.png)
This month (August 2026), Gigasheet crawled the public website of every hospital in CMS's Hospital General Information dataset, all 5,419 of them, and tested for the cms-hpt.txt discovery file that federal regulation has required since January 1, 2024. Only 1,595 hospitals, 29.4%, returned a valid file at the standard location. Another 19.5% blocked automated access entirely.
Hospital price transparency only works if you can actually find the data. Right now, too often, you can't. And this isn't a new problem. Turquoise Health measured txt file adoption in April 2024, three months after the requirement took effect, and found roughly 30% of hospitals had posted the file correctly. Two and a half years later, our number is 29.4%. Adoption is flat. The rules are fine, the enforcement isn't.
That finding matters right now because CMS is asking for input. The CY2027 OPPS proposed rule (CMS-1850-P) includes a Request for Information on strengthening the standardization and comparability of hospital price transparency data, and the comment period closes August 31, 2026. CMS is asking the right questions about data quality and consumer displays. But based on what we found, the biggest opportunity isn't a new data element or a better display template. It's enforcement of the rules already on the books.
Quick background for anyone who hasn't lived in this world.
Hospital price transparency has required hospitals to post a machine-readable file (MRF) of their standard charges since January 1, 2021. The problem in the early years was that even when hospitals published the file, nobody could find it. Files were buried behind portals, renamed, moved, or hidden from search engines. Researchers and vendors, ourselves included, spent enormous effort just locating the data.
CMS fixed this on paper in the CY2024 OPPS final rule. Under 45 CFR 180.50(d)(6), effective January 1, 2024, every hospital must place a .txt file in the root folder of the public website that hosts its machine-readable file. CMS's technical guidance standardizes the filename as cms-hpt.txt. The file must contain the hospital location name, the source page URL, a direct link to the machine-readable file, and hospital contact information. The same rule requires a "Price Transparency" link in the website footer.
The design is smart. It borrows from how the web already solves discovery, the same way robots.txt tells crawlers how to index a site. If every hospital publishes cms-hpt.txt at its root domain, anyone can programmatically locate every MRF in the country. No scraping, no guessing, no phone calls.
That's the theory. Here's the practice.
We started with the full CMS hospital universe: 5,419 unique CCNs covering acute care, critical access, psychiatric, children's, VA, DoD, long-term, and rural emergency hospitals. Because CMS doesn't publish a hospital website field, we matched facilities to candidate web domains using public price transparency directory data, scored every match for confidence, and then made one controlled request per unique host to https://hospital-domain/cms-hpt.txt. We followed redirects, validated content, and preserved every URL, status code, and response hash so the results are auditable.
The headline numbers:
A few things jump out.
First, the 1,595 valid results came from just 692 unique hosts. Health systems publish one file covering many facilities, which is fine and expected. The convention can scale.
Second, nearly one in five hospitals sits behind bot protection that blocks the exact kind of automated discovery the txt file exists to enable. A cms-hpt.txt file behind a CAPTCHA defeats its own purpose.
Third, a fair reading of these numbers is not "70% of hospitals are noncompliant." Some hospitals publish valid files that our conservative, single-pass methodology couldn't confirm. This is a measurement of discoverability, not a compliance scorecard. But that's exactly the point. If a well-resourced analytics company running a careful national crawl can only confirm the standard discovery file for 29.4% of hospitals, the discovery layer is not working as intended.
CMS's RFI asks how to make MRF data more standardized and comparable. Those are worthy goals. But standardization of files nobody can find is a paper victory.
Don't take our word for it. Take CMS's. The agency publishes its own enforcement activities and outcomes dataset, and the July 2026 release tells the story. Since the rule took effect in January 2021, CMS has logged 13,355 enforcement actions, but only 29 of them were civil monetary penalty notices, covering just 27 hospitals. That's an average of about five fines a year across more than 5,400 hospitals. The other 99.8% of actions were warning notices, corrective action plan requests, and case closures. A hospital weighing the cost of compliance against a fine it will almost certainly never receive is making a rational choice to ignore the rule.
The txt file requirement is the easiest price transparency rule to verify in existence. It's binary. Either https://domain/cms-hpt.txt returns a valid file or it doesn't. CMS could check every hospital in the country in an afternoon with a script. No manual review, no sampling, no judgment calls about whether an estimator tool counts.
So our comment to CMS boils down to three recommendations:
1. Automate txt file verification. CMS should run, and publish the results of, a recurring automated check of cms-hpt.txt across all registered hospitals. Make the pass/fail list public. Sunshine is cheap and effective.
2. Require crawler access to the file. Clarify that blocking automated access to cms-hpt.txt and the MRF itself violates the accessibility requirement in 180.50. A file that returns a 403 to any non-browser user agent is not "publicly available" in any meaningful sense.
3. Close the domain gap. Require hospitals to register their public website domain with CMS, tied to their CCN. Roughly a fifth of our effort went to figuring out which website belongs to which hospital. CMS already collects far more burdensome data. One URL field would eliminate the largest source of ambiguity in national discovery.
None of this requires new legislation. The penalty structure already exists, up to $5,500 per day for large hospitals. What's missing is systematic, automated verification of the parts of the rule that are trivially verifiable.
The cms-hpt.txt convention is good policy. It just isn't enforced, and the data shows it. Before CMS invests in the next generation of data standards, it should make sure the discovery layer for the current generation actually functions.
If you work with this data, or want to, the comment period for CMS-1850-P is open on regulations.gov through August 31, 2026. Tell CMS what you're seeing. We will.
And if you want to explore hospital price transparency data without building your own crawler, that's what we do at Gigasheet.
It's a plain text file that every U.S. hospital is required to place at the root of the public website hosting its machine-readable file of standard charges, for example https://hospital.com/cms-hpt.txt. It must list the hospital location name, the source page URL, a direct link to the machine-readable file, and contact information. The requirement comes from 45 CFR 180.50(d)(6) and took effect January 1, 2024.
In Gigasheet's August 2026 crawl of all 5,419 hospitals in CMS's Hospital General Information dataset, 1,595 hospitals (29.4%) returned a valid cms-hpt.txt file at the standard root location. Another 19.5% were blocked by access restrictions and could not be evaluated, so true adoption is likely somewhat higher, but discoverability remains the core problem.
Not necessarily. A hospital may host a valid file behind bot protection, on a system-level domain, or in a configuration a single crawl can't confirm. Our results measure discoverability under a defined method, not legal compliance. That distinction is itself an argument for CMS running its own authoritative checks.
Comments on the CY2027 OPPS proposed rule (CMS-1850-P), which includes the Request for Information on strengthening hospital price transparency data, are due August 31, 2026 via regulations.gov.
CMS can impose civil monetary penalties of $300 per day for hospitals with 30 or fewer beds and $10 per bed per day, capped at $5,500 per day, for larger hospitals. Sustained noncompliance can exceed $2 million per hospital per year.
According to CMS's own enforcement dataset, 27 hospitals have received civil monetary penalty notices since the rule took effect in January 2021, out of 13,355 total enforcement actions through July 2026. The vast majority of actions were warning notices and corrective action plan requests.
Methodology note: Analysis based on the CMS Hospital General Information dataset retrieved August 2026 and public hospital price transparency directory data. The crawl tested https://candidate-host/cms-hpt.txt, followed redirects, validated content conservatively, and classified restricted-access and error responses as indeterminate. Results describe observed web retrieval behavior at crawl time and do not constitute a compliance determination.