Hospital Price Transparency Files: How to Open One
At the University of Chicago Medical Center, an MRI of the brain without and then with contrast carries six prices at once. Code 70553. The Aetna Medicare Advantage rate is $373.86. The Blue Cross PPO rate is $4,063.29. A chargemaster line for the same scan reads $7,132.00, and the discounted cash price attached to that line is also $7,132.00, which is another way of saying there is no cash discount on it.
None of that came from asking anyone. The numbers sit in a 42,386,565-byte file on a public web server, last updated 1 April 2026, which the hospital is required to leave there for anyone who wants it. I downloaded it on 10 September 2026. Every hospital licensed in the United States has one, with a short list of exceptions for federal, tribal, and state forensic facilities at 45 CFR 180.30(b).
Almost nobody opens theirs, and it is not because the file is hidden. It is because the file is awkward: too big for a spreadsheet, named after a tax ID number, and parked three clicks into a billing page nothing links to. Each of those has a fix.
What Part 180 actually requires a hospital to post
Two separate things, and they are not equally useful to you.
The first is the machine-readable file, required by 45 CFR 180.50. It has to carry every item and service for which the hospital has set a standard charge, and for each one, up to five kinds of number defined at 180.20: the gross charge from the chargemaster, the discounted cash price, the payer-specific negotiated charge for each payer and plan, and the de-identified minimum and maximum the hospital has negotiated with anybody at all.
The second is a consumer-friendly display of at least 300 shoppable services under 45 CFR 180.60. A hospital is deemed to meet that one if it runs a price estimator tool instead, which most large systems do. The estimator is what you will find first when you search, and it is the weaker of the two. Seventy of the services in it are named by CMS and the hospital picks the rest, the list stops at three hundred either way, and what comes back is a single estimate rather than the spread. The big file is where the spread lives.
Skip the billing page: go straight to cms-hpt.txt
Since 1 January 2024, paragraph (d)(6) of 180.50 has required the website hosting the file to keep a
plain text file in its root folder giving the hospital location name, the source page URL, a direct
link to the machine-readable file, and a hospital contact. That is a shortcut nobody advertises. Take
the hospital's domain and add /cms-hpt.txt.
Three I opened on 10 September 2026:
location-name: University of Chicago Medical Center
source-page-url: https://www.uchicagomedicine.org/patients-visitors/patient-information/billing/price-transparency
mrf-url: https://edge.sitecorecloud.io/.../363488183_the-university-of-chicago-medical-center_standardcharges.json
contact-name: Office of Managed Care
contact-email: mcare@uchicagomedicine.org
That one listed three locations. Cleveland Clinic's, at my.clevelandclinic.org/cms-hpt.txt, listed
23. Mass General Brigham's listed 14, each pointing at a different source page on a different
hospital's website, which is the exact sprawl the root file exists to collapse.
The counts differ because of 180.50(a)(2): where locations under one hospital license carry different standard charges, each location has to publish its own set. Find the line for the building you were treated in rather than the one at the top. The academic medical center and the community hospital forty miles away are separate files with different numbers in them, and nothing on your bill says which one you belong in.
Notice the contact line. It is a named person or team with a working address, published because the rule says so. That is a better destination for a question about a missing code than the general billing number, and it is one of the few contacts in hospital billing you did not have to ask for.
One more paragraph is worth knowing by heart. 180.50(d)(3) says the information must be free, must not require a user account or a password, must not require you to hand over identifying information, and must be reachable by automated searches and direct download; (d)(4) says the file itself must be digitally searchable. A registration wall in front of the file is therefore not a vendor quirk. It is the specific thing that paragraph was written to stop, and it is worth naming that way in a complaint.
Two systems, Mayo and Johns Hopkins, answered a command-line request with a block page instead of
the file, and were still blocking a headless browser on 10 September 2026. A block is not an
absence, and the body of the response tells you which one you got: Mayo returns an Akamai access
denied notice, Johns Hopkins returns a Cloudflare challenge, and neither is a 404. Read either
address through a text-extraction proxy and the file is plainly there, Mayo's pointing at
410944601_mayo-clinic-hospital-rochester_standardcharges.csv. If a script gets a 403, open the
address in an ordinary browser before concluding the hospital has posted nothing.
The file name is a tax ID, and it is worth checking
180.50(d)(5) sets the naming convention: <ein>_<hospital-name>_standardcharges.[json|csv]. That
leading number is the hospital's employer identification number, which is how you tell two hospitals
in one system apart when their names are nearly identical.
