Re-credentialing every 3 years is the fixed cycle at the center of every accredited credentialing program: NCQA requires that each practitioner be re-credentialed at least once within a 36-month window, and missing that window is one of the most common — and most avoidable — audit findings in the industry. The cycle is unforgiving because it is calendar-driven, not event-driven; the clock starts on the date of the last credentialing decision and runs whether or not anyone is watching it. The organizations that never miss a cycle share one trait: they manage re-credentialing as a rolling, proactive calendar rather than a scramble at expiration.
Why does re-credentialing happen every 3 years?
The 36-month cycle comes from NCQA's credentialing standards, which require organizations to re-credential practitioners at least every three years to confirm that the qualifications verified at initial credentialing remain current and that nothing disqualifying has occurred since. NCQA measures the interval from the last credentialing decision to the next, and its guidance allows very little flexibility — there is effectively no grace period, and a file re-credentialed even a day past 36 months is scoreable during a survey. NCQA's Credentialing standards and its credentialing guidance lay out the requirement in detail.
Hospitals accredited by The Joint Commission operate on a parallel but distinct schedule: reappointment to the medical staff and renewal of privileges occurs at least every two years, and federal law requires a matching two-year NPDB query at that reappointment, per the NPDB querying guidance. Organizations that answer to both frameworks must satisfy the shorter interval — which is why many multi-accredited groups standardize on the tightest applicable cycle rather than tracking two competing clocks.
The rationale is straightforward: credentials decay. A license current in year one can be suspended in year two; a clean malpractice history can gain a settlement; a board certification can lapse. Three years is the accreditors' judgment about how long an organization can safely rely on a point-in-time verification before it must look again — which is also why they pair the three-year re-check with continuous monitoring in between.
What does re-credentialing re-verify?
Re-credentialing is not a rubber stamp; it repeats the core verifications from initial credentialing to confirm the provider is still qualified and unencumbered. A compliant re-credentialing file re-verifies, through the primary source and within the accreditor's timeliness window:
- Current state licensure for every state of practice.
- DEA and controlled-substance registration, where applicable.
- Board certification status.
- Malpractice claims history and current coverage.
- A fresh NPDB query for new malpractice payments and adverse actions.
- Sanctions and exclusion status against OIG and federal lists.
- A current signed attestation covering the provider's continued ability to perform.
Education and training — facts that do not change — generally are not re-verified, but everything with an expiration date or an ongoing-risk profile is. Each re-verification carries the same documentation burden as the initial file: method, source, date, and reviewer. For the full list of approved sources, see our guide to primary-source verification, and confirm the finished record meets the standard of an audit-ready credentialing file.
How do you build a proactive re-credentialing calendar?
The single biggest failure mode is starting late. Because primary-source verifications are valid only within a limited window before the committee decision, you cannot verify too early — but you must begin early enough to gather sources, resolve discrepancies, and secure committee approval before the 36-month date. Best practice is to launch the re-credentialing workflow 90 to 120 days before the anniversary. A durable calendar has a few moving parts:
- A master roster keyed to each provider's last credentialing-decision date, not their hire date.
- Automated ticklers at 120, 90, and 60 days before expiration.
- A committee schedule with enough meeting slots that no file waits for a quorum.
- Alignment with the CAQH attestation cycle, since providers must re-attest their CAQH ProView data roughly every 120 days for payers to pull it.
Throughput is the quiet constraint. A group of 200 providers on a 36-month cycle must complete roughly 65 to 70 re-credentials a year — more than one a week — every week, on top of new hires. When re-credentialing is squeezed in around initial credentialing, the anniversaries that slip are almost always the quiet, long-tenured providers no one is actively onboarding. A calendar that surfaces those anniversaries automatically, months ahead, is what prevents the silent lapse.
Delegated arrangements add a layer: when a group performs credentialing on a health plan's behalf, the plan audits the cycle timing directly, so a late re-credential is not just an internal miss but a delegation-agreement breach the plan can act on.
Special cases: multi-state, locum, and telehealth providers
The 36-month clock gets more complicated as provider arrangements diversify. A physician licensed in six states needs all six licenses re-verified within the window, and a lapse in any one can pull them from that state's payer networks even if the others are current — a multi-state matrix that rewards a single, centralized roster over per-state spreadsheets. Locum tenens and telehealth providers add their own wrinkles: they are subject to the same credentialing and re-credentialing standards as permanent staff, and a common shortcut — assuming a staffing agency ‘handles it’ — leaves the billing organization holding the compliance risk if the file lapses.
Providers who move between affiliated entities in a health system raise a related question. If a system credentials centrally, with one committee and one process, it may be able to align a practitioner's cycle across sites rather than running conflicting clocks — but that only works if the central roster is authoritative and every site trusts the same date.
What happens when a re-credentialing cycle lapses?
A lapse is expensive in more ways than one. During an NCQA survey, a file that blew the 36-month window is scored down and can jeopardize accreditation status. Operationally, a lapsed provider may be dropped from payer networks, which stops clean claims and can force the organization to eat the cost of care already delivered. And because re-credentialing is when fresh sanction and exclusion checks occur, a lapse can mean an excluded or disciplined provider keeps billing undetected — compounding the exposure covered in OIG and SAM exclusion monitoring. The downstream revenue and compliance damage is detailed in our breakdown of the hidden cost of a re-credentialing lapse.
Ongoing monitoring between cycles
Three years is a long time to fly blind, and accreditors do not expect you to. Between re-credentialing events, NCQA requires ongoing monitoring of license actions, Medicare and Medicaid sanctions and exclusions, and member complaints, with prompt action when something surfaces — a standard reinforced by the OIG's recommendation to screen for exclusions every month. The most resilient programs run continuous license and exclusion monitoring and enroll practitioners in NPDB Continuous Query, so an adverse action triggers a review the week it happens rather than at the next anniversary.
Ongoing monitoring is not a courtesy; it is a scored expectation. When NCQA surveys a file, it looks for evidence that the organization detected and acted on interim events — a license restriction, a new exclusion, a pattern of complaints — within a reasonable time, not that it simply waited for the next cycle. Programs that treat the 36-month re-credential as the only checkpoint fail this test even when every three-year file is immaculate.
Handled proactively, re-credentialing every 3 years stops being a recurring fire drill and becomes a quiet, predictable rhythm: a rolling roster, early ticklers, continuous monitoring, and a committee that approves files with weeks to spare. That is how compliant organizations turn a hard deadline into a non-event — and never miss a cycle.
See your own numbers in 60 seconds
CredTek gets providers in-network 40–60% faster — built and run by operators with decades of enterprise credentialing experience, with a human approval gate on every submission.
Run the ROI calculator →