Your hospital has a price transparency file posted. Someone checked that box years ago. Is it actually compliant?
Here's the uncomfortable part of that question: you are the only party in this arrangement who hasn't read your own file recently. Your machine-readable file is a public URL. Payers parse it. Competing systems parse it. Researchers, journalists, and advocacy groups parse it — that's exactly how the compliance studies below got their numbers. Rate-benchmarking tools like ours parse it. Everyone who consumes your file is, incidentally, auditing it. CMS is not the first party to notice a defect in your MRF. It's usually the last.
Independent research says the defect is probably there. A peer-reviewed study found only 33.4% of hospitals in compliance with the Hospital Price Transparency rule. A separate compliance audit by PatientRightsAdvocate.org found just 21.1% fully compliant. Both numbers describe the same underlying pattern: most hospitals have something posted, and most of those somethings don't actually meet CMS's requirements.
The Pain: Hospital Price Transparency Compliance Isn't the Same Question as "We Posted a File"
The Hospital Price Transparency rule, in effect since January 2021, requires two things: a comprehensive machine-readable file listing gross charges, discounted cash prices, and every payer-specific negotiated rate for every item and service, and a consumer-facing "shoppable services" display covering at least 300 common, pre-bookable services.
Posting a file that technically exists is the low bar. Compliance requires the file to actually contain every required field, in the format CMS's own standardization update requires, for every service line, kept current. That's a much higher bar, and it's where most hospitals actually fail — not at "did we publish something" but at "does what we published hold up field by field."
CMS has been tightening that gap deliberately. The maximum daily penalty rose from $300 flat to as much as $5,500/day (calculated at $11 per bed per day, capped near $2 million annually for large hospitals; smaller hospitals with 30 or fewer beds face a flat $323/day). A new machine-readable file format standardization began enforcement in mid-2024, and CMS started a stricter enforcement wave in April 2026. Real fines have followed: one study documented penalties ranging from $56,940 to $979,000 across 14 hospitals since 2022.
The Opinion: This Is a Detection-Latency Problem, Not a Violation-Severity Problem
Look closely at the structure of that penalty and it tells you something most compliance write-ups skip past.
The fine is per day, not per violation. Nothing in it scales with how badly you missed. A file that omits payer-specific breakouts for two payers and a file that omits them for twenty accrue at the same rate. What actually determines the number on the notice is how many days passed before anyone checked.
Run the arithmetic on the cited figures and the point gets sharp fast. At the $5,500/day ceiling, the highest documented fine in that study — $979,000 — is roughly 180 days of accrual. Six months of not knowing. The low end of the documented range, $56,940, is on the order of ten days at that same ceiling. (That's arithmetic on the published penalty structure and the published fine range, not a reconstruction of how any specific fine was calculated — but the shape holds either way.)
So the risk-management question is not "how serious is our defect." It's "what is our time-to-detection." A hospital that finds a formatting failure in week one and one that finds the identical failure in month seven have the same violation and wildly different exposure. That is a monitoring problem wearing a compliance problem's clothes, and it is why an annual legal review — a snapshot, taken once, twelve months apart — is structurally the wrong instrument for it. The gap between snapshots is the liability.
The Proof: Compliance Improved on Paper, Not Necessarily in Substance
The topline number sounds like progress: hospitals with a posted machine-readable file rose from 70% in December 2021 to 88% by December 2022, largely after CMS raised the penalty ceiling. But "posted a file" and "posted a compliant file" are measuring different things, and the two independent compliance studies above — run after that improvement — still found only 21-33% fully compliant.
That gap is the real story, and it has a boring, human explanation. Raising the price of non-compliance without changing what's cheap to observe gets you compliance with the observable part. "Is there a file at this URL" is a check anyone can run in a second. "Does row 412,000 carry a payer-specific negotiated rate in the current required structure" is not. Hospitals responded rationally to the bar that was actually being measured. The 18-point jump in posting rates and the flat 21-33% substantive compliance rate are the same fact viewed twice.
Which means the published guidance doesn't close the gap either. CMS's own materials, the American Hospital Association's fact sheets, and every academic study on this topic explain what the rule requires. None of them tell a hospital whether its own specific file, at its own specific URL, meets those requirements right now.
It's worth separating this from a related but different question we've written about before: whether your contracted rates are competitive once the file is compliant. That's its own benchmarking problem — this piece is about whether the file itself would survive being read.
The Path: What Compliance Actually Requires, Checked Against Your Own File
The rule breaks down into concrete, checkable requirements — not a vague "be transparent" standard:
| Requirement | What it actually means |
|---|---|
| Comprehensive machine-readable file | Every item/service, with gross charge, discounted cash price, and de-identified minimum and maximum negotiated rates |
| Payer-specific negotiated rates | Rates broken out by specific payer and plan name, not aggregated |
| Standardized format | Must follow CMS's required machine-readable format (updated and re-enforced starting mid-2024) — a file in the wrong structure can fail even with the right data in it |
| Shoppable services display | At least 300 CMS-specified common services (or a hospital-selected substitute list meeting the minimum), in consumer-readable form |
| Currency | Updated at least annually, reflecting actual current rates |
Most compliance failures live in the middle three rows, not the first.
An illustrative composite — assembled from the failure modes the published compliance studies describe, not a specific hospital. The recurring shape looks like this. A file was built once, correctly, against the requirements as they stood at setup. It is still posted, still loads, still parses. It fails anyway, on three things at once: some payers' rates were aggregated rather than broken out by plan name, because that's how they arrived from the contracting system; the file structure predates the mid-2024 standardization and was never migrated, since nothing about the file visibly broke when the requirement changed; and the shoppable-services list drifted below the 300-service threshold as service lines were retired and never backfilled. Every one of those is invisible from the outside of the organization and invisible from the inside without reading the file itself. And each was true continuously, from the day it started, accruing at whatever the daily rate is — which is the detection-latency problem stated concretely.
Note what all three have in common: nobody made a mistake. The file didn't rot because someone was careless. It rotted because requirements moved and files don't announce that they've fallen behind.
That's what makes this a bad fit for the two things usually sold against it. A consulting firm will sell you a compliance review — real expertise, priced in hours, delivered as a point-in-time document, and structurally unable to be run monthly against a several-hundred-megabyte file. A SaaS compliance product will sell you a checklist and a dashboard, and then you still have to be the one who opens your MRF, reads it, and decides whether row-level structure matches the current spec. Both hand the actual reading of the file back to you.
Performis already reads files like yours — that's what our payer rate benchmarking does, parsing real machine-readable files at scale to extract structured rate data for comparison across payers and hospitals. We built that capability to look at the market from the outside. Turned inward, the same parsing runs against your own file and checks what's actually there: are the required fields present, is the format the current one, does the shoppable-services list clear the threshold. The agent does the reading. You don't get a framework for auditing your file; you get the file audited.
To be precise about what that is and isn't: this is field, format, and threshold presence — the checks that catch the middle three rows of that table. It isn't a CMS certification, and no vendor can issue you one. It's the difference between finding out in week one and finding out in month seven.
The Prompt
If your hospital's price transparency file was set up once and hasn't been read — actually read, field by field — against the current format requirements since, that's worth confirming directly rather than assuming the original setup still holds. Especially with CMS's enforcement wave active since April 2026, and especially given that the file has been publicly readable by everyone else the entire time.
Check your hospital's price transparency file against current CMS requirements before it gets checked for you.
More on the revenue-cycle side of what your payer data can tell you: Denial Management: Why It's Not Where Most of Your Recoverable Revenue Actually Is.