Skip to content
FonteumPublic-records evidence
FINANCIAL DISTRESS · ISSUE 057
oig-leieOriginal Research

OIG Exclusion Check: The 2026 Excluded-Provider Landscape

At the July 14, 2026 audit cutoff, the OIG LEIE, SAM.gov, and 13 state Medicaid programs contained 10,824 NPI-identified providers barred from a public health program — yet the single most complete list, the OIG LEIE, named only 6,880 of them. Screen against that one source and 36.4% of excluded providers come back clean.

BY FONTEUM LLC · JUNE 15, 2026 · 11 MIN READREVIEWED BY DR. JENNIFER MONTECILLO, MDSNAPSHOT 2026-07-14 · LAST UPDATED JULY 14, 2026
OIG LEIE · 2026-07-14
Share of the excluded-anywhere population each single list coversexclusion-landscape · 2026-07-14
OIG LEIE
63.6
State (13)
45.7
SAM.gov
43.4
Built on OIG LEIE · snapshot 2026-07-14 · reproducible · re-derive the figures yourself
Key findings
distinct NPI-identified providers were barred from a public health program across the OIG LEIE, SAM.gov, and 13 state Medicaid exclusion lists at the July 14, 2026 audit cutoff
exclusion-landscape · CMS
is the most any single list covers — the OIG LEIE names 6,880 of the 10,824, so federal-LEIE-only screening misses 3,944 (36.4%)
oig-leie · CMS
of barred providers (6,031 of 10,824) appear on only one of the three exclusion layers — no two-list check reaches them
exclusion-landscape · CMS
CMS civil money penalty records across 6,884 facilities at the July 14, 2026 audit cutoff sit in the compromised-but-operating layer — and, like the 127 active OIG integrity agreements, carry no NPI to match
cms-cmp · CMS

A provider barred from Medicare in one system is not necessarily barred everywhere a screener looks. The United States has no single master registry of excluded health-care providers. Instead it has a patchwork: the federal OIG List of Excluded Individuals and Entities (the LEIE), the government-wide SAM.gov debarment list run by the General Services Administration, and a Medicaid exclusion program in each state, every one of them maintained on its own authority and its own clock. This study assembles the exclusion sources observed in production on July 14, 2026 into one picture and asks the question a compliance officer actually has to answer: how many providers were barred somewhere — and how much did any single list miss?

The excluded-anywhere population, in one number

At the July 14 audit cutoff, 10,824 distinct providers with a National Provider Identifier were barred from a public health program across the three exclusion layers analyzed. That is the de-duplicated union of the federal OIG LEIE, the federal SAM.gov debarment list, and the 13 state Medicaid exclusion programs loaded in production, counting each provider once however many lists name them, and restricted to records that were in force and carried an NPI.

The number that matters next to it is what the single most complete list covers. The OIG LEIE — the list compliance programs treat as the federal master — names 6,880 of those 10,824, or 63.6%. Screen the LEIE alone and 3,944 barred providers, 36.4% of the excluded-anywhere population, return as having no exclusion on file. No single source names even two-thirds of the population on its own.

Count by source

Each list is large in records but smaller in NPI-identified providers, because most exclusion records carry no NPI at all. The table below reports each source at two grains: distinct in-force providers that carry an NPI (the matchable population), and the in-force records that carry no NPI (reported separately, never matched by name).

Exclusion sourceDistinct in-force NPIShare of the 10,824In-force records, no NPI
OIG LEIE — federal (HHS-OIG)6,88063.6%61,030
SAM.gov — federal debarment (GSA)4,69443.4%286,487
State Medicaid — 13 states4,94945.7%15,487
Excluded anywhere (NPI union)10,824100%363,004 records

The "excluded anywhere" row de-duplicates on NPI: 6,880 + 4,694 + 4,949 sums to 16,523, but the distinct union is 10,824, because thousands of providers appear on more than one list. The no-NPI column is a record count, not an entity count — those rows cannot be de-duplicated across lists because there is no identifier to join them on.

Overlap: how much each list misses

The three exclusion layers are complementary, not redundant. 6,031 of the 10,824 barred providers — 55.7% — appear on only one of the three, and just 906 appear on all three. A screener who checks two of the three lists still cannot reach the more than six thousand providers who sit on a single list.

