Licensing, credentialing, and payer enrollment in one place.

onPanel tracks every provider, every state, and every payer — so nothing expires unnoticed and every application has an owner.

Book a demoSee what it does
NPPES lookup · Append-only audit on every change · Tenant isolation enforced in the database
www.getonpanel.com/dashboardIllustrative — sample data
Active providers
128
Open enrollments
23
Expiring / 30d
6
Median days to approve
34
Needs attentionEach row has an owner and a date
Dr. Alicia Vega
Payer enrollment · Aetna
Jul 24In review
Dr. Priya Nair
Payer enrollment · UnitedHealthcare
Jul 26Submitted
Dr. James Okafor
Licensing · IL medical board
Aug 03Expiring
Sofia Reyes, NP
Payer enrollment · Humana
Not started
One system of record

Three workflows that usually live in three spreadsheets.

Every license, every verification, every payer enrollment — with owners, dates, and documents attached to the provider record.

Licensing
Eight credential types per provider — state license, DEA, CDS, board certification, malpractice, CPR/BLS, supervision agreement — each with its documents attached.
A 120-day expiry horizon, bucketed overdue / 30 / 60 / 90 / 120
The nightly scan opens a renewal task at 90 days
Renewals supersede — a record is never overwritten
Credentialing
Primary source verification recorded evidence-first, so the source, the date and the artifact read from one row.
A PSV checklist generated from the provider's taxonomy
Verification records are insert-only — the grant refuses updates
Screened against the OIG exclusion list, source file archived
Payer enrollment
A twelve-state pipeline with guarded transitions, so a record cannot be closed out with the part that matters missing.
An approval needs its effective date and payer-assigned ID
A denial names the requirement that was missed
Follow-up tasks reschedule on the payer's own cadence
Document extraction

Read the certificate. Don’t retype it.

Upload a license or a certificate and onPanel reads the fields with Amazon Bedrock, showing every value with the confidence it has in it. A person accepts each one before it becomes a credential.

State licenses, DEA registrations, board certificates, malpractice COIs and W-9s
Every value carries a confidence score, and the engine says when it did not read a field
An ambiguous date is dropped rather than reformatted — a guess must never enter the renewal horizon
Accepted values start a draft credential you review and save. Nothing files itself
Review extractionIn pilot
Provider name
Alicia R. Vega, MD
high0.97
License number
MD-114938
high0.94
Expiration date
2027-03-14
medium0.81
State
The engine did not read this field.
no score
The accepted values can start a credential. You will still review and save it.
Expiring in the next 120 days14 items
Dr. James Okafor
IL medical license
2026-08-03Expiring
Dr. Alicia Vega
DEA registration
2026-08-19Expiring
Sofia Reyes, NP
Malpractice
2026-09-01Active
Dr. Marcus Hale
Board certification
2026-09-14Active
Dr. Nina Petrov
TX medical license
2026-10-02Active
Renewals

Nothing expires unnoticed.

Every active credential with an expiry date sits on one 120-day horizon, bucketed overdue, 30, 60, 90 and 120 days out. A nightly scan opens the task and assigns the owner.

A renewal task opens at 90 days and admins are notified at 30
Expiring is computed when you look, so the screen and the scan cannot disagree
Idempotent twice over — a re-run never duplicates a task
Recredentialing runs on its own 365-day view, with tasks opening at 180
Evidence

Built to be audited, not just reported on.

Credentialing files get read by people who are allowed to disagree with you. The record has to hold up on its own.

A change and its audit record commit in the same transaction. There is no way to save one without the other
The audit log is append-only, and every export is itself recorded — with the filter and the row count, never the rows
Tenant isolation is a Postgres row-level-security policy, not an application filter
Multi-factor authentication is required, authenticator app only
Social security numbers and dates of birth are encrypted per column, each bound to its tenant and field
Document bytes never pass through our server, and S3 itself rejects an upload whose checksum does not match
What we do not have yet

No SOC 2 report, no signed BAA, and no NCQA certification. Those are the controls above, described plainly — not an audit anyone has run. We would rather tell you that now than in procurement.

Getting started

A roster in, and a list of what’s already late.

1
Bring your roster
A CSV of up to 500 rows. Column headers map themselves, NPIs are validated including the check digit, and rejected rows come back as a file you fix and re-upload.
2
We fill in what CMS knows
Names, taxonomy and practice address come from the NPPES registry, and every imported field records where it came from and when.
3
See what is already late
The expiry horizon is populated the moment the roster lands. Most teams find something in the first hour that nobody was tracking.

See where every provider stands — in one afternoon.

We’ll load your roster, map your payers, and show you the renewals you didn’t know were coming.

Book a demo