Two Medicaid directories, two different files

We checked 41 Medicaid provider directories every day for eleven days. Seventeen of them changed on almost every check. Fourteen never changed once. A directory that moves daily is not automatically better, and one that never moves is not automatically wrong. Here is how to tell the difference.

What we did

We keep a daily archive of public Medicaid provider directories. Every day we fetch each file, take a fingerprint of the bytes, and store it. If the fingerprint differs from yesterday, we record a change.

This post covers the first eleven days of that archive. We are not guessing at how often these files move. We watched them.

The point is not to name a good plan and a bad plan. The point is narrower and more useful. How recently you checked matters enormously for some directories and not at all for others.

What the law actually requires

The rules here are real, and they are not soft.

Medicare Advantage organizations, Medicaid state agencies, Medicaid managed care plans, and the CHIP equivalents all have to publish a public provider directory API. It must carry provider names, addresses, phone numbers, and specialties (CMS).

The update window is 30 calendar days. CMS puts it plainly: directory information must reach the public "within 30 calendar days of a payer receiving provider directory information or an update to the provider directory information" (CMS).

For state Medicaid programs, CMS says the same 30-day clock applies to the API itself (Medicaid.gov).

Congress also tightened the floor. Section 5123 of the Consolidated Appropriations Act, 2023 moved fee-for-service directories from annual to quarterly updates. It added a statutory duty for managed care programs to refresh electronic directories "at least quarterly or more frequently as required by the Secretary" (Medicaid.gov). Those changes took effect July 1, 2025.

Commercial and exchange plans sit under a separate rule. They must verify each directory entry at least every 90 days and answer a member's network question within one business day (eCFR).

So the legal ceiling on staleness is 30 days for a Medicaid API. Our archive shows what actually happens inside that window.

The headline: 178 changes across 41 files

Here is the whole eleven days, from our own archive.

MeasureValue
Medicaid directory sources tracked41
Sources active41
Capture days11 (2026-08-01 to 2026-08-11)
Snapshots taken453
Successful checks439
Recorded changes178
Sources that changed at least once27
Sources that never changed14

Now split those 41 sources by how often they moved.

BehaviourSourcesChanges
Changed on 6 or more checks17166
Changed 2 to 5 times13
Changed exactly once99
Never changed140

Read the first and last rows together. Seventeen sources produced 166 of the 178 changes. Fourteen produced none. There is almost nothing in the middle.

That shape is the finding. These files do not vary along a smooth range. They fall into two camps.

Sixteen files that move almost every day

Sixteen of the 41 sources changed on 10 of their 11 checks. That is a new file essentially every single day.

They are not obscure endpoints. They include Molina Medicaid directories in Arizona, California, Florida, Illinois, Michigan, New York, Ohio and Texas. They include four state-run FHIR provider directories, in Michigan, North Carolina, Pennsylvania and Texas. They include CareSource in Ohio and Keystone First in Pennsylvania.

If you looked at one of those directories a week ago, you looked at a file that has since been replaced seven times.

Fourteen files that never moved

The other camp did not move once in eleven days.

That group includes the CMS State Medicaid Agency endpoint directory, four separate California Medi-Cal provider listings, two Georgia sources, Meridian in Michigan, and Superior HealthPlan's STAR listing in Bexar County, Texas.

Eleven days is not a long time. A quarterly-update file has no obligation to move in eleven days, and none of this is a compliance finding. It is a description of behaviour.

But it changes what "I checked recently" means. For a file in this group, checking today and checking ten days ago give you the identical answer.

The same state, two different answers

The clearest way to see the split is inside a single state. Same members, same market, same rules.

StateSourceChecksChanges
FLMolina Florida1110
FLAHCA Managed Care PML116
FLUnitedHealthcare FL MMA111
FLFlorida state FHIR capability statement110
TXMolina Texas1110
TXTMHP state provider directory1110
TXUnitedHealthcare TX STAR111
TXSuperior HealthPlan STAR Bexar110
OHMolina Ohio1110
OHCareSource FHIR1110
OHUnitedHealthcare OH111
PAKeystone First1110
PAPennsylvania DHS state directory1110
PAUnitedHealthcare PA111
NCAmeriHealth Caritas NC1110
NCNC Medicaid state directory1110
NCUnitedHealthcare NC111

One pattern repeats in every state above. Nine UnitedHealthcare Community Plan sources changed exactly once in eleven checks, in Arizona, Florida, Michigan, North Carolina, New York, Ohio, Pennsylvania and Texas, plus the national file index.

We do not know why. We are not going to invent a reason. A weekly or monthly publication cadence would produce exactly this, and so would several other things.

What a change does and does not mean

This is the part that matters most, so we will be blunt about it.

A recorded change means the bytes of the file differed from the day before. It does not mean a doctor moved, joined, or left.

Some of those daily changes are almost certainly not clinical at all. A regeneration timestamp inside the file will trip a fingerprint. So will a re-sorted row order. We cannot tell you what share of the 166 changes are real network movement, because a byte-level fingerprint cannot tell you that.

The reverse trap is worse. An unchanged file is not a verified file. It only tells you the publisher has not republished. A directory can sit perfectly still for a month while three of its listed practices stop taking Medicaid.

So neither camp is the good one. Movement is not accuracy, and stillness is not accuracy either.

What to do when you check your own directory

  1. Write down the date you looked, and what the directory said. If a bill arrives later, that record is the thing you argue with.
  2. Do not treat the directory as one source. Phone the practice and name your exact plan, then phone the plan and ask for the answer in writing.
  3. Ask the plan when the directory was last updated. The 30-day API window gives you a standard to hold them to (CMS).
  4. Re-check before you actually book. A file that is replaced daily can disagree with itself between the day you shopped and the day you show up.
  5. If you were billed out of network for a listed in-network provider, say so in writing and quote the record you kept.

Our wider directory accuracy work, checked against the federal provider registry rather than by fingerprint, is in Ghost networks by the numbers.

Where these numbers come from

Every figure above comes from our own archive, queried the day this post was published.

A failed fetch is never counted as a change. Eleven days is a short window, and we will publish a longer one as the archive grows.

Questions people ask

How often does a Medicaid plan have to update its provider directory?

Directory information has to reach the public within 30 calendar days of the plan receiving it, under the CMS interoperability rule. Since July 1, 2025, electronic managed care directories also carry a statutory duty to update at least quarterly.

Is a directory that changes every day more accurate?

Not necessarily. A daily change means the file's bytes moved. It can be caused by a timestamp or a re-sorted row rather than by a doctor joining or leaving. Frequent publication is a good sign, not proof.

Is a directory that never changes out of date?

Not necessarily either. Eleven days is short, and a quarterly file has no reason to move in that time. But an unchanged file is not a verified file. It only tells you nobody republished it.

Why do the plans in one state behave so differently?

We do not know, and we will not guess. Publication cadence, file format and the system generating the file all differ by plan. What we can say is that the difference is large, consistent, and visible from the outside.

Does this mean the plans are breaking the rules?

No, and we are not claiming that. Eleven days of fingerprints cannot establish a compliance failure. The 30-day and quarterly windows are longer than our observation window.

Can I see the underlying archive?

The verticals we archive, and the live counts behind them, are published on our apps page. That page reads the same database this post was queried from.