A provider appears on…ProvidersShare of 10,824
Exactly one exclusion layer6,03155.7%
Two or more layers4,79344.3%
All three layers9068.4%

Broken out by which list carries the single-source-only providers, the state lists and the LEIE each hold a large block that no other source names:

Barred only on this listProviders
State Medicaid only2,997
OIG LEIE only2,278
SAM.gov only756

The pairwise overlaps show where the lists reinforce each other. The federal pair — LEIE and SAM.gov — agree most often, which is expected because SAM.gov ingests OIG exclusion actions as part of the government-wide debarment feed. The state lists overlap the federal lists far less.

Overlap (NPI on both)Providers
OIG LEIE ∩ SAM.gov3,747
OIG LEIE ∩ State Medicaid1,761
SAM.gov ∩ State Medicaid1,097
All three906

There is no master list. The most complete single source names 63.6% of barred providers; check it alone and you clear over a third of them as having nothing on file.

The state Medicaid layer

At the July 14 audit cutoff, 4,949 distinct NPI-identified providers were barred by one of the 13 analyzed state Medicaid programs, and that layer was the one federal-only screening missed most — it overlapped the federal lists less than the federal lists overlapped each other. As we documented in the federal–state exclusion gap study, most state-barred providers carried no matching federal LEIE record at all.

State (program)In-force NPI-identified
New York (OMIG)2,259
Pennsylvania (DHS Medicheck)973
Ohio (ODM)673
Iowa (Medicaid)313
Maryland (MDH)264
Washington (HCA)210
North Carolina (DHHS)149
Mississippi (DOM)138
New Hampshire (DHHS)51
North Dakota (HHS)47
Montana (DPHHS)42
Georgia (DCH-OIG)35
Tennessee (TennCare)9
Thirteen states (distinct)4,949
The per-state rows sum to 5,163, above the 4,949 distinct total, because 214 providers are barred by more than one state and are counted once in the union. Tennessee's 9 and Georgia's 35 reflect tiny NPI-identified samples — most of those states' records carry no NPI — not small programs, so they should be read as illustrative.

State Medicaid agencies act under their own authority and timeline. A state can bar a provider for a Medicaid-specific reason — a state license action, a fraud referral, an administrative termination — without a federal exclusion ever following. The OIG may adopt many of these under its permissive §1128(b) authority, but adoption is discretionary and lagged, which is why a large standing block of state bars never reaches the LEIE.

Compromised but operating: agreements and penalties

A separate layer marks providers under federal monitoring or penalty who are not excluded — still enrolled, still billing, but flagged. At the July 14 audit cutoff, the OIG Corporate Integrity Agreements and CMS civil money penalty sources contained 127 active agreements and 16,277 penalty records across 6,884 facilities. Neither source can be matched to the exclusion universe by NPI because neither carries one.

An OIG Corporate Integrity Agreement is a negotiated settlement under which an entity accepts years of compliance obligations in exchange for staying in the federal programs. There are 127 agreements in force out of 333 distinct entities in the file. The list is keyed to an entity name and a slug; it publishes no NPI.

A CMS civil money penalty is a fine or payment denial levied on a facility — most often a nursing home — short of termination. Production contained 16,277 such penalty records across 6,884 distinct facilities over its reporting window at the audit cutoff. The penalty file is keyed to a CMS certification number (CCN), the facility identifier; it, too, publishes no NPI.

Compromised-but-operating sourceIn-force / activeDistinct entitiesKeyNPI present
OIG Corporate Integrity Agreements127 agreements333entity namenone
CMS Civil Money Penalties (July 14 audit cutoff)16,277 penalty records6,884 facilitiesCCNnone

Because both sources are identifier-disjoint from the NPI-keyed exclusion lists, they are reported here as their own layer and are never joined to the 10,824-provider population. A facility under a civil money penalty or an entity under an integrity agreement is a different — and weaker — signal than an exclusion: it says the provider was penalized or is monitored, not that it is barred from billing.

The providers with no NPI at all

363,004 in-force exclusion records carry no NPI, and they are a screening problem of their own. The matchable population of 10,824 sits inside a far larger body of records: 286,487 no-NPI records on SAM.gov, 61,030 on the OIG LEIE, and 15,487 on the state Medicaid lists. The LEIE in particular carries an NPI on only about one record in ten, a limitation we examine in the OIG exclusion-list reference study.

