Confidential white paper · Prepared for HealthTrust Performance Group · July 2026

Up to $500,000 a year. Per member.

Incoming employment and income verification of member workforces is a paid transaction, and in many cases the fees flow entirely to outside vendors today. MyEmployment routes the money back to the member systems that generate it: a negotiated revenue share of up to 50 percent of verifier fees, up to $500,000 a year per member, employees with notice of each request and the power to deny it, and payroll and HRIS untouched.

This paper explains how the category works, what it is worth at member and membership scale, and the structure through which a GPO participates.

#1Where things stand today

How member verifications appear to be answered today.

When one of a member system's employees applies for a mortgage, rents an apartment, or applies for government benefits, the lender, landlord, or agency confirms that person's employment and income before saying yes. That confirmation is an incoming employment and income verification, and the party requesting it pays a fee for each answer. Across a large workforce it is constant, quiet traffic.

How member systems answer that traffic today is fragmented. In our review of published verification channels across a dozen HealthTrust-affiliated systems, one, HCA, routes requests through Thomas & Company, a respected provider whose client advisory board includes HealthTrust HR leadership. Two route through The Work Number. One uses a smaller verification portal. The remaining eight answer requests through internal HR teams, service centers, and credentialing offices: staff time spent on a paid transaction that returns nothing to the system answering it.

In many cases the channel a member uses arrived with a payroll or HRIS decision, or grew up inside HR by default, on terms the member set alone or inherited without a negotiation.

What does not exist anywhere in that picture is a portfolio answer. Across the membership, incoming verification runs member by member, channel by channel, and as far as we can determine, none of it flows through a HealthTrust agreement or returns anything to the members whose workforces generate it. Aggregating fragmented, member-by-member spend into contracted value is the HealthTrust model. For members, this is a category the model has not touched.

The activity is already running. The fees are already being paid. As far as we can determine, no agreement sits behind any of it.

#2For member employees

Your employees are notified of every verification request at the time it is made.

When a verification request arrives, the employee is notified on their phone and by email. They see who is asking, the stated purpose, and the record that would be released.

From there the request has three possible outcomes.

Approve. The verification proceeds immediately.

Deny. The request stops and nothing is released.

No response. After the response window the member sets, the verification may proceed for a credentialed verifier with a documented permissible purpose, on the authorization the employee already signed. That keeps a missed notification from delaying a mortgage, a lease, or a start date. The member sets the length of that window and can change it later.

Every request and every outcome is logged: the verifier, the purpose, the notice, the employee's response or nonresponse, and what was released.

Debt collection and skip tracing follow a stricter rule. Those requests proceed only on the affirmative approval of the employee or former employee. A nonresponse never authorizes those releases.

Employees can also review their record, flag possible inaccuracies for the member, and produce a verification for their own use without opening an HR ticket. Only the member can change the underlying source record.

In a tight labor market, giving people control of their own employment record is a retention signal. It says something about how the organization treats them.

Request Employee notice Outcome Buying a home Renting an apartment Starting a new job A debt collector calls the member employee sees who is asking and why ApprovedRelease proceeds DeniedRelease stops No responsethe member's waiting period

Debt collection and skip tracing do not proceed without the affirmative approval of the employee or former employee. A nonresponse never releases those.

#3The member revenue share

A negotiated share of up to 50 percent, up to $500,000 a year per member.

The current arrangements are described as free to the employer, and that is accurate as far as it goes. It is not free overall. Verifiers pay per verification to obtain records about member employees, and in many cases none of that comes back to the member. Free means someone else is collecting.

Under our model, a share of that same verifier fee returns to the member as new revenue: negotiated member by member, up to 50 percent of the fees its own workforce generates, up to $500,000 a year, paid monthly while the member is on the platform. Members pay no platform fee to earn it.

The workforce is already generating the underlying activity. The revenue share changes who benefits from it. What a given system receives reflects its own workforce and its own agreement, not a rate card.

