Skip to content
FonteumPublic-records evidence

← NSA Compliance Leaderboard

NSA Compliance Methodology

Version: nsa-compliance/v1 · Effective: Q1 2022 (NSA effective date)

Statutory Basis

The No Surprises Act (NSA), enacted as Division BB of the Consolidated Appropriations Act of 2021 (Pub. L. 116-260), prohibits surprise billing effective January 1, 2022. The Act is implemented through three sets of federal regulations:

  • 29 CFR §2590.716 — Department of Labor (DOL): group health plans and health insurance issuers in the group market
  • 45 CFR §149.140 — Department of Health and Human Services (HHS): health insurance issuers in the individual and group markets
  • 26 CFR §54.9816 — Department of the Treasury / IRS: self-insured group health plans

CMS enforces the NSA's Independent Dispute Resolution (IDR) process and the machine-readable file (MRF) transparency mandate. Both enforcement data streams are published as federal public domain (US-Government-Works) via data.cms.gov.

Provider-Side: IDR Filing Rate Score

Methodology version: nsa-idr/v1

CMS publishes quarterly IDR data aggregated by initiating party NPI. The IDR filing rate per 1,000 claims is a proxy for the frequency of billing disputes initiated by or against a provider.

idr_rate_score = 1 − clamp(avg_idr_per_1k_claims / 50, 0, 1)
  • Ceiling: 50 IDR filings per 1,000 claims → score = 0 (maximum dispute frequency)
  • 0 IDR filings per 1,000 claims → score = 1.0 (no disputes in period)
  • Entities with fewer than 50 NPIs: insufficient sample — score reported as null
  • CMS suppression sentinels ("*", "DS") treated as null, excluded from rate average

Source: CMS IDR data, data.cms.gov/provider-data. Federal public domain.

Payer-Side: MRF Compliance Score

Methodology version: nsa-mrf/v1

Under NSA §2799B-6 and 45 CFR §149.140, health insurance issuers must publish machine-readable files (MRFs) containing in-network rates and out-of-network allowed amounts. CMS publishes a quarterly non-compliant issuer list identifying issuers that have failed to meet MRF publication requirements.

mrf_compliance_score = (# compliant issuers) / (# issuers with known status)
  • Score = 1.0: all tracked issuers in compliance
  • Score = 0.0: all tracked issuers non-compliant
  • Issuers with unknown compliance status (null) excluded from denominator

Source: CMS MRF non-compliant issuer list (quarterly PDF → structured). Federal public domain.

Composite Score

Methodology version: nsa-compliance/v1

  • Provider entities: composite = idr_rate_score (MRF not applicable)
  • Payer entities: composite = mrf_compliance_score (IDR rate not applicable)
  • Mixed entities (both available): composite = simple average of both scores

Grades: A (≥90%) · B (≥75%) · C (≥60%) · D (≥45%) · F (<45%) · insufficient sample

Limitations

  • IDR filing data is aggregate at the NPI level and does not reflect individual dispute outcomes or clinical appropriateness.
  • Absence from the CMS non-compliant issuer list does not guarantee full MRF compliance — CMS audit coverage is periodic, not continuous.
  • State-level breakdowns reflect the NPI billing state or issuer domicile, not necessarily the patient encounter state.
  • This index is a research and transparency tool. It is not a legal determination of NSA compliance status.
  • Data freshness: quarterly. Current issuance reflects the most recent CMS publication available at the time of the last cron run.

Data Access

  • Leaderboard dashboard — latest issuance, all entities, with CSV download (SHA-256 in response header) once the first issuance is published.

Fonteum · https://fonteum.com · License: CC-BY-4.0 · Source data: US-Government-Works

What’s on file, by the numbers

Platform snapshot · 2026-08-29

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
19fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access