These records name a barred party — by business name, by individual name, by a UEI on SAM.gov — with no identifier that maps to the other lists. Matching them across sources would require a name match, and a name match is not a defensible identity assertion, so Fonteum does not attempt one. They are held out of the matchable universe and counted only as records. The practical implication is blunt: NPI-based cross-list screening cannot reach these parties, so they compound the gap rather than shrink it.

What this means for screening compliance

No single list is a complete exclusion check, and the spread here puts a number on it: the most complete source, the OIG LEIE, names 63.6% of the NPI-identified barred population, and more than half of that population sits on only one of the three layers. The OIG's own guidance is that a billing organization or contractor must screen against all applicable exclusion lists — federal and the relevant state Medicaid lists — before submitting claims or contracting, and on an ongoing basis. Billing for or contracting an excluded party in a federally billable role carries civil monetary penalty exposure under a "knew or should have known" standard.

The constructive read is that the layers do something together that none does alone. At the July 14 cutoff, the LEIE was national but NPI-sparse and lagging; SAM.gov was government-wide but mostly entity-keyed; and the 13 loaded state lists were program-specific but jurisdictionally fragmented. Checked together, they closed gaps in each other. The production state table contained 22,917 source records across those 13 states. Fonteum exposes the federal OIG LEIE and state exclusion data through its supported lookup surfaces. It is a screening aid: re-confirm any match against the primary source before acting. An absence becomes a no-match only when serving coverage reconciles to the latest comparable artifact; otherwise it is indeterminate and is not a clearance.

Methodology

Every figure is a direct query against public, read-only production tables at a literal DATE '2026-07-14' cutoff: oig_leie_exclusions (the OIG monthly LEIE bulk download, release 2026-05-08, 68,055 records), sam_exclusions (323,930 active, in-force records at the cutoff), and state_exclusions (22,917 records across 13 state Medicaid programs). The prior 167,582 SAM figure counted rows missing exclusion_date; it was not the source universe. The compromised-but-operating layer reads oig_cia_agreements and cms_civil_money_penalties, both also public and read-only.

The join key throughout is the 10-digit NPI, trimmed of whitespace; a name is never used to assert a match. A LEIE or state record is treated as in force when its reinstatement date is null or later than the literal audit cutoff. A SAM record must also have status = 'Active', with a null or later termination date; an "Indefinite" term stores as null and stays in force. The matchable universe is the distinct set of in-force, NPI-identified providers across the three exclusion layers; per-source coverage is each source's distinct in-force NPI divided by that universe of 10,824; overlap is the count of the three layers a provider's NPI appears on. The compromised layer is read separately and never NPI-joined, because neither oig_cia_agreements (entity-name keyed) nor cms_civil_money_penalties (CCN keyed) carries an NPI. The exact SQL is in the reproducibility block below, and the provenance methodology documents the source-provenance contract. Methodology version: exclusion-landscape/v1.

Limitations

  • NPI is the floor, not the ceiling. 363,004 in-force exclusion records carry no NPI and are excluded from the 10,824-provider universe; they are reported as record counts and never matched by name. The true barred population is larger than 10,824.
  • The compromised layer is unmatchable by identifier. At the July 14 audit cutoff, OIG integrity agreements and CMS penalty records carried no NPI, so its 127 agreements and 16,277 penalty records could not be tied to the exclusion universe or to one another by NPI. They are a distinct, weaker signal reported on their own terms.
  • Thirteen states in this study, not fifty. The state Medicaid layer covers 13 programs. The 4,949 figure describes that 13-state production slice, not the nation.
  • Snapshot, not cumulative. Every list is point-in-time. The LEIE release, the SAM.gov extract, and each state file shift over time; these figures reflect the July 14, 2026 audit cutoff.
  • A compliance signal, aggregate-only. Exclusion and penalty counts are an enforcement and screening signal, never a measure of care quality. No individual barred party is named, surfaced, or attached to any provider profile in this study.

