Both PCI and HIPAA have credentialing (and HIPAA has a statutory mandate to require it, though the implementing regulations have not been adopted on the timeline mandated in the statute, and presumably won't be now since the Trump Administration seems to be applying the same neglect and sabotage approach to the required updates to HIPAA standards as to most of the ACA, perhaps because some of the requirements for the former were adopted with the latter or related bills.)