If your health plan delegates credentialing to Andros, your NCQA oversight relief belongs to a specific certified organization and the verification options it is certified for — not to a brand. Medallion announced on September 15 that it has acquired Andros, an NCQA-certified credentials verification organization founded in 2013 that works with nearly 400 health plans and healthcare organizations. Terms were not disclosed. Andros customers will get Medallion's platform "over time," and no date is attached.
That gap is the story. Before a single file moves, you need three answers in writing: which legal entity will verify your providers, which of NCQA's 11 certification options that entity holds, and which standards year it was surveyed under. Get them while the migration is still a plan. At your next NCQA survey, the evidence has to already exist.
What Medallion Actually Bought From Andros
Medallion bought a large, payer-heavy credentialing book and the NCQA-certified operation that serves it. The acquisition announcement says Andros serves more than a million providers across nearly 400 health plans and healthcare organizations, and that customers will gain Medallion's automated primary source collection, AI agents for provider outreach, real-time tracking and embedded credentialing specialists. Medallion founder and CEO Derek Lo said Andros had "developed strong, trusted relationships with many of the top health plans in the country."
Andros has been through this before. It is the product of the January 2020 union of CredSimple and Glenridge Health, rebranded that September, when it said more than 75 healthcare organizations — including three of the five largest payers in the country — relied on it. Its homepage now reads "We've joined Medallion," still markets the company as a "Fully NCQA-Certified CVO," and says it performs 300,000 credentials a year.
Medallion is the younger, more automated side. It raised $43 million in August 2025, bringing total funding to $130 million, and said it supported roughly a million providers. Its CVO page says "AI agents run data collection and build credentialing packets" while its specialists verify, lists 300+ healthcare organizations as customers, and claims to be "3.5x faster than legacy CVOs on average" — Medallion's own benchmark, not an audited one.
The case for the deal is strong. Andros's VP of sales, Jake Hirschfeld, said in the same release that customers "have pushed us for 13 years to make credentialing faster and more accurate." And the buyer is not an unaccredited startup: Medallion's compliance page says it is "NCQA Certified for Credentialing" and SOC 2 compliant. The risk here is not verification quality. It is delegation paperwork that names the wrong entity, the wrong options or the wrong standards year.
Why NCQA Credit Attaches to Certified Options, Not Brands
NCQA grants oversight relief only for the verification options a CVO has actually been certified to perform. A credentials verification organization (CVO) is a company that verifies practitioners' academic, licensing and clinical practice history through a primary source and reports the results to its clients, per NCQA's credentialing programs guide. The same guide lists 11 separately certified options:
| # | Certification option | # | Certification option |
|---|---|---|---|
| 1 | License to practice | 7 | State licensing board sanctions |
| 2 | DEA or CDS certification | 8 | Medicare/Medicaid sanctions |
| 3 | Education and training | 9 | Practitioner application processing |
| 4 | Board certification status | 10 | Application and attestation content |
| 5 | Work history | 11 | Ongoing monitoring of sanctions |
| 6 | Malpractice claims history |
An organization can earn "1 or up to 11" of those certification statuses. Automatic credit is NCQA's rule that a delegating organization receives full credit for a standard, element or portion of one based on its delegate's NCQA status. For certified CVOs, the guide says clients are relieved of formal oversight "for all evaluation products (elements) for which the CVO has earned Certification": no predelegation evaluation, no semiannual reports, no annual performance evaluation, no annual audit of CVO files. Every option outside that list is back on your oversight calendar.
The 2026 Health Plan standards' delegation appendix, effective for surveys on or after July 1, 2026, sets three conditions worth reading twice:
- Certified CVOs "must be certified to perform the activity delegated by the organization."
- Automatic credit applies only "if all delegates are NCQA Accredited/Certified organizations" — so an uncertified credentialing delegate elsewhere in your network can put the oversight work back on you.
- If a requirement was scored NA during the delegate's own survey, automatic credit does not apply.
None of this is a problem while Andros keeps verifying your files under its own certificate. It becomes one the day the work moves — to a Medallion entity, a shared platform or a clearinghouse record — while your delegation file still points at Andros. Andros publicly calls itself fully certified. Medallion's public compliance page does not list which options it holds. That is not evidence of a gap. It is a reason to ask for the certificate, not the badge.
The Information Integrity Clause Your Delegation Agreement Needs
The 2025 standards replaced system controls with information integrity, and the credit for it carries a standards-year condition. Under NCQA's 2026 delegation appendix, automatic credit for the information integrity requirements (CR 8, Elements A-D) is available when delegates are NCQA-Certified CVOs "under the 2025 standards (or later)." A CVO certified under an earlier cycle can be certified for every option and still not earn you that particular credit.
The agreement itself matters too. Per a Managed Healthcare Resources summary of the 2025 standard, delegation agreements signed on or after July 1, 2025 must include information integrity requirements; older agreements that addressed system controls under the 2022-2024 standards do not need updating, while ones that never addressed system controls do. The descriptors of inappropriate activity the agreement must cover include falsifying credentialing dates, creating documents without performing the required activity, fraudulently altering existing documents, attributing verification to individuals who did not perform it, and unauthorized updates to information.
That fourth item deserves a direct question in an AI-native workflow. Medallion's own description is that AI agents collect the data and build the packet while credentialing specialists verify. That is a sensible division of labour. But when a surveyor opens a migrated file, the record should show what the agent retrieved, what the human checked, and who is named as having verified it. And if a legacy Andros file is re-hosted on a new platform, its verification dates and verifier names need to survive the move untouched — a date rewritten during data migration looks, to a surveyor, exactly like the thing the clause prohibits.