Sources

Frequently asked questions

How many providers are on a US healthcare exclusion list?
At the July 14, 2026 audit cutoff, 10,824 distinct providers with a National Provider Identifier were barred from a public health program across the federal OIG LEIE (6,880), the federal SAM.gov debarment list (4,694), and 13 state Medicaid programs (4,949), de-duplicated on NPI so a provider on multiple lists is counted once.
Does the OIG exclusion list contain every excluded provider?
No. The OIG LEIE is the most complete single list, but it names only 6,880 of the 10,824 NPI-identified barred providers — 63.6%. A federal-LEIE-only screen misses 3,944 providers, 36.4% of the excluded-anywhere population, who are barred by SAM.gov or a state Medicaid program without a matching federal LEIE record.
How much do exclusion lists overlap?
Less than you would expect. Of the 10,824 NPI-identified barred providers, 6,031 — 55.7% — appear on only one of the three exclusion layers, and just 906 appear on all three. The lists are complementary, not redundant: each names thousands of providers the others miss.
What is the difference between exclusion and a compromised-but-operating flag?
An exclusion bars a provider from billing federal health programs. A compromised flag — an OIG Corporate Integrity Agreement or a CMS civil money penalty — marks a provider under federal monitoring or penalty but still operating. At the July 14, 2026 audit cutoff, production held 127 active integrity agreements and 16,277 civil money penalty records across 6,884 facilities.
Why can't the compromised-but-operating layer be matched to the exclusion lists?
Because it carries no NPI. OIG Corporate Integrity Agreements are keyed to an entity name and the CMS civil money penalty file is keyed to a facility certification number (CCN); neither source publishes a National Provider Identifier. With no NPI, these records cannot be joined to the exclusion universe by identifier, so they are reported separately.
How many exclusion records have no NPI at all?
A large majority. Across the three exclusion layers, 363,004 in-force records carry no NPI: 286,487 on SAM.gov, 61,030 on the OIG LEIE, and 15,487 on the state Medicaid lists. These name a barred party with no identifier that maps to other lists, so NPI-based screening cannot reach them and they sit outside the 10,824 matchable population.
Which states are in the state Medicaid exclusion layer?
At the July 14, 2026 audit cutoff the layer covered 13 programs: New York (2,259 NPIs), Pennsylvania (973), Ohio (673), Iowa (313), Maryland (264), Washington (210), North Carolina (149), Mississippi (138), New Hampshire (51), North Dakota (47), Montana (42), Georgia (35), and Tennessee (9). The production table contains 22,917 source records across those 13 states.
Can I reproduce these figures?
Yes. Every count is a direct query against the public oig_leie_exclusions, sam_exclusions, and state_exclusions tables, joined on NPI only, with the compromised layer read from oig_cia_agreements and cms_civil_money_penalties. The exact SQL is published in the reproducibility block below, and no match is ever inferred from a name.

Who uses this data

The source data behind this study is public

Compliance teams, journalists, and researchers work from the same federal source families cited above — queried by NPI or facility identifier through Fonteum’s open dataset pages and API. Every figure traces to a frozen, downloadable snapshot you can reproduce yourself.

Datasets used

Reproducibility

Every claim, reproducible

The SQL
excluded-providers-landscape-2026.sql
-- The excluded-provider landscape — fully reproducible query.
--
-- Question: across every exclusion source Fonteum holds, how many providers
-- are barred somewhere, how does the population split by source, how much do
-- the lists overlap, and how much does any single list miss?
--
-- EXCLUSION layer (the matchable universe — joined on NPI):
--   public.oig_leie_exclusions — OIG List of Excluded Individuals/Entities,
--                                federal monthly bulk download, release
--                                2026-05-08, 68,055 records. Public, read-only.
--   public.sam_exclusions      — SAM.gov / GSA government-wide debarment list,
--                                323,930 active, in-force rows at the audit cutoff.
--   public.state_exclusions    — State Medicaid Exclusion Ring (13 states).
--                                Public, read-only.
--
-- Join key: NPI only (10-digit, btrim). A name match is not a defensible
-- identity assertion, so rows with no NPI are excluded from the matchable
-- universe and reported separately (see no-NPI query below).
--
-- "In force" mirrors the production exclusion lookup (src/lib/exclusions): a row
-- is in force when reinstatement_date IS NULL OR reinstatement_date > today
-- (for SAM.gov, the equivalent lapse signal is termination_date; "Indefinite"
-- stores as NULL and stays in force). Audit cutoff: DATE '2026-07-14'.
--
-- COMPROMISED-BUT-OPERATING layer (reported separately, NEVER NPI-joined —
-- neither source carries an NPI):
--   public.oig_cia_agreements        — OIG Corporate Integrity Agreements
--                                       (entity-name keyed).
--   public.cms_civil_money_penalties — CMS Civil Money Penalties (CCN keyed).
--
-- Every headline figure in the study resolves to one of the rows below.

