Every healthcare GTM team touts its list of target companies and NPI numbers - the National Provider Identifier, which means the provider exists and is billing Medicare. It’s the healthcare industry’s version of a business license.
But a list of NPIs is not an insight by itself. It’s just the starting point.
What the list does not include: the operating margin for every hospital on it, from each hospital’s own filings. The specific survey deficiencies at every nursing home, the F-tag, the severity level, and the remediation deadline. The breach disclosed to HHS last month: the type, scale, and date. The Certificate of Need filing one of your prospects submitted six months ago for a service line that hasn’t been built yet.
Healthcare is one of the most data-rich industries in America, and almost nobody selling into it is actually reading the data.
But you will.
The Inventory
We’ve ranked these public data sources by how much of an edge they give you over every other vendor fighting for attention in your prospect’s inbox.
Medicare Cost Reports (cms.gov/cost-reports)
Every Medicare-certified institutional provider files an annual cost report with CMS, the Centers for Medicare & Medicaid Services which is the federal agency in the Department of Health and Human Services that administers critical public health programs, including Medicare, Medicaid, the Children’s Health Insurance Program (CHIP), and the Health Insurance markets of the Affordable Care Act. This data source is the financial X-ray of each provider and it’s wild that GTM teams are still ignoring it:
Operating margin and net income
Cost per discharge
Payer mix: Medicare %, Medicaid %, commercial %, self-pay %
Bed size, occupancy rate, admissions, patient days
Ownership type, teaching status, urban/rural designation
The data runs 12–18 months old, but a hospital with a declining margin across three consecutive reports is a documented trend you can name before the first call. Revenue-cycle vendors, cost-reduction platforms, advisory firms: anyone whose pitch improves a margin now has a number to put on it.
CMS cost reports · HCRIS data downloads
CMS Care Compare and the Provider Data Catalog (medicare.gov/care-compare)
Quality, safety, and survey data for every Medicare-certified hospital, nursing home, home health agency, and dialysis facility. For nursing homes specifically, you get the exact deficiency findings from every survey inspection: the F-tag, the scope and severity level, the correction deadline. That is healthcare’s OSHA equivalent, a named legal obligation, on a clock, in public record.
Star ratings: overall, health inspection, staffing, quality measures
F-tag citations: specific deficiency, scope/severity (A–L), correction deadline
CMS-2567 findings: surveyor narrative describing what was found
Staffing: RN hours per resident day, total nurse hours
Quality measures: falls, pressure ulcers, hospitalizations, antipsychotic use
Compliance platforms, clinical documentation software, staffing vendors, and EHR companies: the entry point is the specific item cited.
CMS Care Compare · Provider Data Catalog
HHS OCR Breach Portal “the Wall of Shame” (ocrportal.hhs.gov/ocr/breach)
Every reported breach of protected health information affecting 500 or more individuals, posted publicly within about two weeks of HHS receipt. Roughly 700 large breaches per year. The breach is specific, dated, and named:
Covered entity name and state
Business associate involved: yes/no
Individuals affected
Date of breach incident and date reported to HHS
Breach type: hacking/IT incident, unauthorized access, theft, loss, improper disposal
Location of breached PHI: network server, email, EMR, portable device, paper
Most of the vendor field hasn’t noticed the posting yet. Nobody has had time to run a procurement process. The buying window is open. Cybersecurity vendors, HIPAA and GRC platforms, incident-response firms, cyber insurers: if your product prevents breaches or manages their aftermath, this is your trigger.
CMS Open Payments/Sunshine Act (cms.gov/open-payments)
Every payment from a drug or device manufacturer to a physician or teaching hospital is published annually. Before you call on a physician, you can see whether they’re already on a competitor’s speaker bureau. Before you approach a teaching hospital for a research partnership, you can see which manufacturers are already embedded:
Paying the manufacturer and product
Recipient physician or teaching hospital
Amount, date, and nature of payment: consulting, speaking, travel, research, royalty, meals
For device and pharma commercial teams, this maps the competitive landscape before the first call. Cross-reference with OIG exclusions or Care Compare deficiencies, and it becomes a compliance exposure signal as well.
CMS Open Payments data explorer
Medicare Provider Utilization and Payment Data (data.cms.gov)
Per-provider, per-procedure data on what every Medicare provider actually does at what volume: not what they say they do, what they bill. Joint replacements, oncology infusions, cardiac catheterizations, all of it keyed to the NPI, by year.
