's identifier record. A practice location in PECOS is part of Medicare enrollment. A location in CAQH supports provider data sharing, while the payer's own system determines whether that provider is participating at the location for a particular product. Similar-looking fields should therefore be validated against the purpose of each system. Copying the same address everywhere without confirming service, mailing, payment and correspondence roles can create a record that appears consistent but is still operationally wrong.
Build a maintenance calendar, not just an application checklist
Track CAQH attestation and document expiration dates, Medicare revalidation status, NPPES changes and payer-specific renewal or roster requirements. Each item should show the source, owner, next due date and proof of completion. Review the calendar monthly and whenever a provider, location, ownership interest or business name changes. The goal is not to keep every portal open. It is to prevent one outdated record from blocking a new enrollment, creating a directory error or sending claims through an affiliation the payer no longer recognizes.
NPPES is public identification, not payer approval
The NPI and much of its associated record can be found through the public NPI Registry, but appearance there does not mean Medicare or a commercial payer has enrolled the provider. It also does not confirm network status, an effective date or a group affiliation. Use NPPES to verify enumeration data and maintain the identifier record, then obtain separate evidence from PECOS, the Medicare contractor or the health plan for billing participation. Keeping those proofs separate prevents staff from treating a public listing as authorization to submit claims.
PECOS records relationships that NPPES does not
PECOS uses NPI and identity information within a Medicare enrollment process, but it also addresses matters such as enrollment type, ownership, locations, reassignment and effective status. Updating an address in NPPES does not automatically complete the corresponding Medicare change. Determine whether the PECOS record and supporting application must also be updated, then confirm the contractor's outcome. Conversely, a PECOS action should be checked against NPPES and operational systems so the practice does not finish Medicare work while leaving a conflicting public or claim record.
Maintain an evidence trail without copying sensitive credentials
For each change, save the request date, affected provider or entity, old and new verified values, submission confirmation, reference number, owner and final acknowledgement. Store supporting records in the practice's approved secure location and limit access appropriately. A tracker can link to the evidence without containing passwords, banking details or unnecessary personal information. This gives the next reviewer enough history to continue the work while respecting security and privacy boundaries. It also shows which system remains pending when the same change must be completed in several places.
Working reference
NPPES, CAQH and PECOS compared
These systems overlap in the information they request, but each has a different job and update process.
| System | Primary purpose | What it does not complete |
|---|---|---|
| NPPES | Issues and maintains Type 1 and Type 2 NPIs | Commercial credentialing, Medicare enrollment or network participation |
| CAQH Provider Data Portal | Stores individual provider data and documents for authorized participating organizations | Automatic approval with a payer or Medicare enrollment |
| PECOS | Processes Medicare enrollment, changes, revalidation and reassignment actions | Commercial payer credentialing or a CAQH attestation |
| Payer portal or application | Processes the payer's own credentialing and participation requirements | Updates every connected government or provider-data system |
Free working resource
Provider Data Change-Control Tracker
Track one change across NPPES, DataSpring, PECOS and each applicable payer record.
- Built for a practice operations team
- Editable in Excel or Google Sheets
- Do not enter patient information or PHI
Common questions
Questions practice teams ask
Do I need CAQH before receiving an NPI?
No. An NPI is obtained through NPPES. CAQH is a separate provider-data platform used by participating organizations.
Does completing CAQH enroll a provider with insurance?
No. CAQH can provide information to an authorized payer, but the payer still controls its application, credentialing and contracting decisions.
Is PECOS only for individual clinicians?
No. PECOS supports multiple Medicare provider and supplier enrollment types, including individuals and organizations. The correct action depends on the applicant and billing structure.
Will a CAQH address change update PECOS?
No. Update each applicable system and payer separately, then retain the confirmation for every change.
What should match across all three systems?
Legal names, identifiers, practice addresses, taxonomy, licenses and organizational relationships should be reviewed for consistency where the same information is requested.
Primary references
Sources and further reading
Requirements can change. Use these primary sources to confirm the current rule that applies to the payer, service and date of care.
Ready to turn this guidance into action?
Tell us what is happening in your practice, and we will help you identify the most useful next step.