-- audit-claim: exclusion-union-overlap
WITH leie AS (
  SELECT DISTINCT btrim(npi) AS npi FROM public.oig_leie_exclusions
  WHERE nullif(btrim(npi), '') IS NOT NULL
    AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')
),
sam AS (
  SELECT DISTINCT btrim(npi) AS npi FROM public.sam_exclusions
  WHERE nullif(btrim(npi), '') IS NOT NULL
    AND status = 'Active'
    AND (termination_date IS NULL OR termination_date > DATE '2026-07-14')
),
st AS (
  SELECT DISTINCT btrim(npi) AS npi FROM public.state_exclusions
  WHERE nullif(btrim(npi), '') IS NOT NULL
    AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')
),
all_npi AS (
  SELECT npi FROM leie UNION SELECT npi FROM sam UNION SELECT npi FROM st
),
flags AS (
  SELECT a.npi,
         (l.npi IS NOT NULL)::int AS in_leie,
         (s.npi IS NOT NULL)::int AS in_sam,
         (t.npi IS NOT NULL)::int AS in_state
  FROM all_npi a
  LEFT JOIN leie  l USING (npi)
  LEFT JOIN sam   s USING (npi)
  LEFT JOIN st    t USING (npi)
),
scored AS (
  SELECT *, (in_leie + in_sam + in_state) AS src_count FROM flags
)
SELECT
  (SELECT count(*) FROM all_npi)                                  AS excluded_anywhere,   -- 10,824
  (SELECT count(*) FROM scored WHERE src_count = 1)               AS on_exactly_one,       --  6,031 (55.7%)
  (SELECT count(*) FROM scored WHERE src_count >= 2)              AS on_two_or_more,       --  4,793 (44.3%)
  (SELECT count(*) FROM scored WHERE src_count = 3)               AS on_all_three,         --    906 ( 8.4%)
  (SELECT count(*) FROM scored WHERE in_leie  = 1)                AS leie_npi,             --  6,880 (63.6%)
  (SELECT count(*) FROM scored WHERE in_sam   = 1)                AS sam_npi,              --  4,694 (43.4%)
  (SELECT count(*) FROM scored WHERE in_state = 1)                AS state_npi,            --  4,949 (45.7%)
  (SELECT count(*) FROM scored WHERE src_count = 1 AND in_leie  = 1) AS leie_only,         --  2,278
  (SELECT count(*) FROM scored WHERE src_count = 1 AND in_sam   = 1) AS sam_only,          --    756
  (SELECT count(*) FROM scored WHERE src_count = 1 AND in_state = 1) AS state_only,        --  2,997
  (SELECT count(*) FROM scored WHERE in_leie = 1 AND in_sam   = 1) AS leie_and_sam,        --  3,747
  (SELECT count(*) FROM scored WHERE in_leie = 1 AND in_state = 1) AS leie_and_state,      --  1,761
  (SELECT count(*) FROM scored WHERE in_sam  = 1 AND in_state = 1) AS sam_and_state;       --  1,097
-- Coverage = source_npi / excluded_anywhere. Single most complete list (LEIE)
-- covers 6,880 / 10,824 = 63.6% → federal-LEIE-only screening misses 3,944 (36.4%).

-- audit-claim: in-force-source-vector
-- The no-NPI rows are excluded from the universe above and reported separately.
SELECT 'oig-leie' AS source,
       count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL
         AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_distinct_npi,
       count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL
         AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_no_npi
FROM public.oig_leie_exclusions
UNION ALL
SELECT 'sam-gov',
       count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL
         AND status = 'Active'
         AND (termination_date IS NULL OR termination_date > DATE '2026-07-14')),
       count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL
         AND status = 'Active'
         AND (termination_date IS NULL OR termination_date > DATE '2026-07-14'))
FROM public.sam_exclusions
UNION ALL
SELECT 'state-medicaid',
       count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL
         AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')),
       count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL
         AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14'))
FROM public.state_exclusions;
--  source          inforce_distinct_npi  inforce_no_npi
--  oig-leie               6,880              61,030
--  sam-gov                4,694             286,487
--  state-medicaid         4,949              15,487   (no-NPI records total: 363,004)

-- audit-claim: in-force-state-vector
SELECT source_key, state,
  count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL
    AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_distinct_npi
FROM public.state_exclusions
GROUP BY source_key, state
ORDER BY inforce_distinct_npi DESC;
--  ny-omig NY 2,259 | pa-dhs PA 973 | oh-odm OH 673 | ia-medicaid IA 313 | md-mdh MD 264
--  wa-hca WA 210 | nc-dhhs NC 149 | ms-dom MS 138 | nh-dhhs NH 51 | nd-hhs ND 47
--  mt-dphhs MT 42 | ga-dch GA 35 | tn-tenncare TN 9
--  Sum 5,163 vs distinct 4,949 → 214 providers barred by more than one state.

