CMS Moving to API Provider Transparency

By Don Rucker, MD, Chief Strategy Officer, 1upHealth
LinkedIn: Donald Rucker
LinkedIn: 1upHealth

Price transparency has become an increasing requirement for providers and payers over the last number of years, including for out-of-network costs under the No Surprises Act. CMS has been on a multi-year campaign to extend transparency throughout its programs. Folks are familiar with the 2024 CMS-0057 regulation requiring payer historical claims data to be made available to patients, providers, and when switching plans to other payers. However, when patients are making plan purchases, it is not just the price but the product itself which needs transparency.

In Medicare Advantage the “product” starts with the provider network choices – in other words, who is taking care of the patient. Historically, during Medicare Advantage’s annual enrollment period starting in October, patients had to go to individual plans to figure out whether their providers were in network or whether they would be forced to go to a new doctor. This is politically sensitive with millions of voters in play. President Obama’s “you can keep your doctor” promise was famously not kept. The current administration is working to increase awareness of whether you can keep your doctor fully digital and easily accessible, letting patients make that choice; MA’s version of online shopping.

What does provider access transparency look like? The first CMS regulation was the 2020 Interoperability and Patient Access final rule, which required payers to provide Patient Access APIs and a Provider Directory API, though the rule did not fully specify technical details. In 2024, CMS finalized the 0057 rule, which laid the foundation for a full payer API ecosystem required by the end of this year. In 2025, CMS issued CMS-4208-F2, which required MA plans to provide APIs listing all of their in-network providers so CMS can incorporate that information in a single place – a place where the patient can find that information in one spot. Although this requirement was in transition during the previous MA plan year, plans must now implement Provider Directory APIs in time for the 2027 annual enrollment period. This will enable CMS’s Medicare Plan Finder tool to act as a unified place for patients to compare coverage and verify provider networks across plans, and all data must be current within 30 days.

For now, CMS does not require that the information in these APIs matches the information a plan is required to provide CMS for MA plan network adequacy, such as if the plan has adequate coverage by specialty and geography to provide care for potential enrollees in a specific region. It is hard to imagine this key determinant of patient satisfaction will not be required eventually.

The real digital impact will come as plan provider directories are fed into CMS’s National Directory of Healthcare (NDH). Per CMS, “the NDH is intended to serve as a centralized data hub, allowing patients to identify, compare, and locate providers based on criteria such as office accessibility, languages spoken, and other preferences.”

The NDH is an evolution of multiple prior CMS directories, most notably NPPES (National Plan and Provider Enumeration System) which provides NPI numbers for providers. CMS is required to stand up a national endpoint directory under the 21st Century Cures Act. They were slow to do so previously because some parties wanted to require access to endpoint information to only be available in TEFCA’s private directory. This would have prevented a digital infrastructure that is publicly available and with the modern APIs required for real-time phone apps.

Now CMS is all-in on standing up a fully modernized Provider and Plan Directory that is fully API-first and publicly discoverable. In the proposed CMS-0062 rule, CMS is proposing that all 0057 Access, Prior Authorization, and Directory FHIR Endpoint Resources (i.e., APIs) be publicly reported to CMS along with FHIR capability statements, and authorization, authentication, implementation, and API registration details. This is so CMS can do automated API verification. CMS is also proposing that this information be reported to the National Healthcare Directory.

While at first blush this seems like another reporting requirement, it actually lays the rails for a modern digital infrastructure for healthcare. Now apps will be able to securely search for and connect to provider systems. Healthcare technology will become on par with every other app on our phones which are constantly connecting to backend services to provide all their services we see on our screens. Modern Provider Directory APIs are the digital rail line for interacting with the upcoming healthcare app economy. Healthcare will stop being a digital backwater. Provider Directory APIs will put organizations on the starting line for the future.