RSS Amplifier

Cannonball GTM · Jun 29, 2026

Public Data Sources for Healthcare

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

A cavalcade of data sources for outbound outreach and a cookbook of recipes to get you going.

Every healthcare GTM team touts its list of target companies and NPI numbers - the National Provider Identifier, which means the provider exists and is billing Medicare. It’s the healthcare industry’s version of a business license.

But a list of NPIs is not an insight by itself. It’s just the starting point.

What the list does not include: the operating margin for every hospital on it, from each hospital’s own filings. The specific survey deficiencies at every nursing home, the F-tag, the severity level, and the remediation deadline. The breach disclosed to HHS last month: the type, scale, and date. The Certificate of Need filing one of your prospects submitted six months ago for a service line that hasn’t been built yet.

Healthcare is one of the most data-rich industries in America, and almost nobody selling into it is actually reading the data.

But you will.

The Inventory

We’ve ranked these public data sources by how much of an edge they give you over every other vendor fighting for attention in your prospect’s inbox.

Medicare Cost Reports (cms.gov/cost-reports)

Every Medicare-certified institutional provider files an annual cost report with CMS, the Centers for Medicare & Medicaid Services which is the federal agency in the Department of Health and Human Services that administers critical public health programs, including Medicare, Medicaid, the Children’s Health Insurance Program (CHIP), and the Health Insurance markets of the Affordable Care Act. This data source is the financial X-ray of each provider and it’s wild that GTM teams are still ignoring it:

  • Operating margin and net income

  • Cost per discharge

  • Payer mix: Medicare %, Medicaid %, commercial %, self-pay %

  • Bed size, occupancy rate, admissions, patient days

  • Ownership type, teaching status, urban/rural designation

The data runs 12–18 months old, but a hospital with a declining margin across three consecutive reports is a documented trend you can name before the first call. Revenue-cycle vendors, cost-reduction platforms, advisory firms: anyone whose pitch improves a margin now has a number to put on it.

CMS cost reports · HCRIS data downloads

CMS Care Compare and the Provider Data Catalog (medicare.gov/care-compare)

Quality, safety, and survey data for every Medicare-certified hospital, nursing home, home health agency, and dialysis facility. For nursing homes specifically, you get the exact deficiency findings from every survey inspection: the F-tag, the scope and severity level, the correction deadline. That is healthcare’s OSHA equivalent, a named legal obligation, on a clock, in public record.

  • Star ratings: overall, health inspection, staffing, quality measures

  • F-tag citations: specific deficiency, scope/severity (A–L), correction deadline

  • CMS-2567 findings: surveyor narrative describing what was found

  • Staffing: RN hours per resident day, total nurse hours

  • Quality measures: falls, pressure ulcers, hospitalizations, antipsychotic use

Compliance platforms, clinical documentation software, staffing vendors, and EHR companies: the entry point is the specific item cited.

CMS Care Compare · Provider Data Catalog

HHS OCR Breach Portal “the Wall of Shame” (ocrportal.hhs.gov/ocr/breach)

Every reported breach of protected health information affecting 500 or more individuals, posted publicly within about two weeks of HHS receipt. Roughly 700 large breaches per year. The breach is specific, dated, and named:

  • Covered entity name and state

  • Business associate involved: yes/no

  • Individuals affected

  • Date of breach incident and date reported to HHS

  • Breach type: hacking/IT incident, unauthorized access, theft, loss, improper disposal

  • Location of breached PHI: network server, email, EMR, portable device, paper

Most of the vendor field hasn’t noticed the posting yet. Nobody has had time to run a procurement process. The buying window is open. Cybersecurity vendors, HIPAA and GRC platforms, incident-response firms, cyber insurers: if your product prevents breaches or manages their aftermath, this is your trigger.

HHS OCR Breach Portal

CMS Open Payments/Sunshine Act (cms.gov/open-payments)

Every payment from a drug or device manufacturer to a physician or teaching hospital is published annually. Before you call on a physician, you can see whether they’re already on a competitor’s speaker bureau. Before you approach a teaching hospital for a research partnership, you can see which manufacturers are already embedded:

  • Paying the manufacturer and product

  • Recipient physician or teaching hospital

  • Amount, date, and nature of payment: consulting, speaking, travel, research, royalty, meals

For device and pharma commercial teams, this maps the competitive landscape before the first call. Cross-reference with OIG exclusions or Care Compare deficiencies, and it becomes a compliance exposure signal as well.