-- audit-claim: in-force-state-summary
WITH in_force AS (
  SELECT source_key, state, btrim(npi) AS npi
  FROM public.state_exclusions
  WHERE nullif(btrim(npi), '') IS NOT NULL
    AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')
), source_state AS (
  SELECT source_key, state, count(DISTINCT npi) AS distinct_npi
  FROM in_force
  GROUP BY source_key, state
), totals AS (
  SELECT
    (SELECT count(DISTINCT npi) FROM in_force) AS distinct_npi,
    sum(distinct_npi) AS source_state_row_sum
  FROM source_state
)
SELECT
  distinct_npi,
  source_state_row_sum,
  source_state_row_sum - distinct_npi AS cross_state_excess
FROM totals;

-- audit-claim: compromised-layer-vector
-- Both sources carry zero NPI (CIA = entity-name keyed; CMP = CCN keyed).
SELECT 'oig-cia' AS source,
       count(*) FILTER (WHERE closed_date IS NULL OR closed_date > DATE '2026-07-14') AS active,
       count(DISTINCT entity_name) AS distinct_entities,
       count(*) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL) AS with_npi
FROM public.oig_cia_agreements
UNION ALL
SELECT 'cms-cmp',
       count(*) AS active,
       count(DISTINCT ccn) AS distinct_entities,
       count(*) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL) AS with_npi
FROM public.cms_civil_money_penalties;
--  oig-cia   127 active agreements |   333 entities | 0 with NPI
--  cms-cmp  16,277 penalties       | 6,884 facilities | 0 with NPI

-- Source-universe totals are separate from the NPI-matchable universe. SAM is
-- counted with the same Active + termination-window semantics used above;
-- 167,582 is only the missing-exclusion-date subset, not the SAM universe.
-- audit-claim: raw-source-totals
SELECT 'oig-leie' AS source, count(*) AS records
FROM public.oig_leie_exclusions
UNION ALL
SELECT 'sam-gov-active', count(*) FILTER (
  WHERE status = 'Active'
    AND (termination_date IS NULL OR termination_date > DATE '2026-07-14')
)
FROM public.sam_exclusions
UNION ALL
SELECT 'state-medicaid', count(*)
FROM public.state_exclusions
ORDER BY source;
The snapshot
dataset_idoig-leie
snapshot_date2026-07-14
The JOINs
universe: distinct in-force NPI across oig_leie_exclusions ∪ sam_exclusions ∪ state_exclusions (13 states)
join key: btrim(npi), 10-digit, never a name match; no-NPI rows excluded from the universe and reported separately
in_force at DATE '2026-07-14': LEIE/state = reinstatement_date IS NULL OR later than cutoff; SAM = status Active and termination_date IS NULL OR later than cutoff
per-source coverage = distinct in-force NPI on that source ÷ excluded-anywhere total (10,824)
overlap = count of the three exclusion layers (LEIE, SAM, state) a provider's NPI appears on
compromised layer (oig_cia_agreements, cms_civil_money_penalties) carries zero NPI — reported separately, never NPI-joined
The pipeline version
methodology_versionexclusion-landscape/v1

Reproduce this

Run the exact query against the frozen 2026-07-14.

