OIG profile-correction files are not exclusion-verification evidence
HHS-OIG publishes profile corrections beside the monthly exclusion data, but the agency expressly says not to use that file to verify exclusions. The full database, monthly additions and reinstatements, identity matching, and online verification serve different operating purposes.
Editorial figure by Credentialing Current. Source context: HHS-OIG — LEIE Database and Supplement Downloads.
File labels are control instructions
The direct answer on OIG's download page is explicit: profile-correction files should not be used to verify exclusions. They record changes to an excluded person's or entity's profile, such as an address change. A pipeline that ingests every monthly file as though it adds or removes an exclusion can therefore create a false status change from a record whose purpose is only to correct profile information.
A governed ingestion record should preserve file class, reporting month, retrieval time, checksum, schema version, action semantics, source URL, rows accepted and rejected, duplicate handling, and the before-and-after local state. The transformation logic for a full replacement, an exclusion supplement, a reinstatement supplement, and a profile correction should be separately tested and reviewable.
Full refresh and supplements are alternate strategies
OIG tells users maintaining local data to choose one monthly strategy: download the latest full database or update the local database with the supplement files. It specifically says not to use monthly supplements when downloading the full database each month. That instruction prevents the same actions from being applied twice or a local state from mixing snapshots and deltas without a controlled baseline.
The full file contains all exclusions then in effect and is replaced monthly; reinstated individuals and entities are removed. Supplements contain actions for one month only and do not constitute the full database. A system demonstration should start from a known snapshot, apply an exclusion and a reinstatement, handle a corrected identity attribute, reconcile counts, detect a missed month, rebuild from the latest full file, and prove that downstream screening states match.
Download matching does not complete identity verification
OIG notes that the Privacy Act prevents distribution of Social Security numbers in the downloadable data and says users need the online search to verify specific individuals and entities. A local name or identifier match is therefore a candidate screening result, not automatically the final identity conclusion. Common names, changed addresses, incomplete fields, organizations, and other variations need controlled review.
Credentialing and enrollment workflows should retain the source candidate, matching fields, confidence or rule, discrepancies, online verification result, search date, reviewer, evidence, and disposition. They also need escalation for unresolved identity and correction handling for affected downstream records. Automation can prioritize and route the work, but it should not hide uncertainty behind a single excluded or clear flag.
Exclusion screening remains one credentialing control
The LEIE answers a federal exclusion question within its stated scope. It does not establish licensure, board certification, education, work history, sanctions from every authority, Medicare or Medicaid enrollment, payer network participation, appointment, privileges, competency, or current practice location. Those states can share an identity but require their own authoritative sources, timing, criteria, owners, and decisions.
This page provides official file-operation instructions and current download context; it does not decide a disputed identity, prescribe an organization's full screening program, or replace applicable requirements and qualified review. Credentialing, compliance, enrollment, human-resources, clinical, data, security, and legal owners should govern the complete process. Technology should preserve file purpose and evidence boundaries instead of converting a correction row into exclusion verification.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Credentialing Current will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.