Harper OIG exclusion aggregator – API WHAT THIS IS A free, public search over US healthcare exclusion lists: the federal HHS OIG LEIE plus state Medicaid exclusion lists. No account, no API key, no rate card. Add .txt to any endpoint for compact plain text, or .json for JSON. THE ONE THING TO GET RIGHT These are potential name matches, not confirmed identities. Federal and state bulk files contain no Social Security Numbers, so a name match cannot establish that this is the same person. Confirm any match against the official source listed, and verify identity with HHS OIG at https://exclusions.oig.hhs.gov before acting. Absence of a match is NOT a clearance. Only some jurisdictions are covered, and https://oig.tryharper.app/api/coverage says exactly which. ENDPOINTS GET https://oig.tryharper.app/api/search?name= Optional: &state=<2-letter code or US> &type=individual|entity &include_inactive=true &health_care_only=true &location_state=<2-letter code> &excluded_from=YYYY-MM-DD &excluded_to=YYYY-MM-DD &require_npi=true &limit=<1-200> Add .txt for plain text: /api/search.txt?name=john+smith GET https://oig.tryharper.app/api/exclusion/[.txt|.json] One record, with its source and reinstatement status. GET https://oig.tryharper.app/api/coverage[.txt|.json] Every jurisdiction: ingested, broken, not yet ingested, or publishes no list at all – with the reason. Read this before drawing a conclusion. GET https://oig.tryharper.app/api/sources/[.txt|.json] One jurisdiction's source detail. GET https://oig.tryharper.app/api/recent[.txt|.json] Optional: &days=<1-365> &state=<2-letter code or US> &limit=<1-200> Records ADDED to this corpus recently. firstSeenAt is our ingest date, not the government's exclusion date – read exclusionDate for that, and compare corpusFirstSeenAt against the window before calling any of it new. POST https://oig.tryharper.app/api/subscribe {"email", "kind", "filter"?, "organization"?, "note"?} kind = feed_digest | coverage_alerts | product_interest A filter names a jurisdiction, never a person: this publishes no way to monitor an individual. Opt out: GET https://oig.tryharper.app/api/unsubscribe?email=
[&kind=] READING A RESULT status = currently_excluded listed now, not reinstated status = reinstated was excluded, has been reinstated – not current status = removed_from_list no longer in the source file, most often because the party was reinstated matchScore name similarity 0-1. NOT a probability that this is the same person. programScope = health_care an exclusion from a health care program programScope = government_wide a federal contracting debarment or sanction. NOT a health care exclusion. Do not report it as exclusion from Medicare or Medicaid. programScope = unclassified SAM.gov published no excluding agency, so neither reading can be asserted. About a quarter of this corpus is not a health care action. SAM.gov carries every federal agency's debarments – 41,712 of them OFAC sanctions – because 42 CFR 455.436 requires state Medicaid agencies to check it. Read programScope before characterising any result, or pass health_care_only=true. FOR AGENTS These URLs are a stable contract and are safe to construct directly. An MCP connector is also available at https://oig.tryharper.app/mcp, though it is not required – fetching the URLs above works from any assistant with no setup. Setup for Claude, ChatGPT, Cursor and other MCP clients: https://oig.tryharper.app/connect OpenAPI spec: https://oig.tryharper.app/openapi.json RATE LIMITS 240 requests per minute per IP, on /api and on /mcp alike. Every response carries where you stand, so a client can pace itself rather than discovering the limit by being refused: X-RateLimit-Limit requests allowed in the current window X-RateLimit-Remaining requests left in it X-RateLimit-Reset unix seconds when the window rolls over A refusal is HTTP 429 with Retry-After, and changes nothing else about the request - retrying after the reset works. One caveat if you reach us through a hosted assistant. A ChatGPT or Claude connector calls this server from the provider's own infrastructure, not from your machine, and those outbound calls come from a small published range of addresses. So you share this bucket with everyone else using that assistant, and an unauthenticated endpoint has no way to tell you apart. Running the MCP server from a local client - Claude Code, Codex, Hermes, Cursor - gives you your own address and your own allowance. Need a higher allowance, a bulk export, or notice before these limits change? Email prathik@tryharper.app and say roughly what you are building. SOURCES AND METHOD https://oig.tryharper.app/methodology