Provider NPI, specialty, location
Procedure code (HCPCS/CPT) and description
Beneficiary and service counts
Submitted charges and Medicare payment per service
Place of service (facility or non-facility)
Capital equipment sellers, service-line growth tools, anyone whose pitch depends on knowing a provider’s actual procedure mix.
CMS provider utilization and payment data
Hospital Price Transparency Machine-Readable Files (cms.gov/price-transparency)
Since 2021, hospitals must publicly post every standard charge available both in machine readable formats and for consumers. About 91% of hospitals were posted by the end of 2023. Enforcement tightened in April 2026:
Item or service description and code
Service setting: inpatient or outpatient
Gross charge
Payer-specific negotiated rate by payer name and plan name
De-identified minimum and maximum negotiated rates
Discounted cash price
There are two commercial angles for two different products.
Rate intelligence: A hospital’s negotiated rate by payer and plan is now a public record, and a payer-contracting tool that benchmarks those rates against regional peers opens a CFO conversation with the prospect’s own numbers.
Compliance exposure: A missing or non-conforming file is a civil monetary penalty waiting to happen, and the enforcement clock just got shorter. Payer-contracting tools own the first angle. Price-transparency compliance vendors own the second.
CMS price transparency rule · MRF schema on GitHub
openFDA (open.fda.gov)
The FDA’s open data: device adverse events (MAUDE), recalls classified I through III by severity, inspection outcomes (Form 483s and Warning Letters), and device registration. All API-accessible and downloadable.
Adverse events: device or drug involved, event type, patient outcomes, reporter type, date
Recalls: recalling firm, product description, recall classification (I/II/III), reason, distribution scope
Inspections: facility, district, classification (Official Action Indicated, Voluntary Action Indicated, No Action Indicated)
Registration: establishment name, registration number, operation type
A Class I recall is the FDA’s highest severity classification. A Warning Letter means significant violations were found. Both create remediation obligations with known dates. For device, diagnostics, and pharma-adjacent sellers, this is your consent order: a specific, dated, public forced-buying trigger. For medical device sellers, quality management platforms, and post-market surveillance tools, the recall is your entry point.
openFDA · MAUDE adverse events · Recalls database
NPPES NPI Registry (npiregistry.cms.hhs.gov)
The national registry of every provider and organization with a National Provider Identifier. On its own, just a denominator.
NPI number (Type 1: individual provider; Type 2: organization)
Provider name and credentials
Taxonomy codes: specialty and subspecialty classification
Primary practice address, phone, fax
Authorized official name and title (for organizations)
Enumeration date and deactivation date
NPPES NPI Registry · Bulk download
State Licensing and Certificate of Need Filings
A Certificate of Need (CON) filing is one of the few true leading indicators in healthcare: it announces an expansion before the building is built, before the RFP goes out, before any vendor has been called. In the roughly 35 states that maintain CON programs, providers must file a public application before adding beds, building facilities, or launching major new service lines:
Proposed project type and service line
Scope, projected volumes, and cost
Need justification
Approval/denial status and conditions
Coverage and portal quality vary significantly by state. But in the states where it works, this is the rarest signal in the vertical: a named expansion with months of lead time. Capital equipment, EHR modules, staffing, patient-acquisition platforms: anyone who sells into the build-out of a new service line should be watching these filings.
State CON program directories vary. Verify by state before building workflows.
The Healthcare Data Cookbook
Here are five recipes ranked by the asymmetry they create. Each one combines public sources into a specific dish: a pain-based segment plus a message angle no competitor can match, because none of your competitors has combined the same ingredients (yet).
Recipe 1: The Breach Aftermath
The Dish: A provider that just disclosed a large PHI breach and is scrambling to respond.
Ingredients: OCR Breach Portal (filter last 30–60 days, breach type = hacking/IT incident, 500+ individuals affected) + NPPES or Care Compare (facility profile) + (optional garnish) job postings for security, privacy officer, or CISO roles at the same entity in the same window.
Indicator Type: Trailing on the breach; leading on the remediation buying cycle.
Target Segment: Cybersecurity vendors, HIPAA and GRC platforms, incident-response firms, cyber insurers.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.