Under 45 CFR §180.50, every US hospital must publish a machine-readable file (MRF) listing prices for all items and services. CMS has issued 1,000+ penalty actions since enforcement began — and industry studies still find 30–55% of files deficient. Here's exactly what the file must contain.
The 8 Required Data Categories
✗Payer-specific negotiated charges — the rate each plan agrees to pay, for every item/service, for every plan the hospital contracts with.
✗Discounted cash price — the price for cash-paying patients, on every item and service.
✗Gross charges — the full undiscounted charge for every item and service.
✗De-identified minimum & maximum negotiated rates — the low and high negotiated rates across all payers.
✗All 70 shoppable services — CMS publishes a specific list of 70 services that must appear by name.
✗Additional required data elements — 30+ fields including billing codes, drug details, and plan identifiers.
✗Machine-readable format — JSON or CSV, structured so software can parse it without human reading.
✗Public accessibility — no login, no paywall, no bot-blocking; CMS's automated checkers must reach it.
The 5 Most Common Reasons Hospitals Fail
1. Missing payers — file covers only 2-3 of 5+ major commercial payers COMMON
2. Cash price gaps — discounted cash price absent on lab/imaging items COMMON
3. Shoppable services — under 70, or named differently than CMS expects COMMON
4. Bot-blocking — file loads in browser but 403s automated crawlers COMMON
5. Stale file — published once, never updated after contract changes COMMON
What Non-Compliance Costs
CMS fines $5,500 per day per violation. One missing payer rate, left unfixed for a month, is $165,000. Multiple violations across months can reach seven figures. The fine is per day — it accrues while you work on the fix.
Not sure your file passes every check above?
Get a free MRF risk check — 24-hour turnaround, no obligation.
Get Your Free Risk Check