CMS Open Payments data explorer

Medicare Provider Utilization and Payment Data (data.cms.gov)

Per-provider, per-procedure data on what every Medicare provider actually does at what volume: not what they say they do, what they bill. Joint replacements, oncology infusions, cardiac catheterizations, all of it keyed to the NPI, by year.

  • Provider NPI, specialty, location

  • Procedure code (HCPCS/CPT) and description

  • Beneficiary and service counts

  • Submitted charges and Medicare payment per service

  • Place of service (facility or non-facility)

Capital equipment sellers, service-line growth tools, anyone whose pitch depends on knowing a provider’s actual procedure mix.

CMS provider utilization and payment data

Hospital Price Transparency Machine-Readable Files (cms.gov/price-transparency)

Since 2021, hospitals must publicly post every standard charge available both in machine readable formats and for consumers. About 91% of hospitals were posted by the end of 2023. Enforcement tightened in April 2026:

  • Item or service description and code

  • Service setting: inpatient or outpatient

  • Gross charge

  • Payer-specific negotiated rate by payer name and plan name

  • De-identified minimum and maximum negotiated rates

  • Discounted cash price

There are two commercial angles for two different products.

  1. Rate intelligence: A hospital’s negotiated rate by payer and plan is now a public record, and a payer-contracting tool that benchmarks those rates against regional peers opens a CFO conversation with the prospect’s own numbers.

  2. Compliance exposure: A missing or non-conforming file is a civil monetary penalty waiting to happen, and the enforcement clock just got shorter. Payer-contracting tools own the first angle. Price-transparency compliance vendors own the second.

CMS price transparency rule · MRF schema on GitHub

openFDA (open.fda.gov)

The FDA’s open data: device adverse events (MAUDE), recalls classified I through III by severity, inspection outcomes (Form 483s and Warning Letters), and device registration. All API-accessible and downloadable.

  • Adverse events: device or drug involved, event type, patient outcomes, reporter type, date

  • Recalls: recalling firm, product description, recall classification (I/II/III), reason, distribution scope

  • Inspections: facility, district, classification (Official Action Indicated, Voluntary Action Indicated, No Action Indicated)

  • Registration: establishment name, registration number, operation type

A Class I recall is the FDA’s highest severity classification. A Warning Letter means significant violations were found. Both create remediation obligations with known dates. For device, diagnostics, and pharma-adjacent sellers, this is your consent order: a specific, dated, public forced-buying trigger. For medical device sellers, quality management platforms, and post-market surveillance tools, the recall is your entry point.

openFDA · MAUDE adverse events · Recalls database

NPPES NPI Registry (npiregistry.cms.hhs.gov)

The national registry of every provider and organization with a National Provider Identifier. On its own, just a denominator.

  • NPI number (Type 1: individual provider; Type 2: organization)

  • Provider name and credentials

  • Taxonomy codes: specialty and subspecialty classification

  • Primary practice address, phone, fax

  • Authorized official name and title (for organizations)

  • Enumeration date and deactivation date

NPPES NPI Registry · Bulk download

State Licensing and Certificate of Need Filings

A Certificate of Need (CON) filing is one of the few true leading indicators in healthcare: it announces an expansion before the building is built, before the RFP goes out, before any vendor has been called. In the roughly 35 states that maintain CON programs, providers must file a public application before adding beds, building facilities, or launching major new service lines:

  • Proposed project type and service line

  • Scope, projected volumes, and cost

  • Need justification

  • Approval/denial status and conditions

Coverage and portal quality vary significantly by state. But in the states where it works, this is the rarest signal in the vertical: a named expansion with months of lead time. Capital equipment, EHR modules, staffing, patient-acquisition platforms: anyone who sells into the build-out of a new service line should be watching these filings.

State CON program directories vary. Verify by state before building workflows.

The Healthcare Data Cookbook

Here are five recipes ranked by the asymmetry they create. Each one combines public sources into a specific dish: a pain-based segment plus a message angle no competitor can match, because none of your competitors has combined the same ingredients (yet).

Recipe 1: The Breach Aftermath

The Dish: A provider that just disclosed a large PHI breach and is scrambling to respond.

Ingredients: OCR Breach Portal (filter last 30–60 days, breach type = hacking/IT incident, 500+ individuals affected) + NPPES or Care Compare (facility profile) + (optional garnish) job postings for security, privacy officer, or CISO roles at the same entity in the same window.

Indicator Type: Trailing on the breach; leading on the remediation buying cycle.

Target Segment: Cybersecurity vendors, HIPAA and GRC platforms, incident-response firms, cyber insurers.

Read more

Read on cannonballgtm.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.