-- The excluded-provider landscape — fully reproducible query. -- -- Question: across every exclusion source Fonteum holds, how many providers -- are barred somewhere, how does the population split by source, how much do -- the lists overlap, and how much does any single list miss? -- -- EXCLUSION layer (the matchable universe — joined on NPI): -- public.oig_leie_exclusions — OIG List of Excluded Individuals/Entities, -- federal monthly bulk download, release -- 2026-05-08, 68,055 records. Public, read-only. -- public.sam_exclusions — SAM.gov / GSA government-wide debarment list, -- 323,930 active, in-force rows at the audit cutoff. -- public.state_exclusions — State Medicaid Exclusion Ring (13 states). -- Public, read-only. -- -- Join key: NPI only (10-digit, btrim). A name match is not a defensible -- identity assertion, so rows with no NPI are excluded from the matchable -- universe and reported separately (see no-NPI query below). -- -- "In force" mirrors the production exclusion lookup (src/lib/exclusions): a row -- is in force when reinstatement_date IS NULL OR reinstatement_date > today -- (for SAM.gov, the equivalent lapse signal is termination_date; "Indefinite" -- stores as NULL and stays in force). Audit cutoff: DATE '2026-07-14'. -- -- COMPROMISED-BUT-OPERATING layer (reported separately, NEVER NPI-joined — -- neither source carries an NPI): -- public.oig_cia_agreements — OIG Corporate Integrity Agreements -- (entity-name keyed). -- public.cms_civil_money_penalties — CMS Civil Money Penalties (CCN keyed). -- -- Every headline figure in the study resolves to one of the rows below. -- audit-claim: exclusion-union-overlap WITH leie AS ( SELECT DISTINCT btrim(npi) AS npi FROM public.oig_leie_exclusions WHERE nullif(btrim(npi), '') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14') ), sam AS ( SELECT DISTINCT btrim(npi) AS npi FROM public.sam_exclusions WHERE nullif(btrim(npi), '') IS NOT NULL AND status = 'Active' AND (termination_date IS NULL OR termination_date > DATE '2026-07-14') ), st AS ( SELECT DISTINCT btrim(npi) AS npi FROM public.state_exclusions WHERE nullif(btrim(npi), '') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14') ), all_npi AS ( SELECT npi FROM leie UNION SELECT npi FROM sam UNION SELECT npi FROM st ), flags AS ( SELECT a.npi, (l.npi IS NOT NULL)::int AS in_leie, (s.npi IS NOT NULL)::int AS in_sam, (t.npi IS NOT NULL)::int AS in_state FROM all_npi a LEFT JOIN leie l USING (npi) LEFT JOIN sam s USING (npi) LEFT JOIN st t USING (npi) ), scored AS ( SELECT *, (in_leie + in_sam + in_state) AS src_count FROM flags ) SELECT (SELECT count(*) FROM all_npi) AS excluded_anywhere, -- 10,824 (SELECT count(*) FROM scored WHERE src_count = 1) AS on_exactly_one, -- 6,031 (55.7%) (SELECT count(*) FROM scored WHERE src_count >= 2) AS on_two_or_more, -- 4,793 (44.3%) (SELECT count(*) FROM scored WHERE src_count = 3) AS on_all_three, -- 906 ( 8.4%) (SELECT count(*) FROM scored WHERE in_leie = 1) AS leie_npi, -- 6,880 (63.6%) (SELECT count(*) FROM scored WHERE in_sam = 1) AS sam_npi, -- 4,694 (43.4%) (SELECT count(*) FROM scored WHERE in_state = 1) AS state_npi, -- 4,949 (45.7%) (SELECT count(*) FROM scored WHERE src_count = 1 AND in_leie = 1) AS leie_only, -- 2,278 (SELECT count(*) FROM scored WHERE src_count = 1 AND in_sam = 1) AS sam_only, -- 756 (SELECT count(*) FROM scored WHERE src_count = 1 AND in_state = 1) AS state_only, -- 2,997 (SELECT count(*) FROM scored WHERE in_leie = 1 AND in_sam = 1) AS leie_and_sam, -- 3,747 (SELECT count(*) FROM scored WHERE in_leie = 1 AND in_state = 1) AS leie_and_state, -- 1,761 (SELECT count(*) FROM scored WHERE in_sam = 1 AND in_state = 1) AS sam_and_state; -- 1,097 -- Coverage = source_npi / excluded_anywhere. Single most complete list (LEIE) -- covers 6,880 / 10,824 = 63.6% → federal-LEIE-only screening misses 3,944 (36.4%). -- audit-claim: in-force-source-vector -- The no-NPI rows are excluded from the universe above and reported separately. SELECT 'oig-leie' AS source, count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_distinct_npi, count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_no_npi FROM public.oig_leie_exclusions UNION ALL SELECT 