Comparison
Medallion vs. Assured: What differs when you're choosing a credentialing partner
Medallion and Assured both sell credentialing and provider enrollment software, and on a feature list they can look similar. The real differences show up in three meaningful places: how the SLA is structured, how deep the compliance certification goes, and whether the vendor has lived through a full customer renewal.
Medallion has operated since 2020; Assured launched in 2024. That gap is a practical difference. Credentialing partnerships get tested at renewal, when licenses come up for reverification and multi-year contracts roll over, and a vendor that's two years old simply hasn't been through as many of those cycles as one operating since 2020.
Medallion vs. Assured at a glance
| Attribute | Medallion | Assured |
|---|---|---|
| Launch date | 2020 | 2024 |
| Reported customer count | ~300 organizations | ~100 organizations |
| SLA structure | Contractual SLAs on the controllable steps across credentialing, enrollment, and licensing; none attached to board, payer, or hospital timelines | Publicly advertises a 48-hour credentialing-file SLA; confirm coverage, exclusions, and remedy on a miss |
| Security compliance | SOC 2 compliant at the platform level | SOC 2-compliant hosting |
| Renewal / expansion history | Multiple renewal cycles across named customers | None publicly reported yet |
| Go-to-market | Value and long-term partnership | Price-forward; newly funded to move upmarket |
Assured, in brief
Assured launched in 2024 and has reportedly raised $25M to date: a $6M seed round in September 2025, then a $19M Series A in July 2026, led by Insight Partners with First Round Capital and Kindred Ventures participating. Assured looks to have recently become an NCQA-certified CVO and reports roughly 100 healthcare organizations as customers. Its go-to-market approach centers on price and speed, including a publicly advertised 48-hour credentialing-file SLA.
Medallion, in brief
Medallion has raised $130M to date, including a Series C, backed by Sequoia, Spark Capital, GV, Optum Ventures, and others. Roughly 300 healthcare organizations run on Medallion today, managing nearly 500,000 providers, with more than 55 million primary source verifications completed to date. Median turnaround runs about 7 days to credential a provider with a payer and about 13 days for NCQA credentialing. Medallion is an NCQA-certified CVO — certification renewed as of August 2026 across 11 certifications — and is SOC 2 Type 2 compliant at the platform level.
Where the real differences show up
SLA structure
An SLA is only meaningful on work the vendor controls. Medallion puts contractual SLAs on the steps it owns, and is explicit about where those commitments stop:
- NCQA credentialing (packet creation): ≤3 days
- TJC credentialing (packet creation): ≤5 days
- Payer enrollment (application submission): ≤10 days
- Licensing (application submission): ≤10 days
- Hospital applications (submission): ≤10 days
Medallion doesn't attach an SLA to anything dependent on an external entity — a provider returning a document, or a board, payer, or hospital committee reaching a decision — because no vendor controls those timelines.
Assured publicly advertises a 48-hour credentialing-file SLA, which appears to cover a step it controls. So when you compare guarantees, the useful question isn't the headline number, it's the scope: for any vendor, Medallion included, confirm which steps the SLA covers, which are excluded, and what happens when a deadline is missed.
Compliance scope
Compliance scope is where the two vendors diverge most, and the distinction is easy to miss on a feature grid. Medallion holds SOC 2 Type 2 certification at the platform level: the controls governing how provider data is handled inside the application have been audited over a sustained period, not just checked once. Assured's SOC 2 compliance applies to its hosting infrastructure rather than the platform itself, which certifies the data center more than the application layer that actually touches provider data. Its NCQA CVO certification is a real credentialing-quality signal, but it speaks to the credentialing process, not to platform security.
The gap matters most when someone else is doing the asking. A payer's security review, an enterprise vendor-risk assessment, or an internal audit will want to know what layer your credentialing platform is certified at, and hosting-level compliance leaves that question half-answered. Ask each vendor exactly what their certification covers before you assume the two are equivalent.
Track record through renewal
Assured is two years old. It seems there isn't a publicly reported customer that has completed a full renewal or a major expansion with them yet. Medallion has proven its delivery model across hundreds of customers through multiple renewal cycles, and completes 99.9% of recredentialing before the deadline — a timeliness record, not an accuracy claim, but exactly the kind of consistency that only shows up once you've run renewals at volume. WellBe expanded into multi-state operations on Medallion; CareBridge added states without growing its credentialing team; Ivy Rehab scaled across 700+ clinics without adding headcount.
A fast onboarding is easy to demo. A renewal is the actual test of whether a vendor holds up at scale and over time, and it's the one data point a two-year-old company likely can't manufacture with funding alone.
Visibility into progress
Medallion customers track workflow status, blockers, and turnaround directly in-platform, backed by a dedicated customer team that flags issues proactively. When evaluating any vendor, it's key to ask how you'll know where a file stands before you sign. Visibility into your own credentialing pipeline shouldn't require taking someone's word for it.
Where Assured might be the right call
Assured's SLA and pricing can fit an early-stage or single-state organization that needs providers credentialed quickly and doesn't yet need multi-state complexity, delegated credentialing, or a platform built for scale. If your provider volume and complexity are small and likely to stay that way, a lower-cost, newer entrant may cover what you need today. The calculus changes as volume, states, and payer relationships multiply. That's where an unproven renewal history and hosting-level SOC-2 compliance stop being hypothetical.
Questions to ask any credentialing vendor before you sign
- What security certification does the vendor hold directly, and at what layer — the platform, or just the hosting infrastructure?
- Have they supported a customer through a full renewal or a major expansion? What did that actually involve?
- What still requires manual follow-up or internal coordination once the platform is live?
- How will you see where a file stands — blockers, delays, what's holding a provider back from billing?
- When something stalls, is there a clear owner and a timeline, or do you have to chase it down yourself?
These questions apply to Medallion, Assured, or anyone else on your shortlist. A vendor that answers them plainly is worth more than one that answers them well in a demo.
The bottom line
A feature comparison tells you what a platform can technically do. It won't tell you what happens when a provider's license lapses at renewal, when your organization adds three new states in a year, or when a payer's security team asks what layer your platform is certified at. Those are the real tests. Right now, they're where the two vendors aren't comparable: Assured hasn't been in business long enough to have faced them.
If you're evaluating credentialing and enrollment partners, Medallion's team is glad to walk through how the platform handles renewals, multi-state scale, and compliance depth. No pressure, just a real conversation about what your next few years require.

