Skip to content
FonteumPublic-records evidence
Fonteum · Compliance · Attestations

The Audit-Ready Compliance Package

Give us a National Provider Identifier and we return a signed, dated attestation of an exclusion and integrity screen — the federal sources and supported state Medicaid lists currently loaded, the per-source result with its category and snapshot date, the full provenance behind each source, and an Ed25519 signature chained to Fonteum’s append-only attestation chain. The same document is available as machine-readable JSON and as a human-readable PDF.

What the document records

  • The subject NPI and the resolved graph entity it maps to.
  • Every source actually consulted — OIG LEIE, SAM.gov, the supported state Medicaid exclusion lists currently loaded, OIG Corporate Integrity Agreements, CMS Civil Money Penalties, and any other source named in that screen. The artifact does not claim coverage of the other states.
  • The per-source result — excluded, compromised-flag, no-match, or indeterminate — with its category, the snapshot date of the list version screened, and the methodology version.
  • The full 14-field provenance record for each source.
  • The check timestamp, the document SHA-256, and the Ed25519 signature.

How it is signed and chained

The attestation body is canonicalized and hashed with SHA-256. That hash is bound to the current head of Fonteum’s append-only attestation chain and signed with Ed25519. Anyone can recompute the hash from the document, re-derive the chain-bound identifier from the published chain head, and check the signature against the public key published at /.well-known/chain-public-key. A no-match result is issued only when the serving tables reconcile to the latest comparable attested source artifacts. Stale or unreconciled coverage is signed as indeterminate and is not a clearance.

Where it fits

CMS audit response

Attach a dated, signed record of the exclusion + integrity screen you ran on a billing provider, with the snapshot date of each list at the moment of the check.

OIG inquiries

Show which lists were consulted — OIG LEIE, SAM.gov, the supported state Medicaid exclusion lists currently loaded, OIG Corporate Integrity Agreements, and CMS Civil Money Penalties — and the per-source result. Other states are not covered.

NCQA / CAQH / URAC credentialing

Keep a reproducible screening-evidence artifact in the practitioner file: the document hash and the published signing key let a reviewer confirm the record was not altered after signing.

False Claims Act evidentiary use

A timestamped, signed screen documents diligence at a point in time. The attestation states what it asserts and what it does not — it is screening evidence, not a legal certification.

How to consume it

Signed JSON attestation for a single NPI:

GET https://fonteum.com/api/v1/exclusions/{npi}/attestation

Human-readable PDF package (same signed body):

GET https://fonteum.com/api/v1/exclusions/{npi}/attestation/pdf

Anonymous access is rate-limited; an API key raises the limit. Every response carries an X-Fonteum-SHA256 header matching the document hash. A signed-vs-JSON consumer checks the signature against the published chain public key; an auditor files the PDF.

This package is screening evidence, not a credentialing decision or a legal certification. Re-confirm any flagged or excluded result against the primary source list before taking adverse action.

Reviewed by Dr. Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer. Questions: hello@fonteum.com.

What’s on file, by the numbers

Platform snapshot · 2026-08-12

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
73fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access