The link you click may look nothing like that. Cleveland Clinic's mrf-url is a vendor download
endpoint with no file name in it at all. Following it produced a 302 redirect and then a
48,913,084-byte archive whose real name was
340714585_the-cleveland-clinic-foundation_standardcharges (2).zip, stray parenthetical included.
Mass General Brigham posts zip archives too, and the Brigham and Women's Hospital one was 2,876,602
bytes, last modified 23 July 2026. Check what landed in your downloads folder rather than what the
link looked like.
42 MB, and why your spreadsheet is the wrong tool
Do not double-click it. A CSV version of one of these routinely runs past Excel's hard ceiling of 1,048,576 rows, and even when it fits, opening it ties up the machine for a long stretch.
A saner order of operations. If you want one common outpatient service and nothing else, use the hospital's estimator first, because that is the case it was built for. If you want your specific code, open the file in a text editor built for large files and use plain find, or search it from a command line. The record you want is a run of text, and you can read it without parsing anything. JSON files are one long object with an array of items inside. CSV files put general information about the hospital on the first two rows and the actual charges from row three down, which is why loading one into a spreadsheet gives you a header row that looks broken. CSV also comes in two shapes, tall and wide, and the choice decides whether a payer gets its own row or its own pair of columns far off to the right.
CMS publishes the layouts, the column names, and the valid values in a GitHub repository of templates and the data dictionary. The current CSV dictionary is version 3.0. Keep that page open beside the file.
Your CPT code is filed under a different name
Here is the thing that makes people quit thirty seconds in.
I counted the code types in the University of Chicago file: 36,961 entries typed HCPCS, 34,773
typed CDM, 34,559 typed RC, 7,322 typed NDC, 889 typed MS-DRG, and 250 typed APC. Entries
typed CPT: none. Filter that file on the code type CPT and you will conclude the hospital has never
performed your procedure.
CPT is level I of HCPCS. A hospital that labels those codes HCPCS is being correct, not evasive.
Search the code string itself. The list of valid code types runs past twenty in the CMS dictionary,
covering revenue codes, several DRG families, APCs, dental codes, and LOCAL for internal accounting
codes, so guessing which bucket your item landed in is a losing game.
Pull the codes off your bill rather than off the internet. If your statement shows only department totals, that is a separate request with its own wording, covered in requesting an itemized bill.
One code, three rows, two entirely different meanings
Searching 70553 in that file returns three records, and reading them as one number is the error.
Two are chargemaster rows, carrying an internal code (61170553), revenue code 611, a gross charge of
$7,132.00, and a discounted cash price of $7,132.00. The third has no gross charge at all. It carries
a minimum of $373.86, a maximum of $4,063.29, and six payer entries, each with a payer name, a plan
name, a methodology, and a dollar amount.
Two fields decide whether a row is even about you. setting says inpatient, outpatient, or both, and
the same code frequently prices differently in each. billing_class says facility, professional, or
both. A facility row is the hospital's charge for the room, the machine, and the staff. It is not the
radiologist who reads the scan, who bills separately and appears nowhere in this file. That split is
the same one that turns a single appointment into two envelopes, taken apart in
hospital facility fees.
When the price is an algorithm instead of a dollar amount
Some contracts do not resolve to a number in advance, and 180.50(b)(2)(ii)(C) makes the hospital say so and describe the percentage or algorithm. Since 1 January 2026, subparagraph (C)(2) has also required, for those items, the 10th percentile, median, and 90th percentile of what the hospital actually collected over a lookback window of no less than 12 and no more than 15 months, plus a count of the remittances behind those figures.
A real one, MS-DRG 003, Aetna HMO and PPO:
methodology: other
count: 1 through 10
10th_percentile: 761319.86
median_amount: 761319.86
90th_percentile: 1024048.83
standard_charge_algorithm: [Stop Loss: Total Charges > 200000 | Excess % of Charge: 35]
[Lesser Than Charges paid at %: 100] [MSDRG Base Rate: FEE SCHEDULE]
Those percentile fields are the most useful thing added to these files in years, because they are
receipts rather than list prices. Read count before you read them. 1 through 10 is a literal
valid value rather than sloppy data entry, adopted so that a hospital with a handful of remittances
does not publish what amounts to one patient's settlement, and it means the median above is one or
two claims wearing a statistical hat. Where the count reads 0, the hospital had no remittances in
the window at all, the percentiles are legitimately blank, and the rule requires the hospital to
explain why in the additional notes field.