What Happened the Last Time Two CVOs Combined
The brand consolidates in months; the legal entities and platforms behind it take longer, and your survey evidence has to track the entities. The closest precedent is Verisys and Aperture Health. Their merger was announced in June 2021, and a month later Verisys bought the Med Advantage CVO business from Advantum Health, saying its users would transition to Verisys' CheckMedic platform — with no timeline given. In September 2021, Verisys said the Aperture brand would be retired and the company would be based in Louisville. In December 2021, Verisys was still telling practitioners that valid communications might come from Verisys, Aperture Health, Aperture Credentialing LLC or the combined organizations.
Three entity names for one relationship, six months after the deal. That is ordinary integration, not negligence. But a delegation binder that names "Andros" while the verifications are produced by a differently named entity is a finding waiting for a surveyor. It is the same question Deloitte's Wavicle deal raised in a different regulated context: after an acquisition, check which entity actually signs the work you rely on.
There can be a hard clock in this too. An NCQA FAQ dated December 2023 on its 2024 Credentialing Accreditation standards says that if an organization delegates more than 50% of primary source verifications and a delegate loses its NCQA Accreditation or Certification after the organization's survey, NCQA considers it a Reportable Event, and the organization must notify NCQA within 30 calendar days. If that describes you and Andros's certification is ever allowed to lapse because its operations have been folded into Medallion's, that 30-day window is yours to meet.
Does CredAlliance Change Whose Verification Is in Your File?
Potentially, yes — a shared clearinghouse means the verification in your file may have been produced for another payer, on an earlier date. Medallion launched CredAlliance in August 2025 as a clearinghouse that "verifies providers once and syndicates the results across participating payer networks," and said it was already live with several major national payers. Its product page credits it with "cutting $1.2B in redundant credentialing costs for payers" — Medallion's figure — and does not address provider consent, data ownership or governance.
Compare the industry's earlier shared-data utility. CAQH ProView, now the Provider Data Portal under the DataSpring brand, lets providers enter data once and share it "with all plans they designate" — the provider chooses who receives it. ProView shared the application. CredAlliance aims to share the verification, which is the thing NCQA audits in your file. That makes the terms a vendor data-handling question as much as an operations one.
Timeliness is where reuse bites. NCQA's guide notes that it "assesses the client for timeliness of the credentialing decision," and its Certification timeframes are 90 days for license, board certification, malpractice history and sanctions, and 120 days for work history and application attestation. A verification completed for someone else arrives with its clock already running.
Verify-once is the right long-term architecture, and the duplication it attacks is real. But participation should be a decision you make in writing — whether your plan's verifications may be syndicated out, and whether you will accept syndicated ones in — not a default that arrives with the platform migration.
What to Do Before Your Andros Files Migrate
Treat this as a delegation change, not a vendor rename, and close the evidence gap while Andros is still the entity of record.
This Week:
- Put the certificate next to the contract. Pull your Andros delegation agreement and Andros's current NCQA certification documentation. List which of the 11 options Andros is certified for and which activities your agreement delegates. Anything delegated but not certified is oversight you owe regardless of this deal.
- Send Medallion three questions in writing: which legal entity will perform verification on your providers after migration; whether that entity holds the same certified options; and which standards year each certification was surveyed under.
- Name one owner. Give migration sign-off to your delegation-oversight or credentialing compliance lead, not procurement alone.
This Month:
- Check your agreement date against July 1, 2025. If the migration produces a new agreement, an assignment or a new counterparty, write the information integrity requirements in, and name any subdelegate — NCQA's guide says the agreement "specifies the entity responsible for overseeing subdelegates."
- Ask for a sample migrated file showing, for each verification, the source, the date, whether an agent or a specialist performed it, and who is named. Compare it line by line with the same provider's current Andros file.
- Get a CredAlliance position in writing: opt-in or opt-out for sharing your verifications, whether you accept syndicated ones, and how original verification dates travel with them.
Before Your Next NCQA Survey:
- Rebuild the delegation binder so every file maps to an entity, a certified option and a certification date — and confirm the "all delegates" condition holds across your other credentialing delegates.
- Set the 30-day trigger. Put a monthly check on both companies' NCQA status on your compliance calendar, with a named person responsible for filing a Reportable Event, where that rule applies to you, if a delegate's status changes.
The Bottom Line
Credentialing is consolidating the way back-office services markets usually do: a venture-funded automation platform buys a long-tenured services book and moves it onto software. As with other change-of-control deals this month, the press release sets the mood and the paperwork decides what customers keep. What makes credentialing different is that the paperwork is regulated evidence. Your NCQA surveyor does not audit a vendor relationship. It audits a certified entity, a certified option and a dated verification in a file.
Medallion bought the customer list. Your surveyor audits the certificate. Make sure they still match.
Continue Reading
- Deloitte Bought Wavicle. Check Who Signs Your Audit Opinion.
- Bending Spoons Closed Airtable in 31 Days. Miro Says Q4.
- Alianza Bought Skribby. Your Meeting Audio Changed Owners.
- Kiteworks Bought Bonfy. Ask for the Terms WAMNET Got.
- AI Vendor Security Review: 6 Questions That Change the Answer
- Hospitals Test Vendor AI. Fewer Than Half Have a Sandbox.
- NHS Scribes Dropped 'Null.' Patients Caught It, Not GPs.