This is not a cost reduction program. It is a revenue line that does not exist for members today, on a service they do not operate.

#4What HealthTrust receives

A standard administrative fee, on a category with no agreement behind it.

HealthTrust suppliers agree to an administrative fee as a standard term. The same structure applies here: MyEmployment as a contracted supplier, with an administrative fee to HealthTrust on the verifier fees generated across activated members. The arithmetic below models it at 3 percent, the standard construct across GPO supplier agreements, with terms to be agreed.

Estimated employees across the membership4 to 6 million
Industry average verifications per employee1.2 a year
Verifier fee per completed verification$59
Verifier fees at full adoption$283M to $425M a year
HealthTrust fee, modeled at 3 percent$8.5M to $12.7M a year

Full adoption is not the assumption. The math scales in a straight line, so the reader can hold any adoption level they find credible: at one quarter of the membership, the fee line still exceeds $2 million a year, on a category that produces nothing for HealthTrust today.

Employee base benchmarked against national healthcare employment ratios across 1,900 hospitals and more than 90,000 alternate sites, per HealthTrust's published figures. Member revenue share and administrative fee terms are negotiated; figures are illustrative.

#5For a member’s HR and payroll team

What this asks of a member.

A coordinated project, led by MyEmployment. The member approves the architecture, security controls, contractual terms, authorized fields, employee communications, and production cutover. MyEmployment provides the implementation plan, configures and tests the service, credentials and routes verifiers, coordinates the workstreams, and manages the transition.

Your team will not be working from a blank page. We keep a written switch kit covering both halves of the change. Turning the current feeds off: the HRIS or payroll connector settings, the separate instruction required where a partner administers a feed, what a termination notice to a verification vendor should contain, and what to expect on notice periods. Standing us up: the integration system user, the data domains it needs, secure credential handoff, connection testing, and sample record validation before anything reaches production. Your team gets it during the security review rather than after.

No payroll provider change is required. MyEmployment does not charge an integration fee. Any third party requirements or charges would be confirmed during review of the member's current arrangement.

Your existing process remains active until MyEmployment is configured, tested, and approved for production. Nothing changes until the member authorizes the cutover.

Nothing switches until the member says it switches.

#6For IT and security

Two implementation models. The member chooses the architecture.

The employee notice process, verifier controls, and audit trail operate the same way under either model.

No standing workforce copy
Live API at the time of request

When an authorized verification is processed, MyEmployment retrieves only the fields the member has approved for that request. The connection is read only: MyEmployment cannot write to the member's system or change an employment record.

Scheduled data delivery
Secure scheduled workforce feed

The member or its authorized payroll administrator provides an updated workforce file on an agreed schedule, typically weekly or after each payroll cycle. The source, authorized fields, delivery method, hosting terms, and retention periods are established during technical and contractual review.

These are alternative operating models, not implementation stages. The member selects the model that best fits its technical environment, security requirements, and relationship with its payroll administrator.

Two situations sit outside both models, and we can cover them. Some records predate a current system of record and sit in archives an API cannot reach. And the member may want verifications answered while the chosen model is still being configured. In either case a named member of our team can do that work under an individual account the member provisions, scopes to least privilege, and revokes, with multi-factor authentication, full lookup logging, and no local storage. This is a bounded service for transition and archived history, not a third architecture, and neither model depends on it.

What we keep is narrow. We retain the completed verification record for current and former employees, the request that prompted it, the employee's response or nonresponse, and the security logs behind it. That is the audit trail. Fields and retention periods are documented in contracting.

How a single verification moves under the API option:

Inbound request
The request

A credentialed verifier submits a request for one of your people. Nothing has left the member at this point.

Release gate
The gate

The employee is notified and can stop the release. A deny ends it. With no response inside the window the member sets, the request completes only for a credentialed verifier with a documented permissible purpose.

Answered by API
The answer

The authorized fields are read from your system of record and returned to that one verifier. Nothing is written back to your system, and no standing copy of your payroll database is kept.