The elements came out of the CY2026 OPPS final rule
(90 FR 54087),
They took effect on 1 January 2026, and CMS then held enforcement back to 1 April 2026 to give
hospitals a quarter to encode them, which is why so many of these files carry an April date. A file
whose version field reads 3.0.0 is built to that standard. An older version number tells you the hospital has not refreshed since.
What the number in the file is not
It is not your bill. The negotiated charge is the hospital and the insurer agreeing what the service is worth. Your deductible and coinsurance then decide how much of it lands on you.
It is not current by default. 180.50(e) requires an update only once a year. Read the
last_updated_on field before you quote anything out of it.
It is not audited. From 1 January 2026 the hospital must attest under 180.50(a)(3)(iii) that the data is true, accurate, and complete, and name the executive who oversaw the encoding under (a)(3)(iv). The University of Chicago file names Chris Allen. An attestation is an assertion with a person's name attached, which is more than most billing documents carry, and still not a verified figure.
And it is not a quote. If you want a number the provider is answerable for before care happens, that is a good faith estimate, and it comes with a dispute process of its own, laid out in the $400 rule.
Before you call the billing office
Open your hospital's domain followed by /cms-hpt.txt and save two things: the direct file URL for
the location where you were treated, and the contact address. Pull your codes off the itemized bill.
Search the file for the code string rather than the code type, then write down four values, which are
the payer-specific rate for your plan, the de-identified minimum, the de-identified maximum, and the
last_updated_on date.
Set that against the allowed amount on your explanation of benefits. If the two disagree by real money, you now have a specific question with a citation under it, addressed to a named person, and the file date is what keeps it checkable six months from now. If the hospital has posted nothing at all, the complaint goes to CMS through the provider complaints form, and the ladder from warning notice to published penalty runs through 180.70, 180.80, and 180.90.
Regulation text quoted here was read in the eCFR on 10 September 2026, against the Title 45 text issued 8 September 2026. Rules change, and these did as recently as this January. Check the current section before you rely on a date or a figure. Nadia Ellsworth is not a lawyer, a doctor, or a billing professional.
Frequently asked questions
Where do I find my hospital's price transparency file?
Type the hospital's web domain followed by /cms-hpt.txt. Since 1 January 2024, 45 CFR 180.50(d)(6) has required the website hosting the file to keep a plain text file in its root folder listing each hospital location, the page that hosts the charges, a direct link to the machine-readable file, and a hospital contact. The same paragraph requires a footer link on the homepage labeled Price Transparency. I read that rule text on 10 September 2026. Some hospital sites answer a command-line request with a block page rather than the file; Mayo and Johns Hopkins both did on 10 September 2026, and both files were in fact there. Open the address in an ordinary browser if a script gets a 403.
Why can I not find my CPT code in the file?
CPT is level I of HCPCS, and most hospitals label those codes HCPCS rather than CPT in the code type column. In the University of Chicago Medical Center file I downloaded on 10 September 2026, 36,961 code entries carried the type HCPCS and not one carried the type CPT. Search for the five-character code itself instead of filtering on the code type. Your item may also appear under a revenue code, an MS-DRG, an APC, or the hospital's internal chargemaster code, all of which are valid code types in the CMS data dictionary.
Is the negotiated price in the file what I will owe?
No. The payer-specific negotiated charge is what the hospital and the insurer agreed the service is worth. Your share comes from applying your deductible, coinsurance, and copay to that number, and the file knows nothing about where you are in your plan year. The file also covers only the hospital's own charges. The radiologist, anesthesiologist, and pathologist bill separately and are not in it.
What if the hospital has posted nothing at all?
You can report it to CMS through the provider complaints form. Under 45 CFR 180.70(b), CMS may issue a warning notice, request a corrective action plan under 180.80, and then impose a civil monetary penalty under 180.90 and publish the hospital's name. The daily maximums written into 180.90 are adjusted for inflation every year, so quote the adjustment table rather than the regulation: at 45 CFR 102.3, read on 10 September 2026, the adjusted figures were $342 a day for hospitals with 30 or fewer beds, $11 per bed per day from 31 to 550 beds, and $6,277 a day above 550 beds. Those figures came from the annual adjustment published at 91 FR 3665 on 28 January 2026, the most recent amendment to Part 102 in the Title 45 text issued 8 September 2026.