@pipeworx/tx-medical-exclusions
Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/tx-medical-exclusions’s. Install: one-click buttons
Connect to just the @pipeworx/tx-medical-exclusions pack
https://gateway.pipeworx.io/tx-medical-exclusions/mcp — only @pipeworx/tx-medical-exclusions’s own tools, nothing else in the catalog.
No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.
Tools: 2
Texas HHSC Office of Inspector General (OIG) Medicaid Provider Exclusions
Database screening — check a provider by name, NPI or license number against
the ~13,400-row list of providers ever excluded from Texas’s Medicaid
program, the state-level counterpart to the federal HHS OIG LEIE (leie
pack) and the sibling of ny-omig-exclusions (New York) and
ca-medical-exclusions (California).
Tools
tx_medical_check_exclusion(name?, npi?, license?, limit?)— screens a provider against the HHSC OIG Exclusions Database. An NPI or license match is an identification (both are exact, provider-specific identifiers); a name match — even an exact one — is a candidate lead only, since the list carries no date of birth and most individual rows have no company name to disambiguate same-named providers. Every match carries HHSC OIG’s own free-text reason and acurrently_excludedflag derived from whether the provider has since been reinstated.tx_medical_exclusion_coverage()— total exclusions ever recorded, how many are currently excluded vs. reinstated, how many carry an NPI or license number, occupation diversity, and the oldest/newest exclusion date.
Auth
Keyless.
Data sources
- https://oig.hhsc.state.tx.us/oigportal2/exclusions/ctl/dow/mid/384 — the HHSC OIG “Download Exclusions File” page. The downloadable file itself (CompanyName, LastName, FirstName, MidInitial, Occupation, LicenseNumber, NPI, StartDate, AddDate, ReinstatedDate, EligibleToReapplyDate, Waiver, WebComments) is fetched via an ASP.NET VIEWSTATE postback from this same URL — see “Why a VIEWSTATE postback” below.
- https://oig.hhsc.state.tx.us/oigportal2/Exclusions — the online “List of Excluded Individuals/Entities Search” (currently-excluded only; this pack’s data_as_of/source_url always points at the download file, not this page).
Why no open-data-portal mirror — checked, not assumed
California’s S&I list has a stable CKAN resource_id mirror on the CHHS Open
Data Portal. Texas does not have an equivalent for this dataset: a
Socrata catalog search of data.texas.gov
(api.us.socrata.com/api/catalog/v1?domains=data.texas.gov) for “OIG
exclusion”, “HHSC exclusion”, “excluded provider”, “inspector general” and
“Medicaid exclusion” (2026-10-08) returned zero matching datasets. The HHSC
OIG portal is the only source.
Why a VIEWSTATE postback, not a direct URL
The visible “Download TEXT version of the Exclusions Database File” link on
the HHSC OIG page is javascript:__doPostBack(...), not a plain href — a
classic ASP.NET WebForms (DotNetNuke) postback, the same shape as
reference_aspnet_postback_downloads.md / the louisiana-code precedent (a
VIEWSTATE form is not a wall). scripts/bake-index.mjs replays the flow: GET
the page, extract __VIEWSTATE/__VIEWSTATEGENERATOR/__EVENTVALIDATION
from the hidden inputs plus the session cookies, then POST those fields back
with __EVENTTARGET set to the download LinkButton’s control ID. The
response is the file itself (Content-Disposition: attachment;filename=TexasExclusionsData_<today>.txt) — the filename embeds
the request date, confirming HHSC generates this export live from its
database on every request, which is why this pack uses the capture timestamp
itself as data_as_of rather than scraping a separate “last updated” banner
(the page’s own literaldatelastupd placeholder span is empty on a fresh GET).
Why this is baked, not a live proxy
Per root CLAUDE.md’s standing rule for a table this size, the full list
(13,443 rows at capture time, ~4.6MB as generated TypeScript) is baked by
scripts/bake-index.mjs into src/tx-oig-index-data.ts, registered in
workers/gateway/src/pack-baked-indexes.json, uploaded to KV at deploy, and
injected into every call as args._bakedIndex — never a static module-scope
import (fleet #2754: six packs doing that put ~48MB of retained heap into
every gateway isolate and cost about one call in four as a Cloudflare 1102).
A missing or malformed injection throws loudly rather than answering
“not found” — see src/index.test.ts.
Re-run node mcps/tx-medical-exclusions/scripts/bake-index.mjs periodically
and recommit; data_as_of on every response says how stale the baked copy
is.
What this data includes — a real per-record reason field, verified live
The task that filed ca-medical-exclusions (#2805) assumed DHCS publishes a
per-record reason field that turned out not to exist. Checked this dataset
directly against all 13,443 live rows rather than taking HHSC’s column list
on faith: WebComments does carry real per-record reason text — e.g.
“Federal mandated exclusion” (2,105 rows), “License or Certification
revoked, suspended or otherwise terminated” (1,243), “Conviction relating to
Healthcare Fraud” (334). It is free text from decades of case entry, not a
controlled vocabulary — 1,847 distinct values over 13,443 rows, including
inconsistent casing and near-duplicate phrasings (“Board action” / “Board
Action” / “board action” all appear separately). Every response carries this
field as reason, with reason_field_caveat stating plainly that it is free
text, not a normalized statute/reason code.
Ever-excluded vs. currently-excluded
HHSC OIG’s own page says its online search returns only providers
currently excluded, while this download file holds everyone ever
excluded, including providers later reinstated — verified directly against
the data: 1,462 of 13,443 rows (2026-10-08 capture) carry a non-blank
ReinstatedDate. This pack keeps every row and derives currently_excluded
from whether reinstated_date is blank, labelled explicitly as derived
(HHSC does not publish that boolean itself) via ever_vs_current_caveat on
every response.
Matching
An npi query matches only exact 10-digit numeric NPI values (3 of the 600
NPI values in the source data are not well-formed 10-digit strings and are
surfaced as-is but never matched on). A license query matches the
LicenseNumber field, digits-only, leading zeros stripped — the same
comparison ny-omig-exclusions and ca-medical-exclusions use. Name
queries match against the provider’s assembled individual name
(last/first/middle initial) or company name, case/punctuation-insensitive.
Reachability
Verified live 2026-10-08 from both a laptop curl and a throwaway
wrangler dev --remote Worker on the prod account replaying the exact
GET-then-POST VIEWSTATE handshake: identical 200 / 1,837,673-byte file
attachment from the Cloudflare edge. Like ny-omig-exclusions and
ca-medical-exclusions, this host needs no Supabase egress relay.
Tools
- tx_medical_check_exclusion — Is this healthcare provider excluded from the Texas Medicaid program? Screens a person or business name, an NPI, and/or a license number against the Texas HHSC Office of Inspector General (OIG) Medica
- tx_medical_exclusion_coverage — What the Texas HHSC OIG Medicaid Provider Exclusions data covers and how current it is: total exclusions ever recorded, how many are currently excluded vs. reinstated, how many carry an NPI or license
Tools
tx_medical_check_exclusion— Is this healthcare provider excluded from the Texas Medicaid program? Screens a person or business name, an NPI, and/or a license number against the Texas HHSC Office of Inspector General (OIG) Medicatx_medical_exclusion_coverage— What the Texas HHSC OIG Medicaid Provider Exclusions data covers and how current it is: total exclusions ever recorded, how many are currently excluded vs. reinstated, how many carry an NPI or license