CMS Machine-Readable File Requirements: The Complete 2026 Checklist

Under 45 CFR §180.50, every US hospital must publish a machine-readable file (MRF) listing prices for all items and services. CMS has issued 1,000+ penalty actions since enforcement began — and industry studies still find 30–55% of files deficient. Here's exactly what the file must contain.

The 8 Required Data Categories

Payer-specific negotiated chargesthe rate each plan agrees to pay, for every item/service, for every plan the hospital contracts with.
Discounted cash pricethe price for cash-paying patients, on every item and service.
Gross chargesthe full undiscounted charge for every item and service.
De-identified minimum & maximum negotiated ratesthe low and high negotiated rates across all payers.
All 70 shoppable servicesCMS publishes a specific list of 70 services that must appear by name.
Additional required data elements30+ fields including billing codes, drug details, and plan identifiers.
Machine-readable formatJSON or CSV, structured so software can parse it without human reading.
Public accessibilityno login, no paywall, no bot-blocking; CMS's automated checkers must reach it.

The 5 Most Common Reasons Hospitals Fail

1. Missing payers — file covers only 2-3 of 5+ major commercial payers COMMON
2. Cash price gaps — discounted cash price absent on lab/imaging items COMMON
3. Shoppable services — under 70, or named differently than CMS expects COMMON
4. Bot-blocking — file loads in browser but 403s automated crawlers COMMON
5. Stale file — published once, never updated after contract changes COMMON

What Non-Compliance Costs

CMS fines $5,500 per day per violation. One missing payer rate, left unfixed for a month, is $165,000. Multiple violations across months can reach seven figures. The fine is per day — it accrues while you work on the fix.

Not sure your file passes every check above?

Get a free MRF risk check — 24-hour turnaround, no obligation.

Get Your Free Risk Check