What your team will want for the technical review: encryption in transit and at rest, multi-factor authentication, role based access on least privilege, annual independent penetration testing, and continuous control monitoring. Our SOC 2 report covers the controls in detail and is available under NDA. See section #8.

On effort: we will scope the integration with your team against your environment and put the implementation estimate in writing before anything is signed. We would rather your architects size this than have us guess at it.

#8Healthcare

Built by people who know this workforce.

Three decades in employment data

This is not thirty years in healthcare. It is three decades building and running employment data operations, including service to large health systems. The people building this have worked inside this world for a long time.

A large, distributed workforce

Thousands of nurses, techs, and support staff across many facilities, generating a steady stream of employment and income verifications.

A retention signal

A benefit that protects your employees' data and speaks to how a health system values the people who work there.

Mission fit

Putting employees in control of their own records is consistent with how a values driven health system already treats its people.

#9Compliance and SOC 2

Independently examined.

MyEmployment holds a SOC 2 Type 2 report covering the Security, Availability, and Confidentiality trust services criteria. A Type 1 report examined control design and was issued May 22, 2025. The Type 2 followed, testing whether those controls actually operated over an observation period of May 14 through August 15, 2025, with the final report and attestation letter issued August 19, 2025 by Sensiba, formerly AssuranceLab. Both reports, along with our most recent independent penetration test summary, are available to your security and compliance team under NDA.

The platform runs on Microsoft Azure. Controls tested include encryption of data in transit and at rest, multi-factor authentication, role based access on the principle of least privilege, annual independent penetration testing, quarterly access reviews, and continuous monitoring of the control framework.

Attestation
SOC 2 Type 2, Security, Availability, and Confidentiality. Observation period May 14 to August 15, 2025. Report issued August 19, 2025.
Examined by
Sensiba, formerly AssuranceLab, an independent CPA firm, under AICPA attestation standards.
For your team
Full report available under NDA. We are glad to sit with your security reviewers directly.

Who is behind it

Who you will be working with.

MyEmployment was founded by Robert Mather. He spent roughly three decades building one of the largest independent consumer reporting agencies in the United States, and has been a licensed investigator specializing in workplace and employment fraud since 1993. His company processed millions of employment verifications, and its largest client base was healthcare systems and hospitals. The workforces HealthTrust members run and the volumes they generate are familiar ground.

He first raised this publicly in 2013. He was a named source in an NBC News investigation that January reporting Equifax had accumulated salary and employment records on more than a third of US adults, and that employment data was reaching debt collectors. He started a competing service the same year, then paused it to focus on the complete pre-employment screening suite.

His company was acquired on October 28, 2022. He negotiated a carve-out in that sale specifically permitting him to build a model that competes with Equifax on employment verification. MyEmployment is that carve-out.

David K. Reed is President, and he owns delivery. Implementation and account operations run through David, from the security review and contracting through configuration, testing, and cutover, and then into ongoing service. Verifier support and employee exceptions are his as well.

#10What activation looks like

Standard vetting, standard fee, members on their own timelines.

Nothing in this model requires new machinery. A GPO participates through its standard supplier process: vetting, a supplier agreement, and an administrative fee on the category, disclosed to members the way supplier fees already are.

Members activate individually. A first-source directive requires no member contract, so early adopters can begin routing verification traffic while contracting completes, and no member is asked to end an existing relationship to begin. The contracted program follows for members who want the full model and the revenue share that comes with it.

The platform is live, the revenue share structure in section #3 is in use, and the diligence materials in section #9 are ready. What the category has lacked is not infrastructure. It is an agreement.

The open question is whether an agreement sits behind this category, and who is paid when it does.

Questions on this paper: Robert Mather, robert.m@myemployment.com, 702-508-6474.
Confidential. Prepared for HealthTrust Performance Group by MyEmployment. Not for distribution outside HealthTrust.