'sam-gov', count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL AND status = 'Active' AND (termination_date IS NULL OR termination_date > DATE '2026-07-14')), count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL AND status = 'Active' AND (termination_date IS NULL OR termination_date > DATE '2026-07-14')) FROM public.sam_exclusions UNION ALL SELECT 'state-medicaid', count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')), count(*) FILTER (WHERE nullif(btrim(npi),'') IS NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) FROM public.state_exclusions; -- source inforce_distinct_npi inforce_no_npi -- oig-leie 6,880 61,030 -- sam-gov 4,694 286,487 -- state-medicaid 4,949 15,487 (no-NPI records total: 363,004) -- audit-claim: in-force-state-vector SELECT source_key, state, count(DISTINCT btrim(npi)) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14')) AS inforce_distinct_npi FROM public.state_exclusions GROUP BY source_key, state ORDER BY inforce_distinct_npi DESC; -- ny-omig NY 2,259 | pa-dhs PA 973 | oh-odm OH 673 | ia-medicaid IA 313 | md-mdh MD 264 -- wa-hca WA 210 | nc-dhhs NC 149 | ms-dom MS 138 | nh-dhhs NH 51 | nd-hhs ND 47 -- mt-dphhs MT 42 | ga-dch GA 35 | tn-tenncare TN 9 -- Sum 5,163 vs distinct 4,949 → 214 providers barred by more than one state. -- audit-claim: in-force-state-summary WITH in_force AS ( SELECT source_key, state, btrim(npi) AS npi FROM public.state_exclusions WHERE nullif(btrim(npi), '') IS NOT NULL AND (reinstatement_date IS NULL OR reinstatement_date > DATE '2026-07-14') ), source_state AS ( SELECT source_key, state, count(DISTINCT npi) AS distinct_npi FROM in_force GROUP BY source_key, state ), totals AS ( SELECT (SELECT count(DISTINCT npi) FROM in_force) AS distinct_npi, sum(distinct_npi) AS source_state_row_sum FROM source_state ) SELECT distinct_npi, source_state_row_sum, source_state_row_sum - distinct_npi AS cross_state_excess FROM totals; -- audit-claim: compromised-layer-vector -- Both sources carry zero NPI (CIA = entity-name keyed; CMP = CCN keyed). SELECT 'oig-cia' AS source, count(*) FILTER (WHERE closed_date IS NULL OR closed_date > DATE '2026-07-14') AS active, count(DISTINCT entity_name) AS distinct_entities, count(*) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL) AS with_npi FROM public.oig_cia_agreements UNION ALL SELECT 'cms-cmp', count(*) AS active, count(DISTINCT ccn) AS distinct_entities, count(*) FILTER (WHERE nullif(btrim(npi),'') IS NOT NULL) AS with_npi FROM public.cms_civil_money_penalties; -- oig-cia 127 active agreements | 333 entities | 0 with NPI -- cms-cmp 16,277 penalties | 6,884 facilities | 0 with NPI -- Source-universe totals are separate from the NPI-matchable universe. SAM is -- counted with the same Active + termination-window semantics used above; -- 167,582 is only the missing-exclusion-date subset, not the SAM universe. -- audit-claim: raw-source-totals SELECT 'oig-leie' AS source, count(*) AS records FROM public.oig_leie_exclusions UNION ALL SELECT 'sam-gov-active', count(*) FILTER ( WHERE status = 'Active' AND (termination_date IS NULL OR termination_date > DATE '2026-07-14') ) FROM public.sam_exclusions UNION ALL SELECT 'state-medicaid', count(*) FROM public.state_exclusions ORDER BY source;

Download the data: SQL · JSON · CSV

Cite this study

Citation-ready for researchers and AI.

Fonteum Research Bureau (2026). OIG Exclusion Check: The 2026 Excluded-Provider Landscape. OIG LEIE, snapshot 2026-07-14. https://fonteum.com/research/excluded-providers-landscape-2026

Check the chain

The cited snapshot identifies the federal file. Where an attestation is present, its file hash can be re-derived; figures are not individually signed.

1
Snapshot
oig-leie · 2026-07-14
2
Supplied file hash
Not supplied
3
Snapshot attestation
Inspect supplied artifact
Figures are not individually signed · check it in Attest →

Federal source citations

  1. OIG LEIE · snapshot 2026-07-14 · federal source family · US-Government-Works

Fonteum LLC · June 15, 2026 · All figures trace to the frozen federal-data snapshot cited above.

What’s on file, by the numbers

Platform snapshot · 2026-07-30

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
78fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access